Australian businesses have become a massive target for ransomware cyber attacks. In a recent report, Crowdstrike found that over 67% of Australian organisations have suffered a ransomware attack, which is 10% higher than the global average.
And attacks are increasing - in size, severity, and sheer brazenness.
In April this year, a cyber attack on UnitingCare's Queensland hospitals caused chaos across the healthcare network. According to UnitingCare, the attack blocked access to their "digital and technology systems," with local reports suggesting that email and operations booking systems had become infected. Hospital staff also reported Wi-Fi networks coming down, impeding staff from critical communications and assistance, access to patient records, and difficulty in discharging patients. Some were even concerned the attack would impact their pay.
This recent ransomware attack is not the first of this kind to hit Australia’s healthcare sector, nor will it be the last. Businesses and organisations must become ultra-vigilant to protect data assets and customer privacy, and it’s clear Australian organisations are still not up to speed on the risks. So, let’s deep dive into ransomware: what it is, who is it targeting, and what are its effects?
What is ransomware?
Ransomware attacks generally involve a hacker getting malware into a computer’s system that allows them to lock and encrypt data until the victim pays a ransom to get access back. Ransomware seizes on vulnerabilities within a system, network, software, or even human users themselves, to plant malware and infect a device.
According to Deep Instinct’s Threat Report, one hacking trend that has emerged is that of double extortion ransomware tactics. In this new trend, when companies refuse to pay the ransom, cybercriminals will next threaten to publish the stolen data.
How does ransomware enter a network?
There are many techniques that a cyber criminal can use to get this malware into a company’s network, including:
Phishing emails
Email attachments
Malicious links on social media
Malvertising, or clicking a legitimate ad that has malicious code in it
Installing infected programs or applications
Visiting an unsafe or fake website or opening/closing a malicious pop-up
Traffic Distribution System (TDS): clicking a link on a legitimate website that redirects to a malicious website
An employee inserting a USB directly into their computer
Once malware is installed within a company’s system, cyber criminals don’t necessarily act on it immediately. The average cost for a business to remediate a ransomware attack is much higher for those who pay the ransom versus those who don’t. This is partly due to the fact that the business who pays the ransom still needs to make system-wide changes to prevent subsequent attacks.
Who is being targeted?
No industry or business is safe from a ransomware attack. However, the Australian Cyber Security Centre (ACSC) found that in the 2019-20 financial year, health, state governments, and the education sector were the hardest affected industries of ransomware attacks.
The higher prevalence of ransomware attacks directed at the health and government sector may be due to the lack of appropriate defence protocols in many Australian organisations. In a recent three-year study, Macquarie University found that 16% of Australian government websites did not have the most basic security protocol installed, and over one-third of those belonged to the Department of Health.
What are the effects of a ransomware attack?