
The network was on the ambulance database of several cities in the Moscow Region. Openly available were names, addresses and telephones of patients, as well as data on their state of health. This is not the first case of personal data leakage lately.
About a document with a volume of 17.8 GB, laid out on a file hosting, writes RBC. It contains the data of ambulance substations in Mytishchi, Dmitrov, Dolgoprudny, Queen, Balashikha.
Anastasia Tikhonova, head of the Group-IB company, was not surprised at the base of the base, because, according to her, she was already in the public domain and did not require authorization or any other security settings.
“There are various specialized search engines that show available databases that can be connected,” explained Tikhonova. - Many hacker groups or researchers scan addresses and look for similar open databases (like Mongo). Not only is it not too ethical, but often very risky. The danger is that after leakage and publication of such databases, attackers can use these data. ”
Data was stored on an open cloud server, which was forgotten by password. The leak occurred through the Mongodb database control system with open source. The company believes that the Ukrainian group Thick3For is involved in the distribution of the base. Hactivists (activists using the hacking of computer networks to advance the ideology of freedom of speech and political freedoms), apparently, thus wanted to attract attention.
From the data that are released, you can find out the name of the ambulance, his contact phone number, address, date and call time, as well as a description of the patient's condition upon arrival of doctors.
“In this case, there are several violations at once-the FZ-152“ On Personal Data ”, the Order of the FSTEK No. 21, Decree of the Government 1119, the Decree of the Government 687 and the methodological recommendations for medical institutions,” said Anton Fishman, head of the Group-IB system decisions. “The fact that in this case a system is used in which all data is open and stored in Russia shows that its development and acceptance did not take into account the requirements of the law.”
Roskomnadzor will conduct an investigation about the leak of the patient database. It is worth noting that this is not the first scandal associated with a data leak in recent years. At the beginning of the month, 3 thousand participants in the “direct conversation” with the head of Transbaikalia were leaked on the Internet. The complaint was also filed in Roskomnadzor.
Recently, in the Lipetsk region, due to the negligence of employees of the regional health department, medical data of patients were also in the public domain: the department published the names, addresses and diagnoses on the public procurement website when announcing auctions. On this fact, the regional prosecutor's office organized an audit. The inspections were also reported by the territorial body of Roszdravnadzor and the health department of the Lipetsk region.