FBI Warns of FTP Cybersecurity Risk

Share

Attorney Kate Stewart (Mintz Levin) says the FBI recently issued guidance specifically applicable to medical and dental facilities about the cybersecurity risk of File Transfer Protocol (FTP) servers operating in “anonymous” mode. Writing in an online blog post, Stewart says FTPs are routinely used to transfer information between network hosts.

The FBI guidance said that an FTP server can be configured to permit anonymous users (through the use of a common user name such as “anonymous” and without using a password) to gain access to information stored on the server, which might include sensitive information about patients. “In addition to potentially directly compromising the security of the stored information,” she writes, “a hacker could use the FTP server in anonymous mode to launch a cyber attack on the entity.”

The post includes specific FDA guidance on what facilities should do.

Read more