As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…
What kind of monster of an employer makes their employees train the replacements they're getting fired for? If that were me, I'd organize and have everyone quit; let them figure things out. Screw the pittance of a severance.
Update on IT Security Incident at UCSF
31–40 of 150 posts
Re: Update on IT Security Incident at UCSF
#32What I find crazy about this -- no guarantee that the ransom payment would unlock the machines -- did they send 1.14M in one go or was it a smaller amount for the first machine, then an additional fee for each additional machine? Also would be interested to know -- was it Bitcoin or some other cryptocurrency that was used?
Re: Update on IT Security Incident at UCSF
#33As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…
Re: Update on IT Security Incident at UCSF
#34Maybe there should be a law that if you pay a ransom, you are required to pay the same amount as a fine. Because paying these ransoms is funding the criminals.... how about you have to also fund law enforcement to combat those criminals? (also, this should reduce the amount that actually goes to the bad guys, since the amount of ransom would have greater downward pressure, i.e. if they'd probably not be able to colle…
Re: Update on IT Security Incident at UCSF
#35As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…
Re: Update on IT Security Incident at UCSF
#36As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…
Someone, somewhere, is calculating whether the ransomware line item was worth the offshoring and laying off local employees line item.
Re: Update on IT Security Incident at UCSF
#37Earlier quoted context omitted.
Would you want the insurance policy to pay out though? At some level of recklessness, insurance becomes void. I think a lack of infrastructure to restore a hacked server — with data valued at over $1M — is negligent enough to not be covered. But maybe UCSF are on MegaCo’s YOLO tier of server insurance, which is so expensive and isolated it has no impact on my MegaCo pet insurance premiums?
But patients suffering for administrative negligence? I don’t agree with that but there does need to be some kind of incentive there.
Perhaps the health of some businesses is so important that they should be protected by, ahem, state-backed insurance paid for by the taxpayer?
Re: Update on IT Security Incident at UCSF
#38Don’t they have insurance for these things? A small college near me had an attack like this but paid via insurance.
Re: Update on IT Security Incident at UCSF
#39What I find crazy about this -- no guarantee that the ransom payment would unlock the machines -- did they send 1.14M in one go or was it a smaller amount for the first machine, then an additional fee for each additional machine? Also would be interested to know -- was it Bitcoin or some other cryptocurrency that was used?
Apparently crypto-ransom people are actually pretty trustworthy about unlocking the machines. It doesn't really cost them anything (0% chance you were gonna send a 2nd payment if they didn't unlock), and their reputation as 'fair' is very important for securing future ransoms.
Re: Update on IT Security Incident at UCSF
#40How did they not have backups of important data?