Boston Children’s Hospital named in North Korean hacking operation

Advertisement

Boston Children’s Hospital is among roughly a dozen organizations publicly named by security researcher Vangelis Stykas as impacted by a large-scale North Korean hacking operation, Wired report Aug. 5.

The hospital disputes that its own systems were breached, saying the issue traced to a former contractor’s personal device.

Mr. Stykas, chief technology officer at cybersecurity firm Kumio, said he has spent 22 months inside systems used by a North Korean hacking group and found evidence connecting the operation to 1,640 companies across 57 countries, with 700 to 800 of those experiencing intrusions he described as seriously damaging. He gained access to the group’s command-and-control servers and, in some cases, the hackers’ own workstations, Slack and Discord after they apparently infected themselves with their own malware. He is presenting the findings at the Black Hat security conference in Las Vegas, naming organizations that, in his account, handled disclosure well or fixed the compromise.

The operation fits a pattern security researchers have tracked for years. North Korea likely has several hundred trained cyber operators and several thousand IT workers who take fraudulent remote jobs at legitimate companies, according to a report from cybersecurity firm Dtex, which found both groups work against yearly earnings quotas with proceeds funneled to the regime.

The primary tactic in this campaign, known as Contagious Interview and tracked by Microsoft since as early as 2022, involves luring software developers and contractors with fake job offers, then asking targets to download a program framed as a coding test that secretly installs malware. Mr. Stykas said some compromised contractors held system access across as many as 30 companies at once.

Researchers say the hackers have mostly stayed focused on stealing cryptocurrency and gaining root-level server access rather than pursuing other sensitive data, though one threat intelligence researcher warned that persistent access could still be repurposed for espionage if another team within the operation piggybacks on it.

Boston Children’s Hospital was named because of a former contractor’s access tied to its large COVID-19 database of Americans’ personal health data, per the report.

A hospital spokesperson told the publication that the incident involved that contractor’s personal device rather than hospital systems, though Wired‘s reporting does not detail the contractor’s specific role with the database or how the device itself was compromised.

The spokesperson said credentials were disabled within hours of notification and that investigators found no evidence hospital systems were accessed without authorization; the exposed data had already been public.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement