The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Microsoft on March 14, but Merck's IT chose to sit on it for over three months. (Like many large companies, they disable Windows update, choosing to release patches on their own schedule.) Even after the WannaCry attack crippled computers around the world on May 12, they still had a month before NotPetya brought them to their knees on June 27.
Merck’s NotPetya attack: Was it an act of war?
41–50 of 115 posts
Re: Merck’s NotPetya attack: Was it an act of war?
#42I worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Micro…
However in these situations those systems are siloed and segregated do that things don’t propagate. I have no idea how Merck is setup.
Re: Merck’s NotPetya attack: Was it an act of war?
#43Act of war against .... Merck, a company? I've heard of some circuitous logic to deny insurance claims, but this was not an act of war against Merck, which BTW isn't a country, so by definition, one can't go to war with it? Well, maybe hyperbolically a competitor might, but unlike real war, they're bound by the rules and laws of civil society This is the very definition of an accident, if the article is to be believe…
While I’m opposed to using legal terms to weasel out of an insurance claim, it’s an interesting question. If Russia deliberately dropped a bomb on Merck’s factory, it would unquestionably be an act of war. Likewise if they dropped a bomb on a neighboring plant and also accidentally destroyed Merck’s plant. But dropping a bomb on a facility in Ukraine, with equally destructive shrapnel destroying facilities all over t…
It is interesting though to think about aftermath. If it is not an act of war, one can compromise a country's economy without going directly against the country itself.
Re: Merck’s NotPetya attack: Was it an act of war?
#44Act of war against .... Merck, a company? I've heard of some circuitous logic to deny insurance claims, but this was not an act of war against Merck, which BTW isn't a country, so by definition, one can't go to war with it? Well, maybe hyperbolically a competitor might, but unlike real war, they're bound by the rules and laws of civil society This is the very definition of an accident, if the article is to be believe…
Re: Merck’s NotPetya attack: Was it an act of war?
#45Re: Merck’s NotPetya attack: Was it an act of war?
#46I worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Micro…
I'm not familiar with their environment but depending on the software and vendors who support aspects of software, those patches may be held at their request. That is people like Rockwell, Emmerson, whatever, may not “release” a patch because it can have implications for GxP environments. So not saying this is the case, but there are times when that is the case and companies have to sit on fixes. However in these sit…
Re: Merck’s NotPetya attack: Was it an act of war?
#47This stuff is fundamentally different than the case where a group of people end up with guns and engage in politically motivated violence. It is really a form of advanced trolling. The fact that absolutely anyone can do with with no fear for their life or freedom makes it politically meaningless.
There is no such thing as cyberwar...
So insurance is really just about insuring against security lapses. It should be priced appropriately and should come with requirements.
Re: Merck’s NotPetya attack: Was it an act of war?
#48I worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Micro…
Merck has a new IT Head - joined on Nov 2018. The attack happened on Jun 2017 (i.e., 1.5 years earlier). Jim Scholefield - https://www.linkedin.com/in/jimscholefield/ Great pedigree: Nike, Coca Cola etc.
[Edit]
Seems to be: He will also have oversight of cyber-security – a big issue for the company after a ransomware attack in June 2017 brought the company to a grinding halt. Scholefield will be part of the company’s executive committee, reflecting how integral the digital transformation drive is to the business.
http://www.pmlive.com/pharma_news/merck_and_co_picks_nike_ex...
Re: Merck’s NotPetya attack: Was it an act of war?
#49Obama used covert action against Russia in response to election meddling. "Obama used covert retaliation in response to Russian election meddling." https://www.washingtonpost.com/news/monkey-cage/wp/2017/06/2... Trump is not responding.
Is hybrid warfare a warfare until it includes conventional warfare in the mix?
https://en.wikipedia.org/wiki/Hybrid_warfare
> Hybrid warfare is a military strategy which employs political warfare and blends conventional warfare, irregular warfare and cyberwarfare[1] with other influencing methods, such as fake news,[2] diplomacy, lawfare and foreign electoral intervention.
> The U.S. Army Chief of Staff defined a hybrid threat in 2008 as an adversary that incorporates "diverse and dynamic combinations of conventional, irregular, terrorist and criminal capabilities".[9] The United States Joint Forces Command defines a hybrid threat as, “any adversary that simultaneously and adaptively employs a tailored mix of conventional, irregular, terrorism and criminal means or activities in the operational battle space. Rather than a single entity, a hybrid threat or challenger may be a combination of state and nonstate actors".[9] The U.S. Army defined a hybrid threat in 2011 as "the diverse and dynamic combination of regular forces, irregular forces, criminal elements, or a combination of these forces and elements all unified to achieve mutually benefiting effects".[9] NATO uses the term to describe "adversaries with the ability to simultaneously employ conventional and non-conventional means adaptively in pursuit of their objectives"
Re: Merck’s NotPetya attack: Was it an act of war?
#50The ransomware wanted $300 in Bitcoin per computer encrypted. This is a commercial extortion attempt, not an act of war. The insurers, as is their wont don't want to pay out.
Just as a thought experiment, if country X would shut down power in country Y, asking for 100 billion in ransom to start power again. Would that be an act of war, or just commercial extortion? It matters from a legal perspective, and perhaps the laws of war have to be updated for cyber warfare.