X

Microsoft warns hospitals about VPN cyberattacks during coronavirus

The tech giant notes that as more people work remotely, a new breed of hacker could attack.

Ian Sherr Contributor and Former Editor at Large / News
Ian Sherr (he/him/his) grew up in the San Francisco Bay Area, so he's always had a connection to the tech world. As an editor at large at CNET, he wrote about Apple, Microsoft, VR, video games and internet troubles. Aside from writing, he tinkers with tech at home, is a longtime fencer -- the kind with swords -- and began woodworking during the pandemic.
Ian Sherr
2 min read
microsoft-logo-phone-3
Angela Lang/CNET

Roughly four out of five Americans are on government-mandated lockdowns, forcing many of them to work from home to avoid spreading the novel coronavirus. Many of these people use technology to access their work called virtual private networks , or VPNs. And now Microsoft says those companies -- specifically health care workers -- need to be on the lookout for a different breed of threats that come from VPNs.

The tech giant took what it says is its first-ever step to warn hospitals about the threat. "Ransomware operators have identified a practical target -- network devices like gateway and virtual private network (VPN) appliances," Microsoft said in a statement. "These are more difficult to remediate because it can be challenging for defenders to go and extensively hunt to find where the ransomware attackers have established persistence and identify what has been compromised."

Watch this: Coronavirus lockdown: Why social distancing saves lives

Microsoft issued its warning because companies around the world are leaning on VPN technology to allow employees stuck at home to access sensitive work apps and documents. It's concerned that some companies aren't as prepared for the hackers who attack using that technology.

Microsoft has good reason to be concerned.

At the end of February, just as the western world was ramping up its response to the coronavirus, hotel chain Marriott detected "an unexpected amount of guest information" that had been accessed. All told, it said, data from 5.2 million customers may have been compromised, including names, mailing addresses, phone numbers, birthday days and months, and more. Marriott hasn't disclosed details of the hack or if VPN software was involved, but it's a reminder that hackers aren't slowing their activity during the crisis.

In its blog post Wednesday, Microsoft suggested similar steps to CNET's own recommendations for remote workers to protect themselves and their company's data. Among them was to keep applying security updates (something people still regularly don't do, and is the reason behind some hacks.) Microsoft also recommended companies reduce people's access to most documents, only people who need it have access to various data.

Our new reality now that coronavirus has sent the world online

See all photos