The National Cyber Security Centre (NCSC) last year released specific advice on how healthcare organizations should defend themselves against cyber-attacks in light of the increased digital traffic associated with the COVID-19 pandemic. The advisory, which was jointly written with the US Cybersecurity and Infrastructure Security Agency (CISA), highlights the need for advanced security measures as advanced persistent threat (APT) groups target healthcare and essential services involved in national and international COVID-19 responses.
The report identifies the key methods APTs use to perform COVID-19-related cyber-attacks, predominantly highlighting the vulnerability of pharmaceutical and research organizations and other entities with access to sensitive COVID-19 data, particularly through malicious campaigns known as password spraying. The advisory also lays out some suggestions of how healthcare organizations could mitigate these threats. These seek to minimize the risk of password compromising attacks by enforcing stricter institutional password security through, for instance, comprehensive security software, password screening and adding multi-factor authentication (MFA) to login credentials.
Since the beginning of the pandemic, there has been a slew of attacks by cyber-criminals exploiting the amplified sense of uncertainty and fear associated with the disease. The reasons for these attacks have run the gamut: commercial gain, espionage, poaching bulk personal information, response manipulation through misinformation and theft of intellectual property, to name a few. Given the primacy of the pandemic, cyber-criminals will likely be interested in gathering COVID-19-specific information, leaving organizations such as the NHS, integral to the pandemic response, particularly vulnerable to attack.
Password Spraying
One particularly effective and much used line of attack has been through password spraying. Password spraying is the process in which cyber-attackers use a list of commonly used passwords to try and infiltrate end user accounts. Once one account has been successfully hacked, attackers are able to access linked accounts where certain credentials are shared or attempt to infiltrate other users accounts laterally, creating a knock-on compromising effect.
Password spraying is particularly effective in large-scale organizations as there is a high chance that, within a large set of accounts, some users will use predictable, easy-to-crack passwords. In a recent research study, NCSC found that 75% of participating organizations had accounts using the 1000 most commonly-found passwords amongst their ranks.
This position is also reflected in the case of the Greater Manchester West Mental Health NHS Foundation Trust, which took the initiative against potential threats of cyber-attack even before the pandemic by implementing a Breached Password Protection solution which enabled the NHS Trust to block weak passwords for Cyber Essentials Plus accreditation, while enjoying the added benefit of multiple policies and clear end user feedback. Head of ICT Andre de Araujo, who was in charge of the move, highlighted the vulnerable position the Trust was in going into the change: We ran a script to look for hashes that could be cracked. We had hundreds of users with passwords that included the day of the week, month or even the word password, often with a number at the end or an exclamation point. It was interesting to see how many people follow the same patterns, resulting in easy-to-guess passwords.
Threat Mitigation
A key recommendation given by the NCSC to protect against password spraying is to ensure that there is good institutional policy in place to mitigate the threat of infiltration. Although suggesting available pragmatic guidance to employees on how to choose good, secure passwords, there is a strong emphasis on the implementation of security frameworks that block the adoption of high-probability passwords in the first place, as well as offering up solutions such as MFA and protective monitoring software.
These policy frameworks may include disallowed lists, such as the pwned password list collated by the NCSC which is integrated into the Specops Password Policy, password expiration or the implementation of passphrases, which are proven to be more resilient against brute force spraying attacks.
Speaking on the significance of shoring up healthcare organizations against attack, Paul Chichester, director of operations of NCSC, noted the importance of a collaborative cybersecurity effort against APT actors and malicious cyber-actors: Protecting the healthcare sector is the NCSCs first and foremost priority at this time, and were working closely with the NHS to keep their systems safe. By prioritizing any requests for support from health organizations and remaining in close contact with industries involved in the coronavirus response, we can inform them of any malicious activity and take the necessary steps to help them defend against it. However, we cant do this alone, and we recommend healthcare policy makers and researchers take our actionable steps to defend themselves from password spraying campaigns.
Specops Software is working with multiple NHS Trusts and Healthcare organizations to strengthen their cyber-defense and requirements for achieving Cyber Essentials accreditation. Through world class password security and user authentication solutions, Specops solutions and support reduce costs for the IT department, burden on the helpdesk and ensure your first line of defense is protected against the growing threat of cyber-attack.
Specops is currently offering a FREE solution to identify password vulnerabilities in Active Directory, which is an essential first step in your situational analysis against topics discussed in this article.
Read more:
#COVID19, Password Spraying and the NHS - Infosecurity Magazine
- Coronavirus Scam Alert: Watch Out For These Risky COVID-19 Websites And Emails - Forbes [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID19: Broome County Executive expected to sign executive orders on virus - WBNG-TV [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Houston-based company ready to test COVID-19 'vaccine candidate,' but doesn't have the funds - KHOU.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID19 Mesa County Public Health [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Coronavirus Disease 2019 (COVID-19) | SCDHEC [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Coronavirus disease 2019 - Wikipedia [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Hackers are jumping on the COVID-19 pandemic to spread malware - TechCrunch [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID-19 can last a few days on surfaces, according to new experiment findings - ABC News [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- The Guardian view on the UKs Covid-19 response: confused and hesitant - The Guardian [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- The COVID-19 Coronavirus Pandemic Highlights The Importance Of Scientific Expertise - Forbes [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- WHO Expert: Aggressive Action Against Coronavirus Cuts Down On Spread : Goats and Soda - NPR [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- 2 new cases of COVID-19 at Chicago schools - WGN TV Chicago [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Will Gargling with Salt Water or Vinegar 'Eliminate' the COVID-19 Coronavirus? - Snopes.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Worried about dying from COVID-19? You might be a millennial | TheHill - The Hill [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Startups developing tech to combat COVID-19 urged to apply for fast-track EU funding - TechCrunch [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Why do dozens of diseases wax and wane with the seasonsand will COVID-19? - Science Magazine [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- WHO, UN Foundation and partners launch first-of-its-kind COVID-19 Solidarity Response Fund - World Health Organization [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Covid-19: PM to address nation tonight - New Straits Times [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID-19: Where every sport lies after mass disruption - RTE.ie [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID-19: Facts, myths and hypotheses | TheHill - The Hill [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Hong Kong Has Largely Survived COVID-19. Can New York and The US Do It Too? - BuzzFeed News [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- UPDATE: Case of COVID-19 confirmed in Wilson County - WITN [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Is This Train Car Carrying 'COVID-19'? - Snopes.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Coronavirus pandemic: facts, updates and what to do about COVID-19 - The Verge [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- DHS: 34 people test positive for COVID-19 in Wisconsin - WBAY [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- COVID-19 by the numbers; plus key resources to help you stay informed - Berkeleyside [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- The Covid-19 puzzles that scientists are still trying to answer - The Guardian [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- What's the COVID-19 end game? - The San Diego Union-Tribune [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- The Covid-19 coronavirus is not the flu. Its worse. - Vox.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Phones Could Track the Spread of Covid-19. Is It a Good Idea? - WIRED [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- NIH Reports First Known Employee with COVID-19 Infection - National Institutes of Health [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Newborn tests positive for COVID-19 in London - Livescience.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Covid-19: Malaysia's pandemic action plan activated for the coronavirus - The Star Online [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- How Bad Will The COVID-19 Coronavirus Epidemic Get In The U.S.? Health Experts Weigh In - Forbes [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- Can People Who Recover from COVID-19 Become Reinfected? - Snopes.com [Last Updated On: March 16th, 2020] [Originally Added On: March 16th, 2020]
- THE LATEST: 41 test positive for COVID-19 in the state - WFSB [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Twelve new cases of COVID-19 announced in Illinois; bringing total to 105 - KWQC-TV6 [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Eagle County outlines shift for COVID-19 testing, Vail Health shifts operations - Vail Daily News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- 7th positive COVID-19 case announced in Hawaii, all cases related to travel - KHON2 [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Canada tightens borders over coronavirus will it curb COVID-19s spread? - Global News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- As health care workers prepare for COVID-19, medical students pitch in on the homefront - Minnesota Public Radio News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coronavirus First positive case of COVID-19 confirmed in Geauga County Kaylyn Hlavaty 7:58 AM - News 5 Cleveland [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- 2nd presumptive case of COVID 19 reported in Bell County - KWTX [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- New confirmed cases of COVID-19 in Wisconsin - WKOW [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Hawaii National Guard ready to step in against spread of COVID-19 - KHON2 [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Alberta orders all classes cancelled, daycares closed as COVID-19 cases rise to 56 in the province - Global News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Has Italy Stopped Treating the Elderly in the COVID-19 Pandemic? - Snopes.com [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coronavirus testing: Information on COVID-19 tests according to state health departments - NBCNews.com [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Working from home because of COVID-19? Here are 10 ways to spend your time - Science Magazine [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Two positive COVID-19 cases announced in Fairbanks, bringing Alaska's confirmed total to 3 - Anchorage Daily News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- 8 more positive cases of COVID-19 brings Michigan total to 33 - FOX 2 Detroit [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- COVID-19: Who Is Infectious? - Forbes [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- The Guardian view on the latest Covid-19 steps: a recipe for isolation - The Guardian [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Government publishes updated COVID-19 industry guidance - GOV.UK [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- NIH clinical trial of investigational vaccine for COVID-19 begins - National Institutes of Health [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Expanding Colorado's COVID-19 Testing Capacity Proves Frustrating to Polis, Doctors And The Public - Colorado Public Radio [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Microsoft Bing launches interactive COVID-19 map to provide pandemic news - The Verge [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coronavirus tips: How to slow the spread of COVID-19 with hand-washing, social distance - USA TODAY [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- See Which Countries are Flattening their COVID-19 Curve - Visual Capitalist [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- With launch of COVID-19 data hub, the White House issues a call to action for AI researchers - TechCrunch [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- COVID-19 - Cabinet for Health and Family Services [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coronavirus Disease 2019 (COVID-19) | AustinTexas.gov [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- First COVID-19 case in Waterbury is confirmed - Waterbury Republican American [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Covid-19 reveals the alarming truth that many children cant wash their hands at school - The Guardian [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Statement on COVID-19 Panel Discussion Notes That Were Attributed to UCSF - UCSF News Services [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Covid-19 coronavirus testing in the US has been absurdly sluggish. That puts us at risk. - Vox.com [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Regal is closing all theaters until further notice over COVID-19 fears - TechCrunch [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Amazon limiting shipments to certain types of products due to COVID-19 pandemic - TechCrunch [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coralville company to produce millions of kits to test for COVID-19 - KCRG [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Number of COVID-19 cases in Erie County rises to 11, new case confirmed in Wyoming County - WIVB.com - News 4 [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Coronavirus tips and symptoms: What everyone should know about getting the new coronavirus - Vox.com [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Tech giants are getting creative to manage the COVID-19 crisis - The Verge [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- COVID-19: Mental health in the age of coronavirus - UN News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- White House provides an update on COVID-19 testing in the U.S., says theres been a dramatic ramp - TechCrunch [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Covid-19: How long does the coronavirus last on surfaces? - BBC News [Last Updated On: March 17th, 2020] [Originally Added On: March 17th, 2020]
- Hospital in Boston will be converted into Covid-19 treatment center - STAT [Last Updated On: March 18th, 2020] [Originally Added On: March 18th, 2020]
- 78 cases of COVID-19 confirmed in Tennessee - NewsChannel5.com [Last Updated On: March 18th, 2020] [Originally Added On: March 18th, 2020]
- COVID 19: Tennessee confirmed cases reaches 52, Dept of Health releases age ranges of those infected - Clarksville Now [Last Updated On: March 18th, 2020] [Originally Added On: March 18th, 2020]
- Housing associations under pressure to offer Covid-19 rent holidays - The Guardian [Last Updated On: March 18th, 2020] [Originally Added On: March 18th, 2020]
- Sacramento woman dead from COVID-19 attended church with others who have virus - KCRA Sacramento [Last Updated On: March 18th, 2020] [Originally Added On: March 18th, 2020]