The healthcare sector has been the target of numerous attacks recently. This vulnerability is due to unprecedented modernization. This forced transformation must account for the integration of digital technology, connected devices, the arrival of 5G, robotics, and more. However, this integration has mostly been carried out in haste, without a security-first approach. Cybercriminals have seen this as a golden opportunity to access valuable data: medical information, social security numbers, addresses, and the medical histories of patients and healthcare professionals.
Previously the poor relation of the digital world, the sector is now undergoing a full digital transformation. The digitization of the patient journey and the pandemic have made a smooth transition difficult, and cybercriminals have exploited the urgency of the situation to target this easy prey.
Let's look at the challenges and threats facing this sector.

Healthcare and Cyberattacks: What are the priorities?
Since 2021, a healthcare facility has been the victim of a cyberattack every week
Olivier Véran - Minister of Health
Why is the healthcare sector a target for cyberattacks? The fragility of the sector's IT systems, limited budgets, lack of awareness, and time constraints all help explain this booming criminal market.
Budgetary prioritization
Recent social movements and the pandemic have highlighted the clear lack of funding in the healthcare sector. Budgets allocated in general, and specifically for cybersecurity, remain insufficient.
A cyberattack would only worsen the already complex situation in some hospitals. These facilities cannot afford to shut down; every second can be vital for a patient. Cybercriminals are aware of this and know that it creates additional pressure, forcing hospitals to pay ransoms.
Furthermore, each hospital manages its cybersecurity inconsistently from one facility to another. Resources differ, as do the security policies in place. There is a real need for harmonization. The French government intends to help by unlocking a 2-billion-euro budget for digital technology to address the deficit. The main focus is "supporting the adoption of cybersecurity by small and medium-sized structures, including hospitals and local authorities, strengthening training, and doubling the number of jobs in the sector by 2025" (E. MACRON).
In addition to this deficit, there is an absence or insufficiency of budget dedicated to human resources, particularly for "support" functions. Yet, it is important to have expert profiles dedicated to the cybersecurity profession. However, talent is expensive, and the shortage of these profiles does not help.
The need to accelerate training
Cyberattackers target the human flaw above all else, and the healthcare sector is no exception. According to a survey by our partner Proofpoint[1] "58% of CISOs consider the human factor to be their greatest cyber vulnerability." The healthcare sector is one of the most exposed, yet its stakeholders, who are the guardians of data, are sometimes the least trained.
The famous VAPs, or "Very Attacked People," targeted in this sector include: alumni, professors at university hospitals, financial departments of medical insurers, clinical staff, executives, and directors. It is important that this target group understands the role they play in data protection, and this requires awareness training, which we will discuss later.
Time constraints
There is no doubt that urgency is a constant in this sector. The Covid crisis highlighted this state of emergency, the work under pressure, and the lack of time. Staff must react quickly and effectively. However, in emergency situations, humans do not have the capacity to make the right decisions; cybercriminals know this, and medical staff will be the victims.
Ecological transformation
Healthcare services are in the midst of a technological shift. Technology implies security. However, the IT structure of these organizations is most of the time obsolete and not adapted in terms of standards or security, thus becoming a goldmine for security flaws and the criminals who exploit them.
Regarding IoT, "IV (intravenous) pumps represent 38% of a hospital's IoT footprint and (...) 73% of these pumps have at least one vulnerability." Updating devices is crucial, and all must be on an isolated network. Indeed, according to a study conducted by Cynerio[2], 53% of IoT devices pose cybersecurity risks because they run on obsolete versions of Windows or Linux that have not been updated. These connected medical devices require increased attention. The question naturally arises as to what would happen if a surgical robot were to fall under the control of an attacker tomorrow.
The expansion of the attack surface also plays a significant role in the multiplication of risks. We have just seen the impact of IoT, but health-related services have also proliferated: the development of telehealth, telemedicine, remote medical monitoring, appointment booking platforms, and chatbots... and we must not overlook the services provided by third parties.
The complexity of the supply chain in this sector creates new opportunities for cybercriminals looking for vulnerabilities. Indeed, external organizations, medical analysis laboratories, social security agencies, billing and insurance services—this entire ecosystem is interconnected, leading to an expansion of the attack perimeter. The entire chain must be secured from end to end, which is a significant challenge.
The complexity of the infrastructure also plays a role; in fact, for certain software specific to the healthcare sector, vendors request that antivirus software not be applied, or that it be disabled, under penalty of being unable to provide maintenance. Such risky behavior unfortunately facilitates attacks.
Finally, the difficulty of inventorying all connected equipment adds yet another layer of complexity, which TEHTRIS is well aware of. This is why our solutions provide new visibility to CIOs and help reduce the exposure surface.
The accumulation of these shortcomings, combined with all these new technologies and environments, complicates IT infrastructures and weakens security in this sector.
Healthcare and Cyberattacks: What are the threats?
Phishing
Phishing attacks are very frequent, particularly in the healthcare sector, and the pandemic did not help. In May 2020, security researchers detected "more than 300 campaigns related to the COVID-19 theme circulating online"[1]. The goal is to disrupt the operation of institutions and steal data. Cybercriminals adapt to current events. As a result, many healthcare organization websites have been spoofed, such as those of non-governmental organizations (NGOs), the World Health Organization (WHO), the Internal Revenue Service (IRS), the Centers for Disease Control (CDC), and more.


These attacks are extremely effective, especially in this high-pressure environment where manipulation is easy. These social engineering attacks aim to deceive increasingly busy and less attentive users (nurses, doctors, trusted third parties, etc.) in order to obtain information, money, or access to the IT system.
The Montpellier University Hospital was the victim of a phishing attack in March 2019. A total of more than 649 computers were affected; fortunately, the Wi-Fi network was not infected, allowing medical staff to continue providing care.
DNS (Domain Name System) attacks, like phishing, are the most frequent type of attack in this sector. At TEHTRIS, our DNS FW is a security solution that collects DNS resolution requests and analyzes them to block or redirect queries related to suspicious or malicious domains.
It thus protects you from both external and internal threats.
Ransomware

One of the most frequent threats to healthcare organizations like hospitals is ransomware.
In the event of an attack, all vital systems are compromised: from the IT system and communication systems to equipment such as scanners, MRIs, infusion pumps, and more. The entire system is paralyzed in seconds, and patients' lives are at stake. This was notably the case in Germany, where a patient died in September 2020 after an emergency operation could not be performed due to a ransomware attack.
We all remember the WannaCry attack that hit the British public health system hard. France has also been a victim; for proof, the Villefranche-sur-Saône hospitaland the one in Daxunfortunately experienced this situation, being paralyzed by a cyberattack in February 2021. The hospital in Saint-Gaudens had to shut down its IT services in April 2021 following a ransomware attack; the list of victims is long, and examples abound.
Hospitals are not the only victims; patients are too, as evidenced by a case in Finland. In October 2020, Vastaamo, a company managing 25 psychotherapy centers, fell victim to the theft of patient records, which were then published as part of an extortion scheme. Patients had received emails demanding 200 euros in Bitcoin to prevent their data from being leaked.
Data theft
Weak IT infrastructure explains the surge in attacks, but another factor of interest to criminals must not be overlooked: the wealth of data. Hospitals manage information that is highly valuable to attackers. They possess sensitive information such as personal data, social security numbers, intellectual property, research documents, login credentials, and more. Cybercriminals are eager for this data, which fuels industrial espionage and is sold on the dark web to insurance companies and other buyers.
A medical record can be worth up to $350 on the black market, which is 50 times more than a bank record and 2.5 times more than the global average for other types of documents.[4]
In March 2020, the Assistance Publique Hôpitaux de Paris (APHP) suffered an attack: the data of 1.4 million people who came in for a Covid-19 screening test was compromised. This data included names, dates of birth, gender, social security numbers, postal addresses, email addresses, phone numbers, and test results.
DDoS attacks
Denial-of-service attacks are just as devastating as ransomware. A service outage, even for a limited time, can be incredibly dangerous, especially for surgical departments. Some hospitals that have suffered such attacks have had to transfer their patients in emergency situations. This was the case for the Brno University Hospital in the Czech Republic in 2020. The hospital was forced to shut down its entire IT network during the incident.
DDoS attacks in this sector are generally targeted and intended to cover up a second attack. Vigilance is therefore essential. Similarly, if a supplier's computers are compromised, they may become part of a botnet; here again, caution is required, as local network performance will be slowed down.
Protecting our healthcare infrastructure with TEHTRIS
The healthcare sector, much like industrial systems, requires specific cybersecurity solutions. As we have seen, patching IoT devices is complex for several reasons: their origin, as they may involve proprietary software or come from various suppliers, and the "imperatives" of production where lives are at stake. Any production shutdown for patching is out of the question. Technology must adapt to these networks.
TEHTRIS understands this well and offers tailored security solutions. We currently secure several hospitals in Europe as well as public healthcare administrations. Furthermore, we have had experience in the industrial and OT sectors since the company's inception. We are therefore well-equipped to best meet the needs of this specific sector.
The solution TEHTRIS XDR enables this adaptation.
- Our EDR is an ideal solution, as this technology can be used for detection only or for remediation. The solution is modular and can be configured according to the criticality of your machines, such as servers, computers, printers, and phones. It provides visibility into all potential threats: ransomware can be remediated automatically, and intrusions can be detected. In the face of a specific threat, we have the capability to strengthen protection based on IoCs, and more. Furthermore, all EDR modules allow for management throughout the entire chain (updates via the audit module, shadow IT detection, etc.).
- Our SIEM monitors operational activity and helps identify anything unusual. Our hyper-automated solutions, which require no human intervention, are a guarantee of efficiency for teams that are already under pressure. Our offering provides asset-based protection and remediation using machine learning, all without disrupting healthcare services, patient reception, or care. Our solution is the one that adapts to your infrastructure.
- TEHTRIS Deceptive Response, our honeypot, detects malicious activity on a subnet, such as network scanning. If a machine is infected, an attacker's first instinct is to scan the network and connect to surrounding devices (to pivot and continue the attack). Thanks to the honeypot, defense teams immediately know if a machine has attempted to scan or attack the network. The attack can be prevented immediately.
[1] Proofpoint, healthcare threat landscape, 2020
[2] Cynerio manufactures IoT systems for the healthcare sector and has analyzed over 10 million medical devices
[3] https://www.proofpoint.com/uk/blog/threat-insight/ready-made-covid-19-themed-phishing-templates-copy-government-websites-worldwide
[4] Eurogroup Consulting survey - August 2021

