The FBI and Cybersecurity and Infrastructure Security Agency yesterday urged organizations to take steps to protect against Zeppelin ransomware attacks, which use remote desktop protocol and firewall vulnerabilities and phishing campaigns to access victim networks and deploy ransomware.

鈥淭he Zeppelin 鈥楻ansomware as a Service鈥 is especially targeting health care and medical organizations,鈥 said John Riggi, AHA national advisor for cybersecurity and risk. 鈥淭he alert contains very detailed and actionable indicators of compromise which should be immediately loaded in organizations network defense systems. Along with encrypting files, this gang is engaging in the 鈥榙ouble layered鈥 data extortion method. It appears this gang is stealing and threatening to publicly release sensitive information such as patient information, payroll, human resources and non-disclosure-protected information. Thus, even if a victim organization can independently restore encrypted files from backup, they face the dilemma of potential public release of stolen information in the possession of the criminals. The AHA, along with the federal government, strongly discourages the payment of ransom. This alert along with the comprehensive provide extensive guidance on how to protect your systems from ransomware and avoid the ethical and legal dilemma of 鈥榩ay, not pay.鈥欌

For more information on this or other cyber and risk issues, contact Riggi at jriggi@aha.org.

Related News Articles

Headline
The FBI, Cybersecurity and Infrastructure Security Agency and international agencies July 29 released a joint advisory on recent tactics by the Scattered鈥
Headline
Microsoft July 22 released an update on the ongoing cyberattacks to SharePoint servers used within organizations, attributing the incidents to China-based鈥
Headline
The FBI, Cybersecurity and Infrastructure Security Agency, Department of Health and Human Services, and Multi-State Information Sharing and Analysis Center鈥
Headline
Microsoft July 19 issued an alert about active attacks from vulnerabilities targeting SharePoint servers used within organizations. The incidents have not鈥
Headline
In his latest AHA Cyber and Risk Intel blog, Scott Gee, AHA deputy national advisor for cybersecurity and risk, explains how hospitals can prepare for and鈥
AHA Cyber Intel
In today鈥檚 heightened threat environment, driven by domestic and geopolitical issues, it is more critical than ever for hospitals to prepare for and mitigate鈥