Live data from Hacker News

Retail cyber attacks: NCA arrest four for attacks on M&S, Co-op and Harrods

nationalcrimeagency.gov.uk

61–67 of 67 posts

Re: Retail cyber attacks: NCA arrest four for attacks on M&S, Co-op and Harrods

#61
post #16

Earlier quoted context omitted.

This simply isn’t true. Yes, teenagers are morons by the standard of a well adjusted 30 year old, but they’re more than capable of understanding consequences for their actions. I hate to sound like my parents/grandparents but I absolutely knew that causing millions of pounds of damage and attempting to blackmail a major corporation could have huge negative consequences for people and myself at 17.

Maybe I didn't phrase that quite right. I knew a kid who was caught by the FBI carding at just 14. He was totally aware of what he was doing but did not comprehend the severity of his crimes. Like I remember him just casually dismissing it as some cute prank. Apparently he was arrested, had his computer confiscated, then banned from using the Internet or a computer. I only heard that through others who knew him perso…

I’m just going to point out that your story shows two different things:

1. A person who didn’t understand consequences.

2. A person of similar age who did.

Which is kinda my entire point.

Re: Retail cyber attacks: NCA arrest four for attacks on M&S, Co-op and Harrods

#62
post #46

A friend of mine is senior management at one of these companies. His life has been a real nightmare trying to get things back on track - there are so many interconnected systems that they needed to get back up 'clean' and running just to get their normal business running, let alone the online side. And he's not even directly responsible for any of this, but it's all so embedded in a modern retail business that if som…

>it's your problem to deal with to a degree How is it not the responsibility of senior management at a major retailer to ensure an exploit at a vendor can't take the whole house of cards down? Many other major enterprise clients out there are all over vendor security/compliance ... auditing and reauditing vendors to minimise chance of this happening or worst-case, if does happen, containing it and recoverying quickly

>How is it not the responsibility of senior management at a major retailer to ensure an exploit at a vendor can't take the whole house of cards down?

I think you may be misunderstanding their organisation layout - his job is entirely to do with the quality of the products that they offer (and he's very good at it). He's nothing to with sales or online or any of that, but part of the 'normal' retail chain that people would never think goes anywhere this stuff. But their systems were all taken out because of this.

Re: Retail cyber attacks: NCA arrest four for attacks on M&S, Co-op and Harrods

#63
post #61

Earlier quoted context omitted.

Maybe I didn't phrase that quite right. I knew a kid who was caught by the FBI carding at just 14. He was totally aware of what he was doing but did not comprehend the severity of his crimes. Like I remember him just casually dismissing it as some cute prank. Apparently he was arrested, had his computer confiscated, then banned from using the Internet or a computer. I only heard that through others who knew him perso…

I’m just going to point out that your story shows two different things: 1. A person who didn’t understand consequences. 2. A person of similar age who did. Which is kinda my entire point.

I don't understand where you got 1 and 2 from. They're the same story, teenagers doing dumb shit without understanding what would come of it. I didn't understand what you're not getting here

Re: Retail cyber attacks: NCA arrest four for attacks on M&S, Co-op and Harrods

#64
post #61

Earlier quoted context omitted.

I’m just going to point out that your story shows two different things: 1. A person who didn’t understand consequences. 2. A person of similar age who did. Which is kinda my entire point.

I don't understand where you got 1 and 2 from. They're the same story, teenagers doing dumb shit without understanding what would come of it. I didn't understand what you're not getting here

> Maybe I didn't phrase that quite right. I knew a kid who was caught by the FBI carding at just 14... Like I remember him just casually dismissing it as some cute prank.

> Got into a little incident where we pissed off some dudes, one who had a gun... Learned real fast not to do stupid "funny shit" that was really just jerk behavior.

Case 1, the kid didn't learn. Case 2, you learnt. By the way, both of these can—and do—apply to adults. If "young people can't consider consequences," then you would have went out and got shot and probably wouldn't be here telling me about this story.

Re: Retail cyber attacks: NCA arrest four for attacks on M&S, Co-op and Harrods

#65
post #8

Earlier quoted context omitted.

Reminds me of Maersk. They had poor endpoint hygiene and no EDR. In 2017 about 90% of their infrastructure was wiped in less than one minute. They had to reinstall a lot of things due to backups weren't up to par. Usually level 1 merchants (> 6 million transactions per year) are put on an audit and improvement plan if this occurs. In the UK, there could be an investigation and penalty from the ICO for the data breach…

> They had to reinstall a lot of things due to backups weren't up to par. "After a frantic search that entailed calling hundreds of IT admins in data centers around the world, Maersk’s desperate administrators finally found one lone surviving domain controller in a remote office—in Ghana. At some point before NotPetya struck, a blackout had knocked the Ghanaian machine offline, and the computer remained disconnected…

They were lucky.

Remote DC's were always entertaining for us. We had hundreds, and it was usually and reluctantly due to environmental conditions where they didn't want to deal with authentication issues if the network was down.

The downside was the occasional DC that disappeared. Once in Egypt, a fire caused relocation of servers and what not, and we actually had a guy take a photo of our DC on a donkey cart in the process of moving down the street. I thought those were made up things, but donkey carts usually don't need a license or insurance.

Re: Retail cyber attacks: NCA arrest four for attacks on M&S, Co-op and Harrods

#66
post #37

Earlier quoted context omitted.

Was it a professional operation? Says they were 17. Some people playing around with their Commodore 64 except it's connected to the internet and a pretty big company.

Let's not pretend these kids were trying to hack the Gibson just for the lulz. Calling into help desk, requesting password resets with social engineering, getting into network, installing ransomware is all well beyond playing around. I know there are smart teens, but I would not be surprised to find out there is someone more experienced in the background that got the kids going if not even on behalf of. There are ple…

Kids used to do stuff like wardialing, which is kind of on a similar level, with less actual humans involved though.

Re: Retail cyber attacks: NCA arrest four for attacks on M&S, Co-op and Harrods

#67
post #64

Earlier quoted context omitted.

I don't understand where you got 1 and 2 from. They're the same story, teenagers doing dumb shit without understanding what would come of it. I didn't understand what you're not getting here

> Maybe I didn't phrase that quite right. I knew a kid who was caught by the FBI carding at just 14... Like I remember him just casually dismissing it as some cute prank. > Got into a little incident where we pissed off some dudes, one who had a gun... Learned real fast not to do stupid "funny shit" that was really just jerk behavior. Case 1, the kid didn't learn. Case 2, you learnt. By the way, both of these can—and…

I did not mod you down so I am not the only one confused. Yes I learned, but how on earth can you assume the kid who got arrested didn't? He was in fact arrested for that crime and never heard from again. I don't know if he learned but he certainly might have.
Post reply on HN