New Cyber Threats: Use Extra Vigilance with Email and Web Browsing

Submitted by abshaver on

During the past week, two new cyber threats emerged - the "Log4j/Log4Shell" vulnerability that cybercriminals are using to access some organizations' computer systems and the UKG/Kronos ransomware attack.

Our computer systems were not adversely impacted by these events. We continue to monitor cyberthreats, and we urge everyone to remain vigilant when clicking on links or opening attachments. Health care organizations remain a top target for cybercriminals and phishing is a  primary way to carry out these attacks.

About the Log4j/Log4Shell Vulnerability

This vulnerability is a bug in a piece of computer code that is used by many organizations, including Carilion Clinic. The bug allows cybercriminals to gain access to a user’s device and then run computer commands.

Our TSG and Information Security teams were aware of the issue and began working on it as soon as we knew about it. We have installed the recommended patches and do not believe our systems have been adversely impacted.

With that said, other trusted organizations may be compromised by this vulnerability. We urge you to be extra vigilant using email and browsing the internet, even with emails from people you know and websites you trust. If someone works for an organization that has been compromised, their email could be used to send malicious links or attachments. Webpages for organizations that have been compromised could be changed to steal users’ information.

About the UKG/Kronos Ransomware Attack

We use UKG for various functions such as time tracking, scheduling and payroll. Over the Dec. 11-12 weekend, UKG’s cloud computers were impacted by a ransomware attack.  

At Carilion, we do not use UKG’s cloud computers; instead we run the UKG software in our own data center. Because of this, we are not impacted by the current UKG cyberattack and can continue to use UKG/Kronos. There should be no disruption to normal services provided by the UKG software including time and attendance, timekeeping, paychecks, etc.

What You Need To Do

If you receive a suspicious email, report it to our Information Security team by clicking the "report phish" button within Outlook, or forward it to phishing@carilionclinic.org. If a webpage you normally visit is requesting information you do not normally provide, do not enter your information, close the browser, and report it to our Information Security team at phishing@carilionclinic.org.

Publish date / time
News Type
Users that Liked
14180
380
6499
9990
Views
0
Thumbnail Image
red exclamation point on a background of computer code
Unlisted
Off
Banner Image
red exclamation point on a background of computer code
Designated Comment Contact
rmperry
Key Points HTML

We have not been adversely impacted by the Log4j/Log4Shell vulnerability or the ransomware attack on UKG/Kronos's cloud servers.

Health care organizations are a top target for cybercriminals.

Use extra caution with email and websites, even with emails from people you know and websites you trust.