Skip to content
>_ITDITDWeb Security Platform
tag

VPN

5 articles with this tag

2026-09-30

Four Hospitals Disrupted by Cyberattacks in 2026: What Stopped, and What Patients and Hospitals Should Do

In 2026, cyberattacks disrupted care at hospitals in the US, Belgium and Japan. Laid side by side, the hospitals' own statements show one pattern: inpatient and emergency care continued on paper under downtime procedures, while outpatient clinics, chemotherapy, the hospital pharmacy, appointment phones, the patient portal, ambulance intake and imaging stopped — the functions that connect a hospital to the outside. Downtime procedures should be written for those outward-facing functions, not only for the wards. The way in can be equipment nobody counts as a clinical system, such as a VPN appliance used to maintain medical devices. Patients should check official channels, take urgent medication needs to the hospital's designated line, and not answer suspicious calls claiming to be the hospital.

2026-09-11

VPN Appliances Are the Main Way In for Ransomware: Remote Access Defense After Japan's Digital Agency Breach

A VPN appliance connects the internet to an organisation's internal network, and in Japan it is how attackers got in in roughly two thirds of ransomware cases where the route is known. The Digital Agency's GSS incident followed the same shape: in through a VPN vulnerability, then a maintenance operator's account used to reach a large volume of files. This site's view: only keep a VPN appliance if you can keep patching it, and defend it with three things: patch speed, narrow privileges after an intrusion, and detecting bulk access.

2026-07-18

Osaka General Medical Center ransomware (2022) — a contractor's VPN as the way in, and hospital BCP

The way in was not the hospital itself but a meal-service contractor's remote-maintenance VPN device, which was unpatched and reachable using leaked credentials, the investigation committee found. Because the hospital and contractor were constantly connected, and because servers/PCs shared passwords, users held broad admin rights, EMR servers lacked antivirus, and the network wasn't segmented, the encryption spread across the EMR system. Outpatient care, surgery, and emergency intake were restricted; full recovery took over two months. Defend by treating contractor links as your own attack surface: patch internet-facing VPNs, end credential reuse, least privilege, segment, and build a medical BCP (paper fallback, tested restore).

2026-07-18

Tsurugi Handa Hospital ransomware (2021) — an unpatched VPN CVE and backups encrypted along with production

The way in, per the expert committee's report, was an internet-facing VPN device left unpatched against a known vulnerability (CVE-2018-13379), reachable with leaked credentials. Short passwords, no account lockout, and users holding admin rights made it easy to spread to other machines in the hospital (lateral movement). Decisively, the primary system and its backup were on the same network and both were encrypted. A backup that isn't isolated and offline can't be relied on for recovery. EMR recovery took about two months. Defend by patching internet-facing VPNs fast, revoking leaked/reused credentials, and keeping isolated, offline, 3-2-1 backups.

2026-07-07

Capcom Ransomware (2020) — Why an Old VPN Device Was the Way In, and the Double-Extortion Defense

The way in was an old backup VPN device that had been left running at a North American subsidiary after newer units replaced it. From there the network was breached, data was stolen, and then ransomware encrypted systems (double extortion). Up to ~390,000 people's personal data was potentially exposed (no payment-card data). Capcom refused to pay, restored from backup, and disclosed transparently. Defend by decommissioning unused gear, patching edge devices, and covering both theft and encryption (segmentation, detection, backups).