Live data from Hacker News

Merck’s NotPetya attack: Was it an act of war?

inquirer.com

1–10 of 115 posts

Re: Merck’s NotPetya attack: Was it an act of war?

#5

So what does this mean for company cybersecurity? Will companies be motivated to secure their networks by higher insurance rates? Will insurers hire infosec auditors? Will insurers stop offering coverage, and leave companies to consider hacks as Black Swan events?

Don't know but news like this makes me happy I switched from a senior in embedded firmware to a junior in cybersecurity. The future looks good.

Re: Merck’s NotPetya attack: Was it an act of war?

#6

So what does this mean for company cybersecurity? Will companies be motivated to secure their networks by higher insurance rates? Will insurers hire infosec auditors? Will insurers stop offering coverage, and leave companies to consider hacks as Black Swan events?

They would be very wise to hire their own auditors, not necessarily to go into their client's businesses but to review the assessments most of them are already getting periodically, to make sure that evidence presented actually made sense and earned them a pass. It's been my experience that IT auditors are often book smart, but IT-experience poor. Some are simply not savvy or experienced enough to interpret their own framework the same way a week or a month later.

Re: Merck’s NotPetya attack: Was it an act of war?

#9
post #8

The ransomware wanted $300 in Bitcoin per computer encrypted. This is a commercial extortion attempt, not an act of war. The insurers, as is their wont don't want to pay out.

This article is talking about NotPetya. It was NOT ransomware. There was no way to recover the files.

Re: Merck’s NotPetya attack: Was it an act of war?

#10

If the attacker doesn't declare war and the defender doesn't respond by going to war then the blunt answer seems like it'd have to be a no.

The claim in the article is that the target was Ukraine, the attacker Russia, and Merck a collateral casualty at an attempt to disguise a state-sponsored cyber-attack as a criminal extortion attempt.

One would need to dig deeper to get a really informed opinion. I do believe Russia to be able and willing to do that, I do believe the so-called "Western intelligence agencies" to blame any malware on Russia or China on the flimsiest evidences.

There is also the possibility that the same tools were used both by the GRU and Russian criminals, leading to a misleading identification. Black hats would totally take someone else's malware and modify it for their purpose while still hiding their tracks.

Zero days are expensive to get but once they are exploits in the wild, they are anyone's to use.

Post reply on HN