august

Hollywood Presbyterian and Hospital Ransomware, 2016-2018

The Hollywood Presbyterian Attack

The trouble surfaced on Friday, February 5, 2016, when staff at Hollywood Presbyterian Medical Center began finding themselves locked out of the network. The hospital — a 434-bed institution on Vermont Avenue in East Hollywood, serving its Los Angeles neighborhood since the 1920s and owned by South Korea's CHA medical group — declared an internal emergency. The electronic medical record was unreachable. Email was down. Departments that lived on computers, including the CT scanners, the laboratory, and pharmacy operations, could not function normally; the radiation oncology unit was reported to have stopped using its machines' computers altogether. Registration moved to clipboards. Results moved by fax, and when the fax lines jammed, by hand. A small number of emergency patients were diverted to other hospitals, and some inpatients were transferred elsewhere for tests and treatments the hospital could not, for the moment, perform.

Somewhere on the network sat the reason: ransomware had encrypted the hospital's files, and a note demanded payment for the key. The FBI and the Los Angeles Police Department opened investigations. For more than a week the hospital said almost nothing in public. Early reports, citing sources close to the investigation, put the demand at 9,000 bitcoin — roughly $3.4 million — and the figure circulated worldwide before anyone could correct it.

Ransomware itself was not new in 2016. The earliest known example was itself a healthcare incident: in 1989 an evolutionary biologist named Joseph Popp mailed some 20,000 infected floppy disks labeled "AIDS Information" to researchers and subscribers of a computing magazine, with a demand for $189 sent to a post office box in Panama. In the two years before Hollywood Presbyterian, commodity strains like CryptoLocker and CryptoWall had extorted individuals and small organizations by the hundreds of thousands, and a handful of small-town American police departments had quietly admitted paying ransoms of a few hundred dollars each. But a working hospital held hostage — surgeries and scans and lab results traded against a countdown timer — was something the public had not seen. For ten days in February, the question of what a hospital does in that position had no precedent to consult.

The Ransom Payment and Disclosure

The answer arrived on February 17, on hospital letterhead, over the signature of president and chief executive Allen Stefanek. The letter corrected the record first: the demand had been 40 bitcoin, then worth about $17,000, not $3.4 million. The hospital had paid it. Stefanek's explanation ran one sentence and would be quoted for a decade: paying the ransom and obtaining the decryption key was "the quickest and most efficient way to restore our systems and administrative functions." The electronic medical record had come back on February 15. The letter said patient care had never been compromised and that there was no evidence patient information had been accessed.

Two features of the letter made the incident a founding event. The first was the price. Seventeen thousand dollars was small against the operating costs of a mid-sized hospital; a single day of degraded operations plausibly cost more. The attackers had priced the ransom at what the hospital would pay without convening its board — small enough to be an administrative decision, large enough to be worth collecting at scale. That pricing was the innovation.

The second was the disclosure itself. Other hospitals had, in all likelihood, quietly paid ransoms before. Hollywood Presbyterian was the first to say so publicly, in writing, with the chief executive's name at the bottom. It replaced rumor with fact and gave every other hospital administrator in the country a data point about what this decision looks like from the inside. The letter also told criminals that an American hospital, faced with encrypted systems, had paid within days and called it efficiency.

Other 2016 Incidents and the Federal Response

While Hollywood Presbyterian was still negotiating, ransomware arrived at the Lukas Hospital in Neuss, Germany — reportedly through an email attachment — and administrators there made the other choice. They shut their systems down, refused to engage with the demand, reported the crime to state authorities, and rebuilt from backups, running significant parts of a hospital on pen and paper for weeks and postponing a fraction of scheduled procedures while they did. A neighboring hospital group in Arnsberg was struck in the same wave and likewise declined to pay. The German episodes proved refusal survivable. They also showed its price, measured in weeks of manual operation that an American hospital's margins, and an American hospital's lawyers, might not tolerate.

Six weeks later came an American case an order of magnitude larger. On March 28, 2016, MedStar Health — ten hospitals and some 250 outpatient sites across Maryland and Washington, D.C. — detected ransomware moving through its network and shut down its systems wholesale, email and electronic records included, sending more than 30,000 employees back to paper. Reporting by the Associated Press, disputed by the company, traced the entry to a long-unpatched JBoss application server, and the ransom note reportedly asked for about 45 bitcoin, roughly $19,000. MedStar did not pay. Its major systems were restored over the following week from backups, and the incident passed without the company ever confirming most details.

In May, Kansas Heart Hospital, a small cardiac hospital in Wichita, was hit, and its president, Greg Duick, told local television that the hospital had paid a small ransom — whereupon the attackers, rather than restoring everything, demanded a second payment. The hospital refused to pay again and recovered by other means. A ransom payment carries nothing enforceable; the money goes to an anonymous counterparty who has already demonstrated a willingness to extort.

Federal guidance followed over the summer. The FBI's published position was that it did not support paying ransoms — though the bureau's message had been muddled since late 2015, when a supervisory agent in its Boston office told a security conference, "To be honest, we often advise people just to pay the ransom," a remark headquarters spent months walking back. Paying was, and remains, legal in almost all circumstances, and cyber insurers were increasingly willing to fund it, which made the FBI's position guidance without enforcement, in exactly the sense the WannaCry chapter gives that phrase. In July 2016 the Office for Civil Rights at the Department of Health and Human Services issued a fact sheet: when ransomware encrypts electronic protected health information, a HIPAA breach is presumed to have occurred, unless the organization can demonstrate through a documented risk assessment that compromise is improbable. The guidance made a ransomware infection, by default, a reportable regulatory event.

The SamSam Operation

Behind several of these incidents, though nobody outside law enforcement yet knew it, was a single small operation with a distinctive method. The malware family called SamSam had first appeared in December 2015, and it did not spread the way ransomware was supposed to. There was no spam campaign, no poisoned attachment, no worm. Its operators picked targets. They scanned the internet for vulnerable JBoss application servers — later shifting to brute-forcing exposed remote desktop connections — broke in, and then spent time inside: escalating privileges, mapping the network, locating backups. When they were ready, often in the small hours of the night, they launched the encryption across as many machines as they had reached, and priced the ransom to the victim — so much per machine, or a discounted rate for the whole estate. They ran a functioning payment site and, by most accounts, usually delivered working decryption keys, because a reputation for delivering was what made the next victim pay.

Researchers at Sophos who later traced the operation's bitcoin wallets estimated it had collected close to $6 million by mid-2018, from a victim list with an unmistakable shape: hospitals, municipal governments, universities, logistics firms — mid-sized organizations whose work stops when their computers do, and whose IT departments were too thin to keep every server patched and every remote-access port closed. The method acquired a name in the industry, big game hunting, and it inverted the logic of the indiscriminate worm chronicled in the WannaCry chapter. A worm finds the softest connected machines, whoever owns them. A hunter selects for the owner — specifically, for the owner who cannot tolerate downtime. By that criterion a hospital fits the profile closely: it runs around the clock, its tolerance for interruption is measured in hours, its downtime carries life-safety stakes, and its technology budget has long been subordinate to clinical spending.

Within two years the same method — targeted intrusion, network-wide encryption, ransoms priced to the victim — was the template for Ryuk and Conti, and eventually for the industrialized ransomware-as-a-service economy whose reach the opening chapter describes.

Hancock Health, Allscripts, and LabCorp

In the second week of January 2018, on a Thursday evening, SamSam's operators entered the network of Hancock Health, a regional hospital system in Greenfield, Indiana, logging in through its remote-access portal with the credentials of an outside hardware vendor. By morning the hospital's files were encrypted and the demand was on screen: four bitcoin, then about $55,000.

Hancock had backups; the textbook answer — refuse, restore, report — was available. Chief executive Steve Long weighed it and paid anyway, and then, following the precedent Stefanek had set, explained the decision in public. Restoring from backups, he said, would have taken days and perhaps longer, and the hospital was in the middle of one of the worst influenza seasons in years, its emergency department full. Paying brought the systems back by Monday. Long's explanation made explicit what Hollywood Presbyterian's letter had implied: the operative question was how fast the backups could be restored, and against a working decryption key priced at $55,000, a multi-day restore was the slower and costlier option.

A week after Hancock paid, Allscripts, one of the largest electronic health record vendors in the country, was hit by a SamSam variant that took down systems in its North Carolina data centers — and with them the cloud-hosted records and electronic prescribing of roughly 1,500 physician practices, for approximately a week. No hospital was breached; the practices' own networks were untouched; their ability to see charts and send prescriptions vanished anyway. Litigation followed within days. Allscripts was the first ransomware case in which healthcare providers were taken offline by an attack on a company their patients had never heard of — the vendor-side failure mode that reached full scale with Change Healthcare six years later.

The campaign's last known healthcare incident came in July 2018, when the operators broke into LabCorp, one of the world's largest clinical laboratory companies, reportedly through brute-forced remote desktop credentials. LabCorp's detection caught the encryption as it began, systems were taken offline within minutes, and the intrusion was contained over a weekend with disruption to testing operations but, the company said, no evidence that data was removed. The same adversary and the same tooling produced a far smaller outcome; by 2018 the difference between a paralyzed health system and a contained incident was largely a function of how quickly the victim noticed.

The Indictment

On November 28, 2018, a federal grand jury indictment unsealed in Newark, New Jersey put names to the operation: Faramarz Shahi Savandi, 34, and Mohammad Mehdi Shah Mansouri, 27, both of Iran, charged in a six-count indictment with authoring and deploying SamSam over a 34-month campaign. The government counted more than 200 victims, over $6 million collected in ransoms, and over $30 million in losses. The named victims included the City of Atlanta, which had refused a demand of roughly $51,000 that spring and absorbed recovery costs local reporting eventually estimated near $17 million; the City of Newark; the Port of San Diego; the Colorado Department of Transportation; the University of Calgary; and six healthcare organizations — MedStar Health, Kansas Heart Hospital, LabCorp, Allscripts, a Nebraska orthopedic hospital, and Hollywood Presbyterian Medical Center. The indictment settled a question the 2016 coverage had left open, attributing the Hollywood Presbyterian attack to the same two men. The same day, the Treasury Department sanctioned two Iran-based bitcoin traders accused of converting the ransoms into rial, publishing their bitcoin addresses — the first time cryptocurrency addresses appeared on a U.S. sanctions list.

Neither defendant has faced an American courtroom. Iran has no extradition treaty with the United States, and both men remain on the FBI's wanted list. No SamSam attack was publicly reported after the indictment, and the last known attack — the Port of San Diego — had come two months before the unsealing. By late 2018, though, the method had been studied and copied, and the operators who copied it — Ryuk that same year, then Conti, whose attack on an entire national health service is described in the chapter on Ireland — worked at a scale the two men in the indictment never approached.

Lessons

Ransom payments by individual victims fund attacks on the whole sector. Nothing in the record suggests Hollywood Presbyterian or Hancock Health chose wrongly by their own lights; a $17,000 or $55,000 payment against days of hospital-wide downtime, in the middle of patient care, is defensible arithmetic. But the aggregate of those decisions is the revenue stream that funds tooling, recruitment, and the targeting of the next hospital. The sector's first public payment was followed, within 24 months, by the systematic targeting of the sector. Individual victims cannot be expected to weigh that aggregate effect in the middle of an incident, which is why the payment question has migrated, slowly and contentiously, from hospital administrators toward insurers, regulators, and legislatures.

A ransom payment is not enforceable. SamSam's operators usually honored their keys because reliability was their marketing. Kansas Heart Hospital paid once and received a second demand. Whether the deal is honored depends entirely on whether honoring it serves the extortionist. The opening chapter records the same outcome with a $22 million payment.

Backups deter ransom payment only if they can be restored quickly. A backup deters a ransom when its restore time is shorter than the downtime the victim can tolerate, and the only way to know that number is to have rehearsed the restore. Hancock had copies; what it lacked was the hours to rebuild a functioning hospital from them, under load, during a flu surge. The industry term — recovery time objective — existed long before 2018; Hancock showed that an untested or slow restore leaves payment as the faster option.

WannaCry showed that an organization can be hit without being anyone's target. SamSam showed the converse: being a hospital makes an organization somebody's target by construction. Continuous operations, life-safety stakes, thin IT staffing, and aging perimeters — one exposed remote-access port, one unpatched application server, one vendor's password — are the traits a targeting adversary's economics reward. Obscurity was no protection: a small cardiac hospital in Wichita and a county hospital in Indiana were selected as deliberately as MedStar.

Transparency after an incident is a public good, paid for by the victim. Nearly everything this chapter can state with confidence traces to a handful of disclosures — Stefanek's letter, Long's interviews, Duick's television appearance, and a federal indictment. MedStar's near-silence, the more common posture, left the sector to learn from rumor. The victims who spoke absorbed real costs for doing so, including the knowledge that candor doubles as advertisement to the next attacker, and the 2016 HHS guidance that made an encryption event a presumptive HIPAA breach pushed disclosure from virtue toward obligation. The pattern has held across every chapter of this book: the industry's collective defense advances at the speed of its least silent victims.

Between February 2016 and November 2018, ransomware against hospitals traveled the full distance from unthinkable to routine — from a ten-day mystery in Los Angeles that made global news to a threat category with its own federal guidance, insurance products, negotiation consultants, and case law. The sums traveled too. Forty bitcoin bought Hollywood Presbyterian its systems back; eight years later, as the opening chapter records, UnitedHealth would pay 350 bitcoin — $22 million — under the same logic Stefanek fit into a single sentence, the quickest and most efficient way. The malware was not new, and neither was the crime. What February 2016 produced was a piece of market knowledge, confirmed on hospital letterhead and never since retracted: a hospital asked to choose between its money and its mission will pay, quickly, and call the payment efficiency. Other extortion operations, including SamSam's, priced their demands accordingly.