Bitmarck Halts Operations Due to Cybersecurity Breach

German IT service provider Bitmarck has confirmed that it has taken all its customers and internal systems offline following a cyberattack uncovered over the weekend.

Writing on its temporary website on Sunday (and Monday), the company said the cyberattack was detected by its early warning system.

“In compliance with our security protocols, we have taken customers and internal systems off the grid in a controlled manner and conducted an impact analysis,” reads the blog post.

Bitmarck also added that it does not believe customer data was affected by the breach.

“Patient data stored in ePA [electronic patient file] You are not compromised during the attack and remain safe. This data is subject to special protection under gematik regulations,” reads the post. Gematik is the national agency driving the digitization of Germany’s healthcare system.

However, according to Andrew Barratt, vice president of Coalfire, it is often difficult to determine the signs of data theft.

“A big concern is whether the Bitmarck infrastructure is being leveraged to move laterally into other healthcare environments,” Barratt said. Information security on mail.

“Large healthcare infrastructures typically have a large number of third parties connecting to their internal environment, often exhibiting very different types of connections. Tracking the path taken by a particular attacker It involves many layers of complexity.”

Learn more about healthcare data protection: #HowTo: Protect Healthcare Provider’s Data

Since the breach, Bitmarck says it has regained access to some services, including digital processing of electronic certificates of incapacity (eAU) and access to ePAs.

Still, the tech giant has revealed that its entire data center has been disconnected from its network since the attack, so there will be considerable restrictions on its day-to-day operations for the foreseeable future.

“Although few details about this incident have been revealed and it is never wise to speculate about cybersecurity issues without full insight, recent cybersecurity incidents have demonstrated a clear and We’re seeing a clear trend,” said Conversant Group CEO John Anthony Smith. Information security.

“Threat actors have destroyed backups, systems and software, sometimes for no apparent reason. It sounds like you’re following a solid recovery plan of staging the system for the recovery approach we’ve put in place.”

The attack comes weeks after the Russian-affiliated hacktivist group KillNet was confirmed to be targeting a healthcare application hosted using Microsoft Azure infrastructure.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *