Former Infosec COO Pleads Guilty for Hacking Hospitals

Former COO of the Atlanta-based cybersecurity company Securolytics, Vikas Singla, launched a series of cyberattacks on the non-profit healthcare organization Gwinnett Medical Center (GMC), which has locations in Lawrenceville and Duluth, Georgia.

GMC suffered a financial loss of $817,804.12 as a result of the defendant’s computer intrusions that affected the GMC ASCOM phone system, printers, and Digitizer, as well as the defendant’s course of conduct.

Document
Free Webinar

Live API Attack Simulation Webinar

In the upcoming webinar, Karthik Krishnamoorthy, CTO and Vivek Gopalan, VP of Products at Indusface demonstrate how APIs could be hacked. The session will cover: an exploit of OWASP API Top 10 vulnerability, a brute force account take-over (ATO) attack on API, a DDoS attack on an API, how a WAAP could bolster security over an API gateway

Specifics of the Hack

The plea agreement states that on September 27, 2018, the defendant intentionally sent a command that caused an unlawful change to the ASCOM phone system configuration template for the GMC hospital campus in Duluth, Georgia.

Additionally, he knew he did not have the authority to make the changes he intended to make to the configuration files of the ASCOM phone system.

As a result, upon the defendant’s transmission, every ASCOM phone at GMC Duluth that was linked to the phone system became unusable. There was an outage of over two hundred ASCOM handset devices.

Internal communication between nurses and doctors, even during “Code Blue” emergencies, was made possible by the ASCOM phones utilized by the hospital staff members. Making calls from outside the hospital was also possible using the ASCOM phones.

The defendant gained access to over 300 patients’ names, dates of birth, and sex without permission from a Hologic R2 Digitizer that was attached to a mammography machine at the GMC hospital in Lawrenceville.

The Digitizer required a password to access it, and it was available over GMC’s VPN. His access to the Digitizer’s information was not authorized.

Singla intentionally sent a command that led to the printing of a file called Baidu.txt, which caused more than 200 printers at Gwinnett’s hospital campuses in Duluth and Lawrenceville to print patient information such as name, birthdate, and sex that was obtained without consent from the digitizer and interspersed with the statement “WE OWN YOU.”

“The printers were used in connection with patient care and the messages printed on the computer had the potential to cause fear among medical staff and impair the provision of hospital services.”

On October 2, 2018, Singla allegedly “caused” the posting of 43 messages on the @baidu325017231 Twitter account, alleging that Gwinnett had been compromised. 

Prosecutors claim in the plea agreement that Singla received the name, date of birth, and gender of each patient from the hacked digitizer, which was included in each of the 43 messages.

As part of the plea agreement, he has now consented to pay the Insurance Company and Northside Hospital Gwinnett in Lawrenceville more than $817,000 in repayment, plus interest.

Given that Singla has a serious vascular illness and a rare, incurable form of cancer, the plea agreement suggests home detention as an alternative to imprisonment.

Experience how StorageGuard eliminates the security blind spots in your storage systems by trying a 14-day free trial.

Gurubaran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

Implementing Identity First Security for Zero Trust Architectures

Zero Trust is a security framework that operates under the assumption that no implicit trust…

51 minutes ago

InvokeADCheck – New Powershell Module for Active Directory Assessment

Orange Cyberdefense has announced the development of InvokeADCheck, a new PowerShell module designed to streamline…

3 hours ago

Detecting Malicious Activities With Traffic Distribution Systems

Traffic Distribution Systems (TDS) have emerged as critical tools for both legitimate and malicious purposes,…

3 hours ago

Hackers Deploy Advanced Social Engineering Tactics in Phishing Attacks

Cybercriminals are evolving their phishing methods, employing more sophisticated social engineering tactics to deceive their…

3 hours ago

Cybercriminals Exploit Compromised Email Servers for Fraudulent Campaigns

Trend Micro's Managed XDR team has recently investigated a sophisticated Business Email Compromise (BEC) attack…

3 hours ago

Identifying Cyber Attack Patterns Through Threat Actor Infrastructure Analysis

Kudelski Security Research recently published an article detailing advanced methods for tracking and analyzing threat…

3 hours ago