Previous All Posts Next

Cyberattack Economics: How Supply and Demand Drive Hacking

Posted: October 13, 2016 to Cybersecurity.

Tags: Data Breach, HIPAA, Compliance

Everyone knows the law of supply and demand: when a resource is scarce, the price is high.  When the market is glutted, the price falls.  The internet black market is no different. It appears that cybercriminals have flooded the market with Electronic Health Records (EHR) and have forced their value down to the degree that in ordered to make the same amount of money as they used to, they now have to commit more cyberattacks. Last year, a single health record could fetch a hacker between $75 and $100. By contrast, that same record is only worth $20 to $50 today. As a result, criminals are changing how EHRs are sold. Now rather than put everything they have up for sale immediately, at first they only auction off general information stolen in the breach, and then later they sell off the long-form records. Additionally, it’s no longer profitable to steal one piece of information, so criminals are finding ways to package and sell stolen information. Hackers take things like utility bills and insurance information then put it together with a corresponding EHR to make a complete false IDI kit. Unfortunately, clogging up the market with stolen healthcare files and consequently driving the price is only going to make matters worse. Hackers still see the healthcare industry as a cash cow, but criminals are starting to look for ways to regain lost revenue, and executives need to pay attention.

Related Resources

Learn more about how Petronella Technology Group can help:

Need help implementing these strategies? Our cybersecurity experts can assess your environment and build a tailored plan.
Get Free Assessment

About the Author

Craig Petronella, CEO and Founder of Petronella Technology Group
CEO, Founder & AI Architect, Petronella Technology Group

Craig Petronella founded Petronella Technology Group in 2002 and has spent more than 30 years working at the intersection of cybersecurity, AI, compliance, and digital forensics. He holds the CMMC Registered Practitioner credential (RP-1372) issued by the Cyber AB, is an NC Licensed Digital Forensics Examiner (License #604180-DFE), and completed MIT Professional Education programs in AI, Blockchain, and Cybersecurity. Craig also holds CompTIA Security+, CCNA, and Hyperledger certifications.

He is an Amazon #1 Best-Selling Author of 15+ books on cybersecurity and compliance, host of the Encrypted Ambition podcast (95+ episodes on Apple Podcasts, Spotify, and Amazon), and a cybersecurity keynote speaker with 200+ engagements at conferences, law firms, and corporate boardrooms. Craig serves as Contributing Editor for Cybersecurity at NC Triangle Attorney at Law Magazine and is a guest lecturer at NCCU School of Law. He has served as a digital forensics expert witness in federal and state court cases involving cybercrime, cryptocurrency fraud, SIM-swap attacks, and data breaches.

Under his leadership, Petronella Technology Group has served 2,500+ clients, maintained a zero-breach record among compliant clients, earned a BBB A+ rating every year since 2003, and been featured as a cybersecurity authority on CBS, ABC, NBC, FOX, and WRAL. The company leverages SOC 2 Type II certified platforms and specializes in AI implementation, managed cybersecurity, CMMC/HIPAA/SOC 2 compliance, and digital forensics for businesses across the United States.

CMMC-RP NC Licensed DFE MIT Certified CompTIA Security+ Expert Witness 15+ Books
Related Service
Protect Your Business with Our Cybersecurity Services

Our proprietary 39-layer ZeroHack cybersecurity stack defends your organization 24/7.

Explore Cybersecurity Services
Previous All Posts Next
Free cybersecurity consultation available Schedule Now