Globe2 ransomware blamed for Lincolnshire NHS trust cyber attack

clock • 2 min read

As suspected, Northern Lincolnshire and Goole NHS Foundation Trust finally admits that ransomware took its systems down in October

The cyber attack on a NHS trust in Lincolnshire that led to operations being cancelled for four days in October has been attributed to a ransomware outbreak.

In a statement circulated today, Northern Lincolnshire and Goole NHS Foundation Trust finally revealed the source of the outbreak, which led the organisation to shut down almost all the organisation's IT systems, and to cancel all operations for several days until the outbreak was contained and dealt with.

"The cyber attack experienced by Northern Lincolnshire and Goole NHS Foundation Trust in October 2016 was a variant of ransomware called Globe2," Pam Clipson, director of strategy and planning at Northern Lincolnshire and Goole NHS Foundation Trust, told Computing.

Clipson then explained how the Trust sought to tackle the outbreak: "Our teams took immediate action upon detection of the attack, minimising its impact. The Trust took the decision to halt routine appointments in order to ensure patient safety while we eradicated the issue.

"Any potentially encrypted servers were checked and cleansed both prior to switching off and before returning to ‘live' status. The majority of our systems were up and running again within 48 hours. A total of just over 2,800 patient appointments were cancelled as a result of the disruption.

"We liaised with an external cyber security company and the police to ensure our response to the incident was as rigorous as possible.

"As the police regional cyber crime unit's investigation is still in progress, it could be prejudicial to publish any further detail about the case, including the exact details of how the perpetrator gained access."

Reports in the press had suggested that the source of the outbreak was an infected USB stick, but Clipson denied this.

"We can confirm that recent publicly reported information alleging that access was gained through a USB stick or due to remote working have no grounding in fact. We can assure our patients and other stakeholders that we acted swiftly to enhance our existing cyber security but in order to maintain security and support the police investigation, we are unable to share specific information at this time on the exact steps we have taken."

Northern Lincolnshire and Goole NHS Foundation Trust wasn't the first organisation in the county to suffer from a ransomware outbreak. In January, Lincolnshire County Council was targeted in an attack that its CIO Judith Hethington Smith claimed could have cost it more than £1m in ransoms, if it hadn't taken its IT systems offline.

The action effectively shut the Council down for almost a week.

You may also like
Concerns about data compromise after NHS Dumfries and Galloway attack

Hacking

Scottish Health Secretary says disruption to services is 'minimal'

clock 20 March 2024 • 2 min read
University CIO: 'We were owned in 4 hours'

Threats and Risks

And that certainly focused minds, says Salford University’s Mark Wantling

clock 20 March 2024 • 5 min read
NHS England reinstates open source Github page used to maintain central database of GP data

Health

GP Connect page taken down, then reinstated, over 'inaccurate' patient record database claim

clock 19 March 2024 • 3 min read

More on Security

Asian Tech Roundup: Failure at Fujitsu

Asian Tech Roundup: Failure at Fujitsu

Plus, China cracks knuckles

Tom Allen
clock 22 March 2024 • 2 min read
Epic Games hacker isn't a hacker, at all

Epic Games hacker isn't a hacker, at all

Describe themselves as 'criminal geniuses'

Tom Allen
clock 05 March 2024 • 2 min read
IT Essentials: LockBit and load

IT Essentials: LockBit and load

They fought the law, and the law won - for now

Tom Allen
clock 26 February 2024 • 2 min read