Report shows HSE (Irish Health Service) hacked by malicious Excel file [pdf]
1–10 of 13 posts
Re: Report shows HSE (Irish Health Service) hacked by malicious Excel file [pdf]
#2Re: Report shows HSE (Irish Health Service) hacked by malicious Excel file [pdf]
#3Is the implication that they paid the ransom?
The report seems to go out of its way to avoid stating why the attacker posted the decryption key.
Re: Report shows HSE (Irish Health Service) hacked by malicious Excel file [pdf]
#4But security is an expense and people don't like paying money.
A financial company I worked for in mid 2000's decided the only thing they needed to do was buy some encryption for the disks their databases ran on, which of course would do nothing to keep someone from just using SQL to extract all our customers credit card data.
Re: Report shows HSE (Irish Health Service) hacked by malicious Excel file [pdf]
#5> On the same day, the Attacker posted a link to a key that would decrypt files encrypted by the Conti ransomware. [..] Without the decryption key, it is unknown whether systems could have been recovered fully [..] but it is highly likely that the recovery timeframe would have been considerably longer. Is the implication that they paid the ransom? The report seems to go out of its way to avoid stating why the attacke…
Re: Report shows HSE (Irish Health Service) hacked by malicious Excel file [pdf]
#6> On the same day, the Attacker posted a link to a key that would decrypt files encrypted by the Conti ransomware. [..] Without the decryption key, it is unknown whether systems could have been recovered fully [..] but it is highly likely that the recovery timeframe would have been considerably longer. Is the implication that they paid the ransom? The report seems to go out of its way to avoid stating why the attacke…
Maybe, but unlikely. I think it's more of an "ethics" issue (read: attackers don't want to get more heat than needed and also the HSE would have trouble paying for it)
Goverment agency hires a contractor for data recovery, the rate is Ransom + flat rate. they just pay the ransom and recover the data.
Re: Report shows HSE (Irish Health Service) hacked by malicious Excel file [pdf]
#7> On the same day, the Attacker posted a link to a key that would decrypt files encrypted by the Conti ransomware. [..] Without the decryption key, it is unknown whether systems could have been recovered fully [..] but it is highly likely that the recovery timeframe would have been considerably longer. Is the implication that they paid the ransom? The report seems to go out of its way to avoid stating why the attacke…
The discussion at the time was the perpetrators didn't expect to have the effect they did, effectively halting the entire health service for several weeks to months. I think the ethics element as the other commenter stated is a valid one, as one is playing with another's life when you interfere with medical operations, routine or otherwise
Re: Report shows HSE (Irish Health Service) hacked by malicious Excel file [pdf]
#8Earlier quoted context omitted.
Maybe, but unlikely. I think it's more of an "ethics" issue (read: attackers don't want to get more heat than needed and also the HSE would have trouble paying for it)
Usually the ransom is paid by 3rd party. Goverment agency hires a contractor for data recovery, the rate is Ransom + flat rate. they just pay the ransom and recover the data.
https://www.rte.ie/news/2021/0520/1222857-hse-weekly-briefin...
This is the government-funded news media organisation, akin to the BBC here — but I have sufficient trust that they didn't
Re: Report shows HSE (Irish Health Service) hacked by malicious Excel file [pdf]
#9As usual people ignore messages that basically told them what was happening. Reminds me of the Target hack where they installed some anti hacking system which immediately tossed out warnings which seemed excessive so they turned it off for a few months. But security is an expense and people don't like paying money. A financial company I worked for in mid 2000's decided the only thing they needed to do was buy some en…
Re: Report shows HSE (Irish Health Service) hacked by malicious Excel file [pdf]
#10> On the same day, the Attacker posted a link to a key that would decrypt files encrypted by the Conti ransomware. [..] Without the decryption key, it is unknown whether systems could have been recovered fully [..] but it is highly likely that the recovery timeframe would have been considerably longer. Is the implication that they paid the ransom? The report seems to go out of its way to avoid stating why the attacke…