Merck’s NotPetya attack: Was it an act of war?
inquirer.com
Merck’s NotPetya attack: Was it an act of war?
1–10 of 115 posts
Re: Merck’s NotPetya attack: Was it an act of war?
#2Re: Merck’s NotPetya attack: Was it an act of war?
#3Re: Merck’s NotPetya attack: Was it an act of war?
#4So what does this mean for company cybersecurity? Will companies be motivated to secure their networks by higher insurance rates? Will insurers hire infosec auditors? Will insurers stop offering coverage, and leave companies to consider hacks as Black Swan events?
Re: Merck’s NotPetya attack: Was it an act of war?
#5So what does this mean for company cybersecurity? Will companies be motivated to secure their networks by higher insurance rates? Will insurers hire infosec auditors? Will insurers stop offering coverage, and leave companies to consider hacks as Black Swan events?
Re: Merck’s NotPetya attack: Was it an act of war?
#6So what does this mean for company cybersecurity? Will companies be motivated to secure their networks by higher insurance rates? Will insurers hire infosec auditors? Will insurers stop offering coverage, and leave companies to consider hacks as Black Swan events?
Re: Merck’s NotPetya attack: Was it an act of war?
#7Re: Merck’s NotPetya attack: Was it an act of war?
#8This is a commercial extortion attempt, not an act of war. The insurers, as is their wont don't want to pay out.
Re: Merck’s NotPetya attack: Was it an act of war?
#9The ransomware wanted $300 in Bitcoin per computer encrypted. This is a commercial extortion attempt, not an act of war. The insurers, as is their wont don't want to pay out.
Re: Merck’s NotPetya attack: Was it an act of war?
#10If the attacker doesn't declare war and the defender doesn't respond by going to war then the blunt answer seems like it'd have to be a no.
One would need to dig deeper to get a really informed opinion. I do believe Russia to be able and willing to do that, I do believe the so-called "Western intelligence agencies" to blame any malware on Russia or China on the flimsiest evidences.
There is also the possibility that the same tools were used both by the GRU and Russian criminals, leading to a misleading identification. Black hats would totally take someone else's malware and modify it for their purpose while still hiding their tracks.
Zero days are expensive to get but once they are exploits in the wild, they are anyone's to use.