May 12, 2017
Apparent National Security Agency (NSA) malware has been used in a global cyber-attack, including on British hospitals, in what whistleblower Edward Snowden described as the repercussion of the NSA's reckless decision to build the tools.
"Despite warnings, @NSAGov built dangerous attack tools that could target Western software. Today we see the cost," Snowden tweeted Friday.
At least two hospitals in London were forced to shut down and stop admitting patients after being attacked by the malware, which operates by locking out the user, encrypting data, and demanding a ransom to release it. The attacks hit dozens of other hospitals, ambulance operators, and doctors' offices as well.
The Blackpool Gazette in the northwest reported that medical staff had resorted to using pen and paper when phone and computer systems shut down. Elsewhere, journalist Ollie Cowan tweeted a photo of ambulances "backed up" at Southport Hospital as the staff attempted to cope with the crisis.
Other disruptions were reported in at least 74 countries, including Russia, Spain, Turkey, and Japan, and the number is "growing fast," according to Kaspersky Lab chief Costin Raiu. Security architect Kevin Beau said it was spreading into the U.S. as well.
The malware was stolen earlier this year by a group calling itself the Shadow Brokers, which has been releasing NSA hacking tools online since last year, the New York Timesreports.
Times journalists Dan Bilefsky and Nicole Perlroth wrote:
Microsoft rolled out a patch for the vulnerability in March, but hackers apparently took advantage of the fact that vulnerable targets--particularly hospitals--had yet to update their systems.
The malware was circulated by email. Targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets.
Reutersreported that the National Health Service (NHS), England's public health system, was warned about possible hacking earlier in the day, but that by then it was already too late.
A Twitter account with the handle @HackerFantastic, the co-founder of the cyber security company Hacker House, tweeted that the firm had "warned the NHS with Sky news about vulnerabilities they had last year, this was inevitable and bound to happen at some stage."
"In light of today's attack, Congress needs to be asking @NSAgov if it knows of any other vulnerabilities in software used in our hospitals," Snowden tweeted. "If @NSAGov had privately disclosed the flaw used to attack hospitals when they *found* it, not when they lost it, this may not have happened."
Disclosing the vulnerability when it was found would have given hospitals years, not months, to update their systems and prepare for an attack, he added.
Twitter user @MalwareTechBlog added, "Something like this is incredibly significant, we've not seen P2P spreading on PC via exploits at this scale in nearly a decade."
Patrick Toomey, a staff attorney with the American Civil Liberties Union's (ACLU) National Security Project, said, "It would be shocking if the NSA knew about this vulnerability but failed to disclose it to Microsoft until after it was stolen."
"These attacks underscore the fact that vulnerabilities will be exploited not just by our security agencies, but by hackers and criminals around the world," Toomey said. "It is past time for Congress to enhance cybersecurity by passing a law that requires the government to disclose vulnerabilities to companies in a timely manner. Patching security holes immediately, not stockpiling them, is the best way to make everyone's digital life safer."
Join Us: News for people demanding a better world
Common Dreams is powered by optimists who believe in the power of informed and engaged citizens to ignite and enact change to make the world a better place. We're hundreds of thousands strong, but every single supporter makes the difference. Your contribution supports this bold media model—free, independent, and dedicated to reporting the facts every day. Stand with us in the fight for economic equality, social justice, human rights, and a more sustainable future. As a people-powered nonprofit news outlet, we cover the issues the corporate media never will. |
Our work is licensed under Creative Commons (CC BY-NC-ND 3.0). Feel free to republish and share widely.
Nadia Prupis
Nadia Prupis is a former Common Dreams staff writer. She wrote on media policy for Truthout.org and has been published in New America Media and AlterNet. She graduated from UC Santa Barbara with a BA in English in 2008.
Apparent National Security Agency (NSA) malware has been used in a global cyber-attack, including on British hospitals, in what whistleblower Edward Snowden described as the repercussion of the NSA's reckless decision to build the tools.
"Despite warnings, @NSAGov built dangerous attack tools that could target Western software. Today we see the cost," Snowden tweeted Friday.
At least two hospitals in London were forced to shut down and stop admitting patients after being attacked by the malware, which operates by locking out the user, encrypting data, and demanding a ransom to release it. The attacks hit dozens of other hospitals, ambulance operators, and doctors' offices as well.
The Blackpool Gazette in the northwest reported that medical staff had resorted to using pen and paper when phone and computer systems shut down. Elsewhere, journalist Ollie Cowan tweeted a photo of ambulances "backed up" at Southport Hospital as the staff attempted to cope with the crisis.
Other disruptions were reported in at least 74 countries, including Russia, Spain, Turkey, and Japan, and the number is "growing fast," according to Kaspersky Lab chief Costin Raiu. Security architect Kevin Beau said it was spreading into the U.S. as well.
The malware was stolen earlier this year by a group calling itself the Shadow Brokers, which has been releasing NSA hacking tools online since last year, the New York Timesreports.
Times journalists Dan Bilefsky and Nicole Perlroth wrote:
Microsoft rolled out a patch for the vulnerability in March, but hackers apparently took advantage of the fact that vulnerable targets--particularly hospitals--had yet to update their systems.
The malware was circulated by email. Targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets.
Reutersreported that the National Health Service (NHS), England's public health system, was warned about possible hacking earlier in the day, but that by then it was already too late.
A Twitter account with the handle @HackerFantastic, the co-founder of the cyber security company Hacker House, tweeted that the firm had "warned the NHS with Sky news about vulnerabilities they had last year, this was inevitable and bound to happen at some stage."
"In light of today's attack, Congress needs to be asking @NSAgov if it knows of any other vulnerabilities in software used in our hospitals," Snowden tweeted. "If @NSAGov had privately disclosed the flaw used to attack hospitals when they *found* it, not when they lost it, this may not have happened."
Disclosing the vulnerability when it was found would have given hospitals years, not months, to update their systems and prepare for an attack, he added.
Twitter user @MalwareTechBlog added, "Something like this is incredibly significant, we've not seen P2P spreading on PC via exploits at this scale in nearly a decade."
Patrick Toomey, a staff attorney with the American Civil Liberties Union's (ACLU) National Security Project, said, "It would be shocking if the NSA knew about this vulnerability but failed to disclose it to Microsoft until after it was stolen."
"These attacks underscore the fact that vulnerabilities will be exploited not just by our security agencies, but by hackers and criminals around the world," Toomey said. "It is past time for Congress to enhance cybersecurity by passing a law that requires the government to disclose vulnerabilities to companies in a timely manner. Patching security holes immediately, not stockpiling them, is the best way to make everyone's digital life safer."
Nadia Prupis
Nadia Prupis is a former Common Dreams staff writer. She wrote on media policy for Truthout.org and has been published in New America Media and AlterNet. She graduated from UC Santa Barbara with a BA in English in 2008.
Apparent National Security Agency (NSA) malware has been used in a global cyber-attack, including on British hospitals, in what whistleblower Edward Snowden described as the repercussion of the NSA's reckless decision to build the tools.
"Despite warnings, @NSAGov built dangerous attack tools that could target Western software. Today we see the cost," Snowden tweeted Friday.
At least two hospitals in London were forced to shut down and stop admitting patients after being attacked by the malware, which operates by locking out the user, encrypting data, and demanding a ransom to release it. The attacks hit dozens of other hospitals, ambulance operators, and doctors' offices as well.
The Blackpool Gazette in the northwest reported that medical staff had resorted to using pen and paper when phone and computer systems shut down. Elsewhere, journalist Ollie Cowan tweeted a photo of ambulances "backed up" at Southport Hospital as the staff attempted to cope with the crisis.
Other disruptions were reported in at least 74 countries, including Russia, Spain, Turkey, and Japan, and the number is "growing fast," according to Kaspersky Lab chief Costin Raiu. Security architect Kevin Beau said it was spreading into the U.S. as well.
The malware was stolen earlier this year by a group calling itself the Shadow Brokers, which has been releasing NSA hacking tools online since last year, the New York Timesreports.
Times journalists Dan Bilefsky and Nicole Perlroth wrote:
Microsoft rolled out a patch for the vulnerability in March, but hackers apparently took advantage of the fact that vulnerable targets--particularly hospitals--had yet to update their systems.
The malware was circulated by email. Targets were sent an encrypted, compressed file that, once loaded, allowed the ransomware to infiltrate its targets.
Reutersreported that the National Health Service (NHS), England's public health system, was warned about possible hacking earlier in the day, but that by then it was already too late.
A Twitter account with the handle @HackerFantastic, the co-founder of the cyber security company Hacker House, tweeted that the firm had "warned the NHS with Sky news about vulnerabilities they had last year, this was inevitable and bound to happen at some stage."
"In light of today's attack, Congress needs to be asking @NSAgov if it knows of any other vulnerabilities in software used in our hospitals," Snowden tweeted. "If @NSAGov had privately disclosed the flaw used to attack hospitals when they *found* it, not when they lost it, this may not have happened."
Disclosing the vulnerability when it was found would have given hospitals years, not months, to update their systems and prepare for an attack, he added.
Twitter user @MalwareTechBlog added, "Something like this is incredibly significant, we've not seen P2P spreading on PC via exploits at this scale in nearly a decade."
Patrick Toomey, a staff attorney with the American Civil Liberties Union's (ACLU) National Security Project, said, "It would be shocking if the NSA knew about this vulnerability but failed to disclose it to Microsoft until after it was stolen."
"These attacks underscore the fact that vulnerabilities will be exploited not just by our security agencies, but by hackers and criminals around the world," Toomey said. "It is past time for Congress to enhance cybersecurity by passing a law that requires the government to disclose vulnerabilities to companies in a timely manner. Patching security holes immediately, not stockpiling them, is the best way to make everyone's digital life safer."
We've had enough. The 1% own and operate the corporate media. They are doing everything they can to defend the status quo, squash dissent and protect the wealthy and the powerful. The Common Dreams media model is different. We cover the news that matters to the 99%. Our mission? To inform. To inspire. To ignite change for the common good. How? Nonprofit. Independent. Reader-supported. Free to read. Free to republish. Free to share. With no advertising. No paywalls. No selling of your data. Thousands of small donations fund our newsroom and allow us to continue publishing. Can you chip in? We can't do it without you. Thank you.