Live data from Hacker News

Update on IT Security Incident at UCSF

ucsf.edu

21–30 of 150 posts

Re: Update on IT Security Incident at UCSF

#21
post #13

As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…

What kind of monster of an employer makes their employees train the replacements they're getting fired for?

If that were me, I'd organize and have everyone quit; let them figure things out. Screw the pittance of a severance.

Re: Update on IT Security Incident at UCSF

#22
post #18

What I find crazy about this -- no guarantee that the ransom payment would unlock the machines -- did they send 1.14M in one go or was it a smaller amount for the first machine, then an additional fee for each additional machine? Also would be interested to know -- was it Bitcoin or some other cryptocurrency that was used?

It’s in the best interest of the people who make these types of malware to provide the decryption tools once the ransom is paid.

If news gets out that even if you pay the ransom you won’t get the decryption tools then no one would pay the ransom and the hackers get no money at all.

Re: Update on IT Security Incident at UCSF

#23
post #6

Don’t they have insurance for these things? A small college near me had an attack like this but paid via insurance.

How would that work? Would the bad guys just ask for 10 times as much, since the insurance company is obligated to pay whatever it costs?

Re: Update on IT Security Incident at UCSF

#24
post #10
post #3

The paid ransom, will unfortunately embolden the criminals to strike again in search of the next big payday. If it worked once, it could work again.

If the data is worth paying a million dollar ransom to unlock, it is worth setting up proper backups. I for one am grateful to people who commit these crimes in which they "lock" data in place rather than sell it to the highest bidder. Proper data hygiene isn't brain surgery. There is zero excuse for this event. I don't blame the criminals. I blame the university system. Shame!

Depends, those kinds of outfits tend to poke around and lurk a while before striking. In that time they can exfiltrate and you cannot prove that the baddies didn't exfiltrate data (if you had that sophistication, they wouldn't have been in the mess they got into).

Re: Update on IT Security Incident at UCSF

#25
post #21
post #13

As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…

What kind of monster of an employer makes their employees train the replacements they're getting fired for? If that were me, I'd organize and have everyone quit; let them figure things out. Screw the pittance of a severance.

Their severance pay was probably on the line...too sad

Re: Update on IT Security Incident at UCSF

#26
post #18

What I find crazy about this -- no guarantee that the ransom payment would unlock the machines -- did they send 1.14M in one go or was it a smaller amount for the first machine, then an additional fee for each additional machine? Also would be interested to know -- was it Bitcoin or some other cryptocurrency that was used?

Apparently crypto-ransom people are actually pretty trustworthy about unlocking the machines. It doesn't really cost them anything (0% chance you were gonna send a 2nd payment if they didn't unlock), and their reputation as 'fair' is very important for securing future ransoms.

Re: Update on IT Security Incident at UCSF

#27
post #6

Don’t they have insurance for these things? A small college near me had an attack like this but paid via insurance.

Would you want the insurance policy to pay out though? At some level of recklessness, insurance becomes void. I think a lack of infrastructure to restore a hacked server — with data valued at over $1M — is negligent enough to not be covered. But maybe UCSF are on MegaCo’s YOLO tier of server insurance, which is so expensive and isolated it has no impact on my MegaCo pet insurance premiums?

But patients suffering for administrative negligence? I don’t agree with that but there does need to be some kind of incentive there.

Re: Update on IT Security Incident at UCSF

#28
CISO: https://cio.ucop.edu/spotlight-patrick-phelan-once-a-ucla-br...

I can't think of any reason not to use a cloud hosted service for backup today. OneDrive, Dropbox, and Google Drive all sign BAAs and give you versioning amongst a million other security features. AWS even has offerings that let you take periodic snapshots of on-premise volumes.

Point in time recoveries for the entire account would be nice add too but not having to fork over a million dollars in exchange for a few clicks sounds like a bargain. Hell we were setting up write-only S3 buckets for critical data stores 5+ years ago.

Gross incompetence, I'd fire everyone. A district-wide outage for a week, fine. A 1.4 million dollar check to get data that should have been archived somewhere GTFO.

Re: Update on IT Security Incident at UCSF

#29
post #10
post #3

The paid ransom, will unfortunately embolden the criminals to strike again in search of the next big payday. If it worked once, it could work again.

If the data is worth paying a million dollar ransom to unlock, it is worth setting up proper backups. I for one am grateful to people who commit these crimes in which they "lock" data in place rather than sell it to the highest bidder. Proper data hygiene isn't brain surgery. There is zero excuse for this event. I don't blame the criminals. I blame the university system. Shame!

I know how much IT personnel at UCSF make -- you get what you pay for. If you want expertise, it's not hard to find.

Re: Update on IT Security Incident at UCSF

#30
post #16
post #5

How did they not have backups of important data?

there was mentioned a threat of publishing of some secret data, and that i think may be a reason why UCSF was willing to pay https://www.trialsitenews.com/hacking-group-launches-success...

This seems much more likely than the scenario where they simply didn’t have any backups of the data.
Post reply on HN