Since the beginning of the pandemic, the media has warned of a surge in cyberattacks on hospitals, private users, and businesses. At onBRANDING, we have observed numerous cases of victims falling prey to some form of cybercrime during this period.
The healthcare sector is one that cybercriminals have traditionally respected more; however, in recent months, cases of cyberattacks on medical center databases have also been detected, with consequences that can be fatal for patients and institutions.
Alert in Finland Over Illicit Access to Data of Thousands of Patients.
Last week, an alert was triggered in Finland following the blackmail of patients at a mental health center. Criminals threatened users with the publication of their psychology sessions with specialists if they did not agree to pay €200 in bitcoins.
It goes without saying how delicate the situation is for patients attending these types of therapies, and the need to safeguard the privacy of what occurs within them.

In this way, they were able to access strictly confidential and sensitive information that patients share with their therapists. Following several investigations, a 10 GB file was located on the Dark Web containing private notes between at least 2,000 patients and their therapists.
The National Bureau of Investigation in Finland confirms that a security breach and extortion, among other charges, are being investigated.
The country’s authorities have provided a web platform for victims, urging them not to give in to the blackmail, given the possibility that they could be asked for more money in the future to keep their privacy safe.
How do these types of attacks work?
At onBRANDING, we have warned on numerous occasions about the dangers and risks we face in the digital environment.
The most common entry points used by cybercriminals include the following:
- Phishing via SMS or email: Cybercriminals send a link, either en masse or targeted at a specific institution, under the identity of an official body or a company recognized by the victim.
In this way, by accessing the link and providing, for example, login details for a platform we believe to be legitimate, we are actually opening the door to hacking through a fake platform that simulates the real one. - Sending infectious content via email: The lack of cybersecurity knowledge among companies and employees is compounded by the low protection of the devices used.
Consequently, cybercriminals manage to access systems by sending emails with malicious content, such as Excel files or compressed files, which, when downloaded or opened, allow the cybercriminal access to the device. - Ransomware: Another very common type of cyberattack is the kidnapping of the victim’s data. Cybercriminals manage to access private information, such as company files or databases, or intimate photographs of private individuals or celebrities. They then encrypt or hijack the data or content and request a payment in exchange for returning access to their data and preserving privacy.
- Reputational crisis or employee issues: Another problem institutions may face are reputational issues that trigger waves of negative comments and critical sentiment toward the company, stemming from a company action or communication.
This encourages the emergence of “vigilantes” or enemies of the institution who might attack computer systems to bring the company down. The same would happen in the case of an employee angry with the organization who still has active access to systems and files. In the event of potential revenge, they could disseminate confidential and private information.
The objective or motivation of cybercriminals is usually purely economic, although at times it can take on a personal tone through which revenge or irreversible damage to the victim is sought.
Increase in attacks on hospitals during the pandemic.
In the midst of the Coronavirus wave, cybercriminals have begun to focus on health centers and hospitals, partly due to the chaos generated by the situation.
In Spain, a wave of mass emails to hospitals was detected during the month of March. These cyberattacks had the capacity to infect the computer via a computer virus and access login credentials and documents.
The company that owns the Quirón Salud hospitals suffered an unlawful intrusion into its systems via ransomware. The company’s refusal to pay the “ransom” for its data resulted in the publication of confidential patient data on the Dark Web.
INTERPOL has reported the vulnerability of hospitals regarding these types of attacks.
A truly serious case occurred in a German hospital, where the cyberattack suffered caused the death of one of its patients.
In the United States, the FBI has also recently warned about a campaign of cyberattacks and ransomware targeting hospitals and medical centers.
How can cyberattacks on hospitals be prevented?
- Have a professional and certified cybersecurity provider who can advise on and protect computer systems, encrypt data, and secure corporate devices.
- Access only digital platforms certified by the hospital itself.
- Block access on all computers or devices to web platforms that are not considered proprietary or necessary for work.
- Ensure employees do not download software applications onto computer systems or work networks.
- Blocking the automatic installation of applications, programs, or tools can be fundamental in preventing cyberattacks on hospitals.
- Implement encryption for email and corporate files.
- Configure email filters correctly.
- Activate anti-spam filters on servers and with email providers.
- Perform data backups periodically.
- Have certified and recognized anti-malware software on all corporate digital devices and work networks.
- Do not download files or open links from doubtful sources. If they come from certified providers, verify that it is the legitimate sender and not an identity spoof.
- Disable the option in Windows to hide extensions for known file types.
- Keep device software updated.
- Avoid public or unsecured Wi-Fi networks.
How to prevent risks in the case of remote work?
- Provide employees with company-owned computer equipment and mobile devices.
- Use different passwords for each service.
- Do not install software programs from sources other than official providers or those that are not strictly necessary for job performance.
- Avoid accessing social networks or personal accounts.
- Log out of devices when finished.
- Use a secure VPN network.
- Do not use public Wi-Fi.
- Do not fall for potential fraudulent messages received via SMS or email.
- Avoid using banking applications if it is not among the job functions to be performed.
- Do not publish or send confidential information through messaging systems that are not certified or official for the company.
The protection of company and employee devices is fundamental to avoid potential illicit access to hospital data. The consequences can be very serious and damaging given the pandemic situation we are experiencing.
Furthermore, remote work opens another door to cybercrime. The human factor and cybersecurity training are essential to avoid potential risks; however, low protection of company devices and data can lead to critical situations for the institution and its patients.
At onBRANDING, we are experts in Privacy and Cybersecurity, Cyber-investigation, Digital Identity, Online Reputation, and the protection of corporate and personal digital identity.
If you know of any institution that is in danger or suffering an attack, you can contact us.