Early in 2022, health and social care providers were warned to check their cyber security and protect themselves after alleged Russian cyber-attacks. You can read about the warnings and alleged attacks in carehome.co.uk’s article here.
With this in mind, we have compiled our Cyber Threats & Social Care Insurance Guide. Which looks to explain and discuss:
- Why the care sector is often targeted
- Cyber security terminology
- Real-life claims scenarios
Why are health and social care providers targeted?
Health and social care providers are mainly targeted because they hold a great deal of personal information, which is highly valuable to cyber criminals. Cybercriminals believe health and social care providers to be more vulnerable to cyber security breaches. It has been well reported that the care sector has been underfunded for many years with less available funds to spend on new IT infrastructure; with the main priority being caring for the vulnerable, cyber security can sometimes be bypassed.
Stolen personal information is then typically sold to other cybercriminals for their own criminal gains, such as:
- Identity theft
- Phishing attacks/extortion
- Targeted company attacks
Cyber security terminology
There’s a lot of terminology used when it comes to cybercrime and security, here, we explain what some of the more common terms used, mean.
Malware
Malware is malicious software that is installed into a system, often by using a vulnerable user to breach a network by having them click on a “planted” dangerous link or email attachment, which triggers the installation. Malware can, amongst other things:
- Deny access to the critical components of the network
- Obtain information by retrieving data from the hard drive
- Disrupt the system or even render it inoperable
The most common types of malware are:
- Viruses — these infect applications by attaching themselves to the initialisation sequence; the virus replicates itself, infecting other code in the computer system.
- Trojans — a program hiding inside a useful program with malicious purposes. Unlike viruses, a trojan doesn’t replicate itself and it is commonly used to establish a ‘backdoor’ to be exploited by attackers.
- Worms — unlike viruses, they don’t attack the host (a piece of hardware device that can permit access to a network) as they are self-contained programs that propagate across networks and computers. Worms are often installed through email attachments, sending a copy of themselves to every contact in the infected device’s email list. They are commonly used to overload an email server and achieve a denial-of-service attack.
- Ransomware — a type of malware that denies access to the victim’s data, threatening to publish or delete it unless a ransom is paid. Advanced ransomware uses cryptoviral extortion, encrypting the victim’s data so that it is impossible to decrypt without the decryption key.
- Spyware — a type of program installed to collect information about users, their systems or browsing habits, sending the data to a remote user. The attacker can then use the information for blackmailing purposes or download and install other malicious programs from the web.
Phishing
Phishing attacks are extremely common and involve sending mass amounts of fraudulent emails to unsuspecting users, disguised as though they come from a reliable source. Fraudulent emails often have the appearance of being legitimate but link the recipient to a malicious file or script designed to grant attackers access to your device to control it, gather recon, install malicious scripts/files, or extract data such as user information, financial info, and more.
Man-in-the-Middle (MitM) Attacks
Occurs when an attacker intercepts a two-party transaction, inserting themselves in the middle. From there, cyber attackers can steal and manipulate data by interrupting traffic. One example of an MITM attack is active eavesdropping, in which the attacker makes independent connections with the victims and relays messages between them to make them believe they are talking directly to each other over a private connection, when in fact the entire conversation is controlled by the attacker.
Denial-of-Service (DoS) Attack
DoS attacks work by flooding systems, servers and/or networks with traffic to overload resources and bandwidth. The result is rendering the system unable to process and fulfil legitimate requests. In addition to denial-of-service (DoS) attacks, there are also distributed denial-of-service (DDoS) attacks.
DoS attacks saturate a system’s resources with the goal of impeding response to service requests. On the other hand, a DDoS attack is launched from several infected host machines with the goal of achieving service denial and taking a system offline, thus paving the way for another attack to enter the network/environment.
Password Attack
Passwords are the most widespread method of authenticating access to a secure information system, making them an attractive target for cyber attackers. By accessing a person’s password, an attacker can gain entry to confidential or critical data and systems, including the ability to manipulate and control said data/systems.
Password attackers use a myriad of methods to identify an individual password, including using social engineering, gaining access to a password database, testing the network connection to obtain unencrypted passwords, or simply guessing.
The last method mentioned is executed in a systematic manner known as a “brute-force attack”. A brute-force attack employs a program to try all the possible variants and combinations of information to guess the password.
Social Engineering
In the context of information security, social engineering is the psychological manipulation of people to get them to perform actions or divulge confidential information.
Claim scenarios
It is important to note that anyone can fall victim to a cyber incident. The first claim scenario looks at a direct attack on a care home, the second shows the impact an attack on a 3rd party supplier can have on your business.
Care home victim of “CEO fraud”
In this instance, the fraud appears to have stemmed from a targeted brute-force attack on the care home’s CEO’s business email account. Unfortunately, the CEO’s email account did not have a strong password in place.
With the password lacking in both length and complexity, the program was able to crack it. To make matters worse, the care home did not have multi-factor authentication enabled for remote access to email accounts, meaning that as soon as the CEO’s password was cracked, the hacker was able to gain access to his account without having to go through a second verification procedure, such as inputting a verification code or number.
Having gained access to the CEO’s email account, the fraudster was able to spend time perusing their inbox and outbox, gathering valuable information about how wire transfers were processed at the company as well as establishing the working relationship that the CEO had with members of the care home’s finance team. What’s more, the fraudster was also able to access the CEO’s calendar and establish what the CEO would be doing on any given day. Having worked out the CEO’s schedule from his calendar, the fraudster waited until they were on holiday. With them away there was a reduced chance of the scam being uncovered and so the fraudster chose this moment to strike.
The first step was to send an email impersonating the CEO to a member of the care home’s finance team. The fraudster used a method known as email spoofing, which is when someone sends an email from one email address but labels it as being sent from a different address.
Fraudsters use programs or websites which enable them to make an email look as though it has come from a legitimate email address, as well as allowing them to alter the address that the recipient responds to. As such, the fraudster sent an email that appeared to come from the genuine email address of the care home’s CEO, and any response to the email was sent to a remarkably similar-looking email address set up by the fraudster, thus ensuring that the CEO wouldn’t see any response from the member of the finance team and uncover what was happening. The fraudulent email explained that the CEO had received notice of an outstanding payment of £47,584 that needed to be paid urgently to a firm that had supposedly provided some management consultancy work for the care home a few months ago. The email included the account details that the funds needed to be sent to and the fraudster was keen to stress that the payment had to be made the same day.
The fraudster also added some subtle touches to the email to make it look as authentic as possible. The CEO addressed the member of the finance team using an abbreviated version of her full name, which the fraudster appears to have picked up from viewing previous email correspondence between the CEO and this member of the finance team. The fraudster also mentioned that he was enjoying his holiday and would be busy all day and signed off with the CEO’s genuine email signature. In normal circumstances, the member of the finance would have confirmed the details of the transfer with the CEO in person. But with the CEO on holiday, and with the email appearing to come from the correct address, along with the use of her nickname and a genuine email signature, the employee assumed that the request was genuine. Not wanting to disturb the CEO while on holiday and conscious that the payment was urgent, the employee paid the funds into the account and sent an email confirming this to the account run by the fraudster.
Seeing that the initial ruse had worked, the fraudster sent a similar email the following day, this time requesting a payment be made for £39,731 to another account. The employee arranged the payment once more, meaning that some £87,315 in total was transferred to accounts controlled by the fraudster. The scam was only discovered a week later when the CEO returned to the office and the payments were brought up in conversation. The care home reported the incident to local law enforcement and tried to get the recipient banks to recover the funds, but most of the money had already been withdrawn. One of the banks was able to recover a meagre £600, leaving the care home £86,715 out of pocket.
Fortunately, the care home had purchased cybercrime cover and was able to recover most of the loss.
HR service provider loses contracts due to a cyber-attack suffered by one of its supply chain partners
Over the past two decades, technology has transformed the way businesses operate, and most now depend on their computer systems in one way or another. Rather than having to deal with everything in-house, many businesses choose to outsource elements of their IT infrastructure to third-party providers, whether that be in the form of website hosting, data storage or application-level services.
In many cases, outsourcing IT can prove to be a more efficient and cost-effective way of doing things, with businesses benefitting from the expertise of their third-party providers. However, outsourcing is not without risks. In a cyber insurance context, describes a situation in which a policyholder is affected by unexpected downtime as a result of a cyber event or system failure that the third-party goods or services supplier has experienced. Even though the policyholder’s computer systems may not be directly affected by the incident, the loss of the goods or services provided by the third party can still have a major impact on the insured business’s ability to operate effectively. This means that a business can still suffer a business interruption loss even when its computer systems are unaffected by a cyber-attack.
The client provides its payroll processing services through an online application, which in turn is owned and hosted by a third-party provider. Their customers gain access to the payroll application through a link on their website, which then takes them through to a landing page hosted by a third party, where they can log into the application. Once these customers log in to the application, they are effectively operating on the third party’s computer systems, even though their contracts are with the policyholder.
The issue began when the third party responsible for providing the payroll processing application was hit by a ransomware attack. This ransomware attack managed to encrypt the servers hosting the application, which meant that neither the policyholder nor their customers could gain access to the application. As the application was hosted by a third party, the policyholder was powerless to control the situation and had to rely on the application provider to respond to the incident. The only thing they could do was explain to their customers that the application was unavailable due to a cyber-attack affecting the application provider and that regular status updates would be provided.
In the meantime, the third-party provider went about trying to deal with the issue by decrypting the affected servers, removing the ransomware, and returning the application to its normal functionality. After three days of downtime, it looked as though the issue had been resolved and the insured and its customers were able to log into the application once again. However, this breakthrough proved to be short-lived. During the encryption process, the ransomware had damaged the application and impaired its underlying functionality. This meant that while customers were able to log into the application and view employee data, they were unable to update the data or process any payments.
To remedy the problems caused by the ransomware, the application was taken down once more and it was only after a further five days of downtime that the application was fully restored. To make matters worse, the downtime occurred at the end of the calendar month, a time during which most of the policyholder’s customers would ordinarily pay their employees.
Frustrated customers lead to lost contracts – with the payroll processing application rendered inaccessible because of the ransomware attack, some of the insured’s customers were unable to pay their employees on time. Although they were able to pay them once the application was up and running again, the delay in payment was a source of great frustration for both the businesses and employees affected. As the customers that were impacted had contracts with the insured rather than the application provider, it was the insured that bore the brunt of this anger.
In the end, eight customers chose to cancel their contracts and take their business elsewhere. All 8 customers sent individual letters or emails to the insured, explaining their reasons for cancelling. In each case, these cancellations came down to a combination of two factors: firstly, the delay in paying employees as a result of the ransomware attack and, secondly, a concern that the ransomware attack meant that sensitive data stored on the payroll application might not be secure. This served as confirmation that these customers were lost as a result of the cyberattack as opposed to regular customer churn.
The total value of these annual contracts came to £72,554 and despite the insured’s attempts to placate these clients and win them back, unfortunately, none of these customers decided to reinstate their contracts, meaning that over the course of the 12-month indemnity period, the insured suffered a business interruption loss of £72,554.
While these losses are potentially recoverable from the application provider, this can be a costly and lengthy process and in the meantime, the insured would suffer from cash flow issues due to the drop-off in income. Fortunately, the income loss from these cancelled contracts was covered under the Dependent Business Interruption section of the company’s cyber policy, which covers business interruption losses arising due to a cyber event or system failure at a policyholder’s supply chain partner.
This claim highlights a few key points; firstly, it underscores the importance of having Dependent Business Interruption cover in a cyber insurance policy. Some cyber insurers will only provide cover for business interruption losses as a result of cyber events that directly affect an insured’s computer systems. However, in this instance, at no point were the insured’s computer systems directly impacted by the ransomware. By having Dependent Business Interruption cover in place, the business was able to fully recover its financial loss.
Secondly, it illustrates the value of longer indemnity periods. Many cyber insurers only offer 3 to 6-month indemnity periods as standard. However, this ignores the fact that the financial impact of a cyber event can be felt for much longer than a 3 or 6-month indemnity period would allow for. In this case, the cancellation of annual contracts meant that for each cancelled contract, the insured lost 12 months’ worth of income. By having a 12-month indemnity period in place, they were able to reclaim quadruple the amount that they would have been able to claim on a policy with a 3-month indemnity period.
Finally, it highlights that businesses that receive their income on a contractual basis could be more exposed to business interruption losses, as the cancellation of monthly or annual contracts could very quickly result in sizeable financial losses. Accordingly, businesses that receive their revenue in this way should consider factoring this in when selecting an appropriate limit for their cyber policy.
Summary
We hope we have provided some context around cyber-related risk and how a robust insurance policy can react.
At McClarrons, we have a specialist team working with social care providers. With access to a number of cyber liability products which can be tailored to your needs, we can help find the right policy and cover for your organisation, giving you peace of mind about your protection.
For more information, or if you would like a complimentary insurance review, please do not hesitate to contact the McClarrons Care & Social Welfare Team on 01653 600477 or by emailing care@mcclarroninsurance.com.
Sources:
https://www.cfcunderwriting.com/en-gb/resources/case-studies/