Transparency paramount after cyberattacks to prevent future breaches: tech expert
Shared Health has kept tight lid on investigation progress after Aug. 10 incident at HSC
Advertisement
Read this article for free:
or
Already have an account? Log in here »
To continue reading, please subscribe:
Digital Subscription
One year of digital access for only $205*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.
To continue reading, please subscribe:
Add Free Press access to your Brandon Sun subscription for only an additional
$1 for the first 4 weeks*
- Enjoy unlimited reading on winnipegfreepress.com
- Read the E-Edition, our digital replica newspaper
- Access News Break, our award-winning app
- Play interactive puzzles
*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.
Read unlimited articles for free today:
or
Already have an account? Log in here »
After a ransomware attack, no news isn’t always good news, a tech expert warns.
Little public information has emerged since a cybersecurity breach last month affected door access and heating, ventilation, and air conditioning at Health Sciences Centre.
“It’s critical for all of us to ask for greater levels of communication after events like this so that we can minimize the potential for these events to recur,” said Ontario tech analyst Carmi Levy.
JOHN WOODS / FREE PRESS FILES
Very little information has been made public about a ransomware attack on Health Sciences Centre Aug. 10.
During a ransomware attack, cybercriminals use malicious software to encrypt, steal or delete data, then demand payment to restore it.
“Silence in the wake of that initial attack supports those cybercriminals’ efforts and gives them a greater chance of succeeding because we’re not sharing best practices and we’re not trying to understand as a group, as a community, precisely what happened and how we can ensure that it doesn’t happen again,” he said from London, Ont.
A recent confidential memo addressed to staff by HSC chief operating officer Monika Warren provided an update on the systems that were hit on Aug. 10 — but very little information has been made public.
Shared Health, the provincial health authority that oversees Manitoba’s health-care system, issued a statement to the Free Press Thursday reiterating its response from last month — the forensic investigation with the help of third-party cybersecurity experts is ongoing.
The cyberincident response plan is being followed “to ensure that we are engaging in the right ways at the right times while maintaining the focus on restoring affected systems,” the statement said.
While the attack did not affect patient care, it did impact maintenance systems as well as staff ID badges that allow door access at Manitoba’s largest hospital. The security office was not able to issue photo ID badges and was closed. It reopened Aug. 31 by appointment only. Staff and students at the HSC campus are receiving door access cards, Shared Health said.
The internal staff memo said HVAC systems continue to run normally and that the security office are able to issue new ID badges for identification only. Door access cards are being issued separately by manager request for staff who require card access.
The building remains secure, and access cards already issued still work, staff were told. Additional security remains at the site and continues to monitor the buildings, the memo said.
There’s still no sign that any staff or patient personal information was hacked, Shared Health.
“Based on the investigation conducted to date, there is no indication that employee information, financial information, or patient health information has been accessed or removed from our systems,” it said.
In December 2024, Pembina Trails School Division was targeted in a ransomware attack. A hacker group claimed responsibility and leaked sensitive personal information and photos of students and employees to the dark web after a ransom was not paid and attempts to sell the stolen data for $1.6 million in bitcoin failed.
Pembina Trails spent about $536,000 on credit monitoring for staff for three years, IT and legal services, and public relations, the division said in response to a freedom of information request made by the Free Press. All but about $50,000 was being claimed for reimbursement under a cyber-insurance policy.
Ransomware is the most common cyberthreat Canadians face and it is on the rise, the Canadian Centre for Cyber Security says. Basic cybersecurity practices would prevent the vast majority of incidents in Canada, the federal agency’s website says.
Manitoba auditor general Tyson Shtykalo reviewed Shared Health’s cybersecurity and in a December 2024 report recommended training programs to ensure cybersecurity incident response team members are fully aware of their specific roles and responsibilities. He called for a strategy to review and test Shared Health’s cybersecurity incident-response plan. The auditor general recommended a regular schedule of activities to test it.
Shared Health said last month that it is “actively implementing” the auditor general’s recommendations.
Levy said it’s important to press for answers when a cyberattack occurs to prevent it from happening again.
“There’s a lot of fear and shame and embarrassment attached to being victimized and so, of course, the institution wouldn’t want to share any more information than it absolutely has to because it makes them look bad and could potentially result in some people losing their job,” the tech analyst said.
“Unless they’re pushed to share more, we’ll never know what happened in this case — and we increase the potential for future events like this to happen again. Criminals love when we don’t talk about a successful cyberattack, when we don’t share best practices about how to prevent the next one, because it allows them to operate in silence, in the dark, with impunity.”
carol.sanders@freepress.mb.ca
Our newsroom depends on a growing audience of readers to power our journalism. If you are not a paid reader, please consider becoming a subscriber.
Our newsroom depends on its audience of readers to power our journalism. Thank you for your support.