back to article UK hospital meltdown after ransomware worm uses NSA vuln to raid IT

UK hospitals have effectively shut down and are turning away non-emergency patients after ransomware ransacked its networks. Some 16 NHS organizations across Blighty – including several hospital trusts such as NHS Mid-Essex CCG and East and North Hertfordshire – have had their files scrambled by a variant of the WannaCrypt, …

Page:

      1. alain williams Silver badge

        Re: Using Windows?

        We use Windows PCs because a lot of the dedicated software we use won't run on anything else.

        Aw, come on! The NHS is a large enough customer that if they wanted it on a Linux or BSD system the supplier would do the port.

        1. MisterHappy

          Re: Using Windows?

          With few exceptions the NHS is not a single large organisation, it is made up of lots and lots of Trusts & surgeries that are all responsible for their own IT systems.

          1. Pen-y-gors

            Re: Using Windows?

            @MisterHappy

            "With few exceptions the NHS is not a single large organisation, it is made up of lots and lots of Trusts & surgeries that are all responsible for their own IT systems."

            Remind me again, how did such an odd and inefficient system come to pass?

            1. MisterHappy

              Re: Using Windows?

              Someone in government decided that it would 'save money' to make each and every Trust/Surgery/Dentist etc responsible for their own budgets. There are a few NHS purchasing consortia but this is typically for consumables & not IT systems.

            2. Tom Paine

              Re: Using Windows?

              That's more or less how it's always been since 1947.

            3. AlbertH

              Re: Using Windows?

              Remind me again, how did such an odd and inefficient system come to pass?

              A clue for you..... The NHS began in 1948. Who was in government in 1948?

              Most NHS computer systems were installed in the early 2000s..... Who was in government in 2000...?

              Who got a nice house bought for him in Eaton Square SW1 by Bill Gates? Clue: He was Prime Minister in 2001......

              1. InNY

                Re: Using Windows?

                Re: Using Windows?

                what a load of bollocks.

                The NHS was created by popular demand after the 2nd World War because the men and women who went to war, to defend the free democracies, didn't want to return to a system that punished them for being poor or "just about managing". They wanted a society where equality in the provision of society's services was equal for everyone. - do your homework - look up the Beveridge Report 1942

                Most NHS systems were not installed in 2000. They were installed well before - they were extended in the late 1990's so that patients and those providing the required services could do efficiently and safely. The installation of IT services within the NHS was, and continues to be, a model of efficiency and effectiveness. That the service has been downgraded since 2010 is not the fault of the government in power in 2001.

                Microsoft Windows was/is used for the exact same reason that nearly every governmental organization in the world uses it. Because it was available; relatively cheap; easy to use; easy to install; there were/are plenty of people skilled in its various technicalities and it does the job exceedingly well.

                Who the f* cares who bought whom a house in a posh bit of London? Apart form which, where on earth did you dig that up from? Perhaps you could provide a valid link for the report? I've looked an can't find it. I look forward to enlightening us.

                Now, sod off and on your way admire the sheer grit, determination and marvel at the amazing skills of the NHS IT staff as they do all they can to remediate a catastrophic mess for which they can carry no blame.

                If you really want know who's responsible look towards the cheapskate management and chap who's name rhymes with c*nt...

          2. Alan Ferris

            Re: Using Windows?

            I can only speak for England, but you the taxpayer provide ALL GPs with computers and software. And it's all Windows based. I get no choice over hardware, clinical software or even antivirus. And the electronic booking system is only compatible with Internet Explorer... and not even the most recent versions.

            We are all doomed

        2. John 110

          Re: Using Windows?

          "Aw, come on! The NHS is a large enough customer that if they wanted it on a Linux or BSD system the supplier would do the port."

          The NHS is, but bits of the NHS aren't, software running microtitre plate readers for Lab tests is quite specialized and there just aren't that many labs in the NHS in the UK. It took us forever to get a version that would run under Windows 7.

          I think you'll find that replicated across many machines and services.

    1. Big Z

      Re: Using Windows?

      Windows can be secured from running rogue .exes, most Malware is JavaScript based, or macro based, and Sophos' 2017 malware forecast report stated they have seen significant (albeit still low) increases on Linux based ransomware attacks over the past 18 months. It essentially comes down to poor security implementation and practices (the IoT devices used in botnets are running Linux), and poor user education.

      1. Tom Paine

        Re: Using Windows?

        Windows can be secured from running rogue .exes, most Malware is JavaScript based, or macro based [...]

        Bollocks. Sorry, but it is.

        1. Tridac

          Re: Using Windows?

          Ok, so what is the main culprit, or is that just a bollocks response as well ?...

          1. InNY

            Re: Using Windows?

            Read last sentence...

    2. Delapsus

      Re: Using Windows?

      Unfortunatly none of the clinical software runs on Linux. Even the MRI scanners run windows

      1. Daggerchild Silver badge

        Re: Using Windows?

        Honestly, I'd skip Linux and port medical devices to Android. Everyone's computer is a phone these days anyway and they should be dedicated devices with decent realtime foo that you can lock down to the ground. If you're running antivirus on it, you've already lost.

        ChromeOS might also make a good cheap disposable desktops, seeing as the local practise PC's seem to be client-only anyway.

        *umbrella*

  1. crivensjings

    Oh, for goodness sake... It's only $300. Just pay it!

    1. Bill M

      Probably $300 per computer. I don't how many computers the NHS has but certainly a lot more the one.

      1. Shocker-z

        Well there's also the case that if any network files were encrypted then surely the last pc to encrypt them would have to be the first to decrypt the previously encrypted PCs.. Also NHS has 1.7 million staff.. so even a 1% infection is $5.1million.. Soon adds up. Obviously most PCs shouldn't have any data local so can just be wiped anyway, but then you're dealing with the huge IT task of wiping PC's and checking first, which ones do or don't have any local data that's needed...

        I know that I certainly wouldn't like to be IT support on a day like this for them...

        1. Anonymous Coward
          Stop

          And even if you can mass-pay the ransom, there is the little issue of making crime pay well enough that the criminals will be back again.

          1. Anonymous Coward
            Anonymous Coward

            So don't vote Tory then.

      2. katrinab Silver badge

        The NHS has the world's largest deployment of Microsoft Exchange server. I believe it is somewhere in the region of 850,000 users. NHS England has 1.2 million employees in total, if you include NHS Scotland and NHS Wales, it is 1.4 million. Northern Ireland has its own health service which isn't called the NHS.

        They are the world's fourth largest employer, and the three largest - Walmart, People's Liberation Army and Indian Railways, don't have as many people who would use email at work.

        So anyway, we are looking at a ransomware demand of at least £200m, which the NHS certainly doesn't have as spare cash.

        1. Anonymous Coward
          Anonymous Coward

          >if you include NHS Scotland and NHS Wales, it is 1.4 million

          The NHS census used for this counts employees multiple times

          >They are the world's fourth largest employer, and the three largest Walmart, People's Liberation Army and Indian Railways

          McDonalds employs 1.9 million, DoD 3.2 million - there are a dozen more larger than NHS employers even if you use the bogus census data.

          Please stop repeating this 'cut the overblown NHS' Daily Telegraph bull

          1. Anonymous Coward
            Anonymous Coward

            "McDonalds employs 1.9 million"

            Aren't most McDonalds franchises?

    2. Anonymous Coward
      Anonymous Coward

      $300 - but $300 for what?

      Per PC, and Per server? That could be a massive amount of money in the NHS and the logistics of trying to pay against a separate code for every PC and server would be daunting. Then there's the clean up to stop the same thing happening tomorrow.

      Not easy AT ALL!

    3. Dr Dan Holdsworth

      "Oh look, the sucker just paid! Stick him on the list of plonkers we can re-visit".

    4. Alumoi Silver badge

      "Oh, for goodness sake... It's only $300. Just pay it!"

      And we found the criminal!

  2. Prosthetic Conscience
    Unhappy

    My heart goes out to the IT grunts dealing with this on a Friday

    1. wyatt

      Yep, and me. I'm on call this weekend and we run some services over the N3 network.. here's to hoping our firewalls and patching are up to date.

      1. Danny 14

        Im on call too. But we have sophos interceptX. Im tempted to fire up a quarantined VM and try running the ransomware.

        1. Anonymous Coward
          Anonymous Coward

          Had a demo of InterceptX this week looks good, so every cloud and all that this'll help me get the buget out of our bean counter!

    2. Tom Paine

      Why oh why...

      ...is it always Friday?

      And when will they let us work Wednesday to Sunday so we can rely on having a couple of days a week off?

      Currently still sat at my desk when I was hoping to be away 30 mins ago (17:00), waiting to hear we're definitely OK...

  3. Nash

    something or nothing....

    I've never worked on the NHS systems but ive worked on a lot of systems and some were NOT setup to handle this type of attack.....i would hope that the NHS endpoint PC's which are being presented with this ransomeware message are acting as Terminals i.e Installed with windows but locked down to the point that data CANNOT be saved locally to the C:\ drive. That way if the PC is infact encrypted then the patient records that the PC has been accessing are on a Network location and that network location (server) is not affected? - the PC can be re-imaged although inconvenient, recoverable to OS Level. if the PC's hold local databases loaded with patient info then im afraid someone needs an @ss kicking.

    N.B would be nice to heard from someone who has worked on the NHS IT Systems at Engineer/1'st/2'nd/3'rd line level to get an idea of the setup.

    1. Anonymous Coward
      Anonymous Coward

      Re: something or nothing....

      Why would the data not be affected, if it's on a network share? It encrypts the data. It doesn't really care where the data is.

      1. Nash

        Re: something or nothing....

        ever tried deleting/moving/modifying a file on a network share that you only have "read" permissions to?

        1. Doctor Syntax Silver badge

          Re: something or nothing....

          "ever tried deleting/moving/modifying a file on a network share that you only have "read" permissions to?"

          Those file you only have read permission to - how did they get there? Could it be that someone has to have write permission?

          On a more practical, albeit longer term scale alternatives to simple shared folder need to be looked at. As one approach I'm currently setting up Nextcloud at home. I have several alternative ways to share files with a client. One is to use the webdav client to sync a specific desktop folder with the server. That means that even if I had a ransomware program running wild on the client PC it could only (a) affect files on the synced folder and (b) the contents of the folder on the server are versioned so that the last good version can be restored.

        2. Adam 52 Silver badge

          Re: something or nothing....

          As we discovered last time the NHS had a ransomware attack - which must have been all of a few months ago - everyone has full permission on everything at an SMB level.

          If this turns out to be spread via SMB or anything below layer then someone needs to explain how the network was configured so badly.

          1. Anonymous Coward
            Anonymous Coward

            Re: something or nothing....

            trouble is smbv1 is ON by default to turn it off you have to do this (win7) on EACH BOX

            sc.exe config lanmanworkstation depend= bowser/mrxsmb20/nsi

            sc.exe config mrxsmb10 start= disabled

            Now who in a Doctors surgery is going to do that!? And with XP turning of SMBv1 is likely to break things!

  4. Anonymous Coward
    Anonymous Coward

    NHS staff

    PEBKAC.

    1. Anonymous Coward
      Anonymous Coward

      Re: NHS staff

      I've taken your name in case you need a kidney some day...

      1. Bill M

        Re: NHS staff

        I think all NHS staff are wonderful and all deserve a medal or at the very least some hearty thanks and congratulations.

        ps. any chance of earmarking a liver for me - may need a new one next year.

    2. h4rm0ny
      Paris Hilton

      Re: NHS staff

      Having worked in the NHS and seen how hard people at the bottom often work, I'm more inclined to say it's PEIDO. (Problem Exists In Director's Office).

    3. AlbertH

      Re: NHS staff

      No - PICNIC

      Problem In Chair Not In Computer

  5. bexley

    these exploits are worthless

    this is not a ¨cyber attack¨, this is somebody with admin privileges clicking on something they should not have done.

    Some local files being encrypted really should not be a problem these days for a decent IT department, they should have it all puppetised and be wiping and rebuilding those machines now, or this morning, whenever this started.

    If their databases have been encrypted then lets hope that they have tested their backup strategy and have already restored this last nights backups

    1. Alister

      Re: these exploits are worthless

      this is not a ¨cyber attack¨, this is somebody with admin privileges clicking on something they should not have done.

      Curious then that it has affected so many dispersed bits of the country. I think you'll find that the evidence so far is that this is collateral damage from an attack on Telefonica (who just happen to manage network links for some of the NHS).

      1. Naselus

        Re: these exploits are worthless

        "Curious then that it has affected so many dispersed bits of the country. "

        The term you're looking for is 'continent'. Or possible 'world'; Russia has millions of infections right now, with Taiwan and China both heavily hit too. Half of Europe is being hit. List on the BBC's breaking news site currently says UK, Spain, Italy, China, Russia, Vietnam, Kazakhstan and Taiwan. Avast alone has 36,000 infections going live right now.

        This is fucking massive.

      2. Danny 14

        Re: these exploits are worthless

        It could also be a zero day exploit or a known unpatched exploit. This would bypass local admin requirements but would still fail on network read only shares.

      3. Adam 52 Silver badge

        Re: these exploits are worthless

        "an attack on Telefonica (who just happen to manage network links for some of the NHS)."

        If it is, we need to be asking serious questions about why the end user PCs are so trusting of the wide area network.

  6. 0laf
    Facepalm

    Awareness issues, tech will do so much but some spam will always get in. You can't sop the signal Mal! Someone somewhere clicked.

    I imagine hospitals are a bit like schools with lots of staff that feel very important and that security measures are not for them because they must not be impeded in doing their important stuff (even if that is playing on their new phone).

    Ok I'm generalising but I've yet to be proved wrong.

    1. chivo243 Silver badge

      @0laf

      well said, people that are too important to be bothered to act like it...

  7. Martin Summers Silver badge

    Just been in to my doctors. He didn't know until I told him. Couldn't bring up any patient history and has had to resort to paper. Their phone system is down too.

Page:

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like