Heartbleed Led To Health Care Hack

You might recall that I posted a story recently on a hack that led to the theft of 4.5 million patient records. Now we have the cause for the hack:

According to a blog post from TrustedSec, an information security consultancy in Ohio, the breach at Community Health Systems (CHS) is the result of attackers targeting a flaw OpenSSL, CVE-2014-0160, better known as Heartbleed.

The incident marks the first case Heartbleed has been linked to an attack of this size and type.

I find it stunning that they would not have addressed any Heartbleed related vulnerabilities in a timely manner given how much attention the flaw was given earlier this year. This is a lesson that if you’re responsible for securing your network, you have to address issues like these or bad things will happen to you. It’s also proof that we need to hold companies who choose not to address issues like these responsible.

This really isn’t going to end well for the victims of this hack.

 

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading