Incident: Cyber Attack on Scottish Mental Health Charity SAMH.

Published Date: 2022-03-21

Postmortem Analysis
Timeline 1. The software failure incident at the Scottish mental health charity SAMH happened last Thursday, as mentioned in the article [125717]. 2. Published on 2022-03-21 07:00:00+00:00. 3. The incident at SAMH occurred around March 17, 2022.
System The software failure incident at the Scottish mental health charity SAMH was due to a cyber attack. The specific systems that failed in this incident were: 1. Email system 2. Phone lines [125717]
Responsible Organization 1. The cyber attack on the Scottish mental health charity SAMH was caused by unknown malicious actors [125717].
Impacted Organization 1. Scottish mental health charity SAMH [Article 125717]
Software Causes 1. Cyber attack targeting the Scottish mental health charity SAMH, affecting emails and phone lines, leading to disruption of services [Article 125717].
Non-software Causes 1. The cyber attack on the Scottish mental health charity SAMH was caused by a "sophisticated and criminal" act, indicating a deliberate malicious intent [125717].
Impacts 1. The cyber attack on the Scottish mental health charity SAMH affected their emails and phone lines, disrupting communication channels for staff and service users [Article 125717].
Preventions 1. Implementing robust cybersecurity measures such as firewalls, intrusion detection systems, and regular security audits could have potentially prevented the cyber attack on the Scottish mental health charity SAMH [125717]. 2. Providing cybersecurity training to staff members to enhance awareness of potential threats like phishing emails or social engineering attacks could have helped prevent the incident [125717]. 3. Regularly updating and patching software systems to address known vulnerabilities could have reduced the risk of a successful cyber attack on the charity [125717].
Fixes 1. Enhancing cybersecurity measures such as implementing stronger firewalls, intrusion detection systems, and regular security audits to prevent future cyber attacks [125717].
References 1. Charity chief executive Billy Watson [Article 125717] 2. Police Scotland [Article 125717]

Software Taxonomy of Faults

Category Option Rationale
Recurring one_organization, multiple_organization (a) The software failure incident having happened again at one_organization: The article mentions that the cyber attack on the Scottish mental health charity SAMH occurred just over a year after Scotland's environmental watchdog, Sepa, was targeted in a cyber attack on Christmas Eve 2020. This indicates that SAMH experienced a similar incident to another organization within a relatively short timeframe [125717].
Phase (Design/Operation) design (a) The software failure incident at the Scottish mental health charity SAMH was due to a cyber attack, which can be attributed to contributing factors introduced during the system development or system updates. The attack affected the charity's emails and phone lines, disrupting their operations and services [125717]. (b) The operation of the system was impacted by the cyber attack, leading to disruptions in the staff's ability to receive and respond to emails, as well as affecting some of the national phone lines of the charity [125717].
Boundary (Internal/External) within_system (a) within_system: The software failure incident at the Scottish mental health charity SAMH was due to a cyber attack, which is an internal factor originating from within the system. The attack affected the charity's emails and phone lines, disrupting their operations and services [125717].
Nature (Human/Non-human) non-human_actions, human_actions (a) The software failure incident at the Scottish mental health charity SAMH was due to a cyber attack, which is a non-human action. The incident was described as a "sophisticated and criminal" cyber attack that affected the charity's emails and phone lines. The attack disrupted the organization's work and support services, impacting its ability to communicate and provide vital services to those in need [Article 125717]. (b) The human actions involved in this incident include the charity's staff trying to keep support services running despite the attack. The charity's chief executive, Billy Watson, expressed his gratitude towards the staff for finding ways to minimize disruption and continue delivering support services to those in need. Additionally, the charity is working closely with various agencies, including Police Scotland, to effectively deal with the situation, indicating human involvement in response and mitigation efforts [Article 125717].
Dimension (Hardware/Software) hardware, software (a) The software failure incident reported in the article is related to a cyber attack on the Scottish mental health charity SAMH. The incident affected emails and phone lines at SAMH, indicating a disruption in communication systems. This disruption is likely due to external factors originating in hardware, such as servers, network infrastructure, or other physical components that support the software systems [125717]. (b) The software failure incident is primarily attributed to a "sophisticated and criminal" cyber attack, indicating that the contributing factors originate in software vulnerabilities exploited by malicious actors. The attack targeted SAMH's systems, impacting their ability to receive and respond to emails as well as affecting their phone lines. This points to weaknesses in the software infrastructure or applications used by the charity, making them susceptible to cyber threats [125717].
Objective (Malicious/Non-malicious) malicious (a) The software failure incident at the Scottish mental health charity SAMH was malicious in nature. The incident was described as a "sophisticated and criminal" cyber attack, indicating that the attack was intentional and aimed at disrupting the organization's operations [Article 125717]. The charity's chief executive mentioned that it was difficult to understand why someone would deliberately try to disrupt the work of an organization that provides vital support to vulnerable individuals, further emphasizing the malicious intent behind the attack. Additionally, the involvement of the police in investigating the incident and the collaboration with various agencies, including Police Scotland, suggest that the attack was viewed as a criminal act rather than an accidental failure.
Intent (Poor/Accidental Decisions) unknown (a) The intent of the software failure incident was deliberate and criminal, as the article mentions that the Scottish mental health charity SAMH was the victim of a "sophisticated and criminal" cyber attack. The charity's chief executive expressed difficulty in understanding why anyone would deliberately try to disrupt the organization's work, especially considering the vulnerable people who rely on their services [Article 125717].
Capability (Incompetence/Accidental) development_incompetence (a) The software failure incident at the Scottish mental health charity SAMH was due to a cyber attack, which is considered a form of development incompetence as it involves deliberate actions by malicious actors targeting the organization's systems [125717]. The attack disrupted the charity's emails and phone lines, impacting their ability to provide vital mental health support services. The charity's chief executive expressed disbelief at why someone would intentionally disrupt their work, highlighting the malicious nature of the attack and the lack of professional competence on the part of the attackers. (b) The software failure incident was not accidental but rather a deliberate cyber attack aimed at disrupting the charity's operations and services [125717]. The attack was described as "sophisticated and criminal," indicating a purposeful and intentional act rather than an accidental occurrence. The charity's staff were devastated by the attack, emphasizing the deliberate nature of the incident and the malicious intent behind it.
Duration temporary The software failure incident at the Scottish mental health charity SAMH due to a cyber attack can be categorized as a temporary failure. The incident affected the charity's emails and phone lines, causing disruption to their communication channels and services. SAMH posted notices on its website acknowledging the incident and mentioned that they were working closely with various agencies, including Police Scotland, to address the issue. Despite the disruption, the charity stated that local services could still be contacted by phone and that they were continuing to support people across Scotland [125717].
Behaviour unknown (a) crash: The software failure incident in the article is not described as a crash where the system loses state and does not perform any of its intended functions [125717]. (b) omission: The incident does not mention the software omitting to perform its intended functions at an instance(s) [125717]. (c) timing: The incident does not indicate that the software performed its intended functions correctly but too late or too early [125717]. (d) value: The software failure incident does not specify that the system performed its intended functions incorrectly [125717]. (e) byzantine: The incident does not mention the software behaving erroneously with inconsistent responses and interactions [125717]. (f) other: The behavior of the software failure incident is not explicitly described in the article [125717].

IoT System Layer

Layer Option Rationale
Perception None None
Communication None None
Application None None

Other Details

Category Option Rationale
Consequence property, delay, theoretical_consequence, unknown (a) unknown (b) unknown (c) unknown (d) People's access to communication channels like emails and phone lines at SAMH, the Scottish Association for Mental Health, was impacted due to the cyber attack [125717]. (e) People had to postpone activities as SAMH staff were finding ways to keep support services running amidst the cyber attack [125717]. (f) unknown (g) unknown (h) The potential consequence of disrupting the work of an organization relied on by vulnerable people was discussed, but there is no specific mention of this consequence occurring [125717]. (i) unknown
Domain health The software failure incident reported in the article is related to the health industry. The incident involved a cyber attack on the Scottish mental health charity SAMH, impacting their emails and phone lines, which disrupted their support services for vulnerable individuals seeking mental health support [Article 125717].

Sources

Back to List