Cybercriminals are exploiting the vulnerability of the healthcare community affected by COVID-19, an increase in teleworking and the need by medical professionals to stay current on coronavirus information. Ransomware attacks that lockdown hospital networks and medical practices at this critical time have become more prevalent as well as other types of attacks. Phishing, remote access technical exploits, and targeting unsecured devices used by stay-at-home staff are a few of the other schemes being used by cybercriminals. This alert focuses on phishing schemes.
On April 21, 2020 the FBI Cyber Division issued a FLASH alert warning that cybercriminals are using targeted email phishing attempts specifically targeting US-based healthcare providers using subject lines and content related to COVID-19. According to the alert, the emails contain malicious files that, when downloaded, are believed to create an intrusion vector that enables the attacker to exploit, dwell on and even exfiltrate information once the attacker gains access to the victim’s system.
The subject lines of the emails exploit healthcare providers’ need to keep up to date on COVID-19 information and the need to provide patients continuity of care in the event of disruption by COVID-19. The emails identified by the FBI had subject lines such as, “Information About COVID-19 in the United States,” “Business Contingency Alert – COVID-19”, and “Todays Update on COVID.” Perhaps even worse, some of the email subject lines have suggested that the email was from the World Health Organization.
The FLASH alert is to inform healthcare providers of the increased targeting they face as well as to ask that providers report back on receiving emails that appear to be part of this phishing scam. The FLASH alert explains:
If you or your company are targeted by a phishing campaign, please provide the FBI with a copy of the email with the full email header and a copy of any attachments. Please do not open the attachment if you or your organization does not have the capability to examine the attachment in a controlled and safe manner. Additionally, if you or your company is a victim of a cyber intrusion related to email phishing, please retain any logs, image(s) of infected device(s), and memory capture of all affected equipment, if possible, to assist in the response by the FBI.
The FBI recommends healthcare providers implement the following to mitigate their risk:
- Be wary of unsolicited attachments, even from people you know. Cyber actors can "spoof" the return address, making it look like the message came from a trusted associate.
- Keep software up to date. Install software patches so that attackers can't take advantage of known problems or vulnerabilities.
- If an email or email attachment seems suspicious, don't open it, even if your antivirus software indicates that the message is clean. Attackers are constantly releasing new viruses, and the antivirus software might not have the signature.
- Save and scan any attachments before opening them.
- Turn off the option to automatically download attachments. To simplify the process of reading email, many email programs offer the feature to automatically download attachments. Check your settings to see if your software offers the option, and disable it.
- Consider creating separate accounts on your computer. Most operating systems give you the option of creating multiple user accounts with different privileges. Consider reading your email on an account with restricted privileges. Some viruses need "administrator" privileges to infect a computer.
- Apply additional security practices. You may be able to filter certain types of attachments through your email software or a firewall.
Lewis Roca attorneys can assist healthcare providers with the preventative management of data protection and cybersecurity risks as well as those who are responding to cyberattacks. We have developed a strategic alliance with eosedge Legal and engaged Doug DePeppe as a Strategic Advisor. Together, we have strong ties with the FBI and the newly formed global cyber threat hunting organization – the COVID-19 CTI League, which has received acclaimed attention in online media. DePeppe is a member of the COVID-19 CTI League, which coordinates with law enforcement and cyber service providers, to support cybercrime protection for the healthcare industry. DePeppe and eosedge Legal complement the legal services the firm provides with the technical expertise and know-how to evaluate, mitigate and respond to cyberattacks in a fully informed manner. This specialized level of cyber service, with connections to the FBI, the CTI League, provide more protection for our clients as our team focuses on duties and exposures associated with data protection and cyberattacks. Lewis Roca attorneys are available to assist clients implementing data security practices and systems designed to mitigate the ever-present risk of cybercrime and to navigate the response when cyberattacks occur
To see the FBI FLASH alert visit their website here.
For more information, please contact Hilary Wells at hwells@lewisroca.com, Doug DePeppe at doug@eosedgelegal.com or visit www.lewisroca.com.
This material has been prepared by Lewis Roca Rothgerber Christie LLP for informational purposes only and is not legal advice. Specific issues dealing with COVID-19 are fluid and this alert is intended to provide information as it is currently available. Readers should not act upon any information without seeking professional legal advice. Any communication you may have with a Lewis Roca Rothgerber Christie LLP attorney, through this announcement or otherwise, should not be understood by you to be attorney-client communication unless and until you and the firm agree to enter into an attorney-client relationship.
Tags: COVID-19 Rapid Response Team, Data Privacy and Cybersecurity, Health Care Regulation and Services- Partner
Hilary Wells is a partner in the firm’s Litigation Practice Group and serves as chair of the firm's Data Privacy and Cybersecurity Practice Group. She has represented a wide range of businesses including banks, financial advisors, private equity companies, insurance companies, and ...
About This Blog
Lewis Roca is immersed in your industry and invested in your success. We share insights and trends that can affect your business.
Search
Topics
Archives
- September 2024
- August 2024
- May 2024
- March 2024
- February 2024
- September 2023
- April 2023
- March 2023
- February 2023
- December 2022
- November 2022
- October 2022
- September 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- February 2021
- January 2021
- December 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- October 2019
- September 2019
- August 2019
- July 2019
- June 2019
- May 2019
- April 2019
- March 2019
- November 2018
- April 2018
- February 2018
- January 2018
- December 2017
- November 2017
- September 2017
- August 2017
- June 2017
- May 2017
- April 2017
- March 2017
- November 2016
- October 2016
- September 2016
- August 2016
- April 2016
- January 2016
Authors
- Alfredo T. Alonso
- Amy E. Altshuler
- Edwin A. Barkel
- Trevor G. Bartel
- Nick Bauman
- G. Warren Bleeker
- Brooks Brennan
- Ogonna M. Brown
- Chad S. Caby
- John Carson
- Rob Charles
- Joshua T. Chu
- Howard E. Cole
- Katherine Costella
- Thomas J. Daly
- Pat Derdenger
- Thomas J. Dougherty
- Susan M. Freeman
- Yalda Godusi Arellano
- John C. Gray, CIPP/US
- Art Hasan
- Frances J. Haynes
- Dietrich C. Hoefner
- Jennifer K. Hostetler
- David A. Jackson
- Andrew Jacobsohn
- Kyle W. Kellar
- Kris J. Kostolansky
- Gregory S. Lampert
- Shaun P. Lee
- Glenn J. Light
- Laura A. Lo Bianco
- Karen Jurichko Lowell
- James M. Lyons
- H. William Mahaffey
- Constantine Marantidis
- A.J. Martinez
- Patrick Emerson McCormick, CIPP/US
- Michael J. McCue
- Lindsay L. McKae
- Linda M. Mitchell
- Gary J. Nelson
- Rachel A. Nicholas
- Laura Pasqualone
- Michael D. Plachy
- David A. Plumley
- Kurt S. Prange
- Katie M. (Derrig) Rios
- Robert F. Roos
- Karl F. Rutledge
- Daniel A. Salgado
- Mary Ellen Simonson
- Susan Strebel Sperber
- Jan A. Steinhour
- Ryan M. Swank
- Dustin R. Szakalski
- Chris A. Underwood
- Jennifer A. Van Kirk
- Hilary D. Wells
- Drew Wilson, CIPP/US
- Karen L. Witt
- Meng Zhong
Recent Posts
- The Importance of Retaining a Grandfathered Gaming Location in Nevada
- Welcome our 2024 Michael D. Nosler Scholarship Intern
- Going Viral: Navigating Promotional Sweepstakes Legality in the Social Media Era
- Arizona Voters Modify Creditors' Remedies with Passage of Proposition 209
- Nevada Gaming Control Board Issues Gaming Technology Approval Guidelines
- Amendments to Nevada Gaming Regulation 5
- Nevada Gaming Control Board Workshop on Public Regulation
- New Wave of Arizona Privacy Litigation Regarding Tracking Pixels
- Legal Issues, Problems, and Unanswered Questions Regarding a State’s Ability and Potential Departure from the Depository Institution Deregulation and Monetary Control Act of 1980 (“DIDMCA”)
- New Trademark Scam