Menu
Browse
Date:

Feb 2022

Location:

Japan

Summary

A healthcare organization experienced a malware infection involving Emotet-type viruses on some internal computers, leading to unauthorized emails impersonating legitimate departments or staff. The compromise resulted in the leakage of historical email correspondence and stored address data, which facilitated fraudulent communications to external parties. The institution responded by disinfecting affected devices using security software, collaborating with internet providers for log analysis, and strengthening email server protections. Ongoing efforts included quarantining potentially compromised systems to contain further data exposure. Recipients of suspicious messages were advised to verify sender addresses and avoid interacting with attachments or links.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 2 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On February 8, 2022, Daiyukai General Hospital discovered that some of its internal computers had been infected by an Emotet-type virus. The infection occurred after employees received sophisticated spoofed emails impersonating legitimate hospital departments or staff members. Upon investigation, the hospital confirmed the malware compromise and identified that historical email correspondence stored on affected devices had been exfiltrated. This data breach enabled threat actors to send fraudulent emails posing as the hospital or its employees to addresses contained within the stolen communication records. The hospital immediately deployed antivirus software to detect and remove the malware from compromised endpoints. Concurrently, they collaborated with their internet service provider to initiate log analysis and strengthened the mail server's virus-checking capabilities to prevent further exploitation of the email infrastructure.

Cyber Incident Image

By February 9, 2022, the hospital confirmed the leakage of multiple registered email addresses and portions of historical email exchange records from infected computers. Containment efforts focused on quarantining additional devices showing potential infection indicators to limit further data exposure. The incident caused operational disruptions and imposed significant inconvenience on business partners and other stakeholders who received malicious emails leveraging the stolen data. The hospital publicly advised recipients to scrutinize sender email addresses for authenticity and avoid interacting with attachments or hyperlinks in suspicious messages. They directed affected parties to guidance resources from Japan's Information-technology Promotion Agency (IPA) and JPCERT Coordination Center regarding Emotet mitigation. Internal response coordination was handled through the hospital's Information Strategy Group, which established a dedicated contact line for inquiries related to the breach.

Sources
Sources available to members
1 source