Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Cybersecurity Threats To The COVID-19 Vaccine
Articles

Cybersecurity Threats To The COVID-19 Vaccine

Raymond PomponBy Raymond PomponMarch 23, 2021Updated:February 9, 20236 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

We’ve already seen our fair share of pandemic-driven fraud and cybercrime, but what can we expect as vaccine rollouts pick up pace worldwide?

Cyber Espionage to Steal Vaccine Data

A viable vaccine is valuable intellectual property. Beyond the pharmaceutical formula itself, even data on testing and drug trials can be valuable to an organization working to develop its own drug. With countries struggling to secure an effective vaccine,2 such data is a tempting target. We’ve already seen some attacks.

In late 2020, North Korean cyber attackers reportedly targeted the vaccine maker AstraZeneca in the UK.3 They apparently used spear phishing via social media to try to inject malware by way of job description documents. Over the summer, Russian cyber attackers were also detected in a vaccine theft attempt.4

Threat actors on the hunt for vaccine data are advanced cyber attackers, either working for or hired by nation states. This makes them the most capable and well-resourced threat that organizations could face.

The goal of these attackers is unauthorized access to information, such as data related to research proposals, drug development, manuscripts, virus testing, clinical trials, and drug manufacturing.

Healthcare and drug research facilities tend to have elevated security controls to protect their intellectual property. However, cyber attacks will also target their business partners and third parties, which may have lower levels of security.

The likelihood of vaccine cyber espionage is high, and we’ve already seen attacks targeting coronavirus research organizations, including academic institutions, biomedical research laboratories, pharmaceutical companies, hospitals, and drug manufacturers.

Sabotage the Vaccine Pipeline

In October 2020, a large U.S. clinical trial software manufacturer involved in coronavirus drug testing experienced a ransomware attack.5 And we’ve seen ransomware and malware hitting hospitals regularly.

In 2017, the NotPetya malware attack that targeted Ukraine appeared to be ransomware but later, experts concluded that it was a denial-of-service weapon wielded by Russian threat actors. The software was designed to be more crippling than ransomware; not just encrypting data but wiping it out permanently.6

The cooling systems required by vaccines are also vulnerable to cyberattack, especially if they are tied to IoT controls. As we’ve seen over the years, IoT systems have very poor security controls and are often subverted and infected by malware. We have also seen anti-vaccine activists in trusted positions physically sabotaging vaccine cooling systems.7 IoT tampering would be much easier and potentially harder to trace.

Cybercriminals could stand to make a lot of money by slowing or crippling vaccine distribution efforts. But it also would be easy for competitor nation states to use ransomware (and cybercriminals) to conceal other sinister moves such as slowing down a nation’s recovery. Right now, the vaccine pipeline is as essential as much of our other critical infrastructure.

Vaccine saboteurs are likely to be highly motivated and well-resourced, and the newer versions of ransomware are faster, smarter, and stealthier than before. Attackers are looking to deny access to data and critical computing resources, either short-term for ransom payment or as long as possible to sabotage the rollout.

Many targeted facilities are regulated and aware of the threat of malware. But, again, third parties are a potential Achilles heel. Many smaller clinics, retail drugstores, regional government agencies, and other entities with reduced cybersecurity capabilities are also potential victims.

Using Stolen Vaccine Data for Disinformation

In October of 2020, the Centre for Countering Digital Hate reported that 50 million people follow anti-vaccine groups on social media.8  In January of 2021, regulatory data regarding the COVID-19 vaccine was stolen by cyber attackers, reportedly to fuel disinformation campaigns.9

In the past, F5 Labs wrote about how hacktivists can use doxing (the unauthorized release of private or personal information) to intimidate or embarrass an opponent. We also noted that leakers can release carefully curated and incriminating emails or confidential documents, which can be effective against organizations or public figures. Sometimes they will modify leaked vaccine data prior to publication in an attempt to sow disinformation.10

 Vaccine Cyber Thieves

The most proficient attackers are hostile nation states that use misinformation to slow down vaccinations.

There are also the anti-vaxxers, who tend to act as a loose confederation.

It is important to note that the anti-vaxxer movement isn’t only about fear or ignorance, but also about profit. There are individuals and groups attempting to discredit vaccines in order to sell alternative medical therapies for COVID-19.12

The attackers’ goal here is to violate confidentiality by stealing data for disclosure. They may modify that stolen data to help sway opinion. The targeted assets are the same as the cyber espionage attacker’s, most notably research data, virus testing, and clinical trials that show side effects or potential problems.

Most targeted organizations will be subject to regulation and intellectual property protection. However, their connections with third parties can expand the attack surface.  Furthermore, individual researchers’ personal accounts, such as home emails, are also potential targets. These could perhaps hold personal notes expressing vaccine doubts. which attackers could use to influence opinion.

Hacking the Vaccine Appointment System

The likely attackers here would be individuals with hacking skills and cyber criminals looking to sell vaccine access. Their capabilities would be variable but tending toward the lower end of the scale. There is a profit to be made, but it’s not as lucrative and easy as other cybercrime schemes. The ultimate goal is to weaken the integrity of the appointment system by unauthorized modifications or additions to the waiting list.

The controls around the vaccine registration systems are likely to be highly variable, but also tending towards the higher side, as they are also regulated medical systems.

Evidence of this type of criminal activity is starting to emerge. For example, a healthcare provider in Michigan recently cancelled 2,700 vaccine appointments after a breach allowed people to cut in line. The attempt failed, and the likelihood of similar successful attacks remains on the low side. There is a considerable risk of getting caught. Less traceable methods of getting early access to vaccines like bribing medical professionals are more likely.

Mitigation Against Vaccine Cyberthreats

If you or your organization have any role in the vaccine supply chain, you should evaluate your security and strengthen defences accordingly. The two most probable attacks are either by phishing or web attacks.

If you are an individual, a good resource is the Department of Justice Coronavirus Response web page, which gives information about COVID-19 fraud and steps to take to prevent or combat it. Before you start sharing personal or financial information online, it’s a good idea to double-check the request with state or local health department websites as well as the Centers for Disease Control and Prevention (CDC). You should never share health or financial information over untrustworthy Internet channels such as email or social media.

One warning though: Don’t spend too much time trying to figure out how attackers think. Even if we could perfectly understand their motives and methods (and we can’t), they will shift over time. The key is to assess the most likely kinds of attacks each system and asset could face, and build defences for them accordingly.

Raymond Pompon

Director F5 Labs, Threat Research, for F5 Networks

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    New Phishing Kit Starkiller Defeats Multi-Factor Authentication

    February 23, 20264 Mins Read

    ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

    January 22, 20266 Mins Read

    What Happens after a Phishing Email Lands in Your Inbox?

    January 5, 20266 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}