Live data from Hacker News

US companies hit by 'colossal' cyber-attack

bbc.com

81–90 of 514 posts

Re: US companies hit by 'colossal' cyber-attack

#81
post #24

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

It's not enough to just gain access - once you're in you need to compromise other defenses, you need to communicate your demand to the victim, you need to know how much to extort, you need to actually process the payment. Either you do this on a case by case basis or you take advantage of additional exploits that will only be viable for a subset of your potential targets, and this is all a race against time before so…

Maybe you’re a state actor and a ransom demand, at least an overt one, is not your objective.

Re: US companies hit by 'colossal' cyber-attack

#82
Really good thread here:

https://www.reddit.com/r/msp/comments/ocggbv/crticial_ransom...

When these things happen, I feel like there's a predictable response. A few smaller vendors (above, Huntress Labs) provide a great running commentary. Then two weeks later, the dust has settled, everyone's patched, and I'll start receiving sales calls from Enterprise Vendor X wanting to talk about how they were all over it.

Re: US companies hit by 'colossal' cyber-attack

#83
In some not-so-distant future dystopia, ransomware hackers will morph into a file encryption service w/ optional data exfiltration as a backup. Just don't stop paying the bill.

Or at least that's where we're headed if companies keep giving in to the ransom demands.

Re: US companies hit by 'colossal' cyber-attack

#84

I think this should be the death knell of cryptocurrencies. Or at least exchanges that allow the exchange of them for fiat.

Without crypto, would it be impossible to extract cash from a company? What is the current mechanism used to get funds that the FBI can’t track down? Wire the money to a jurisdiction mostly out of our sphere of influence.

More difficult, but feasible.

One way is to demand that a smaller amount of money be wired to 1,000 accounts throughout the world.

You — the bad guy - own merely one of them.

Difficult to trace them all before you empty your particular account.

Re: US companies hit by 'colossal' cyber-attack

#86
post #69
post #49

The Microsoft team at a company I used to work for tried to push this very software out onto all staff machines. Our Platform Engineering team managed to push back on it based on the grounds that it was a serious security concern and is essentially an "enterprise" backdoor. The following year the bulk of our team decided to resign move on to other employment - I was told Kaseya was rolled out to all machines shortly…

What software are you referring to? The article only mentions "VSA tool", and that does not ddg well.

The article links to https://us-cert.cisa.gov/ncas/current-activity/2021/07/02/ka... , which says it was Kaseya VSA and links to their advisory.

Re: US companies hit by 'colossal' cyber-attack

#87

Earlier quoted context omitted.

I think that the problem is these companies are publicly-traded. Chasing YoY returns and never having a down quarter are antithetical to building a lasting security model.

Microsoft, Apple, and Google seem to be doing ok.

That's true, but when have FAANG unicorns ever had the same "laws of physics" that other companies have?

Re: US companies hit by 'colossal' cyber-attack

#88

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

Give it time, these are start-ups bootstrapping themselves. They don't have the support infrastructure in place yet to scale to beyond a few hundred companies. As it is, there are going to be a lot of over-worked people at REvil doing crunch time, missing family dinners and their kids' recitals and soccer games managing the logistics of this hack.

No worries though, the ransom from this round should serve nicely as a Series B round of financing & enable rapid scaling of the post-hack ransom extraction process.

Re: US companies hit by 'colossal' cyber-attack

#89

I never quite understood why these ransom-ware attackers restrict themselves to a small subset of the MSP's clients. E.g.: The SolarWinds attack affected only something like 1% of their customers, when it could easily have been 50% or more! If you're evil and out for money, wouldn't you want to cast the widest net possible? Similarly, by encrypting a huge number of corporations concurrently, you'd "exhaust" the abili…

And I think Cloud computing is covertly 'leaking' vital data and has its role in ransom-ware attacks https://archive.is/x1Hvh

Re: US companies hit by 'colossal' cyber-attack

#90

Honestly, I think this should be the death knell of these "remote monitoring and management" tools that have extreme low-level access to networks and systems, but just like the SolarWinds attack, it feels like these are run by companies with extremely poor security culture. I mean, I'd be willing to trust security to Microsoft or Apple (I mean, at some level, you've got to trust the OS). But giving the keys to the ca…

Statistically EVERYONE has extremely poor security culture.

It's been wallpapered over as just cutting unnecessary expense for too long.

Post reply on HN