The Scotsman

Warning that cyber attack escalation is ‘likely today’

●Scottish Government puts 120 public bodies on alert over security measures

- By ANGUS HOWARTH

Public bodies across Scotland have been placed on alert amid fears of a fresh wave of cyber attacks today.

The wan na de crypt or ransom ware which brought chaos to NHS computer systems across the country is likely to strike again as people return to work and machines are switched on after the weekend.

Justice Secretary Michael Matheson said more than 120 public bodies were being contacted to ensure their defences were adequate.

He said NHS systems in Scotland were expected to be recovered by today and reassured patients with appointmen­ts that they should attend as planned.

Eleven health boards as well as NHS National Services and the Scottish Ambulance Service were affected in the unpreceden­ted cyber attack that hit scores of countries on Friday.

The attack affected acute hospital sites in Lanarkshir­e, as well as GP surgeries, dental practices and other primary care centres around the country.

Organisati­ons across the globe, including investigat­ors from the UK’S National Crime Agency (NCA), are working to hunt down those responsibl­e for the Wanna Decryptor ransomware, also known as Wannacry.

Mr Matheson said the Scottish Government was liaising closely with the National Cyber Security Centre and NHS Scotland to identify the cause of the attack.

Ministers are to convene an extraordin­ary meeting of the National Cyber Resilience leaders’ board tomorrow to review the response to the breach.

A “lessons learned” exercise will also take place to help mitigate the risks from further attacks.

The Justice Secretary said: “Friday’s attack has highlighte­d the need for everyone to have appropriat­e and robust measures in place to protect against cyber attacks which could strike any IT system at any time.

“NHS Scotland systems are being recovered, we expect them to have returned to normal by Monday, and it is important to emphasise that there is no evidence that patient data has been compromise­d.

“Patients who have appointmen­ts booked for Monday and beyond should attend as planned.

“However, we must remain particular­ly vigilant against further incidents and the Scottish Government is taking action to enhance security, including contacting over 120 public bodies to ensure they have appropriat­e defences in place.

“One of the most common methods of infecting computer systems is through links and attachment­s in emails.

“Therefore I would urge everyone to think twice before clicking on attachment­s or links from sources that

they don’t know.” The head of Europol, Rob Wainwright, warned the threat from the cyber attack that crippled internatio­nal services “will continue to grow” as people return to work.

Since Friday’s breach more than 200,000 victims – including the NHS – across 150 countries have been infected by Wanna Decryptor.

Mr Wainwright said the attack was indiscrimi­nate across the private and public sectors.

“At the moment we are in the face of an escalating threat; the numbers are going up. I am worried about how the numbers will continue to grow when people go to work and turn their machines on Monday morning.

“The latest count is over 200,000 victims in at least 150 countries. Many of those will be businesses including large corporatio­ns.”

Meanwhile, health authoritie­s are racing to upgrade security software amid fears hackers could exploit the same vulnerabil­ity with a new virus.

There have been calls for an inquiry into the circumstan­ces surroundin­g Friday’s major incident, with the government and NHS chiefs facing questions over their preparedne­ss and the robustness of vital systems.

Mr Wainwright added: “We have been concerned for some time. The healthcare centres in many countries are particular­ly vulnerable. They are processing a lot of sensitive data.”

Ciaran Martin, chief exec utive of the National Cyber Security Centre (NCSC), added to warnings of new attacks, saying: “We have not yet seen Friday’s attack reoccur, there’s been no new wave of attacks. On Monday morning at the start of the new working week we can expect it’s likely that successful attacks from Friday that haven’t yet become apparent will become apparent.

“We can’t say what scale the new cases will occur at but it’s likely there will be some.”

A British cyber whizz was hailed an “accidental hero” after he registered a domain name that unexpected­ly stopped the spread of the virus, which exploits a vulnerabil­ity in Microsoft Windows software.

The anonymous specialist, known only as Malwaretec­h, prevented more than 100,000 computers across the globe from being infected.

Yesterday Malwaretec­h issued a warning that hackers could upgrade the virus to remove the “kill switch”.

“You’re only safe if you patch ASAP,” he wrote on Twitter.

The Scottish boards affected by the ransomware attack are NHS Borders, NHS Dumfries and Galloway, NHS Fife, NHS Forth Valley, NHS Lanarkshir­e, NHS Greater Glasgow and Clyde, NHS Tayside, NHS Western Isles, NHS Highlands, NHS Grampian, NHS Ayrshire and Arran, NHS National Services and the Scottish Ambulance Service.

In many areas – with the exception of NHS Lanarkshir­e – the number of PCS or systems affected is said to be in single figures.

“The healthcare centres in many countries are particular­ly vulnerable. They are processing a lot of sensitive data” ROB WAINWRIGHT, EUROPOL

 ??  ?? 0 It is believed fresh waves of attack from the ransomware could be seen as people return to work and switch their computers on
0 It is believed fresh waves of attack from the ransomware could be seen as people return to work and switch their computers on

Newspapers in English

Newspapers from United Kingdom