Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty
Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty
Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty
Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty

Hackers target Pfizer exposing sensitive patient information


Nick Webster
  • English
  • Arabic

Hackers have broken through the "front door" of online data storage units used by pharmaceutical giant Pfizer and leaked hundreds of chatbot conversations and patient information.

Scores of victims could now be exposed to phishing scams after having their full names, home addresses and email contacts taken from a misconfigured Google Cloud storage bucket.

Data included hundreds of conversations between customers and chatbots enquiring about cancer drugs, epilepsy medication and Viagra.

It is not known how many patients were in the UAE.

When administrators leave the front door open it's unsurprising attackers walk straight in unnoticed

Cybercrime experts said the blunder could lead to patients inadvertently handing over bank card information to criminals claiming to process bogus prescriptions.

“While name, addresses, and email addresses are not highly sensitive information like birth dates or social security numbers, the conversations could reveal very private medical data,” said Morey Haber, chief technology officer at BeyondTrust, a cyber security company in the UAE.

“The information could easily lead to future spear phishing attacks because the details about an individual would make a potential attack credible.

“Pfizer did not know the data was accessible nor [that] it was obtained.

“It is feasible therefore to assume the data has been accessed in the past as well.”

Phishing is the most common technique used by hackers to extract restricted data or gain access to accounts by encouraging users to relinquish passwords.

Sensitive information about patients, who asked questions online about smoking cessation drug, Chantix, was also obtained by hackers.

The breach was reported to Pfizer and regulators by online security researchers at tech-company vpnMentor.

Pfizer headquarters in New York. Carlo Allegri / Reuters
Pfizer headquarters in New York. Carlo Allegri / Reuters

They said the information remained exposed online for months before action was taken to remove it in September.

It is the fifth similar failure to secure patient information by Pfizer, that has offices in Dubai Media City, following incidents in 2007 and 2019.

"Pfizer is aware that a small number of non-HIPAA data records on a vendor operated system used for feedback on existing medicines were inadvertently publicly available," Pfizer said in response.

"We take privacy and product feedback extremely seriously. To that end, when we became aware of this event we ensured the vendor corrected the issue and notifications compliant with applicable laws will be sent to individuals."

Industry experts said cloud storage is becoming increasingly difficult to secure as hacking techniques become more sophisticated.

In 2014, celebrities including Jennifer Lawrence, Rihanna and Kim Kardashian were among those who had compromising photos leaked online after cloud storage was hacked.

A two-step verification process was then introduced to bolster security around Apple’s iCloud data storage service.

“The recent Pfizer data breach tells us it is extremely difficult for even the largest companies in the world to secure their data every hour, every day and every week,” said Sam Curry, chief security officer at Cybereason, a company working with businesses in the UAE to bolster online defences.

“It's irrelevant whether an internal or external error led to this data breach.

“The digital footprint for enterprises is expanding at such a rapid pace, errors will occur and data will be exposed.

“Customers want transparency and guarantees that the company will continue to make sure data protection is their top priority.”

Read More

Chat conversations between human and chatbots that give an automated conversation response were some of the information exposed in the leak.

While replies were preprogrammed into the solution, humans would realistically have to answer a series of questions to determine the proper response.

Those questions were designed to provide a high confidence in the results and often forced the exposure of more information to obtain the desired results.

“As no system, or person, is ever perfect, the ability to monitor, detect and respond to unauthorised or malicious access to cloud services can make the difference between a contained security incident and a full-blown breach as being reported at Pfizer,” said Matt Walmsley, a tech industry analyst and director at Vectra AI.

“We performed analysis on Office 365 – the worlds most used software and service cloud – and identified how attackers are using existing tools and services within the cloud to spy and steal.

“When administrators inadvertently leave the front door open it’s unsurprising that attackers walk straight in and out unnoticed.”

Dr Amal Khalid Alias revealed a recent case of a woman with daughters, who specifically wanted a boy.

A semen analysis of the father showed abnormal sperm so the couple required IVF.

Out of 21 eggs collected, six were unused leaving 15 suitable for IVF.

A specific procedure was used, called intracytoplasmic sperm injection where a single sperm cell is inserted into the egg.

On day three of the process, 14 embryos were biopsied for gender selection.

The next day, a pre-implantation genetic report revealed four normal male embryos, three female and seven abnormal samples.

Day five of the treatment saw two male embryos transferred to the patient.

The woman recorded a positive pregnancy test two weeks later. 

The specs

Engine: 3.8-litre twin-turbo V8

Power: 611bhp

Torque: 620Nm

Transmission: seven-speed automatic

Price: upon application

On sale: now

The specs: 2018 Mercedes-Benz E 300 Cabriolet

Price, base / as tested: Dh275,250 / Dh328,465

Engine: 2.0-litre four-cylinder

Power: 245hp @ 5,500rpm

Torque: 370Nm @ 1,300rpm

Transmission: Nine-speed automatic

Fuel consumption, combined: 7.0L / 100km

DUBAI%20BLING%3A%20EPISODE%201
%3Cp%3E%3Cstrong%3ECreator%3A%20%3C%2Fstrong%3ENetflix%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EStars%3A%20%3C%2Fstrong%3EKris%20Fade%2C%20Ebraheem%20Al%20Samadi%2C%20Zeina%20Khoury%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ERating%3A%3C%2Fstrong%3E%202%2F5%3C%2Fp%3E%0A

Western Clubs Champions League:

  • Friday, Sep 8 - Abu Dhabi Harlequins v Bahrain
  • Friday, Sep 15 – Kandy v Abu Dhabi Harlequins
  • Friday, Sep 22 – Kandy v Bahrain
Lexus LX700h specs

Engine: 3.4-litre twin-turbo V6 plus supplementary electric motor

Power: 464hp at 5,200rpm

Torque: 790Nm from 2,000-3,600rpm

Transmission: 10-speed auto

Fuel consumption: 11.7L/100km

On sale: Now

Price: From Dh590,000

Infiniti QX80 specs

Engine: twin-turbocharged 3.5-liter V6

Power: 450hp

Torque: 700Nm

Price: From Dh450,000, Autograph model from Dh510,000

Available: Now

Brief scores:

Day 2

England: 277 & 19-0

West Indies: 154

Monday's results
  • UAE beat Bahrain by 51 runs
  • Qatar beat Maldives by 44 runs
  • Saudi Arabia beat Kuwait by seven wickets
Company profile

Name: Back to Games and Boardgame Space

Started: Back to Games (2015); Boardgame Space (Mark Azzam became co-founder in 2017)

Founder: Back to Games (Mr Azzam); Boardgame Space (Mr Azzam and Feras Al Bastaki)

Based: Dubai and Abu Dhabi 

Industry: Back to Games (retail); Boardgame Space (wholesale and distribution) 

Funding: Back to Games: self-funded by Mr Azzam with Dh1.3 million; Mr Azzam invested Dh250,000 in Boardgame Space  

Growth: Back to Games: from 300 products in 2015 to 7,000 in 2019; Boardgame Space: from 34 games in 2017 to 3,500 in 2019