What I find crazy about this -- no guarantee that the ransom payment would unlock the machines -- did they send 1.14M in one go or was it a smaller amount for the first machine, then an additional fee for each additional machine? Also would be interested to know -- was it Bitcoin or some other cryptocurrency that was used?
Apparently crypto-ransom people are actually pretty trustworthy about unlocking the machines. It doesn't really cost them anything (0% chance you were gonna send a 2nd payment if they didn't unlock), and their reputation as 'fair' is very important for securing future ransoms.
Update on IT Security Incident at UCSF
41–50 of 150 posts
Re: Update on IT Security Incident at UCSF
#42The paid ransom, will unfortunately embolden the criminals to strike again in search of the next big payday. If it worked once, it could work again.
If the data is worth paying a million dollar ransom to unlock, it is worth setting up proper backups. I for one am grateful to people who commit these crimes in which they "lock" data in place rather than sell it to the highest bidder. Proper data hygiene isn't brain surgery. There is zero excuse for this event. I don't blame the criminals. I blame the university system. Shame!
Re: Update on IT Security Incident at UCSF
#43Don’t they have insurance for these things? A small college near me had an attack like this but paid via insurance.
Would you want the insurance policy to pay out though? At some level of recklessness, insurance becomes void. I think a lack of infrastructure to restore a hacked server — with data valued at over $1M — is negligent enough to not be covered. But maybe UCSF are on MegaCo’s YOLO tier of server insurance, which is so expensive and isolated it has no impact on my MegaCo pet insurance premiums?
Re: Update on IT Security Incident at UCSF
#44This is a very selfish thing to do, as you encourage the authors of such attacks.
Re: Update on IT Security Incident at UCSF
#45As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…
How the heck did they qualify for H1Bs when they were replacing already employed Americans? Not only did the H1Bs unemploy citizens, we didn't even get the long term benefits of trained workers living and paying taxes in the States.
Re: Update on IT Security Incident at UCSF
#46As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…
How the heck did they qualify for H1Bs when they were replacing already employed Americans? Not only did the H1Bs unemploy citizens, we didn't even get the long term benefits of trained workers living and paying taxes in the States.
Re: Update on IT Security Incident at UCSF
#47Earlier quoted context omitted.
Apparently crypto-ransom people are actually pretty trustworthy about unlocking the machines. It doesn't really cost them anything (0% chance you were gonna send a 2nd payment if they didn't unlock), and their reputation as 'fair' is very important for securing future ransoms.
Someone's gotta be thinking about doing a ransomware operation that doesn't unlock the data in order to poison the well.
Re: Update on IT Security Incident at UCSF
#48Don’t they have insurance for these things? A small college near me had an attack like this but paid via insurance.
How would that work? Would the bad guys just ask for 10 times as much, since the insurance company is obligated to pay whatever it costs?
Re: Update on IT Security Incident at UCSF
#49As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…
Someone, somewhere, is calculating whether the ransomware line item was worth the offshoring and laying off local employees line item.
Re: Update on IT Security Incident at UCSF
#50As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…
How the heck did they qualify for H1Bs when they were replacing already employed Americans? Not only did the H1Bs unemploy citizens, we didn't even get the long term benefits of trained workers living and paying taxes in the States.
A large percentage of H1Bs go to "bodyshops", which import workers from abroad to temporarily work at companies that are offshoring their employees. Yes, it's perverse; they are in effect being used to replace American workers, but not explicitly.