Skip to content
>_ITDITDWeb Security Platform
tag

business continuity

3 articles with this tag

2026-09-30

Four Hospitals Disrupted by Cyberattacks in 2026: What Stopped, and What Patients and Hospitals Should Do

In 2026, cyberattacks disrupted care at hospitals in the US, Belgium and Japan. Laid side by side, the hospitals' own statements show one pattern: inpatient and emergency care continued on paper under downtime procedures, while outpatient clinics, chemotherapy, the hospital pharmacy, appointment phones, the patient portal, ambulance intake and imaging stopped — the functions that connect a hospital to the outside. Downtime procedures should be written for those outward-facing functions, not only for the wards. The way in can be equipment nobody counts as a clinical system, such as a VPN appliance used to maintain medical devices. Patients should check official channels, take urgent medication needs to the hospital's designated line, and not answer suspicious calls claiming to be the hospital.

2026-07-18

Osaka General Medical Center ransomware (2022) — a contractor's VPN as the way in, and hospital BCP

The way in was not the hospital itself but a meal-service contractor's remote-maintenance VPN device, which was unpatched and reachable using leaked credentials, the investigation committee found. Because the hospital and contractor were constantly connected, and because servers/PCs shared passwords, users held broad admin rights, EMR servers lacked antivirus, and the network wasn't segmented, the encryption spread across the EMR system. Outpatient care, surgery, and emergency intake were restricted; full recovery took over two months. Defend by treating contractor links as your own attack surface: patch internet-facing VPNs, end credential reuse, least privilege, segment, and build a medical BCP (paper fallback, tested restore).

2026-07-07

KADOKAWA / Niconico Ransomware (2024) — Why It Spread Company-Wide, and Network Segmentation & BCP

The way in was described as phishing that stole an employee's credentials; from there the internal network was breached and ransomware ran, taking down many of the group's services (including Niconico) for months and leaking ~250,000 people's data. Reporting and analysis attribute the company-wide spread to systems of very different criticality sharing the same network, reportedly with too little segmentation. Defend by segmenting the network by criticality, using phishing-resistant authentication, and preparing business continuity (BCP) and recovery.