Securolytics COO launched cyberattack on a hospital (Imge Credit: Olga Guryanova on Unsplash)The US Department of Justice has arrested Vikas Singla, Chief Operating Officer (COO) and founder of Securolytics, a network security company. He is charged with a cyberattack against the Gwinnett Medical Center, Lawrenceville, Georgia. The indictment lists 18 offences that took place in 2018. However, it has taken until now for a federal grand jury to indict Singla.

Acting Assistant Attorney General Nicholas L McQuaid of the Justice Department’s Criminal Division said: “Criminal disruptions of hospital computer networks can have tragic consequences. The department is committed to holding accountable those who endanger the lives of patients by damaging computers that are essential in the operation of our healthcare system.”

What does the indictment tell us?

The attack initially took place on Sept 17, 2018. According to the indictment, the impact lasted for a period of one year and the Gwinnett Medical Centre lost over $5,000. There is also a claim that Singla stole data from a Hologic R2 Digitizer. The attack also impacted the hospital’s Ascom phone systems and 16 printers.

According to the indictment, the cyberattack:

  • Disrupted the phone service
  • Obtained information from a digitizing device
  • Disrupted network printer services

The indictment says that Singla: “committed the attack for purposes of commercial advantage and private financial gain.

It is not clear if Singla sold the stolen data or used it to extort the hospital.

Enterprise Times: What does this mean?

Cyberattacks from criminals and insider attacks from staff are nothing new. Organisations deal with both daily. What they don’t expect are the companies they trust to keep them safe to betray that trust. That is exactly what has happened here and seemingly for little gain.

The monetary value put on this case in the indictment is just a few thousand dollars, not the hundreds of thousand that most cyberattacks cost. It raises a number of questions. Among them, why such a small amount? Also, what was Singla’s goal? Until the trial, however, that won’t become clear, and the court documents currently give no date for that.

What is important is that this doesn’t impact the trust that organisations have with their cybersecurity providers.

Previous articleWhat is the key to delivering Customer Success?
Next articleWSO2 acquires Platformer
Ian Murphy
Ian Murphy is an enterprise technology journalist, podcaster, editor and industry analyst with more than 40 years' experience covering enterprise IT, cybersecurity, networking, cloud and artificial intelligence. His career combines hands-on technology experience with long-term industry analysis and journalism. In the 1980s, Ian authored an industry report on expert systems, an early application of artificial intelligence, and founded an IT training company delivering accredited training on enterprise software. He later became a Microsoft Certified Trainer, helping professionals understand and apply business technologies. Alongside his work as a freelance journalist and analyst, Ian developed software, deployed enterprise networks and managed software and technical support teams. That practical experience informs his writing, providing insight into not only what technologies promise, but how they are implemented and used in real enterprise environments. Ian has written thousands of articles, produced industry research, hosted podcasts and interviewed technology leaders across enterprise software, infrastructure, cybersecurity and AI. His work focuses on helping CIOs, IT leaders and technology professionals understand the opportunities, challenges and real-world impact of emerging technologies.

LEAVE A REPLY

Please enter your comment!
Please enter your name here