back to article Barts Health seeks High Court block after Clop pillages NHS trust data

Barts Health NHS Trust has confirmed that patient and staff data was stolen in Clop's mass-exploitation of Oracle's E-Business Suite (EBS), and says it is now taking legal action in an effort to stop the gang publishing any of the snatched information. The UK's largest NHS trust, which runs five major hospitals across London, …

  1. stiine Silver badge

    Is this going to work? Can you really sue to prevent the publication of documents that were stolen from you?

    1. Aladdin Sane Silver badge

      It'll stop the press from publishing details of celebrities undergoing treatment, which they shouldn't publish anyway as it isn't public interest anyway.

      1. Aladdin Sane Silver badge
        Headmaster

        That's some terrible grammar on display right there.

        1. m4r35n357 Silver badge

          Well I would lose the first "anyway" (or the second), but can't detect any grammatical error ;)

          1. Aladdin Sane Silver badge

            I said terrible, not wrong. Either "anyway" could be removed.

  2. IanRS

    Your data is perfectly safe.

    "To date no information has been published on the general internet, and the risk is limited to those able to access compressed files on the encrypted dark web."

    So only accessible to those most likely to abuse it then?

    1. alcachofas

      Re: Your data is perfectly safe.

      Yeah that’s a crummy statement. Especially as they’re just throwing words in to make it sound like a higher bar.

      Access to compressed files means nothing. That sentence should just read “the risk is limited to those able to access the dark web”. Which frankly isn’t much of a relief!

  3. Furious Reg reader John

    Is this an attempt to stop the press talking about Barts?

    As any injunction given will be ignored by Clop, isn't this purely a play to restrict reporting about the incident and nothing to do with data privacy?

    1. Martin hepworth

      Re: Is this an attempt to stop the press talking about Barts?

      Well it worked for Qantas in Aus where local journos and people like Troy Hunt can't touch the data

    2. Aladdin Sane Silver badge

      Re: Is this an attempt to stop the press talking about Barts?

      I think it's a ploy to protect the privacy of their patients, but I tend to be an optimist.

    3. Anonymous Coward
      Anonymous Coward

      Re: Is this an attempt to stop the press talking about Barts?

      Maybe they're trying to limit reporting. Maybe they're setting it up so that if people use the data to try to blackmail/extort then they'll be able to get an easy conviction for breaching the injunction by using/sharing the data.

      1. Tron Silver badge

        Re: Is this an attempt to stop the press talking about Barts?

        I think it is just to stop the media reporting stuff in the UK. The government use D-Notices. Celebs use superinjunctions.

        If UK celebs were involved, foreign media wouldn't be interested. It is just to block the UK tabloids and TV news. It may be that they are better protected from being sued if they have made an effort to block data releases.

        Now they have done this, there is more chance that the Streisand effect may kick in.

        Stuff gets hacked all the time, most of the data is dull and worthless, and sorting anything juicy from the noise is next to impossible. The NHS can't afford ransoms. I doubt they can afford lawyers, so I'm not sure there was much point in all this.

        Weirdly, hackers never seem to go after government e-mails, which would be interesting. I guess they are more interested in bagging a few quid from low hanging fruit.

        As always: Design out the problem. Your intranet (and infrastructure) should never connect to the public internet. Ditch the scams of SaaS, AI and cloud storage, which are designed to make money for GAFA at the expense of your security. Treat internet-connected systems as high risk and disposable, retaining minimal data on them, transiently. Air gap your net connected systems from your intranet with staff. Two screens on each desk. Use the larger webmail services for your company e-mail and benefit from their malware filters.

  4. Martin hepworth

    qantas

    Because this methods worked so well for Qantas.

    As if filing an injunction again criminals will do anything

    Sigh

  5. Alan Mackenzie
    WTF?

    Negligence?

    > Barts is now one of the highest-profile victims to confirm data exfiltration, joining a growing list of public bodies, universities, and other organizations caught in the blast radius.

    It seems abundantly clear that storing personal data on an internet facing computer is unsafe. Given how easy it is to "steal" such data, it would appear to be negligent on the part of the data controllers to store it so accessibly.

    How long is it going to be before a victim of such negligence (successfully) sues the data controllers?

    1. Anonymous Coward
      Anonymous Coward

      Re: Negligence?

      I was going to suggest the Data Controllers could sue the software suppliers, but I suppose if you buy your software from a hostile foreign power, that's not going to get you far.

      1. Doctor Syntax Silver badge

        Re: Negligence?

        Is the data actually being processed by Oracle or some other clous provider and not by themselves? If multiple users were affected that seems likely. In that event Data Controller could sue Data Processor.

        1. CorwinX Silver badge

          Re: Negligence?

          Sounds right to me.

          It's not just about OS/DB systems. Who is the "owner/controller" of the data and what steps did they take to keep it secure?

          That's not scapegoating - very little anyone can do about zero-days in advance.

          It's about how effective the *response* is to what's already happened.

          To use the venerable "horses have bolted" analogy - first fix the gate *then* round up the horses"!

    2. Herring`

      Re: Negligence?

      It's an interesting question. I mean, I have a static IP address, I could stand up a box at home with MS Access and offer to host people's sensitive data. Anyone taking me up on the offer would be negligent. Given the repeated high-profile breaches, are data controllers who choose any of the major cloud providers negligent? Proving that in court would be tricky but I would love to watch the fallout..

  6. may_i Silver badge

    Negligence

    Sensitive personal data should be encrypted at rest.

    If proper IT policies were in place at Barts, it should have been impossible to steal any data. So why was it possible and when will the responsible people at the trust be held accountable for their negligence?

    Proving that you have absolutely no idea what you are talking about by saying things like "risk is limited to those able to access compressed files on the encrypted dark web." does not help your case.

    1. alcachofas

      Re: Negligence

      “Sensitive personal data should be encrypted at rest”

      Do we know it wasn’t? This was an exploit of the software that reads the sensitive data, which will definitely have the means to read the data.

      Your database files can be as encrypted as you like but if you give me a login to your database I can read your files…

      (Though I totally agree on their awful statement)

  7. Anonymous Coward
    Anonymous Coward

    Here we go again...

    When will Barts start parroting "the security of our patients data is very important to us"?

    Because it clearly wasn't.

    In 'Ye Olde Days' (tm) of IT when we had computers the size of football pitches, we used to have regular audits, of security, processes, resilience and recoverability (hot standby/DR etc.) to ensure these dirt of things couldn't happen.

    Today it seems you just hire numpties who get AI to do all their work, then just dump terabytes of personal customer or business data into some random cloud, and hope for the best.

    Where is the accountability? At any level? In 'Ye Olde Days' I and others would have lost our jobs immediately over something less than half as bad as this complete omnishambles.

  8. steviebuk Silver badge

    Very funny

    This is like telling bank robbers "We're going to take urgent legal action to make the high court order you NOT to spend that stolen money".

    Fuck whits.

    They broke in. I really don't think they'll give a shit about your high court judgement.

  9. Anonymous Coward
    Anonymous Coward

    Round and round we go...

    https://www.theregister.com/2018/01/18/nhs_buntu_trademark_cease_and_desist/

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon