Cyber attack on NHS affects more than 100,000 users

Unauthorised access to NHS user data through compromised credentials of a doctor resulted in at least more than 100,000 victims.

Cyber attack on NHS affects more than 100,000 users

Cyber attack on NHS affects more than 100,000 users

A computer attack on the National Health Service (NHS) compromised personal data of more than one hundred thousand users. Intruders used access credentials of a healthcare professional to enter the systems. The National Cybersecurity Centre (NCSC) received an alert about the case on 21 May.

According to Correio da Manhã, the NCSC is working with the Shared Services of the Ministry of Health (SSMS) and with the Judicial Police (JP) to analyse the incident. The national cyber incident response team, CERT.PT, has been monitoring the situation in coordination with the entities managing the systems and with the security forces.

The SSMS has already proceeded with the deactivation of the accounts linked to the attack, which made it possible to control the situation. The NCSC and the JP continue to gather information and carry out forensic analyses to identify how the systems were invaded.

On 25 May, the JP disclosed that the incident affected more than one hundred thousand people. José Ribeiro, head of the JP's cybercrime unit, indicated at a press conference that the attackers gathered a large quantity of information in a few days — a volume which, until recently, would have taken three months to obtain. Given this, the JP does not rule out the use of artificial intelligence in the attack.

The victims are distributed throughout the country, including the autonomous regions. Ribeiro also corrected initial information that pointed to a particular focus on data of children and minors, considering that interpretation hasty.

Users do not have means to protect their information individually, as management of the platform is the responsibility of the SSMS. The credentials used improperly were blocked, the data leak was halted and equipment was collected for examination. Supplementary security measures are being implemented.

The case became public following complaints from users on social media about alerts of access to their clinical records through NHS 24, with complaints being filed with various entities in the health sector.

Source: Correio da Manhã

Read this article in the original language