Live data from Hacker News

Update on IT Security Incident at UCSF

ucsf.edu

31–40 of 150 posts

Re: Update on IT Security Incident at UCSF

#31
post #21
post #13

As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…

What kind of monster of an employer makes their employees train the replacements they're getting fired for? If that were me, I'd organize and have everyone quit; let them figure things out. Screw the pittance of a severance.

Disney did this same thing: https://www.orlandosentinel.com/business/tourism/os-bz-disne...

Re: Update on IT Security Incident at UCSF

#32
post #18

What I find crazy about this -- no guarantee that the ransom payment would unlock the machines -- did they send 1.14M in one go or was it a smaller amount for the first machine, then an additional fee for each additional machine? Also would be interested to know -- was it Bitcoin or some other cryptocurrency that was used?

As weird as it sounds its pretty much in their best interest to send the unlock key because if they don't then people are going to stop paying them.

Re: Update on IT Security Incident at UCSF

#33
post #13

As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…

Someone, somewhere, is calculating whether the ransomware line item was worth the offshoring and laying off local employees line item.

Re: Update on IT Security Incident at UCSF

#34

Maybe there should be a law that if you pay a ransom, you are required to pay the same amount as a fine. Because paying these ransoms is funding the criminals.... how about you have to also fund law enforcement to combat those criminals? (also, this should reduce the amount that actually goes to the bad guys, since the amount of ransom would have greater downward pressure, i.e. if they'd probably not be able to colle…

This would make the payers far less likely to report it, and ultimately make it much harder to track

Re: Update on IT Security Incident at UCSF

#35
post #13

As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…

How the heck did they qualify for H1Bs when they were replacing already employed Americans? Not only did the H1Bs unemploy citizens, we didn't even get the long term benefits of trained workers living and paying taxes in the States.

Re: Update on IT Security Incident at UCSF

#36
post #13

As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…

Someone, somewhere, is calculating whether the ransomware line item was worth the offshoring and laying off local employees line item.

What would it mean if it was?

Re: Update on IT Security Incident at UCSF

#37
post #27

Earlier quoted context omitted.

Would you want the insurance policy to pay out though? At some level of recklessness, insurance becomes void. I think a lack of infrastructure to restore a hacked server — with data valued at over $1M — is negligent enough to not be covered. But maybe UCSF are on MegaCo’s YOLO tier of server insurance, which is so expensive and isolated it has no impact on my MegaCo pet insurance premiums?

But patients suffering for administrative negligence? I don’t agree with that but there does need to be some kind of incentive there.

That’s a good point, I hadn’t thought of that.

Perhaps the health of some businesses is so important that they should be protected by, ahem, state-backed insurance paid for by the taxpayer?

Re: Update on IT Security Incident at UCSF

#39
post #18

What I find crazy about this -- no guarantee that the ransom payment would unlock the machines -- did they send 1.14M in one go or was it a smaller amount for the first machine, then an additional fee for each additional machine? Also would be interested to know -- was it Bitcoin or some other cryptocurrency that was used?

Apparently crypto-ransom people are actually pretty trustworthy about unlocking the machines. It doesn't really cost them anything (0% chance you were gonna send a 2nd payment if they didn't unlock), and their reputation as 'fair' is very important for securing future ransoms.

Someone's gotta be thinking about doing a ransomware operation that doesn't unlock the data in order to poison the well.
Post reply on HN