2023 - Cyber Threats To US Infrastructure 

Cyber attacks in the US have significantly increased over the past year, with the health care system and other critical sectors being attacked as the threat of malware like ransomware and foreign spyware continues to evolve. 

2022 saw US government officials and lawmakers renew their focus on cyber security and seek to secure the country’s critical sectors from rising cyber threats. This issue is expected to increase in 2023, as many of those threats are still escalating while the cyber sector is confronting an ongoing workforce shortage in its efforts to bolster the US’s digital defenses.

In addition to deploying ransomware, the threat actors have used “double extortion” techniques, whereby they exfiltrate data and demand a ransom payment to decrypt it, then threaten to expose the data if a ransom payment is not made.

Threats To Critical Sectors

The financial, energy and health care sectors are all facing a skyrocketing number of hacks. Cyber attacks have robbed companies in those industries of hundreds of millions of dollars, exposed data and even disrupted essential services, as when a ransomware attack forced the Colonial Pipeline to shut down in 2021, causing gas shortages in several states.

The health care sector in particular has seen a rise in cyber attacks in the last few years, particularly ransomware attacks targeting hospitals in order to gain access to sensitive information like patient data or medical research and technology. In Washington, Senator Mark Warne, chairman of the Senate Intelligence Committee, has warned that cyber attacks could lead to delays in treatment and even patients’ deaths.

US officials have already stepped up their efforts to protect critical sectors from those evolving threats, and have indicated that doing so will remain a top priority this year. Securing critical infrastructure like the energy and health care sectors plays a key part in mitigating cyber risks. 

Ransomware Attacks

Recent years have seen an especially dramatic spike in ransomware attacks, particularly targeting the health care and financial sectors. Last year, ransomware groups caused outages in multiple hospital systems, temporarily closed schools in parts of the US, carried out multimillion-dollar hacks on a number of companies and drove Costa Rica to declare a state of emergency in May as a barrage of attacks impacted its government services.

Tackling ransomware at home and abroad is also expected to take precedence this year as the US and its allies have come together to counter the heightened threat.

In 2021, the Biden administration, along with several other countries, launched its first annual initiative intended to counter ransomware globally. In November 2022, the White House held its 2nd International Counter Ransomware Initiative Summit, in which it invited more than 30 countries to discuss steps they can take to curb the rise of ransomware globally. “Ransomware is a pocketbook issue that impacts thousands of companies and individuals every year globally,” the White House said in a press release.

During the summit, the countries laid out several initiatives, including establishing an international counter-ransomware task force, actively sharing information between the public and private sectors and taking joint steps to stop ransomware actors using the crypto-currency system. The ransomware task force, which is led by Australia, is expected to become operational in January.

CISA:    The Hill:     CybeReason:   Cyberscoop:    FirerceHealthcare:      Silicon Republic:    Security Week:    

You Might Also Read: 

Critical Infrastructure: A Flashing Beacon For Cybercrime:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible






 

« Dissent Over British  Internet Safety Laws
The Application Of Artificial Intelligence In Cybersecurity »

CyberSecurity Jobsite
Check Point

Directory of Suppliers

IT Governance

IT Governance

IT Governance is a leading global provider of information security solutions. Download our free guide and find out how ISO 27001 can help protect your organisation's information.

Tines

Tines

The Tines security automation platform helps security teams automate manual tasks, making them more effective and efficient.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

Syxsense

Syxsense

Syxsense brings together endpoint management and security for greater efficiency and collaboration between IT management and security teams.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

ReadWrite

ReadWrite

ReadWrite is a leading media platform dedicated to IoT and the Connected World.

Synopsys

Synopsys

Synopsys delivers trusted and comprehensive silicon to systems design solutions, from electronic design automation to silicon IP and system verification and validation.

Kent Interdisciplinary Research Centre in Cyber Security (KirCCS) - University of Kent

Kent Interdisciplinary Research Centre in Cyber Security (KirCCS) - University of Kent

KirCCS harnesses expertise across Kent University to address current and potential cyber security challenges.

Compnet

Compnet

Compnet is a service company that assists customers in integrating complete ICT systems including network infrastructure and security solutions.

Advisera 27001Academy

Advisera 27001Academy

Advisera is a market leader in providing documentation and online support for the implementation of business standards including ISO 27001, ISO 22301 and EU GDPR.

Osirium

Osirium

The Osirium PxM Privileged Access Management platform addresses both security and compliance requirements by defining who gets access to what and when.

CONCORDIA

CONCORDIA

Concordia is a Cybersecurity Competence Network with leading research, technology, and competences to build the European Secure, Resilient and Trusted Ecosystem.

Enea

Enea

Enea is one of the world’s leading specialists in software for telecommunications and cybersecurity. Our products are used to enable services for mobile subscribers, enterprise customers and IoT.

CliftonLarsonAllen (CLA)

CliftonLarsonAllen (CLA)

CLA exists to create opportunities for our clients through industry-focused advisory, outsourcing, audit, tax, and consulting services.

tru.ID

tru.ID

We’re tru.ID, and we're reimagining mobile authentication, one API at a time.

Arctic Group

Arctic Group

Arctic Group is a Swedish service provider focusing on cybersecurity, integration services and deployment of software development tools.

Lighthouse IT

Lighthouse IT

At Lighthouse IT, we are focused on delivering seamless and reliable services to unlock the value of technology for your business.

NST Cyber

NST Cyber

NST Cyber provides comprehensive Threat Exposure Management to Global banks and Forbes 2000 companies.

INTfinity Consulting

INTfinity Consulting

The INTfinity team brings together decades of professional experience in cybersecurity. We're here to apply that same experience and proficiency in defending your networks.

SafeShark

SafeShark

SafeShark are Product Security and Telecommunications Infrastructure (PTSI) Act and Radio Equipment Directive (RED) compliance specialists.

Forsyte IT Solutions

Forsyte IT Solutions

Forsyte Guardian 365 provides 24x7x365 personalized protection to keep your most valuable assets safe.