Security

Cyber-crime

IT giant Bitmarck shuts down customer, internal systems after cyberattack

Patient data 'was and is never endangered', says medical tech slinger


German IT services provider Bitmarck has shut down all of its customer and internal systems, including entire datacenters in some cases, following a cyberattack. 

The company, one of the largest service providers for German health insurers, said no customer, patient, or insured individuals' data had been accessed in the security breach — at least not according to "the current state of knowledge," according to an April 30 update posted on its temporary website. 

Patient data "was and is never endangered by the attack," the alert read, noting that this sensitive information is subject to "special protection" under Germany's Gematik healthcare data regulations. 

"The security of customer, insured and patient data had and still has the highest priority both when defending against the attack and when putting our systems back into operation," Bitmarck assured customers.

Bitmarck sunk

The service provider doesn't yet have a timeline for when it expects to have all of its systems back up and running. "It should be noted that the systems can be put back into operation at different speeds depending on the customer situation," according to the alert.

"Services that are already available or will be available shortly include, in particular, the digital processing of electronic certificates of incapacity for work (eAU) and access to the electronic patient file (ePA)," it noted, adding that other key services, including monthly transmission of statistical data, the KIM digital communication service, and health insurance companies' central processing services "will be available again shortly."

Bitmarck said it's also looking into setting up a short-term IT environment to bring health insurers' central processes — such as payments — back online.  

While its IT and security teams are "working to restore the systems as quickly as possible," it may be a while before its managed services are performing at pre-cyberattack levels," the company warned. According to the notice:

Even if BITMARCK is gradually providing services again for the first statutory health insurance companies and some statutory health insurance companies are hardly affected by the disruptions, there will continue to be considerable restrictions in day-to-day business for the foreseeable future. This is due to the fact that in some cases entire BITMARCK data centers were taken offline, individual services may have to be shut down again and the restarting of individual services is associated with renewed temporary service failures. In order to fully restore normal operation, emergency solutions must also be switched back to normal operation, which can lead to short-term service failures.

Bitmarck "cannot answer" the question of who attacked its network and how, and at press time did not respond to The Register's inquires about how the intruders broke in, and what data they accessed in the breach.

After the firm's early warning tool detected a breach of one of its internal systems, Bismarck said it "immediately" informed law enforcement and government regulators, and brought in external security experts.

"The specialists of the LKA are also closely involved in the analysis of the facts," the biz said. "BITMARCK is also working closely with its customers, the Federal Ministry of Health, associations, Gematik and other players in the healthcare market to process the incident." ®

Send us news
6 Comments

Ex-CEO of 'unicorn' app startup HeadSpin heads to jail after BS'ing investors

Lachwani faked it but didn't make it

Governments issue alerts after 'sophisticated' state-backed actor found exploiting flaws in Cisco security boxes

Don't get too comfortable: 'Line Dancer' malware may be targeting other vendors, too

Cisco creates architecture to improve security and sell you new switches

Hypershield detects bad behavior and automagically reconfigures networks to snuff out threats

OpenAI's GPT-4 can exploit real vulnerabilities by reading security advisories

While some other LLMs appear to flat-out suck

Microsoft squashes SmartScreen security bypass bug exploited in the wild

Plus: Adobe, SAP, Fortinet, VMware, Cisco issue pressing updates

Australia’s spies and cops want ‘accountable encryption’ - aka access to backdoors

And warn that AI is already being used by extremists to plot attacks

Germany arrests trio accused of trying to smuggle naval military tech to China

Prosecutors believe one frikkin' laser did make its way to Beijing

Ransomware feared as IT 'issues' force Octapharma Plasma to close 150+ centers

Source blames BlackSuit infection – as separately ISP Frontier confirms cyberattack

185K people's sensitive data in the pits after ransomware raid on Cherry Health

Extent of information seized will be a concern for those affected

Japanese government rejects Yahoo<i>!</i> infosec improvement plan

Just doesn't believe it will sort out the mess that saw data leak from LINE messaging app

Indian bank’s IT is so shabby it’s been banned from opening new accounts

After two years of warnings, and outages, regulators ran out of patience with Kotak Mahindra Bank

Cybercriminals threaten to leak all 5 million records from stolen database of high-risk individuals

It’s the second time the World-Check list has fallen into the wrong hands