Hey fellas! Welcome back to Layer8's weekly blog <3

Movies often portray "hacking" as a dramatic event featuring a dude in a black hoodie typing furiously until a red screen flashes "ACCESS GRANTED." However, this cinematic trope is far from what hacking really is. In real life hacking is slow, methodical and lands in places you wouldn't expect - a hospital - which brings us to our case study today: the ransomware attack on AIIMS Delhi.

AIIMS Delhi isn't just any hospital, it is one of the most important medical institutes in the country and thousands of patients walk in every day from all over the country for treatment here. And thus everything from registrations to labs to billing run on systems. Therefore any system attack or failure triggers a rapid domino effect across the organization.

What happened?

On 23 November 2022, AIIMS Delhi was hit by a ransomware attack that disrupted its entire digital operations, forcing them to conduct all operations manually for the next 2 weeks. Here's what was reported:

  • Around five servers were said to be encrypted
  • Online services like appointments, billing and lab reports stopped working
  • Staff had to run things on paper for close to two weeks
  • Millions of patient records were reported to be at risk
  • A very large amount of data, reportedly over a terabyte, was said to be locked

Everything shifted to handwritten slips and manual registers, patients had to wait longer and reports took time to reach them. The incident was identified as cyberterrorism by the Delhi Police and India's cyber response team, and services were gradually restored over the following days.

Two things worth understanding here

1. Ransomware

Ransomware locks your files using encryption and asks for money in return for the key.

Imagine someone changing the locks on your house when you are out and then selling you the key - everything you own is still inside but you cannot get to it.

It usually gets in through something very small - a phishing email, software whose security update wasn't performed, or a password that was too easy to guess. Once it is inside, it spreads through the network, encrypting essential files and displaying ransom messages demanding payment to unlock them.

2. Availability

This incident was more than just a data problem - it was a people's problem. With the systems down, patients could not be registered and nor did the doctors have access to reports. This is what "A" means in the CIA triad (confidentiality, integrity, availability) - data wasn't accessible to those who needed it. If the hospital couldn't open its own records then the damage is already done.

Key takeaways

  • Hospitals are high-pressure targets. They cannot afford to wait weeks to fix a system, and hackers take advantage of this very point. As human lives are on the line, hospitals are pressured to pay ransoms to restore their systems.
  • Backups and network separation. If systems are kept apart, an attack cannot spread as far, and good backups can recover without giving in.
  • Software updates. Hospitals often skip updates because upgrading can be expensive, and old, unpatched systems give attackers an easy way in - known security holes act like unlocked back doors.
  • Incident response takes a village. Several agencies (Delhi Police and the national cyber team) had to work together to contain and investigate.
  • Always have a plan B. AIIMS was able to continue operations because staff could fall back on manual work - a manual backup plan is a form of security in itself.

What can you do about it?

A few habits can go a long way:

  • Think before you click on links or attachments, even from people you know
  • Turn on the extra login step (2FA) on your important accounts
  • Keep your phone and laptop updated
  • Back up the files you cannot afford to lose, and keep one copy offline

Imagine you were on the security team in this case, where would you start? Perhaps setting up firewalls or installing an antivirus? But the honest answer is much more basic - knowing the systems you have, keeping them updated, separating important ones from the rest and testing backups beforehand. There is also a human side - staff need to know what suspicious mail looks like and need a clear idea of what to do when the systems go down.

Cybersecurity is not only about guarding secrets. Sometimes it is about making sure people can still use a system at the moment they need it most.

Until next week, stay curious and stay secure!