Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty
Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty
Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty
Cybersecurity firms in the UAE have reacted to a major leak of patient information held by pharmaceutical giant Pfizer. Getty

Hackers target Pfizer exposing sensitive patient information


Nick Webster
  • English
  • Arabic

Hackers have broken through the "front door" of online data storage units used by pharmaceutical giant Pfizer and leaked hundreds of chatbot conversations and patient information.

Scores of victims could now be exposed to phishing scams after having their full names, home addresses and email contacts taken from a misconfigured Google Cloud storage bucket.

Data included hundreds of conversations between customers and chatbots enquiring about cancer drugs, epilepsy medication and Viagra.

It is not known how many patients were in the UAE.

When administrators leave the front door open it's unsurprising attackers walk straight in unnoticed

Cybercrime experts said the blunder could lead to patients inadvertently handing over bank card information to criminals claiming to process bogus prescriptions.

“While name, addresses, and email addresses are not highly sensitive information like birth dates or social security numbers, the conversations could reveal very private medical data,” said Morey Haber, chief technology officer at BeyondTrust, a cyber security company in the UAE.

“The information could easily lead to future spear phishing attacks because the details about an individual would make a potential attack credible.

“Pfizer did not know the data was accessible nor [that] it was obtained.

“It is feasible therefore to assume the data has been accessed in the past as well.”

Phishing is the most common technique used by hackers to extract restricted data or gain access to accounts by encouraging users to relinquish passwords.

Sensitive information about patients, who asked questions online about smoking cessation drug, Chantix, was also obtained by hackers.

The breach was reported to Pfizer and regulators by online security researchers at tech-company vpnMentor.

Pfizer headquarters in New York. Carlo Allegri / Reuters
Pfizer headquarters in New York. Carlo Allegri / Reuters

They said the information remained exposed online for months before action was taken to remove it in September.

It is the fifth similar failure to secure patient information by Pfizer, that has offices in Dubai Media City, following incidents in 2007 and 2019.

"Pfizer is aware that a small number of non-HIPAA data records on a vendor operated system used for feedback on existing medicines were inadvertently publicly available," Pfizer said in response.

"We take privacy and product feedback extremely seriously. To that end, when we became aware of this event we ensured the vendor corrected the issue and notifications compliant with applicable laws will be sent to individuals."

Industry experts said cloud storage is becoming increasingly difficult to secure as hacking techniques become more sophisticated.

In 2014, celebrities including Jennifer Lawrence, Rihanna and Kim Kardashian were among those who had compromising photos leaked online after cloud storage was hacked.

A two-step verification process was then introduced to bolster security around Apple’s iCloud data storage service.

“The recent Pfizer data breach tells us it is extremely difficult for even the largest companies in the world to secure their data every hour, every day and every week,” said Sam Curry, chief security officer at Cybereason, a company working with businesses in the UAE to bolster online defences.

“It's irrelevant whether an internal or external error led to this data breach.

“The digital footprint for enterprises is expanding at such a rapid pace, errors will occur and data will be exposed.

“Customers want transparency and guarantees that the company will continue to make sure data protection is their top priority.”

Read More

Chat conversations between human and chatbots that give an automated conversation response were some of the information exposed in the leak.

While replies were preprogrammed into the solution, humans would realistically have to answer a series of questions to determine the proper response.

Those questions were designed to provide a high confidence in the results and often forced the exposure of more information to obtain the desired results.

“As no system, or person, is ever perfect, the ability to monitor, detect and respond to unauthorised or malicious access to cloud services can make the difference between a contained security incident and a full-blown breach as being reported at Pfizer,” said Matt Walmsley, a tech industry analyst and director at Vectra AI.

“We performed analysis on Office 365 – the worlds most used software and service cloud – and identified how attackers are using existing tools and services within the cloud to spy and steal.

“When administrators inadvertently leave the front door open it’s unsurprising that attackers walk straight in and out unnoticed.”

COMPANY%20PROFILE
%3Cp%3E%3Cstrong%3ECompany%3A%3C%2Fstrong%3E%20Eco%20Way%3Cbr%3E%3Cstrong%3EStarted%3A%3C%2Fstrong%3E%20December%202023%3Cbr%3E%3Cstrong%3EFounder%3A%3C%2Fstrong%3E%20Ivan%20Kroshnyi%3Cbr%3E%3Cstrong%3EBased%3A%3C%2Fstrong%3E%20Dubai%2C%20UAE%3Cbr%3E%3Cstrong%3EIndustry%3A%3C%2Fstrong%3E%20Electric%20vehicles%3Cbr%3E%3Cstrong%3EInvestors%3A%3C%2Fstrong%3E%20Bootstrapped%20with%20undisclosed%20funding.%20Looking%20to%20raise%20funds%20from%20outside%3Cbr%3E%3C%2Fp%3E%0A
The specs

Engine: 2.0-litre four-cylinder turbo

Power: 268hp at 5,600rpm

Torque: 380Nm at 4,800rpm

Transmission: CVT auto

Fuel consumption: 9.5L/100km

On sale: now

Price: from Dh195,000 

Getting there

The flights

Emirates and Etihad fly to Johannesburg or Cape Town daily. Flights cost from about Dh3,325, with a flying time of 8hours and 15 minutes. From there, fly South African Airlines or Air Namibia to Namibia’s Windhoek Hosea Kutako International Airport, for about Dh850. Flying time is 2 hours.

The stay

Wilderness Little Kulala offers stays from £460 (Dh2,135) per person, per night. It is one of seven Wilderness Safari lodges in Namibia; www.wilderness-safaris.com.

Skeleton Coast Safaris’ four-day adventure involves joining a very small group in a private plane, flying to some of the remotest areas in the world, with each night spent at a different camp. It costs from US$8,335.30 (Dh30,611); www.skeletoncoastsafaris.com

Key facilities
  • Olympic-size swimming pool with a split bulkhead for multi-use configurations, including water polo and 50m/25m training lanes
  • Premier League-standard football pitch
  • 400m Olympic running track
  • NBA-spec basketball court with auditorium
  • 600-seat auditorium
  • Spaces for historical and cultural exploration
  • An elevated football field that doubles as a helipad
  • Specialist robotics and science laboratories
  • AR and VR-enabled learning centres
  • Disruption Lab and Research Centre for developing entrepreneurial skills
UAE currency: the story behind the money in your pockets
UK’s AI plan
  • AI ambassadors such as MIT economist Simon Johnson, Monzo cofounder Tom Blomfield and Google DeepMind’s Raia Hadsell
  • £10bn AI growth zone in South Wales to create 5,000 jobs
  • £100m of government support for startups building AI hardware products
  • £250m to train new AI models
The Voice of Hind Rajab

Starring: Saja Kilani, Clara Khoury, Motaz Malhees

Director: Kaouther Ben Hania

Rating: 4/5

How to become a Boglehead

Bogleheads follow simple investing philosophies to build their wealth and live better lives. Just follow these steps.

•   Spend less than you earn and save the rest. You can do this by earning more, or being frugal. Better still, do both.

•   Invest early, invest often. It takes time to grow your wealth on the stock market. The sooner you begin, the better.

•   Choose the right level of risk. Don't gamble by investing in get-rich-quick schemes or high-risk plays. Don't play it too safe, either, by leaving long-term savings in cash.

•   Diversify. Do not keep all your eggs in one basket. Spread your money between different companies, sectors, markets and asset classes such as bonds and property.

•   Keep charges low. The biggest drag on investment performance is all the charges you pay to advisers and active fund managers.

•   Keep it simple. Complexity is your enemy. You can build a balanced, diversified portfolio with just a handful of ETFs.

•   Forget timing the market. Nobody knows where share prices will go next, so don't try to second-guess them.

•   Stick with it. Do not sell up in a market crash. Use the opportunity to invest more at the lower price.

The specs

Engine: 3.0-litre six-cylinder MHEV

Power: 360bhp

Torque: 500Nm

Transmission: eight-speed automatic

Price: from Dh282,870

On sale: now

Ronaldo's record at Man Utd

Seasons 2003/04 - 2008/09

Appearances 230

Goals 115

Stats at a glance:

Cost: 1.05 billion pounds (Dh 4.8 billion)

Number in service: 6

Complement 191 (space for up to 285)

Top speed: over 32 knots

Range: Over 7,000 nautical miles

Length 152.4 m

Displacement: 8,700 tonnes

Beam:   21.2 m

Draught: 7.4 m