Practice lost $150,000 after cyber attack locked staff out of Best Practice

The deidentified story of the attack was shared at the RACGP Practice Owners Conference.

A practice hit by a ransomware attack that blocked access to Best Practice software ultimately faced a bill of some $150,000 to fix the damage, a conference has been told.

The deidentified story of the attack was shared at the RACGP Practice Owners Conference in Sydney by Jay Carters, the IT technician who was brought in to fix it.

Mr Carters from Databox Solutions said staff had turned up to work at 6.30am to discover they had no access to patient files or Best Practice software.

Patients were due to arrive within the hour, and a ransom email had just landed in the inbox.

It was written in partly broken English and made no mention of dollar figures it was demanding.

But it said the practice should negotiate with the hackers to get everything back to normal or else they would publish company data on what it described as a “popular public blog”.

Mr Carters said the first thing the practice did was call in one of its former IT technicians. They managed to restore the last data backup but did not get involved further.

After deciding to shut the clinic for the day, the practice manager then called Mr Carters in a panic.

Mr Carter said he had found various problems, including multiple staffers using the same passwords, no business-grade firewall and data backups that were only performed weekly and stored on a portable drive.

“The servers were like a mid-range gaming computer,” he noted.

Jay Carters. Photo: LinkedIn.

Mr Carters said the practice manager had repeatedly warned that the practice’s IT was outdated, but it had avoided upgrading because of the cost.

Mr Carters discovered that a doctor had clicked on a phishing email and unknowingly given their email password to hackers.

It was the same password used for the practice’s administrator server, while none of the accounts used multifactor authentication.

The entire server had to be rebuilt and all clinic computers reset and reconnected to Best Practice and other systems, Mr Carters said.

He had then performed an upgrade to Microsoft 365, set up multifactor authentication and daily cloud backups.

The practice did not pay any ransom or respond to the hackers’ vague demand for negotiations. But the cyber attack ultimately cost the practice owner about $150,000 in repairs, digital forensics and lost revenue.

He said a forensic specialist had later found stolen data for sale on the dark web, but he expected that its value would have depreciated fast.

He said Databox Solutions staff regularly saw practices with unlocked server cabinets, patient information left open on unattended computers and consumer-grade IT.

“Typically, when we engage with a practice, it starts with the practice manager, and it’s the same story every time,” he said.

“They say, ‘We don’t call IT because they overcharge us,’ or ‘The guy doesn’t get back to us.’

“They start to understand how to fix certain things themselves — ‘I know how to reset this printer,’ or ‘I know how to reset the server.’

“But it’s not their job, it’s not their area of expertise, and it shouldn’t be falling on them.”

He compared it to patients who wanted medical care from a pharmacist rather than a doctor.

“One of the analogies I use is, ‘I can go and pay to see a GP or I can jump on ChatGPT, enter my symptoms, and if I’ve not got too much of an ailment, it’s probably going to get most of the way. It might tell me what might fix my problem.’

“But what if there’s an underlying condition? What if there’s something that I’m missing that then pops up later?

“Just as they would recommend seeing a GP and don’t self-diagnose, we recommend the same thing.”


Read more: Hackers calling GP practice staff posing as IT to steal passwords, expert warns