DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Fr: Baclesse cuts its Internet connection to prevent the spread of a computer worm

Posted on April 30, 2021 by chum1ng0

The Centre François Baclesse is one of three proton therapy centers for fighting cancer in France. This week, they also had to fight the results of a cyberattack by heartless criminals. Thankfully, their recent investment in improving their cybersecurity seems to have paid off. On April 28, the center issued the following statement on their web site (translation):

The IT department of the François Baclesse Center detected and blocked a “worm” type computer virus on April 21 at 9 pm.

The purpose of this malicious program was:

– retrieve data;
– encrypt them so that they could no longer be read;
– then blackmail to restore this data.

The Internet connection of the François Baclesse Center was cut off for 6 days to prevent the worm from leaving with data and spreading outside. The analysis showed that one third of the IT park had been affected.

For 6 days, the IT department performed complete checks on our information system (servers and computer stations) while protecting our external partners.

No data was lost, no data was stolen, no data was encrypted. All our care services continued to function normally, with no impact on patients (no appointment delays, no treatment delays, etc.).

Fortunately, the Center’s IT department had been trained to react to such situations. Following cyber-attacks in other hospitals, the François Baclesse Center very recently took the decision to invest heavily in IT security, for a total budget of €100,000. The security solution implemented in January 2021 made it possible to quickly detect and contain the malware.

The origin of the worm’s appearance has been identified: it was the consultation of a website from which the “PC 0” computer was infected. This security flaw is now fixed. The situation is healthy and it is planned to further strengthen user vigilance through educational actions.

It’s not totally clear to DataBreaches.net what that explanation in the last paragraph means, but we may not be translating properly.

Update: Thanks to @fs0c131y, who informs us that “PC 0” refers to the first infected PC.

Category: Health DataMalwareNon-U.S.

Post navigation

← Cyberspies target military organizations with new Nebulae backdoor
Babuk closes one shop, switches to RaaS? →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • DOJ’s Data Security Program: Key Compliance Considerations for Impacted Entities
  • UBS reports data leak after cyber attack on provider, client data unaffected
  • Scania confirms insurance claim data breach in extortion attempt
  • Cybersecurity takes a big hit in new Trump executive order
  • Episource notifying 5.4 million patients of cyberattack in January
  • Investigation of 2024 Helsinki data breach – Report
  • Major trial underway for data leak that left 72,000 victims in France
  • Anubis: A Closer Look at an Emerging Ransomware with Built-in Wiper
  • HealthEC Agrees to $5.48 Million Settlement to End Data Breach Lawsuit
  • US offering $10 million for info on Iranian hackers behind IOControl malware

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • DOJ’s Data Security Program: Key Compliance Considerations for Impacted Entities
  • 23andMe fined £2.31 million for failing to protect UK users’ genetic data
  • DOJ Seeks More Time on Tower Dumps
  • Your household smart products must respect your privacy – including your air fryer
  • Vermont signs Kids Code into law, faces legal challenges
  • Data Categories and Surveillance Pricing: Ferguson’s Nuanced Approach to Privacy Innovation
  • Anne Wojcicki Wins Bidding for 23andMe

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.