Monday, February 10, 2025
Homecyber securityFormer Infosec COO Pleads Guilty for Hacking Hospitals

Former Infosec COO Pleads Guilty for Hacking Hospitals

Published on

SIEM as a Service

Follow Us on Google News

Former COO of the Atlanta-based cybersecurity company Securolytics, Vikas Singla, launched a series of cyberattacks on the non-profit healthcare organization Gwinnett Medical Center (GMC), which has locations in Lawrenceville and Duluth, Georgia.

GMC suffered a financial loss of $817,804.12 as a result of the defendant’s computer intrusions that affected the GMC ASCOM phone system, printers, and Digitizer, as well as the defendant’s course of conduct.

Document
Free Webinar

Live API Attack Simulation Webinar

In the upcoming webinar, Karthik Krishnamoorthy, CTO and Vivek Gopalan, VP of Products at Indusface demonstrate how APIs could be hacked. The session will cover: an exploit of OWASP API Top 10 vulnerability, a brute force account take-over (ATO) attack on API, a DDoS attack on an API, how a WAAP could bolster security over an API gateway

Specifics of the Hack

The plea agreement states that on September 27, 2018, the defendant intentionally sent a command that caused an unlawful change to the ASCOM phone system configuration template for the GMC hospital campus in Duluth, Georgia.

Additionally, he knew he did not have the authority to make the changes he intended to make to the configuration files of the ASCOM phone system.

As a result, upon the defendant’s transmission, every ASCOM phone at GMC Duluth that was linked to the phone system became unusable. There was an outage of over two hundred ASCOM handset devices.

Internal communication between nurses and doctors, even during “Code Blue” emergencies, was made possible by the ASCOM phones utilized by the hospital staff members. Making calls from outside the hospital was also possible using the ASCOM phones.

The defendant gained access to over 300 patients’ names, dates of birth, and sex without permission from a Hologic R2 Digitizer that was attached to a mammography machine at the GMC hospital in Lawrenceville.

The Digitizer required a password to access it, and it was available over GMC’s VPN. His access to the Digitizer’s information was not authorized.

Singla intentionally sent a command that led to the printing of a file called Baidu.txt, which caused more than 200 printers at Gwinnett’s hospital campuses in Duluth and Lawrenceville to print patient information such as name, birthdate, and sex that was obtained without consent from the digitizer and interspersed with the statement “WE OWN YOU.”

“The printers were used in connection with patient care and the messages printed on the computer had the potential to cause fear among medical staff and impair the provision of hospital services.”

On October 2, 2018, Singla allegedly “caused” the posting of 43 messages on the @baidu325017231 Twitter account, alleging that Gwinnett had been compromised. 

Prosecutors claim in the plea agreement that Singla received the name, date of birth, and gender of each patient from the hacked digitizer, which was included in each of the 43 messages.

As part of the plea agreement, he has now consented to pay the Insurance Company and Northside Hospital Gwinnett in Lawrenceville more than $817,000 in repayment, plus interest.

Given that Singla has a serious vascular illness and a rare, incurable form of cancer, the plea agreement suggests home detention as an alternative to imprisonment.

Experience how StorageGuard eliminates the security blind spots in your storage systems by trying a 14-day free trial.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

NetSupport RAT Grant Attackers Full Access to Victims Systems

The eSentire Threat Response Unit (TRU) has reported a significant rise in incidents involving...

Quishing via QR Codes Emerging as a Top Attack Vector Used by Hackers

QR codes, once a symbol of convenience and security in digital interactions, have become...

New ‘BYOTB’ Attack Exploits Trusted Binaries to Evade Detection, Researchers Reveal

A recent cybersecurity presentation at BSides London 2024 has unveiled a sophisticated attack technique...

SAML Bypass Authentication on GitHub Enterprise Servers to Login as Other User Account

A severe security vulnerability, tracked as CVE-2025-23369, has been identified in GitHub Enterprise Server...

Supply Chain Attack Prevention

Free Webinar - Supply Chain Attack Prevention

Recent attacks like Polyfill[.]io show how compromised third-party components become backdoors for hackers. PCI DSS 4.0’s Requirement 6.4.3 mandates stricter browser script controls, while Requirement 12.8 focuses on securing third-party providers.

Join Vivekanand Gopalan (VP of Products – Indusface) and Phani Deepak Akella (VP of Marketing – Indusface) as they break down these compliance requirements and share strategies to protect your applications from supply chain attacks.

Discussion points

Meeting PCI DSS 4.0 mandates.
Blocking malicious components and unauthorized JavaScript execution.
PIdentifying attack surfaces from third-party dependencies.
Preventing man-in-the-browser attacks with proactive monitoring.

More like this

NetSupport RAT Grant Attackers Full Access to Victims Systems

The eSentire Threat Response Unit (TRU) has reported a significant rise in incidents involving...

Quishing via QR Codes Emerging as a Top Attack Vector Used by Hackers

QR codes, once a symbol of convenience and security in digital interactions, have become...

New ‘BYOTB’ Attack Exploits Trusted Binaries to Evade Detection, Researchers Reveal

A recent cybersecurity presentation at BSides London 2024 has unveiled a sophisticated attack technique...