- Home
- Medical news & Guidelines
- Anesthesiology
- Cardiology and CTVS
- Critical Care
- Dentistry
- Dermatology
- Diabetes and Endocrinology
- ENT
- Gastroenterology
- Medicine
- Nephrology
- Neurology
- Obstretics-Gynaecology
- Oncology
- Ophthalmology
- Orthopaedics
- Pediatrics-Neonatology
- Psychiatry
- Pulmonology
- Radiology
- Surgery
- Urology
- Laboratory Medicine
- Diet
- Nursing
- Paramedical
- Physiotherapy
- Health news
- Fact Check
- Bone Health Fact Check
- Brain Health Fact Check
- Cancer Related Fact Check
- Child Care Fact Check
- Dental and oral health fact check
- Diabetes and metabolic health fact check
- Diet and Nutrition Fact Check
- Eye and ENT Care Fact Check
- Fitness fact check
- Gut health fact check
- Heart health fact check
- Kidney health fact check
- Medical education fact check
- Men's health fact check
- Respiratory fact check
- Skin and hair care fact check
- Vaccine and Immunization fact check
- Women's health fact check
- AYUSH
- State News
- Andaman and Nicobar Islands
- Andhra Pradesh
- Arunachal Pradesh
- Assam
- Bihar
- Chandigarh
- Chattisgarh
- Dadra and Nagar Haveli
- Daman and Diu
- Delhi
- Goa
- Gujarat
- Haryana
- Himachal Pradesh
- Jammu & Kashmir
- Jharkhand
- Karnataka
- Kerala
- Ladakh
- Lakshadweep
- Madhya Pradesh
- Maharashtra
- Manipur
- Meghalaya
- Mizoram
- Nagaland
- Odisha
- Puducherry
- Punjab
- Rajasthan
- Sikkim
- Tamil Nadu
- Telangana
- Tripura
- Uttar Pradesh
- Uttrakhand
- West Bengal
- Medical Education
- Industry
1.5 lakh patients' data of TN hospital on Dark Web
The stolen database is advertised for $100, meaning that multiple copies of the database would be sold. For actors seeking to be the exclusive owner of the database, the price is raised to $300 and if the owner intends to resell the database, the quoted price is $400.
Bengaluru: After the massive ransomware attack has crippled the nation's premier healthcare institution for days, a new case of a cyber attack has emerged on Tamil Nadu-based multispecialty hospital, Sree Saran Medical Center, as hackers are currently selling at least 1.5 lakh patients' data records for hundreds of dollars on the Dark Web, revealed cyber-security researchers.
The stolen database is advertised for $100, meaning that multiple copies of the database would be sold. For actors seeking to be the exclusive owner of the database, the price is raised to $300, and if the owner intends to resell the database, the quoted price is $400.
Also Read:Cyber Attack on Apollo Hospital server, hackers access Jayalalitha health records
The cyber attack came on the heels of the massive AIIMS ransomware attack that has crippled nation's premier healthcare institution for days.
According to security researchers from AI-driven cyber-security firm CloudSEK, the data fields being sold on the Dark Web include patient name, guardian name, date of birth, doctor's details and address information.
The data was allegedly sourced from a compromised third-party vendor, Three Cube IT Lab, the report claimed. However, CloudSEK said it had no information that ThreeCube may be operating as a software vendor for Sree Saran Medical Center.
"A sample was shared as proof for potential buyers to inspect the authenticity of the data. This data was found to be containing patient details from a hospital, based in Tamil Nadu. The sample image has data records dated from the years 2007-2011," the report mentioned.
CloudSEK's AI digital risk platform XVigil discovered a post made by a threat actor, advertising sensitive data allegedly sourced from Three Cube IT Lab India.
CloudSEK said it has informed all the stakeholders about the incident.
"The sensitive data that was stolen from Three Cube IT Lab has been advertised on popular cybercrime forums and a Telegram channel used to sell databases and which is frequented by threat actors," the report noted.
"We can term this incident as a supply chain attack, since the IT vendor of the Hospital, in this case Three Cube IT Lab, was targeted first," said Noel Varghese, Threat Analyst, CloudSEK.
Using the access to the vendor's systems as initial foothold, "the threat actor was able to exfiltrate Personally identifiable information (PII) and Protected Health Information (PHI) of their hospital clients," Varghese added.
CloudSEK's researchers used the names of doctors from the database, in order to identify the healthcare firm, whose data was present in the sample.
They were able to identify that the doctors work at a medical firm known as Sree Saran Medical Center.
Meanwhile, nearly 1.9 million cyber attacks have been recorded on the Indian healthcare network this year, especially from countries like Pakistan, China and Vietnam, according to the CyberPeace Foundation and Autobot Infosec Private Ltd, along with the academic partners under CyberPeace Center of Excellence (CCoE).
Kajal joined Medical Dialogue in 2019 for the Latest Health News. She has done her graduation from the University of Delhi. She mainly covers news about the Latest Healthcare. She can be contacted at editorial@medicaldialogues.in.