Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty
Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty
Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty
Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty

Hackers target Pfizer exposing sensitive patient information


Nick Webster
  • English
  • Arabic

Hackers have broken through the "front door" of online data storage units used by pharmaceutical giant Pfizer and leaked hundreds of chatbot conversations and patient information.

Scores of victims could now be exposed to phishing scams after having their full names, home addresses and email contacts taken from a misconfigured Google Cloud storage bucket.

Data included hundreds of conversations between customers and chatbots enquiring about cancer drugs, epilepsy medication and Viagra.

It is not known how many patients were in the UAE.

When administrators leave the front door open it's unsurprising attackers walk straight in unnoticed

Cybercrime experts said the blunder could lead to patients inadvertently handing over bank card information to criminals claiming to process bogus prescriptions.

“While name, addresses, and email addresses are not highly sensitive information like birth dates or social security numbers, the conversations could reveal very private medical data,” said Morey Haber, chief technology officer at BeyondTrust, a cyber security company in the UAE.

“The information could easily lead to future spear phishing attacks because the details about an individual would make a potential attack credible.

“Pfizer did not know the data was accessible nor [that] it was obtained.

“It is feasible therefore to assume the data has been accessed in the past as well.”

Phishing is the most common technique used by hackers to extract restricted data or gain access to accounts by encouraging users to relinquish passwords.

Sensitive information about patients, who asked questions online about smoking cessation drug, Chantix, was also obtained by hackers.

The breach was reported to Pfizer and regulators by online security researchers at tech-company vpnMentor.

Pfizer headquarters in New York. Carlo Allegri / Reuters
Pfizer headquarters in New York. Carlo Allegri / Reuters

They said the information remained exposed online for months before action was taken to remove it in September.

It is the fifth similar failure to secure patient information by Pfizer, that has offices in Dubai Media City, following incidents in 2007 and 2019.

"Pfizer is aware that a small number of non-HIPAA data records on a vendor operated system used for feedback on existing medicines were inadvertently publicly available," Pfizer said in response.

"We take privacy and product feedback extremely seriously. To that end, when we became aware of this event we ensured the vendor corrected the issue and notifications compliant with applicable laws will be sent to individuals."

Industry experts said cloud storage is becoming increasingly difficult to secure as hacking techniques become more sophisticated.

In 2014, celebrities including Jennifer Lawrence, Rihanna and Kim Kardashian were among those who had compromising photos leaked online after cloud storage was hacked.

A two-step verification process was then introduced to bolster security around Apple’s iCloud data storage service.

“The recent Pfizer data breach tells us it is extremely difficult for even the largest companies in the world to secure their data every hour, every day and every week,” said Sam Curry, chief security officer at Cybereason, a company working with businesses in the UAE to bolster online defences.

“It's irrelevant whether an internal or external error led to this data breach.

“The digital footprint for enterprises is expanding at such a rapid pace, errors will occur and data will be exposed.

“Customers want transparency and guarantees that the company will continue to make sure data protection is their top priority.”

Read More

Chat conversations between human and chatbots that give an automated conversation response were some of the information exposed in the leak.

While replies were preprogrammed into the solution, humans would realistically have to answer a series of questions to determine the proper response.

Those questions were designed to provide a high confidence in the results and often forced the exposure of more information to obtain the desired results.

“As no system, or person, is ever perfect, the ability to monitor, detect and respond to unauthorised or malicious access to cloud services can make the difference between a contained security incident and a full-blown breach as being reported at Pfizer,” said Matt Walmsley, a tech industry analyst and director at Vectra AI.

“We performed analysis on Office 365 – the worlds most used software and service cloud – and identified how attackers are using existing tools and services within the cloud to spy and steal.

“When administrators inadvertently leave the front door open it’s unsurprising that attackers walk straight in and out unnoticed.”

If you go

The flights
There are various ways of getting to the southern Serengeti in Tanzania from the UAE. The exact route and airstrip depends on your overall trip itinerary and which camp you’re staying at. 
Flydubai flies direct from Dubai to Kilimanjaro International Airport from Dh1,350 return, including taxes; this can be followed by a short flight from Kilimanjaro to the Serengeti with Coastal Aviation from about US$700 (Dh2,500) return, including taxes. Kenya Airways, Emirates and Etihad offer flights via Nairobi or Dar es Salaam.   

Traits of Chinese zodiac animals

Tiger:independent, successful, volatile
Rat:witty, creative, charming
Ox:diligent, perseverent, conservative
Rabbit:gracious, considerate, sensitive
Dragon:prosperous, brave, rash
Snake:calm, thoughtful, stubborn
Horse:faithful, energetic, carefree
Sheep:easy-going, peacemaker, curious
Monkey:family-orientated, clever, playful
Rooster:honest, confident, pompous
Dog:loyal, kind, perfectionist
Boar:loving, tolerant, indulgent   

Real estate tokenisation project

Dubai launched the pilot phase of its real estate tokenisation project last month.

The initiative focuses on converting real estate assets into digital tokens recorded on blockchain technology and helps in streamlining the process of buying, selling and investing, the Dubai Land Department said.

Dubai’s real estate tokenisation market is projected to reach Dh60 billion ($16.33 billion) by 2033, representing 7 per cent of the emirate’s total property transactions, according to the DLD.

'Unrivaled: Why America Will Remain the World’s Sole Superpower'
Michael Beckley, Cornell Press

What is blockchain?

Blockchain is a form of distributed ledger technology, a digital system in which data is recorded across multiple places at the same time. Unlike traditional databases, DLTs have no central administrator or centralised data storage. They are transparent because the data is visible and, because they are automatically replicated and impossible to be tampered with, they are secure.

The main difference between blockchain and other forms of DLT is the way data is stored as ‘blocks’ – new transactions are added to the existing ‘chain’ of past transactions, hence the name ‘blockchain’. It is impossible to delete or modify information on the chain due to the replication of blocks across various locations.

Blockchain is mostly associated with cryptocurrency Bitcoin. Due to the inability to tamper with transactions, advocates say this makes the currency more secure and safer than traditional systems. It is maintained by a network of people referred to as ‘miners’, who receive rewards for solving complex mathematical equations that enable transactions to go through.

However, one of the major problems that has come to light has been the presence of illicit material buried in the Bitcoin blockchain, linking it to the dark web.

Other blockchain platforms can offer things like smart contracts, which are automatically implemented when specific conditions from all interested parties are reached, cutting the time involved and the risk of mistakes. Another use could be storing medical records, as patients can be confident their information cannot be changed. The technology can also be used in supply chains, voting and has the potential to used for storing property records.

Results

Women finals: 48kg - Urantsetseg Munkhbat (MGL) bt Distria Krasniqi (KOS); 52kg - Odette Guiffrida (ITA) bt Majlinda Kelmendi (KOS); 57kg - Nora Gjakova (KOS) bt Anastasiia Konkina (Rus)

Men’s finals: 60kg - Amiran Papinashvili (GEO) bt Francisco Garrigos (ESP); 66kg - Vazha Margvelashvili (Geo) bt Yerlan Serikzhanov (KAZ)

The Perfect Couple

Starring: Nicole Kidman, Liev Schreiber, Jack Reynor

Creator: Jenna Lamia

Rating: 3/5

Vidaamuyarchi

Director: Magizh Thirumeni

Stars: Ajith Kumar, Arjun Sarja, Trisha Krishnan, Regina Cassandra

Rating: 4/5

 

Polarised public

31% in UK say BBC is biased to left-wing views

19% in UK say BBC is biased to right-wing views

19% in UK say BBC is not biased at all

Source: YouGov