Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty
Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty
Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty
Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty

Hackers target Pfizer exposing sensitive patient information


Nick Webster
  • English
  • Arabic

Hackers have broken through the "front door" of online data storage units used by pharmaceutical giant Pfizer and leaked hundreds of chatbot conversations and patient information.

Scores of victims could now be exposed to phishing scams after having their full names, home addresses and email contacts taken from a misconfigured Google Cloud storage bucket.

Data included hundreds of conversations between customers and chatbots enquiring about cancer drugs, epilepsy medication and Viagra.

It is not known how many patients were in the UAE.

When administrators leave the front door open it's unsurprising attackers walk straight in unnoticed

Cybercrime experts said the blunder could lead to patients inadvertently handing over bank card information to criminals claiming to process bogus prescriptions.

“While name, addresses, and email addresses are not highly sensitive information like birth dates or social security numbers, the conversations could reveal very private medical data,” said Morey Haber, chief technology officer at BeyondTrust, a cyber security company in the UAE.

“The information could easily lead to future spear phishing attacks because the details about an individual would make a potential attack credible.

“Pfizer did not know the data was accessible nor [that] it was obtained.

“It is feasible therefore to assume the data has been accessed in the past as well.”

Phishing is the most common technique used by hackers to extract restricted data or gain access to accounts by encouraging users to relinquish passwords.

Sensitive information about patients, who asked questions online about smoking cessation drug, Chantix, was also obtained by hackers.

The breach was reported to Pfizer and regulators by online security researchers at tech-company vpnMentor.

Pfizer headquarters in New York. Carlo Allegri / Reuters
Pfizer headquarters in New York. Carlo Allegri / Reuters

They said the information remained exposed online for months before action was taken to remove it in September.

It is the fifth similar failure to secure patient information by Pfizer, that has offices in Dubai Media City, following incidents in 2007 and 2019.

"Pfizer is aware that a small number of non-HIPAA data records on a vendor operated system used for feedback on existing medicines were inadvertently publicly available," Pfizer said in response.

"We take privacy and product feedback extremely seriously. To that end, when we became aware of this event we ensured the vendor corrected the issue and notifications compliant with applicable laws will be sent to individuals."

Industry experts said cloud storage is becoming increasingly difficult to secure as hacking techniques become more sophisticated.

In 2014, celebrities including Jennifer Lawrence, Rihanna and Kim Kardashian were among those who had compromising photos leaked online after cloud storage was hacked.

A two-step verification process was then introduced to bolster security around Apple’s iCloud data storage service.

“The recent Pfizer data breach tells us it is extremely difficult for even the largest companies in the world to secure their data every hour, every day and every week,” said Sam Curry, chief security officer at Cybereason, a company working with businesses in the UAE to bolster online defences.

“It's irrelevant whether an internal or external error led to this data breach.

“The digital footprint for enterprises is expanding at such a rapid pace, errors will occur and data will be exposed.

“Customers want transparency and guarantees that the company will continue to make sure data protection is their top priority.”

Read More

Chat conversations between human and chatbots that give an automated conversation response were some of the information exposed in the leak.

While replies were preprogrammed into the solution, humans would realistically have to answer a series of questions to determine the proper response.

Those questions were designed to provide a high confidence in the results and often forced the exposure of more information to obtain the desired results.

“As no system, or person, is ever perfect, the ability to monitor, detect and respond to unauthorised or malicious access to cloud services can make the difference between a contained security incident and a full-blown breach as being reported at Pfizer,” said Matt Walmsley, a tech industry analyst and director at Vectra AI.

“We performed analysis on Office 365 – the worlds most used software and service cloud – and identified how attackers are using existing tools and services within the cloud to spy and steal.

“When administrators inadvertently leave the front door open it’s unsurprising that attackers walk straight in and out unnoticed.”

AGL AWARDS

Golden Ball - best Emirati player: Khalfan Mubarak (Al Jazira)
Golden Ball - best foreign player: Igor Coronado (Sharjah)
Golden Glove - best goalkeeper: Adel Al Hosani (Sharjah)
Best Coach - the leader: Abdulaziz Al Anbari (Sharjah)
Fans' Player of the Year: Driss Fetouhi (Dibba)
Golden Boy - best young player: Ali Saleh (Al Wasl)
Best Fans of the Year: Sharjah
Goal of the Year: Michael Ortega (Baniyas)

Four tips to secure IoT networks

Mohammed Abukhater, vice president at FireEye in the Middle East, said:

- Keep device software up-to-date. Most come with basic operating system, so users should ensure that they always have the latest version

- Besides a strong password, use two-step authentication. There should be a second log-in step like adding a code sent to your mobile number

- Usually smart devices come with many unnecessary features. Users should lock those features that are not required or used frequently

- Always create a different guest network for visitors

Other workplace saving schemes
  • The UAE government announced a retirement savings plan for private and free zone sector employees in 2023.
  • Dubai’s savings retirement scheme for foreign employees working in the emirate’s government and public sector came into effect in 2022.
  • National Bonds unveiled a Golden Pension Scheme in 2022 to help private-sector foreign employees with their financial planning.
  • In April 2021, Hayah Insurance unveiled a workplace savings plan to help UAE employees save for their retirement.
  • Lunate, an Abu Dhabi-based investment manager, has launched a fund that will allow UAE private companies to offer employees investment returns on end-of-service benefits.
Company%20profile
%3Cp%3E%3Cstrong%3EName%3A%3C%2Fstrong%3E%20WallyGPT%3Cbr%3E%3Cstrong%3EStarted%3A%20%3C%2Fstrong%3E2014%3Cbr%3E%3Cstrong%3EFounders%3A%20%3C%2Fstrong%3ESaeid%20and%20Sami%20Hejazi%3Cbr%3E%3Cstrong%3EBased%3A%3C%2Fstrong%3E%20Dubai%3Cbr%3E%3Cstrong%3ESector%3A%20%3C%2Fstrong%3EFinTech%3Cbr%3E%3Cstrong%3EInvestment%20raised%3A%20%3C%2Fstrong%3E%247.1%20million%3Cbr%3E%3Cstrong%3ENumber%20of%20staff%3A%3C%2Fstrong%3E%2020%3Cbr%3E%3Cstrong%3EInvestment%20stage%3A%20%3C%2Fstrong%3EPre-seed%20round%3C%2Fp%3E%0A
MATCH INFO

Uefa Champions League semi-final, second leg

Roma 4
Milner (15' OG), Dzeko (52'), Nainggolan (86', 90 4')

Liverpool 2
Mane (9'), Wijnaldum (25')

The specs

Engine: 2.0-litre 4-cyl turbo

Power: 247hp at 6,500rpm

Torque: 370Nm from 1,500-3,500rpm

Transmission: 10-speed auto

Fuel consumption: 7.8L/100km

Price: from Dh94,900

On sale: now

Jetour T1 specs

Engine: 2-litre turbocharged

Power: 254hp

Torque: 390Nm

Price: From Dh126,000

Available: Now

Avatar: Fire and Ash

Director: James Cameron

Starring: Sam Worthington, Sigourney Weaver, Zoe Saldana

Rating: 4.5/5

DUBAI%20BLING%3A%20EPISODE%201
%3Cp%3E%3Cstrong%3ECreator%3A%20%3C%2Fstrong%3ENetflix%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3EStars%3A%20%3C%2Fstrong%3EKris%20Fade%2C%20Ebraheem%20Al%20Samadi%2C%20Zeina%20Khoury%3C%2Fp%3E%0A%3Cp%3E%3Cstrong%3ERating%3A%3C%2Fstrong%3E%202%2F5%3C%2Fp%3E%0A
UAE v IRELAND

All matches start at 10am, and will be played in Abu Dhabi

1st ODI, Friday, January 8

2nd ODI, Sunday, January 10

3rd ODI, Tuesday, January 12

4th ODI, Thursday, January 14

The specs: 2018 Ford F-150

Price, base / as tested: Dh173,250 / Dh178,500

Engine: 5.0-litre V8

Power: 395hp @ 5,000rpm

Torque: 555Nm @ 2,750rpm

Transmission: 10-speed automatic

Fuel consumption, combined: 12.4L / 100km

Heavily-sugared soft drinks slip through the tax net

Some popular drinks with high levels of sugar and caffeine have slipped through the fizz drink tax loophole, as they are not carbonated or classed as an energy drink.

Arizona Iced Tea with lemon is one of those beverages, with one 240 millilitre serving offering up 23 grams of sugar - about six teaspoons.

A 680ml can of Arizona Iced Tea costs just Dh6.

Most sports drinks sold in supermarkets were found to contain, on average, five teaspoons of sugar in a 500ml bottle.

'Doctor Strange in the Multiverse Of Madness' 

   

 

Director: Sam Raimi

 

Cast: Benedict Cumberbatch, Elizabeth Olsen, Chiwetel Ejiofor, Benedict Wong, Xochitl Gomez, Michael Stuhlbarg and Rachel McAdams

 

Rating: 3/5