Globe2 ransomware blamed for Lincolnshire NHS trust cyber attack

clock
Globe2 ransomware blamed for Lincolnshire NHS trust cyber attack

As suspected, Northern Lincolnshire and Goole NHS Foundation Trust finally admits that ransomware took its systems down in October

The cyber attack on a NHS trust in Lincolnshire that led to operations being cancelled for four days in October has been attributed to a ransomware outbreak.

In a statement circulated today, Northern Lincolnshire and Goole NHS Foundation Trust finally revealed the source of the outbreak, which led the organisation to shut down almost all the organisation's IT systems, and to cancel all operations for several days until the outbreak was contained and dealt with.

"The cyber attack experienced by Northern Lincolnshire and Goole NHS Foundation Trust in October 2016 was a variant of ransomware called Globe2," Pam Clipson, director of strategy and planning at Northern Lincolnshire and Goole NHS Foundation Trust, told Computing.

Clipson then explained how the Trust sought to tackle the outbreak: "Our teams took immediate action upon detection of the attack, minimising its impact. The Trust took the decision to halt routine appointments in order to ensure patient safety while we eradicated the issue.

"Any potentially encrypted servers were checked and cleansed both prior to switching off and before returning to ‘live' status. The majority of our systems were up and running again within 48 hours. A total of just over 2,800 patient appointments were cancelled as a result of the disruption.

"We liaised with an external cyber security company and the police to ensure our response to the incident was as rigorous as possible.

"As the police regional cyber crime unit's investigation is still in progress, it could be prejudicial to publish any further detail about the case, including the exact details of how the perpetrator gained access."

Reports in the press had suggested that the source of the outbreak was an infected USB stick, but Clipson denied this.

"We can confirm that recent publicly reported information alleging that access was gained through a USB stick or due to remote working have no grounding in fact. We can assure our patients and other stakeholders that we acted swiftly to enhance our existing cyber security but in order to maintain security and support the police investigation, we are unable to share specific information at this time on the exact steps we have taken."

Northern Lincolnshire and Goole NHS Foundation Trust wasn't the first organisation in the county to suffer from a ransomware outbreak. In January, Lincolnshire County Council was targeted in an attack that its CIO Judith Hethington Smith claimed could have cost it more than £1m in ransoms, if it hadn't taken its IT systems offline.

The action effectively shut the Council down for almost a week.

More on Security

Is it time for open source to be treated as a public good?

Is it time for open source to be treated as a public good?

Open source is everywhere, including critical infrastructure. Should governments be playing more of a role in its governance?

John Leonard
clock 21 January 2022 • 6 min read
International police operation closes VPN service favoured by ransomware gangs

VPN service favoured by ransomware gangs closed in international police operation

15 VPNLab servers shut down in ten different countries in Europol-coordinated action

John Leonard
clock 19 January 2022 • 2 min read
Industry Voice: Digital transformation: Leaders need to form the new tech landscape carefully

Industry Voice: Digital transformation: Leaders need to form the new tech landscape carefully

Intel
clock 12 January 2022 • 3 min read