Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

111–120 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#111

Earlier quoted context omitted.

This isn't really true. Stock price is not an indicator of a company's "bottom line". As someone who helps respond to major breaches at big companies, these types of breaches often result in enormous expenditures on company-wide efforts to close security gaps or revamp processes. Either a regulatory agency, or more often the company's board of directors, will make a mandate to the C-suite that something must be done.…

Please point out some 10Q/10K filings that go into detail about these enormous expenditures related to security breaches. The SEC EDGAR database [0] is where you can find public quarterly financial statements and forward guidance from management (which will definitely mention the security breach related expenses), for every US-listed publicly traded company. Good luck! [0] https://www.sec.gov/edgar/searchedgar/compan…

Literally the first company I pulled up, Capital One, has this in the 2020 10-K:

>During the year ended December 31, 2020, we incurred $66 million of incremental expenses related to the remediation of and response to the Cybersecurity Incident, offset by $39 million of insurance recoveries. To date, we have incurred $138 million of incremental expenses, offset by $73 million of insurance recoveries pursuant to the cyber risk insurance coverage we carry. These expenses mainly consist of customer notifications, credit monitoring, technology costs, and professional and legal support.

Go look at Equifax's 2018 10-K and it has pages upon pages talking about the impact, including:

> During the year ended December 31, 2018, the Company recorded $401.2 million of pre-tax expenses related to the 2017 cybersecurity incident and insurance recoveries of $75.0 million for net expenses of $326.2 million. Costs related to the 2017 cybersecurity incident are defined as incremental costs to transform our information technology infrastructure and data security; legal fees and professional services costs to investigate the 2017 cybersecurity incident and respond to legal, government and regulatory claims; as well as costs to provide the free product and related support to the consumer.

For Equifax, there is also an additional $112 million (net, after insurance recovery) in breach-related expenditures in the 2017 10-K.

Re: US companies hit by 'colossal' cyber-attack

#112

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

Statistically EVERYONE has extremely poor security culture. It's been wallpapered over as just cutting unnecessary expense for too long.

It is almost proof we can't collectively think statistically.

I get it at a pretty deep level individually but even knowing this I make enormous mistakes.

Re: US companies hit by 'colossal' cyber-attack

#113
post #65

I think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.

Toothpaste's out of the tube. Banning the exchanges won't stop the ransomware.

Why not? What's to prevent e.g. the U.S. Government from outlawing the use of exchanges, and/or outlawing the payment of cryptocurrency ransoms, just as it forbids globally the payment of bribes?

Re: US companies hit by 'colossal' cyber-attack

#114

Earlier quoted context omitted.

This isn't really true. Stock price is not an indicator of a company's "bottom line". As someone who helps respond to major breaches at big companies, these types of breaches often result in enormous expenditures on company-wide efforts to close security gaps or revamp processes. Either a regulatory agency, or more often the company's board of directors, will make a mandate to the C-suite that something must be done.…

I don't believe you. Give me an example of a company spending 100's of millions as a result of a breach. Companies understand it costs them nothing and if there is a cost it's trivial. When there is no penalty or the fine is a pittance, no company is going to spend 10's to 100's of millions. It makes no business sense first of all and secondly they can blame a foreign actor to mask their own incompetence.

See: https://news.ycombinator.com/item?id=27719281

Re: US companies hit by 'colossal' cyber-attack

#115

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

RMM is absolutely vital to securing systems. This is as ridiculous as suggesting we should just get rid of firewalls because there are vulnerabilities found in them. RMMs are how enterprise scale networks close off every other security hole on a network. That being said, RMM tools have plenty of examples that they need to beef up their security practices or get replaced.

No, RMM is the magic beans someone wants you to trade your cows for. All OS and networking vendors have better tools, but people pay for RMMs because they make a lot of promises and charge less money. People who use them will invariably get burned.

Re: US companies hit by 'colossal' cyber-attack

#116
post #95

Earlier quoted context omitted.

This isn't really true. Stock price is not an indicator of a company's "bottom line". As someone who helps respond to major breaches at big companies, these types of breaches often result in enormous expenditures on company-wide efforts to close security gaps or revamp processes. Either a regulatory agency, or more often the company's board of directors, will make a mandate to the C-suite that something must be done.…

Dude, if you look at Equifaxes and Solarwinds EBITDA/earnings statements following their respective breaches, you will clearly see that there has been no major impact to their bottom line. Sure, expenses rise a bit for a short period of time, but these are not catastrophic by any means. I mean, I'm looking at Solarwinds last earnings statement and comparing quarters from last year to now, they are up about 3.5% in re…

>Dude, if you look at Equifaxes and Solarwinds EBITDA/earnings statements following their respective breaches, you will clearly see that there has been no major impact to their bottom line.

I'm looking at Equifax's 2018 statements right now. With Operating Revenue of $3.4 billion and profits of $850 million, they had $400 million of expenses related to the breach. "No major impact" my ass.

Re: US companies hit by 'colossal' cyber-attack

#117
post #24

Earlier quoted context omitted.

It's not enough to just gain access - once you're in you need to compromise other defenses, you need to communicate your demand to the victim, you need to know how much to extort, you need to actually process the payment. Either you do this on a case by case basis or you take advantage of additional exploits that will only be viable for a subset of your potential targets, and this is all a race against time before so…

Maybe you’re a state actor and a ransom demand, at least an overt one, is not your objective.

My mind went there as well. Say I'm an affluent oligarch shorting major companies. I'd paying the ransom group to massively attack the company or various companies. Then cash out during the chaos.

Re: US companies hit by 'colossal' cyber-attack

#118

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

The interesting part about last year's incidents of solarwinds, fireeye and fortinet is that there's a switch away from actually targeting the hosts after the first line of defense.

Redteams / hackers now target the infastructure, because it's way easier and they're more outdated in regards of code, stability and used libraries.

Most enterprise-grade VPN solutions still use OpenSSL from decades ago, and most of their fixes (even if they react to CVEs) are always too late.

As SOCs need VPN access because they are usually not on-site, especially at larger corporations...the result is when you exploit the VPN gateway, you are the new administrator because you have a large time window until the SOC team arrives on-site. These couple hours are usually everything you need as a time window to raid the place, install and run ransomware, and clean up afterwards.

From a cybersec perspective I cannot even begin to write how stupid it is to put literally all your company's value in the hands of a single security company - which is legally not responsible for anything by contract. Security through obscurity never worked, why should it do in this case?

Last year showed that we desperately need an open source OpenVPN based graphical and scalable alternative that uses a standard TOTP based token generation mechanism and not some proprietary crap for authentication.

Re: US companies hit by 'colossal' cyber-attack

#119
Oddly explosive headline, considering:

> It is not clear what specific companies have been affected - a Kaseya representative contacted by the BBC declined to give details.

So why "colossal"?

> "This is a colossal and devastating supply chain attack," Huntress Labs' senior security researcher John Hammond said in an email to Reuters news agency.

The BBC is going with "colossal" in their headline simply because the guy who discovered the incident said so?

Re: US companies hit by 'colossal' cyber-attack

#120
post #52

Earlier quoted context omitted.

I feel like this is a bold claim. I understand this to mean that you assume without crypto there would be less of a way to get payed for attacks like these? Or am I missing something here. Also, Do you have an evidence to support the argument: Crypto has increased cyber crime? (I hope that is an acceptable parse of your sentiment)

These attacks didn't exist before crypto.

I recall they provided multiple payment options back when crypto was too hard for victims to obtain / figure out.

e.g. this 2013 article from a quick web search, where the payment method dropdown contains Bitcoin and MoneyPak payment cards: https://arstechnica.com/information-technology/2013/10/youre...

Post reply on HN