Live data from Hacker News

Update on IT Security Incident at UCSF

ucsf.edu

41–50 of 150 posts

Re: Update on IT Security Incident at UCSF

#41
post #18

What I find crazy about this -- no guarantee that the ransom payment would unlock the machines -- did they send 1.14M in one go or was it a smaller amount for the first machine, then an additional fee for each additional machine? Also would be interested to know -- was it Bitcoin or some other cryptocurrency that was used?

Apparently crypto-ransom people are actually pretty trustworthy about unlocking the machines. It doesn't really cost them anything (0% chance you were gonna send a 2nd payment if they didn't unlock), and their reputation as 'fair' is very important for securing future ransoms.

That creates an interesting grey hat scenario where a normally good actor could execute a few ransoms and not unlock the machines. Eroding trust in the entire scheme could reduce the long-term effectiveness of the scheme

Re: Update on IT Security Incident at UCSF

#42
post #10
post #3

The paid ransom, will unfortunately embolden the criminals to strike again in search of the next big payday. If it worked once, it could work again.

If the data is worth paying a million dollar ransom to unlock, it is worth setting up proper backups. I for one am grateful to people who commit these crimes in which they "lock" data in place rather than sell it to the highest bidder. Proper data hygiene isn't brain surgery. There is zero excuse for this event. I don't blame the criminals. I blame the university system. Shame!

Don’t entirely disagree, but also think it’s fair to say they almost certainly use the stolen data to find weaknesses in their next targets, so it’s not just a one to one thing. This doesn’t at all negate the main statement: good motivation to actually do proper backup and security.

Re: Update on IT Security Incident at UCSF

#43
post #6

Don’t they have insurance for these things? A small college near me had an attack like this but paid via insurance.

Would you want the insurance policy to pay out though? At some level of recklessness, insurance becomes void. I think a lack of infrastructure to restore a hacked server — with data valued at over $1M — is negligent enough to not be covered. But maybe UCSF are on MegaCo’s YOLO tier of server insurance, which is so expensive and isolated it has no impact on my MegaCo pet insurance premiums?

I'll venture a guess that UCSF was nominally in compliance with some relevant bureaucratic regime (ISO 27001, SOC 2, etc), and that was good enough for a stodgy insurance company that's not very sophisticated about "cyber risk" (in case use of the term "cyber" isn't a giveaway...)

Re: Update on IT Security Incident at UCSF

#45
post #35
post #13

As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…

How the heck did they qualify for H1Bs when they were replacing already employed Americans? Not only did the H1Bs unemploy citizens, we didn't even get the long term benefits of trained workers living and paying taxes in the States.

using H1B for 4 months stint is very strange. It is too valuable a visa slot (significantly oversubscribed lottery usually, at least in the recent years) to be wasted that way. Usually it is done using something like B1 for such a short trips, especially if it is training, etc. I wonder whether the journalists and others did mistake one visa for another, especially given that they naturally wouldn't be privy to such internal details of a 3rd party company like the HCL in this case.

Re: Update on IT Security Incident at UCSF

#46
post #35
post #13

As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…

How the heck did they qualify for H1Bs when they were replacing already employed Americans? Not only did the H1Bs unemploy citizens, we didn't even get the long term benefits of trained workers living and paying taxes in the States.

but they did get the benefit of cheaper IT workforce? What they did to their existing employees was certainly morally wrong but is outsourcing your IT support to cheaper third party seen as morally wrong too? Isn't that the idea of free captial market? Sure the state didn't get taxes from those employees but state owned university saved costs.

Re: Update on IT Security Incident at UCSF

#47

Earlier quoted context omitted.

Apparently crypto-ransom people are actually pretty trustworthy about unlocking the machines. It doesn't really cost them anything (0% chance you were gonna send a 2nd payment if they didn't unlock), and their reputation as 'fair' is very important for securing future ransoms.

Someone's gotta be thinking about doing a ransomware operation that doesn't unlock the data in order to poison the well.

It's been done. There was one "ransomware" attack that just erased everything.

Re: Update on IT Security Incident at UCSF

#48
post #6

Don’t they have insurance for these things? A small college near me had an attack like this but paid via insurance.

How would that work? Would the bad guys just ask for 10 times as much, since the insurance company is obligated to pay whatever it costs?

If kidnap & ransom insurance is any precedent: the policy has a limit, the insurance company's business is negotiation, and the whole thing is shrouded in secrecy to keep attackers from knowing who is insured & for how much. Even attackers who get paid have an incentive not to piss off the insurer.

Re: Update on IT Security Incident at UCSF

#49
post #13

As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…

Someone, somewhere, is calculating whether the ransomware line item was worth the offshoring and laying off local employees line item.

While what they did was may not be right, is there any direct link about this to work done by HCL? Have all of such previous attacks been linked to work done by H1Bs?

Re: Update on IT Security Incident at UCSF

#50
post #35
post #13

As a reminder, in 2017 UCSF offshored all of its IT staff to HCL Technologies and forced their then-employees to train their replacements before laying them off. They brought the replacements into the Bay Area on H1B temporarily while they were trained by their soon-to-be-laid-off counterparts and then sent back overseas to continue their roles once training was complete. https://sanfrancisco.cbslocal.com/2017/02/28/…

How the heck did they qualify for H1Bs when they were replacing already employed Americans? Not only did the H1Bs unemploy citizens, we didn't even get the long term benefits of trained workers living and paying taxes in the States.

Because HCL employed them, not UCSF.

A large percentage of H1Bs go to "bodyshops", which import workers from abroad to temporarily work at companies that are offshoring their employees. Yes, it's perverse; they are in effect being used to replace American workers, but not explicitly.

Post reply on HN