News: 1596199814

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

First rule of Ransomware Club is do not pay the ransom, but it looks like Carlson Wagonlit Travel didn't get the memo

(2020/07/31)


Exclusive US corporate travel management firm Carlson Wagonlit Travel has suffered an intrusion and it is believed the company paid a $4.5m ransom to get its data back.

The attack hit the company a week ago, causing a shutdown of all systems while the infection was contained and dealt with.

It appears that Carlson Wagonlit may have paid a ransom demand in excess of 400 Bitcoins, or $4.5m at current rates – a sum its $1.5bn annual revenues may have been able to absorb without too much trouble. A Twitter user [1]posted the first indication of a breach , as well as the ransom, on Thursday:

[2]

Twitter user @JAMESWT_MHT posted about Ragnar Locker hitting CWT. Click to enlarge

Malware analysis sites linked in the tweet showed that a sample of the ransomware was uploaded on Monday 27 July.

Carlson Wagonlit, which recently rebranded itself CWT, provides travel and hotel booking services on what it calls a B2B2E basis – business to business to employee. Companies contract out the tedious parts of arranging corporate travel to CWT rather than doing it themselves. The Register understands that while CWT notified some of its corporate customers earlier this week, it also told them that individual travellers' data was not compromised – and that seems to be where the notification chain stopped.

In a statement, the company told The Register :

CWT experienced a cyber-incident at the weekend. We can confirm that after temporarily shutting down our systems as a precautionary measure, our systems are back online and the incident has now ceased. We immediately launched an investigation and engaged external forensic experts. While the investigation is at an early stage, we have no indication that PII/customer and traveller information has been affected. The security and integrity of our customers' information is our top priority.

A spokesman referred us back to the prepared statement when we asked whether CWT paid the ransom and if so, how much. Regrettably, it seems the firm has joined the ranks of other multinationals paying off criminals, including, from the last month alone, [3]navigation and fitness-tracking firm Garmin and cloud [4]CRM purveyor Blackbaud . Warnings that [5]less than half of businesses paying ransoms don't recover all of their data are simply falling on deaf ears, as is the fact that paying these crooks simply sustains their business model and encourages them to continue their crime sprees.

UK data watchdog the Information Commissioner's Office said it had not yet received a breach notification from CWT, which has an extensive UK presence, adding that organisations must report breaches within 72 hours of becoming aware of them unless the breach does not appear to "pose a risk to people's rights and freedoms".

Its published guidance states:

When a personal data breach has occurred, you need to establish the likelihood and severity of the resulting risk to people's rights and freedoms. If it's likely that there will be a risk then you must notify the ICO; if it's unlikely then you don't have to report it. However, if you decide you don't need to report the breach, you need to be able to justify this decision, so you should document it.

It is thought that the nasty involved was Ragnar Locker. The ransomware, a relatively new strain first seen late last year, [6]deploys a Windows XP virtual machine onto the target network in order to unleash the ransomware itself. According to Brit threat intelligence firm Sophos, typical attack vectors include poorly configured security controls around remote desktop services or supply chain attacks against managed service providers.

Matt Walmsley, EMEA director of infosec biz Vectra, told The Register : "Ragnar Locker is a novel and insidious ransomware group, as Portuguese energy provider EDP found out earlier this year when they reportedly lost 10TB of private information to the ransomware operator. Mirroring the 'name and shame' tactic used by Maze Group ransomware, victim's data is exfiltrated prior to encryption and used to leverage ransomware payments. The bullying tactics used by these ransomware groups are making attacks even more expensive, and they are not going to stop any time soon, particularly within the current climate.

"Ragnar Locker has also used service providers as a means to distribute their payload. These attackers will attempt to exploit, coerce, and capitalise on organisations' valuable digital assets, and now service companies, with their extensive number of tantalising downstream corporate customers, appear to have been targeted too."

Bert Steppé, researcher in F-Secure's Tactical Defence Unit, added: "Ragnar Locker is a relatively new ransomware family, used in targeted attacks. The ransom note is personalised for each victim. It was first observed in the beginning of this year, where it was deployed on vulnerable Citrix servers. The ransomware is still under active development, and the attackers are quite innovative to evade detection: in one known case, they have deployed a complete WinXP virtual machine to encrypt files on the host from within the VM."

Ragnar Locker is also said to hunt down and delete backups, related utilities and connected storage drives. ®

Updated to add

The Information Commissioner's Office got in touch to let us know: "Carlson Wagonlit UK Ltd have reported an incident to us. We will be assessing the information provided."

Get our [7]Tech Resources



[1] https://twitter.com/JAMESWT_MHT/status/1288797666688851969

[2] https://regmedia.co.uk/2020/07/31/cwtragnarlocker.jpg

[3] https://www.theregister.com/2020/07/27/garmin_ransomware_recovery/

[4] https://www.theregister.com/2020/07/17/blackbaud_paid_ransomware/

[5] https://www.theregister.com/2018/03/09/less_than_half_of_ransomware_marks_get_their_files_back/

[6] https://www.theregister.com/2020/05/22/byovm_ransomware_in_virtualbox/

[7] https://whitepapers.theregister.com/

DavCrav

"The bullying tactics used by these ransomware groups are making attacks even more expensive, and they are not going to stop any time soon, particularly within the current climate."

Yeah they are. Just make paying a ransom a criminal offence, punishable by, say, ten years in prison for the CEO. Sorted.

AIBailey

Just stop acknowledging Bitcoin (and other such "currencies") as legitimate currencies.

The only reason blackmail attempts such as this are able to succeed is due to the anonymising effect of Bitcoin etc.

Loyal Commenter

Care to point out anyone who actually does claim that cryptocurrencies are actually "legitimate currencies"?

Even if they were considered as such, I think your suggestion would have about as much effect as trying to stop football violence by declaring that football isn't a sport.

edit - I'll also point out that Bitcoin transactions are technically less anonymous than cash, since every transaction is recorded for posterity in the blockchain along with the sender and recipient's IDs. If you bother to google it, you'll discover that these have, in the past, been linked to people's identities and used in police operations to trace the movement of cryptocurrency. It's just that until you work out who those wallet IDs correspond to, they are anonymous.

Cash, on the other hand... Well, there's a reason there’s such a thing as money laundering, and there are many, many forms it can come in. If you found £20 on the street, could you tell where it had come from? And before that? Back to the point in time it was minted? Because you can with bitcoin. It's all there in the blockchain.

Loyal Commenter

Just to add: I'm no Bitcoin evangelist, but they are a thing that exists (and they do kind-of have a purpose, although it's not one that will replace money in any meaningful way).

That genie is out of the bottle, and they are a tool that criminals can use, because although their value fluctuates wildly, they can be passed on for cash, and they are a lot easier to use for ransom than a suitcase of unmarked non-sequential bills, or bearer bonds, or diamonds, or whatever.

Getting rid of the means of payment won't get rid of the crime they are used in. if you go down that line of thinking, you might as well end up with the Dark Judges from 2000AD. All crime is committed by the living, the crime is life, the sentence is death.

In re tracing cash...

Bill Gray

At my local bank, I noticed someone depositing cash. The bills were inserted in a cash counter, which (I assume) would have no difficulty detecting serial numbers. And, of course, when dispensing cash at an ATM, the bank could know which bills were passed out to whom.

I dunno to what extent banks and other cash-scanning/dispensing businesses are taking advantage of this ability. It's very limited, in that the bank in question can't be especially confident that it'll see the same bills twice. But it does seem that if there's a way to conduct surveillance, people will do it.

Lars

Stop using Windows could help a lot too.

Loyal Commenter

A well thought-through bit of victim blaming you've come up with there. What have you got for a follow-up? Rape victims shouldn't dress so slutty?

Anonymous Coward

Totally not the same. Any business that doesn't have a robust backup solution doesn't deserve to be in business.

Lon24

"Yeah they are. Just make paying a ransom a criminal offence, punishable by, say, ten years in prison for the CEO. Sorted."

Surprised at the downvotes. As a business if I stand to lose £5 million but can pay a ransom of £1 million it's a no-brainer. I'll pay up and the fact that will incentivise attacks on my competitors is not my problem. But if it's a choice between my business and prison then it's another no-brainer ;-)

The only possible ethical reason to pay a ransom is if human life is at risk. That's a difficult one because that invites more attacks in that direction. Which is why any decision should be considered by a disinterested party who can take the 'public good' into account not the financial balance sheet.

NightFox

"Just make paying a ransom a criminal offence, punishable by, say, ten years in prison for the CEO. Sorted."

Not really. As I mentioned in another thread, in countries that have made ransom payments for kidnap illegal, people are less likely to inform the authorities of a kidnap so the authorities can't then obstruct/prosecute them for paying the ransom to save their loved one (it's not unheard of for authorities to freeze the assets of someone who reports a kidnap to prevent any ransom payment). As a result, it's easier for kidnappers to operate knowing that there's little chance of the police getting involved. The same would probably apply with ransomware.

There's also ways around making an obvious payment to the demanders. You can't be seen to pay a $5m ransom, but you can engage a 'specialist' consultant to either negotiate with the kidnappers or disinfect your IT systems for maybe $1m, that consultant being either a front for the kidnappers/malware pushers, or a legitimate consultant laundering the ransom payment before passing it on to the baddies.

Have to say though, it seems a poorly-chosen time to target CWL when business travel is at an all time low.

Nice precise guidance

Mike 137

"... If it's likely that there will be a risk then you must notify the ICO ..."

What a muddle! Of course there's always a risk - the real question is what the level of risk is. And of course likelihood is one of the two parameters of risk - the other being consequence, so "likelihood of risk" is both specious and tautological.

Official guidance should be neither, so why does the guidance not say something like "if there is a high likelihood of significant harm to the rights and freedoms of data subjects..."?

Maybe because the use of the term "risk" in the vernacular has always been utterly sloppy and even risk professionals in general don't seem to use a consistent definition of it. It's about time we did.

Negotiations still online?

BobBobBobBobBob

This is not a good look for them https://twitter.com/jc_stubbs/status/1289199762663604224

One good turn usually gets most of the blanket.