Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

121–130 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#121

Earlier quoted context omitted.

Please point out some 10Q/10K filings that go into detail about these enormous expenditures related to security breaches. The SEC EDGAR database [0] is where you can find public quarterly financial statements and forward guidance from management (which will definitely mention the security breach related expenses), for every US-listed publicly traded company. Good luck! [0] https://www.sec.gov/edgar/searchedgar/compan…

Literally the first company I pulled up, Capital One, has this in the 2020 10-K: >During the year ended December 31, 2020, we incurred $66 million of incremental expenses related to the remediation of and response to the Cybersecurity Incident, offset by $39 million of insurance recoveries. To date, we have incurred $138 million of incremental expenses, offset by $73 million of insurance recoveries pursuant to the cy…

I'm not sure which number to use, but Capital One had either 2.4 or 5 Billion in income... .066 billion on cybersecurity remediation isn't an existential threat.

Re: US companies hit by 'colossal' cyber-attack

#122

Oddly explosive headline, considering: > It is not clear what specific companies have been affected - a Kaseya representative contacted by the BBC declined to give details. So why "colossal"? > "This is a colossal and devastating supply chain attack," Huntress Labs' senior security researcher John Hammond said in an email to Reuters news agency. The BBC is going with "colossal" in their headline simply because the gu…

[deleted]

Re: US companies hit by 'colossal' cyber-attack

#123

This really seems like a deliberate provocation testing the "16 sectors" considered off limits, delivered to Putin from the Biden Administration. And now waiting to see what the response is going to be, whether it was an indelible line or one drawn in sand. I could be wrong, it could be coincidental, but the timing makes it pretty interesting for perhaps the largest single (in terms of affected companies) ransomware…

There is also allegedly a reciprocal agreement to allow extradition and prosecution for cyber attacks. So we'll see if that comes to pass or if it's just a little fake glad handing until you actually try to take them up on it.

Re: US companies hit by 'colossal' cyber-attack

#124

Earlier quoted context omitted.

Would you mind briefly explaining the concept of "tech debt" to a layperson?

"tech debt" is when you decide that you will cut a corner to build something. If you did it when building a plane, and it killed people, you would go to prison, but in the technology industry, this is acceptable as "the cost of being first"

Also the cost of understanding the problem more fully. And the cost of discovering a better way to do it.

Re: US companies hit by 'colossal' cyber-attack

#125
post #95

Earlier quoted context omitted.

Dude, if you look at Equifaxes and Solarwinds EBITDA/earnings statements following their respective breaches, you will clearly see that there has been no major impact to their bottom line. Sure, expenses rise a bit for a short period of time, but these are not catastrophic by any means. I mean, I'm looking at Solarwinds last earnings statement and comparing quarters from last year to now, they are up about 3.5% in re…

>Dude, if you look at Equifaxes and Solarwinds EBITDA/earnings statements following their respective breaches, you will clearly see that there has been no major impact to their bottom line. I'm looking at Equifax's 2018 statements right now. With Operating Revenue of $3.4 billion and profits of $850 million, they had $400 million of expenses related to the breach. "No major impact" my ass.

Roughly 10% of revenue is something, but not that big of a deal, especially since their overall revenue is up.

Don’t you think stronger consequences than that should happen when a company unintentionally discloses tens of millions of people’s personally identifiable information that has been collected without any particularly explicit permission given by those people?

Credit agencies hold a special place in the US economy, and when they messed up this badly, the team threat of some near-going-out-of-business level consequences seem like the only way to truly get other companies to take this seriously. Especially considering that there are other credit agencies in the country - they don’t have a monopoly on this.

Re: US companies hit by 'colossal' cyber-attack

#126
post #110

Earlier quoted context omitted.

No, they typically sold stolen information on private/underground/invite forums or IRC. Instead of crypto-randomware, it would be an all out worm or booter that would crush a service who would have to acquiesce to demands. Luckily, there weren't too many good services in existence, Cloudflare didnt exist, c10k was a mind blower, webdev was AJAX, XMLRPC, and CGI. The term TLS hadn't been coined, it was still called SS…

> it would be Apple or Google Play codes I don't think Apple or Google credits would be effective for large-scale ransomware. Not anonymous, could be stopped by a slightly-motivated central authority. It works for preying on individuals, however, because they don't have enough clout to force the issue.

No, of course not. However, they could easily be used to exchange for access to data exfiltrated in the post exploitation phase. Or just money orders held in escrow a'la 1990's Ebay.

The workflow is:

Target->Crack->Retrieve->Store->Sell on hackforums

Maybe there is a way to automate this old school method, but nobody developed it because why bother.

Re: US companies hit by 'colossal' cyber-attack

#128
post #17

Earlier quoted context omitted.

Agreed. Companies that are great at selling to governments and massive enterprises tend to be great at security theatre and security certifications, but that’s not the same as being great at security. Their tech tends to be bloated spaghetti full of tech debt, with a huge surface area for attacks, and systems like that are nearly impossible to secure in a truly robust way. Embedding this kind of software deep in your…

Would you mind briefly explaining the concept of "tech debt" to a layperson?

"Code other people who are not me have written and frameworks I didn't pick"

(I jest. A bit cynical but that's often how it comes out in practice).

Re: US companies hit by 'colossal' cyber-attack

#129
post #95

Earlier quoted context omitted.

Dude, if you look at Equifaxes and Solarwinds EBITDA/earnings statements following their respective breaches, you will clearly see that there has been no major impact to their bottom line. Sure, expenses rise a bit for a short period of time, but these are not catastrophic by any means. I mean, I'm looking at Solarwinds last earnings statement and comparing quarters from last year to now, they are up about 3.5% in re…

>Dude, if you look at Equifaxes and Solarwinds EBITDA/earnings statements following their respective breaches, you will clearly see that there has been no major impact to their bottom line. I'm looking at Equifax's 2018 statements right now. With Operating Revenue of $3.4 billion and profits of $850 million, they had $400 million of expenses related to the breach. "No major impact" my ass.

If you compare year over year, many of the things they attribute to the breach are actually just IT/overhead costs they were able to shift to a loss. If you look at their EBITDA, everything is essentially static. In the grand scheme of things, it really isn't a huge impact to them.

Lets say you are a CEO: If you underspend on technology/security by ~50-100m/year, for 5 or 10 years... then have a bad breach, which costs you 400m, what do you get?

A: A Ferrari, because you saved the company 500m dollars and got a cyber insurer to pay for your technology/security program.

I'm not even joking you, I have been in meetings with a CEO, CIO and CISO, where they literally joked around that they should have more breaches because they actually made money on the intrusion and that they were able to upgrade a bunch of stuff they were planning on upgrading next year anyways.

Re: US companies hit by 'colossal' cyber-attack

#130
post #113
post #65

Earlier quoted context omitted.

Toothpaste's out of the tube. Banning the exchanges won't stop the ransomware.

Why not? What's to prevent e.g. the U.S. Government from outlawing the use of exchanges, and/or outlawing the payment of cryptocurrency ransoms, just as it forbids globally the payment of bribes?

Nothing. Also nothing prevents the US government from outlawing drugs. Likely with the same effectiveness.

BTW are most of these hackers transferring to fiat through U.S. exchanges? I can't imagine that's the case but maybe it is.

Post reply on HN