Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

141–150 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#141

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

Give it time, these are start-ups bootstrapping themselves. They don't have the support infrastructure in place yet to scale to beyond a few hundred companies. As it is, there are going to be a lot of over-worked people at REvil doing crunch time, missing family dinners and their kids' recitals and soccer games managing the logistics of this hack. No worries though, the ransom from this round should serve nicely as a…

I wonder how much of a human element is involved in each individual hack. I would have thought the sticky note, encryption, payment & decryption was all automated.

Re: US companies hit by 'colossal' cyber-attack

#142

Earlier quoted context omitted.

Please point out some 10Q/10K filings that go into detail about these enormous expenditures related to security breaches. The SEC EDGAR database [0] is where you can find public quarterly financial statements and forward guidance from management (which will definitely mention the security breach related expenses), for every US-listed publicly traded company. Good luck! [0] https://www.sec.gov/edgar/searchedgar/compan…

Literally the first company I pulled up, Capital One, has this in the 2020 10-K: >During the year ended December 31, 2020, we incurred $66 million of incremental expenses related to the remediation of and response to the Cybersecurity Incident, offset by $39 million of insurance recoveries. To date, we have incurred $138 million of incremental expenses, offset by $73 million of insurance recoveries pursuant to the cy…

If I am being frank, based on anecdotes I have heard, Equifax had their heads so far up their asses that they basically had to rebuild their entire infrastructure because it was an unmitigated disaster.

This was a conscious business decision to not make the necessary changes to address their infrastructure.

Re: US companies hit by 'colossal' cyber-attack

#143
It's amazing that the World Economic Forum was able to predict a global pandemic in 2019 with Event 201 [1] and widespread cyber attacks in 2021 with Cyber Polygon [2]. Their timing for conducting these trainings is impeccable.

We'll probably need Internet Passports, with malware scan certificates, to get online safely. Hope you're not an anti-scanner (it's totally secure). Evil Russian hackers will be a convenient scapegoat for food supply shortages and power outages, but we really needed climate lockdowns, anyway, so we're actually saving the environment here!

So begins Act II of the global feudalist coup.

[1] https://www.centerforhealthsecurity.org/event201/

[2] https://www.weforum.org/projects/cyber-polygon

Re: US companies hit by 'colossal' cyber-attack

#144
post #71
post #26

Earlier quoted context omitted.

Because there are plenty of zero-days the NSA can deploy if you step out of your lane. It’s as much a political game at this point as anything. If anyone thinks they can hide behind cryptocurrency and hold truly strategic companies hostage they are deluding themselves. They’ll either end up hacked beyond their wildest imagination or facing literal hellfires. It’s brinkmanship. When the devs literally die, they think…

At some point, some nation-state will get annoyed enough to do something drastic. That's what ended state-sponsored terrorism. Or even a company. Uber's security chief once became annoyed with an attack from Nigeria. They traced the attack to an Internet cafe and sent some "lawyers" to talk to the attacker. Someone tried a ransomware attack on the Teamsters Union in 2019.[1] The FBI advised them to pay. The Teamsters…

I wish you would have sourced the Uber Nigeria story instead.

Re: US companies hit by 'colossal' cyber-attack

#145

Really good thread here: https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransom... When these things happen, I feel like there's a predictable response. A few smaller vendors (above, Huntress Labs) provide a great running commentary. Then two weeks later, the dust has settled, everyone's patched, and I'll start receiving sales calls from Enterprise Vendor X wanting to talk about how they were all over it.

Wow

| We received an emergency call from our Kaseya rep to shut down our onprem VSA

Re: US companies hit by 'colossal' cyber-attack

#146
post #71

Earlier quoted context omitted.

At some point, some nation-state will get annoyed enough to do something drastic. That's what ended state-sponsored terrorism. Or even a company. Uber's security chief once became annoyed with an attack from Nigeria. They traced the attack to an Internet cafe and sent some "lawyers" to talk to the attacker. Someone tried a ransomware attack on the Teamsters Union in 2019.[1] The FBI advised them to pay. The Teamsters…

I wish you would have sourced the Uber Nigeria story instead.

It's in the book "Super Pumped: The Battle for Uber".

Re: US companies hit by 'colossal' cyber-attack

#147
post #68

After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line. You can also see this in the Solarwinds stock price. Year over year, they are down a hair under 4 percent... After being directly responsible for…

“After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line.” It’s even worse than just weathering a storm. Lax security has been incentivized. The Equifax CEO, Richard Smith, stepped down shortly after th…

Isn't Equifax a government organization? How do they have severance packages?

Re: US companies hit by 'colossal' cyber-attack

#148

“ At a summit in Geneva last month, US President Joe Biden said he told Russian President Vladimir Putin he had a responsibility to rein in such cyber-attacks.” I don’t understand how Putin can stop these attacks unless he is personally responsible for them. Imagine someone in the US hacking systems in Russia or China. How in the hell Biden would know who did that and stop them? The naivety of US government is just a…

Uh... maybe Russia has a bad rap:

By providing cybercriminals a safe harbor to carry out their attacks.

By refusing to cooperate with foreign LE unless they have targeted RU citizens.

By using the LE/MLAT requests that are sent to them to track down these criminals and force them into moonlighting for state intelligence services or be arrested.

Re: US companies hit by 'colossal' cyber-attack

#149

Earlier quoted context omitted.

“After the Equifax breach, everyone learned that until there are actual repercussions for cyber attacks (like fines and people going to jail for negligence), if you can weather the storm, over the course of a year or two, there is effectively zero impact to your bottom line.” It’s even worse than just weathering a storm. Lax security has been incentivized. The Equifax CEO, Richard Smith, stepped down shortly after th…

Isn't Equifax a government organization? How do they have severance packages?

It is a publicly traded corporation.

Re: US companies hit by 'colossal' cyber-attack

#150

Earlier quoted context omitted.

RMM is absolutely vital to securing systems. This is as ridiculous as suggesting we should just get rid of firewalls because there are vulnerabilities found in them. RMMs are how enterprise scale networks close off every other security hole on a network. That being said, RMM tools have plenty of examples that they need to beef up their security practices or get replaced.

No, RMM is the magic beans someone wants you to trade your cows for. All OS and networking vendors have better tools, but people pay for RMMs because they make a lot of promises and charge less money. People who use them will invariably get burned.

This is... laughably and demonstrably false. Neither Microsoft nor Apple tools even pass muster for large-scale IT management. Generally speaking, you'll pay more for a worse product direct from the OS developers. In most cases, your Microsoft-based solutions are less secure (RDP) than pretty much anything else. Apple is pretty much going to give you the minimum glue necessary to use a third party tool (see Apple Business Manager).
Post reply on HN