{"id":9588,"date":"2021-04-30T13:26:25","date_gmt":"2021-04-30T10:26:25","guid":{"rendered":"https:\/\/www.kaspersky.com.tr\/blog\/?p=9588"},"modified":"2021-04-30T13:26:25","modified_gmt":"2021-04-30T10:26:25","slug":"ransomware-vs-healthcare","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.tr\/blog\/ransomware-vs-healthcare\/9588\/","title":{"rendered":"Sa\u011fl\u0131k hizmetlerine y\u00f6nelik fidye yaz\u0131l\u0131m\u0131 sald\u0131r\u0131lar\u0131"},"content":{"rendered":"<p>Bir klinik veya hastaneye d\u00fczenlenen bir siber sald\u0131r\u0131, kelimenin tam anlam\u0131yla bir \u00f6l\u00fcm kal\u0131m meselesidir. 2020\u2019de ya\u015fanan COVID-19 salg\u0131n\u0131 nedeniyle zaten zor zamanlar ge\u00e7iren d\u00fcnya genelindeki sa\u011fl\u0131k sistemlerinin i\u015f y\u00fck\u00fcne bir de siber su\u00e7lular\u0131n eylemlerinin neden oldu\u011fu y\u00fck eklendi. Sa\u011fl\u0131k kurumlar\u0131 a\u00e7\u0131s\u0131ndan ge\u00e7en y\u0131l\u0131n en \u00f6nemli tehditlerinden biri, siber su\u00e7lular\u0131n verileri \u015fifreledi\u011fi veya \u00e7al\u0131nan verileri yay\u0131nlamakla tehdit ederek para s\u0131zd\u0131rd\u0131\u011f\u0131 siber sald\u0131r\u0131 olan fidye yaz\u0131l\u0131m\u0131 sald\u0131r\u0131lar\u0131 kaynakl\u0131 tehditlerdi.<\/p>\n<p>Bu t\u00fcr sald\u0131r\u0131lar \u00e7ok \u00e7e\u015fitli sonu\u00e7lar do\u011furabilir. Sa\u011fl\u0131k kurumlar\u0131, sald\u0131r\u0131lar\u0131n sa\u011fl\u0131k hizmetlerinde neden olaca\u011f\u0131 bariz ve tehlikeli kesintilerine ek olarak, yasal para cezalar\u0131ndan ki\u015fisel verileri ihlal edilen hastalar\u0131n \u015fikayetlerine kadar uzanan, etkileri uzun s\u00fcre devam eden sonu\u00e7larla kar\u015f\u0131 kar\u015f\u0131ya kalabilir.<\/p>\n<h2><strong><em>Kamuoyunun dikkatini \u00e7eken fidye yaz\u0131l\u0131m\u0131 olaylar\u0131 <\/em><\/strong><\/h2>\n<p>Ge\u00e7en y\u0131l\u0131n en \u00e7ok konu\u015fulan ve fidye yaz\u0131l\u0131m\u0131 sald\u0131r\u0131lar\u0131n\u0131n sebep olaca\u011f\u0131 sorunlar\u0131n boyutunu g\u00f6zler \u00f6n\u00fcne seren vakalardan biri, ge\u00e7en Eyl\u00fcl ay\u0131nda<a href=\"https:\/\/www.nbcnews.com\/tech\/security\/cyberattack-hits-major-u-s-hospital-system-n1241254\" target=\"_blank\" rel=\"noopener nofollow\"> Universal Health Services\u2019a (UHS) d\u00fczenlenen<\/a> Ryuk fidye yaz\u0131l\u0131m\u0131 sald\u0131r\u0131s\u0131yd\u0131. Grubun, Amerika Birle\u015fik Devletleri, Birle\u015fik Krall\u0131k ve di\u011fer \u00fclkelerde faaliyet g\u00f6steren 400 sa\u011fl\u0131k kurumu bulunuyor. Neyse ki, ABD\u2019nin baz\u0131 eyaletlerinde faaliyet g\u00f6steren hastane ve klinikler d\u0131\u015f\u0131nda sald\u0131r\u0131dan etkilenen ba\u015fka UHS tesisi bulunmuyordu. Bir pazar sabah\u0131 erken saatlerde meydana gel gelen olayda \u015firketin bilgisayarlar\u0131 \u00f6ny\u00fckleme yapamad\u0131 ve baz\u0131 \u00e7al\u0131\u015fanlara fidye talebi g\u00f6nderildi. Sald\u0131r\u0131dan telefon a\u011f\u0131 da etkilendi. BT departman\u0131 personelden eski usulle, yani BT sistemleri olmadan \u00e7al\u0131\u015fmalar\u0131n\u0131 istemek zorunda kald\u0131. Do\u011fal olarak bu durum, hasta bak\u0131m\u0131, laboratuar testleri gibi klini\u011fin ola\u011fan ak\u0131\u015f\u0131nda olan bir \u00e7ok s\u00fcre\u00e7te b\u00fcy\u00fck kesintilere neden oldu. Baz\u0131 tesisler hastalar\u0131 di\u011fer hastanelere sevk etmek zorunda kald\u0131.<\/p>\n<p>UHS\u2019nin yapt\u0131\u011f\u0131 <a href=\"https:\/\/www.uhsinc.com\/statement-from-universal-health-services\/\" target=\"_blank\" rel=\"noopener nofollow\">resmi a\u00e7\u0131klamada<\/a>, \u201cherhangi bir hasta veya \u00e7al\u0131\u015fan verisine yetkisiz eri\u015fim sa\u011fland\u0131\u011f\u0131na, verilerin kopyaland\u0131\u011f\u0131na veya k\u00f6t\u00fcye kullan\u0131ld\u0131\u011f\u0131na ili\u015fkin bir kan\u0131t bulunmad\u0131\u011f\u0131n\u0131\u201d belirtiyordu. Bu y\u0131l\u0131n Mart ay\u0131nda \u015firket, veri kurtarma maliyetleri, kesinti nedeniyle ya\u015fanan gelir kayb\u0131, hasta say\u0131s\u0131n\u0131n azalmas\u0131 ve daha bir \u00e7ok olumsuzluk da dahil olmak \u00fczere ger\u00e7ekle\u015fen sald\u0131r\u0131n\u0131n neden oldu\u011fu zarar\u0131n 67 milyon dolar oldu\u011funu belirten bir rapor yay\u0131nlad\u0131.<\/p>\n<p>Ayn\u0131 zamanda, b\u00f6brek hastal\u0131klar\u0131na y\u00f6nelik test hizmetlerinde uzmanla\u015fan <a href=\"https:\/\/www.hipaajournal.com\/ascend-clinical-and-alamance-skin-center-suffer-ransomware-attacks\/\" target=\"_blank\" rel=\"noopener nofollow\">Ascend Clinical\u2019\u0131n ya\u015fad\u0131\u011f\u0131 bir olayda<\/a>, 77.000\u2019den fazla hastay\u0131 etkileyen bir veri s\u0131z\u0131nt\u0131s\u0131 ger\u00e7ekle\u015fti. S\u0131z\u0131nt\u0131n\u0131n nedeni bilindik bir durumdu: Bir \u00e7al\u0131\u015fan, kimlik av\u0131 e-postas\u0131nda yer alan bir ba\u011flant\u0131ya t\u0131klam\u0131\u015ft\u0131. Sisteme s\u0131zan sald\u0131rganlar, di\u011fer verilerin yan\u0131 s\u0131ra hastalar\u0131n ki\u015fisel verilerini de \u2014 isimleri, do\u011fum tarihleri, sosyal g\u00fcvenlik numaralar\u0131 \u2014 ele ge\u00e7irdiler.<\/p>\n<p>Nisan 2020\u2019de <a href=\"https:\/\/healthitsecurity.com\/news\/magellan-health-data-breach-victim-tally-reaches-365k-patients\" target=\"_blank\" rel=\"noopener nofollow\">Magellan Health\u2019e d\u00fczenlenen bir sald\u0131r\u0131da<\/a> ise, hem \u00e7al\u0131\u015fanlar\u0131n hem de hastalar\u0131n ki\u015fisel verileri ihlal edildi (bas\u0131nda \u00e7\u0131kan haberlere g\u00f6re sald\u0131r\u0131dan etkilenen kurban say\u0131s\u0131 365.000\u2019di). Siber su\u00e7lular, sosyal m\u00fchendislik yoluyla bir m\u00fc\u015fteriyi taklit ederek, i\u00e7 a\u011fa eri\u015fim sa\u011flamay\u0131, oturum a\u00e7ma bilgilerini ele ge\u00e7irmek i\u00e7in k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m kullanmay\u0131 ve nihayetinde sunucudaki verileri \u015fifrelemeyi bir \u015fekilde ba\u015fard\u0131lar.<\/p>\n<p>Genelleme yaparsak, siber su\u00e7lular sa\u011fl\u0131k kurumlar\u0131na sald\u0131r\u0131rken, i\u015f istasyonlar\u0131n\u0131n yerine sunuculardaki verileri \u015fifrelemeyi ve \u00e7almay\u0131 tercih ediyor. Sald\u0131rganlar\u0131n Florida Ortopedi Enstit\u00fcs\u00fc\u2019n\u00fcn sunucular\u0131nda eri\u015ftikleri 640.000 hastaya ait veriyi \u015fifreledi\u011finde (\u00f6ncesinde \u00e7ald\u0131klar\u0131) ya\u015fanan durum da ayn\u0131s\u0131yd\u0131. Bu olay, olduk\u00e7a tats\u0131z \u015fekilde <a href=\"https:\/\/www.hipaajournal.com\/florida-orthopaedic-institute-facing-class-action-lawsuit-over-ransomware-attack\/\" target=\"_blank\" rel=\"noopener nofollow\">toplu dava<\/a> a\u00e7\u0131lmas\u0131yla sonu\u00e7land\u0131.<\/p>\n<p>Yukar\u0131da bahsetti\u011fimiz olaylar, ge\u00e7en y\u0131l haberlerde yer alan ve kamuoyunun dikkatini \u00e7eken olaylara ili\u015fkin yaln\u0131zca birka\u00e7 \u00f6rnek. Asl\u0131nda, yukar\u0131da verdi\u011fimiz \u00f6rneklere benzer onlarca olay daha ya\u015fand\u0131.<\/p>\n<h2>Sa\u011fl\u0131k kurumlar\u0131 g\u00fcvenliklerini nas\u0131l sa\u011flayabilir<\/h2>\n<p>K\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m bir sisteme \u00e7ok \u00e7e\u015fitli yollarla girebilir: E-posta ekleri, kimlik av\u0131 ba\u011flant\u0131lar\u0131, vir\u00fcsl\u00fc internet siteleri ve daha bir\u00e7ok y\u00f6ntem. Sald\u0131rganlar kullan\u0131c\u0131lara ait uzaktan eri\u015fim kimlik bilgilerini \u00e7alabilir, sosyal m\u00fchendislik yoluyla onlar\u0131 kand\u0131rabilir veya sadece <a href=\"https:\/\/encyclopedia.kaspersky.com\/glossary\/brute-force\/\" target=\"_blank\" rel=\"noopener\">zor kullanarak (brute force)<\/a> bilgileri ele ge\u00e7irmeye \u00e7al\u0131\u015fabilir. Tedbir tedaviden iyidir \u015feklindeki eski bir t\u0131p atas\u00f6z\u00fc, siber g\u00fcvenlik i\u00e7in ve en az\u0131ndan fidye yaz\u0131l\u0131mlar\u0131na kar\u015f\u0131 koruma i\u00e7in de ayn\u0131 \u015fekilde ge\u00e7erlidir. \u0130\u015fte siber g\u00fcvenlikle ilgili al\u0131nacak tedbirler konusunda size verece\u011fimiz ipu\u00e7lar\u0131:<\/p>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kasap\">\n<ul>\n<li>Yaln\u0131zca bilgisayarlar\u0131 de\u011fil <a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">t\u00fcm cihazlar\u0131<\/a> koruyun. \u015eirkete ait ak\u0131ll\u0131 telefonlar\u0131, tabletleri, terminalleri, bilgi kiosklar\u0131n\u0131, t\u0131bbi ekipman\u0131 ve kurumsal a\u011fa ve internete eri\u015fimi olan di\u011fer her \u015feyi.<\/li>\n<li>B\u00fct\u00fcn cihazlar\u0131n\u0131z\u0131 g\u00fcncel tutun. Ve yine bu konuda da sadece bilgisayarlarla s\u0131n\u0131rl\u0131 kalmay\u0131n. Siber g\u00fcvenlikten bahsetti\u011fimizde akl\u0131n\u0131za gelen ilk \u015fey bir tomografi olmayabilir, ancak tomografi cihaz\u0131 ayn\u0131 zamanda g\u00fcvenlik a\u00e7\u0131\u011f\u0131 bulunabilecek bir i\u015fletim sistemine sahip bir bilgisayard\u0131r. \u0130deal olan, ekipman se\u00e7iminde g\u00fcvenlik konusunun dikkate al\u0131nmas\u0131 gereken bir konu olmas\u0131d\u0131r \u2014 en az\u0131ndan sat\u0131n almadan \u00f6nce ekipman sat\u0131c\u0131s\u0131n\u0131n yaz\u0131l\u0131m g\u00fcncellemeleri yay\u0131nlad\u0131\u011f\u0131n\u0131 teyit etmesini isteyin;<\/li>\n<li><a href=\"https:\/\/www.kaspersky.com.tr\/small-to-medium-business-security\/mail-server?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener\">E-posta korumas\u0131<\/a> sa\u011flayan g\u00fcvenlik \u00e7\u00f6z\u00fcmleri y\u00fckleyin. Elektronik ileti\u015fimin korunmas\u0131 hayati \u00f6nem ta\u015f\u0131yor; t\u0131bbi kurulu\u015flar, spam dahil olmak \u00fczere, yaln\u0131zca zarars\u0131z \u00e7\u00f6p i\u00e7erik de\u011fil ayn\u0131 zamanda tehlikeli ekler de i\u00e7erebilen \u00e7ok say\u0131da e-posta al\u0131r;<\/li>\n<li>T\u00fcm \u00e7al\u0131\u015fanlar\u0131 \u2014 di\u011fer deyi\u015fle y\u00f6neticileri<em>,<\/em> doktorlar\u0131 <em>ve<\/em> teknolojiye dokunan herkesi \u2014 <a href=\"https:\/\/k-asap.com\/tr\/?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______&amp;utm_source=kdaily&amp;utm_medium=blog&amp;utm_campaign=tr_wpplaceholder_nv0092&amp;utm_content=link&amp;utm_term=tr_kdaily_organic_avmwswubv8qh92b\" target=\"_blank\" rel=\"noopener\">siber g\u00fcvenlik fark\u0131ndal\u0131\u011f\u0131n\u0131n temelleri<\/a> konusunda e\u011fitin. T\u0131bbi kay\u0131tlar\u0131n dijital ortama aktar\u0131lmas\u0131ndan \u00e7evrimi\u00e7i video yoluyla ger\u00e7ekle\u015ftirilen kons\u00fcltasyona kadar sa\u011fl\u0131k alan\u0131ndaki s\u00fcre\u00e7lerin daha fazla b\u00f6l\u00fcm\u00fc elektronik hale geliyor. Ameliyat s\u0131ras\u0131nda maske kullan\u0131m\u0131 gibi siber g\u00fcvenlik bilincinin de rutin bir g\u00fcvenlik \u00f6nlemi haline gelmesi gerekir.<\/li>\n<\/ul>\n<p>\u00a0<\/p>\n<ul>\n<li>Bir\u00e7ok modern fidye yaz\u0131l\u0131m\u0131 sald\u0131r\u0131s\u0131, \u201cmanuel\u201d olarak adland\u0131rd\u0131\u011f\u0131m\u0131z y\u00f6ntemle ger\u00e7ekle\u015ftiriliyor. Di\u011fer bir deyi\u015fle, modern fidye yaz\u0131l\u0131m\u0131 sald\u0131r\u0131lar\u0131n\u0131n ard\u0131ndaki siber su\u00e7lular, rastgele yap\u0131lan bir k\u00f6t\u00fc ama\u00e7l\u0131 yaz\u0131l\u0131m\u0131 bombard\u0131man\u0131 yerine, genellikle se\u00e7tikleri belirli kurbanlar\u0131n bilgisayarlar\u0131na ve sunucular\u0131na sosyal m\u00fchendislik sanat\u0131ndan yararlanarak fidye yaz\u0131l\u0131m\u0131 yollar\u0131n\u0131 bula\u015ft\u0131rman\u0131n ar\u0131yorlar. Kimi zaman bir a\u011fa s\u0131zd\u0131ktan sonra, hemen aksiyona ge\u00e7mek yerine en de\u011ferli verileri bulmak amac\u0131yla altyap\u0131y\u0131 uzun s\u00fcre incelerler. U\u00e7 nokta korumas\u0131n\u0131n kar\u015f\u0131 koymakta yeterli olamayabilece\u011fi bu t\u00fcr sald\u0131r\u0131lar\u0131 tespit etmek i\u00e7in, altyap\u0131n\u0131z\u0131 uzaktan izlemek \u00fczere bir <a href=\"https:\/\/www.kaspersky.com\/enterprise-security\/managed-detection-and-response?icid=tr_kdailyplacehold_acq_ona_smm__onl_b2b_kasperskydaily_wpplaceholder_______\" target=\"_blank\" rel=\"noopener nofollow\">y\u00f6netilen tespit yan\u0131t hizmeti<\/a> alman\u0131z\u0131 \u00f6neriyoruz.<\/li>\n<\/ul>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"kesb-ransomware\">\n","protected":false},"excerpt":{"rendered":"<p>Sa\u011fl\u0131k hizmetlerine y\u00f6nelik kamuoyunda dikkat \u00e7eken fidye yaz\u0131l\u0131m\u0131 sald\u0131r\u0131lar\u0131n\u0131 g\u00f6z \u00f6n\u00fcnde bulundurdu\u011fumuzda, i\u015fletmenizi tehditten korumak i\u00e7in yapman\u0131z gerekenler bu yaz\u0131m\u0131zda.<\/p>\n","protected":false},"author":2581,"featured_media":9589,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1726,1194],"tags":[591,2362,2411,1975],"class_list":{"0":"post-9588","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-enterprise","8":"category-business","9":"tag-fidye-yazilimi","10":"tag-para-sizdirma","11":"tag-saglik-hizmetleri","12":"tag-veri-sizintilari"},"hreflang":[{"hreflang":"tr","url":"https:\/\/www.kaspersky.com.tr\/blog\/ransomware-vs-healthcare\/9588\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/ransomware-vs-healthcare\/22793\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/ransomware-vs-healthcare\/18275\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/ransomware-vs-healthcare\/24681\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/ransomware-vs-healthcare\/22670\/"},{"hreflang":"es-mx","url":"https:\/\/latam.kaspersky.com\/blog\/ransomware-vs-healthcare\/21794\/"},{"hreflang":"es","url":"https:\/\/www.kaspersky.es\/blog\/ransomware-vs-healthcare\/25163\/"},{"hreflang":"it","url":"https:\/\/www.kaspersky.it\/blog\/ransomware-vs-healthcare\/24544\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/ransomware-vs-healthcare\/30604\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/ransomware-vs-healthcare\/39635\/"},{"hreflang":"fr","url":"https:\/\/www.kaspersky.fr\/blog\/ransomware-vs-healthcare\/16861\/"},{"hreflang":"pt-br","url":"https:\/\/www.kaspersky.com.br\/blog\/ransomware-vs-healthcare\/17412\/"},{"hreflang":"pl","url":"https:\/\/plblog.kaspersky.com\/ransomware-vs-healthcare\/14784\/"},{"hreflang":"de","url":"https:\/\/www.kaspersky.de\/blog\/ransomware-vs-healthcare\/26594\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/ransomware-vs-healthcare\/30659\/"},{"hreflang":"nl","url":"https:\/\/www.kaspersky.nl\/blog\/ransomware-vs-healthcare\/26984\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/ransomware-vs-healthcare\/23834\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/ransomware-vs-healthcare\/29169\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/ransomware-vs-healthcare\/28966\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.tr\/blog\/tag\/fidye-yazilimi\/","name":"Fidye Yaz\u0131l\u0131m\u0131"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9588","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/users\/2581"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/comments?post=9588"}],"version-history":[{"count":1,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9588\/revisions"}],"predecessor-version":[{"id":9590,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/posts\/9588\/revisions\/9590"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media\/9589"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/media?parent=9588"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/categories?post=9588"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.tr\/blog\/wp-json\/wp\/v2\/tags?post=9588"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}