Hospital pays $17,000 ransom to get access back to its encrypted files

The payment will likely prompt debate over how to deal with a pervasive type of cybercrime

A Los Angeles hospital has paid US$17,000 to cyberattackers who crippled its network by encrypting its files, a payment that will likely rekindle a fierce debate over how to deal with a problem known as ransomware.

Hollywood Presbyterian Medical Center issued a statement saying that its systems were restored on Monday, 10 days after malware locked access to its systems.

The hospital contacted law enforcement as well as computer experts, wrote Allen Stefanek, president and CEO of Hollywood Presbyterian, in a statement on Wednesday. But it is apparent those efforts did not help in recovering files.

"The quickest and most efficient way to restore our systems and administrative functions was to pay the ransom and obtain the decryption key," Stefanek wrote. "In the best interest of restoring normal operations, we did this."

The cyberattackers requested 40 bitcoins, or about $17,000, not 9,000 bitcoins, worth about $3.4 million, as reported in the media, Stefanek wrote.

The style of attack, known as ransomware, has become increasingly common, affecting companies, organizations and individuals.

Ransomware attacks have been occurring for more than a decade, but only in the last couple of years have the attacks become large scale. Computer security experts have theorized that this type of attack has a higher rate of success versus other cybercrime activity that has become more difficult.

Ransomware victims just have two choices: either pay the ransom or permanently lose access to their files. The malware used to encrypt files can be difficult to defend against, and the encryption in most cases can't be broken.The best insurance is to have offline or segregated backups of data.

Paying the attackers likely encourages the schemes. Hollywood Presbyterian may face criticism for paying, but it appears the hospital had little choice.

The ransomware affected its electronic medical record system, and hospital employees couldn't communicate electronically, Stefanek wrote.

Companies have paid ransoms to cyberattackers before and come under fire. Last November, ProtonMail, a Switzerland-based encrypted email service, paid a ransom to a group that was crippling its network with distributed denial-of-service attacks.

ProtonMail wrote a blog post saying it paid a ransom in bitcoins, but the DDoS attack didn't stop. A second group began attacking the company.

Later, ProtonMail said it regretted paying and that it "was clearly a wrong decision so let us be clear to all future attackers – ProtonMail will never pay another ransom."

Join the newsletter!

Or

Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Tom Pope

Dynabook Portégé X30L-G

Ultimately this laptop has achieved everything I would hope for in a laptop for work, while fitting that into a form factor and weight that is remarkable.

Ada Chan

Dynabook Portégé X30L-G

I highly recommend the Dynabook Portégé® X30L-G notebook for everyday business use, it is a benchmark setting notebook of its generation in the lightweight category.

Tom Sellers

MSI P65

This smart laptop was enjoyable to use and great to work on – creating content was super simple.

Lolita Wang

MSI GT76

It really doesn’t get more “gaming laptop” than this.

Jack Jeffries

MSI GS75

As the Maserati or BMW of laptops, it would fit perfectly in the hands of a professional needing firepower under the hood, sophistication and class on the surface, and gaming prowess (sports mode if you will) in between.

Taylor Carr

MSI PS63

The MSI PS63 is an amazing laptop and I would definitely consider buying one in the future.

Featured Content

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?