Attacks/Breaches
3/27/2017
04:30 PM
Connect Directly
Twitter
LinkedIn
Google+
RSS
E-Mail
50%
50%

FBI: Attackers Targeting Anonymous FTP Servers in Healthcare

The FBI warns medical and dental organizations of cybercriminals targeting anonymous FTP servers to steal personal health data.

The FBI has issued a warning that threat actors are going after anonymous File Transfer Protocol (FTP) servers associated with medical and dental organizations.

The goal of these attackers is to access protected health information (PHI) and personally identifiable information (PII). The anonymous FTP extension lets users authenticate to the server with a common username and no password, or a generic password or email address.

Because anyone can connect and look through these files, avoiding sensitive data has been the "standard guidance" for using anonymous FTP servers, says SANS Institute director John Pescatore.

"Make sure nothing but public information goes on that server, because anyone can read anything that goes on it," he cautions, noting how some businesses don't heed this advice. "In many organizations, that guidance has been ignored as an easy way to make information available to third parties."

Any unsecured server operating on a business network storing sensitive information can expose the organization to theft, the FBI explains in its warning. Threat actors can use anonymous FTP servers to steal and compromise users' personal health data.

There are several ways to do this, says Carson Sweet, CTO and co-founder of CloudPassage. Cybercriminals can add data to a fraudster database or sell it on the dark Web. They may also use it for blackmail, leveraging records with information patients wouldn't want made public, he says.

The vulnerability of FTP servers isn't a new problem, but it's still relevant to small healthcare practices. Many healthcare companies running these servers are organizations where security isn't top of mind, says Sweet. They buy personalized software from small vendors and use it for years.

"Small medical and dental practices don't want to change their technology often," he explains. "They end up with a proliferation; a long-term existence of poorly secured apps."

The feds crack down on large healthcare organizations using outdated technology, but smaller businesses tend to slip through the cracks. This is why they continue to use older sytsems and run the risk of their information being exposed and stolen, experts say.

Data theft isn't the only danger related to anonymous FTP servers, SANS' Pescatore notes. Companies also run the risk of cybercriminals storing malicious or incriminating content on their server. They can use this as the foundation for a ransomware attack, threatening to publicize their possession of this information unless they pay. A hacker could use an anonymous FTP server to store and sell pirated software, involving the business in selling stolen goods.

This threat is more difficult to detect than data theft, he continues. Firewalls or intrusion detection will reveal if cybercriminals are scanning for vulnerable FTP servers, but it's tougher to tell if they're implementing dangerous content.

"If they're putting dangerous material on your servers after that, it's hard to detect because companies invest in data loss prevention to look for information leaving the organization, not information coming in," he says.

While there were no details on what sparked this notification from the FBI, Pescatore notes it's likely related to a current case. "They're usually reactive in these warnings," he notes.

Both Pescatore and Sweet urge companies to turn off their anonymous FTP servers. Years ago businesses couldn't turn them off because they were still used in business processes, says Pescatore. Now, it's getting easier to make the switch.

"The trend of using an anonymous FTP server should have been eradicated a decade ago," Sweet emphasized. "It's not something we should see growing; it's something we should see shrinking."

The FBI recommends medical and dental organizations request their IT teams to check their networks for FTP servers running in anonymous mode. If the business has a legitimate reason for using an anonymous FTP server, admins should ensure it isn't storing PHI or PII.

Related Content:

Kelly Sheridan is Associate Editor at Dark Reading. She started her career in business tech journalism at Insurance & Technology and most recently reported for InformationWeek, where she covered Microsoft and business IT. Sheridan earned her BA at Villanova University. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ScottM092
50%
50%
ScottM092,
User Rank: Apprentice
4/7/2017 | 12:00:56 PM
Managing FTP - Anonymous Logon
ftpsentry.com offers a free audit that will locate all of your company's FTP servers and tell you which ones allow anonymous logon.
Register for Dark Reading Newsletters
Dark Reading Live EVENTS
INsecurity - For the Defenders of Enterprise Security
A Dark Reading Conference
While red team conferences focus primarily on new vulnerabilities and security researchers, INsecurity puts security execution, protection, and operations center stage. The primary speakers will be CISOs and leaders in security defense; the blue team will be the focus.
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: No, no, no! Have a Unix CRON do the pop-up reminders!
Current Issue
Security Vulnerabilities: The Next Wave
Just when you thought it was safe, researchers have unveiled a new round of IT security flaws. Is your enterprise ready?
Flash Poll
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
[Strategic Security Report] How Enterprises Are Attacking the IT Security Problem
Enterprises are spending more of their IT budgets on cybersecurity technology. How do your organization's security plans and strategies compare to what others are doing? Here's an in-depth look.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.