Epidemic: Researchers Find Thousands of Medical Systems Exposed to Hackers
ID: c67e2efe-c1ab-5528-8497-fa9150ff9913
STIX ID: report--c67e2efe-c1ab-5528-8497-fa9150ff9913
Feed Name: Security Ledger
Researchers demonstrated at DerbyCon that searches using Shodan uncovered approximately 68,000 medical devices and clinical systems exposed to the public Internet — including PACS, MRI, infusion pumps and GE Healthcare systems — many accessible via default or vendor-documented credentials (they found ~130 credential sets and weak passwords like "bigguy"). Back-end storage often lacked proper permissions, enabling easy file access; combined with common physical access opportunities and phishing, these exposures create high risk for patient data theft, network pivoting and long-term attacker persistence, while remediation is slow due to device lifecycles and approval processes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
