Australia's Lion brewery hit by second cyber attack as nation staggers under suspected Chinese digital assault
- Reference: 1592593809
- News link: https://www.theregister.co.uk/2020/06/19/lion_brewery_second_cyber_attack_australia/
- Source link:
The Sydney Morning Herald [1]reported that Lion told its staff today "it had been hit by a second cyber attack that had further disrupted its IT systems."
"The company is now focusing on defence efforts over restoration from the previous attack, its chief executive officer Stuart Irvine told employees during the briefing," said the newspaper, citing a source who had listened to the call.
The second attack was "anticipated" and Lion's IT security bods of choice, Accenture, are said to be dealing with it. Earlier today Prime Minister Scott Morrison declared that [2]Australia's public sector was under attack – and while he didn't identify who was responsible, weeks of Chinese diplomatic belligerence means the world is already pointing fingers.
As we reported this morning, China "recently took offence at Australia's call for an international inquiry into the source of the COVID-19 pandemic and appears to have retaliated with new trade disputes and advice that its citizens should not visit Australia as tourists or students," in a tit-for-tat move.
Matt Lawrence, director of detection and response at threat intel biz F-Secure, opined in a canned comment that blaming China is unwise without further evidence: "Some are pointing the finger at China for these cyber attacks and, while we have seen some Chinese APT groups ramping up their attacks, we wait to see if evidence is released publicly that confirms they are directly targeting Australia. Although it's reasonable to assume that such a country is being targeted by a range of cyber criminals and state-sponsored threat actors, it's dangerous to speculate further without appropriate evidence and threat intelligence."
Last week, ransomware criminals (which El Reg can confirm were the REvil gang) targeted Lion, [3]causing chaos for the entire company .
At the time a company spokeswoman said: "Our IT teams and expert cyber advisors are working around the clock, investigating the issue and assessing how long the impacts will continue. Our focus is on bringing systems back online safely so we can resume our business as usual manufacturing, and customer services. This is taking some time, but it is necessary that we work through this properly."
The firm refused to comment on reports of an $800,000 equivalent ransomware demand, made in the Monero cryptocurrency. ®
Sponsored: [4]The Forrester Wave™: Streaming Analytics, Q3 2019
[1] https://www.smh.com.au/technology/cyber-crisis-deepens-at-lion-as-second-attack-bites-beer-giant-20200618-p5540c.html
[2] https://www.theregister.com/2020/06/19/australia_state_cyberattack/
[3] https://www.theregister.com/2020/06/11/australia_brewery_lion_cyber_attack/
[4] https://go.theregister.com/tl/1956/-8460/the-forrester-wave-streaming-analytics-q3-2019?td=wptl1956
Re: An Attack or a Screwup?
Considering that the attacks are spread across a wide range of industries simultaneously, I'd suggest it's more than Scotty from Marketing opening an attachment.
Re: An Attack or a Screwup?
I don't get the WFH angle. Just as much chance of being clickjacked while in the office network.
Two questions
Ask yourself two questions
How ready is your company to deal with one let alone two attacks?
How luck do you feel today?
If China has nothing to hide...
then it should have nothing to fear in an international investigation :)
Re: If China has nothing to hide...
Of late, the Middle Kingdom has become simultaneously defensive, belligerent and very thin skinned.
Stand by for tears at bedtime.
Firewall chicken
Networking people really need to get more aggressive about blocking huge chunks of the Internet that doesn't like playing nice. The potential loss of a few legitimate customers isn't anything compared to the constant attacks that certain networks pride themselves on hosting. Start with Chinese, Korean, and Vietnamese government networks, OVH, and DigitalOcean. If it works out, maybe try FOS VPN, Google, and Amazon too.
Or do nothing and let the Internet slowly decay into nothing but constant attacks. It's why there's no more free WiFi. Free WiFi companies did nothing about customers with infected laptops and eventually everything was supersaturated with botnet attacks.
An Attack or a Screwup?
There's no way to really know but it sounds like a typical situation where someone (maybe working from home and connected via VPN?) checked one of their email accounts and opened an attachment that seemed to be from a supplier... maybe Newlabel.img to see if the new labels looked good, or maybe proforma invoice.zip (proforma invoice.exe), Enquiry.lzh, New Purchase - June.zip (New Purchase - June.bat), VALIDATE HERE.html, awb_1446275724_invoice-receipt.xlsm ... etc etc - these are just the ones I've received (and deleted) since lunchtime.
If you are connected to the internet in any way then you have the potential to be under attack. Everything flowing through the internet must be checked and quarantined if there is even the slightest possibility of infection.