Floating COVID incubation tank becomes data-leaking ransomware rust bucket
(2020/08/19)
- Reference: 1597829294
- News link: https://www.theregister.co.uk/2020/08/19/carnival_plc_ransomware/
- Source link:
The cruise ship industry is all but shuttered worldwide because the floating hotels are a great way to contract coronavirus. And now the industry's biggest player, Carnival Corporation, has also come down with a case of ransomware.
The company on Tuesday issued a [1]regulatory filing [PDF] in which it admitted: "On August 15, 2020, Carnival Corporation and Carnival plc... detected a ransomware attack that accessed and encrypted a portion of one brand's information technology systems. The unauthorized access also included the download of certain of our data files."
UCSF had data protection but didn't use it on affected systems, and had to pay ransomware attackers $1.14m
In other ransomware news, sister site Blocks & Files has revealed that the University of California San Francisco paid attackers $1.14m in Bitcoin to recover encrypted files, despite having data protection provided by Rubrik.
B&F understands the ransomware took root in the School of Medicine's IT environment, but that Rubrik's product wasn't covering the affected servers at the time. [2]Full story here .
The filing also reveals that the company expects "that the security event included unauthorized access to personal data of guests and employees, which may result in potential claims from guests, employees, shareholders, or regulatory agencies". The filing also said Carnival can't be completely sure that the incident did not hit more than one of its brands (it has at least 10).
The company was at least able to act quickly and did not cover things up, as shown by the statement emerging two days after the attack was detected and detailing containment and remediation efforts. The document also said Carnival has called the cops, hired lawyers, and brought in white hats to get to the bottom of the mess.
Perhaps ironically, the filing includes a section titled "Cautionary Note Concerning Factors That May Affect Future Results", which includes the boilerplate observation: "Breaches in data security and lapses in data privacy as well as disruptions and other damages to our principal offices, information technology operations and system networks... may adversely impact our business operations, the satisfaction of our guests and crew and lead to reputational damage."
Which, like a stopped watch, has now been proven correct. ®
Get our [3]Tech Resources
[1] https://www.carnivalcorp.com/static-files/4560bf11-dbfd-4224-9251-cafa5d17d9f1
[2] https://blocksandfiles.com/2020/08/18/ucsf-ransomware-attack-data-protection/
[3] https://whitepapers.theregister.com/
The company on Tuesday issued a [1]regulatory filing [PDF] in which it admitted: "On August 15, 2020, Carnival Corporation and Carnival plc... detected a ransomware attack that accessed and encrypted a portion of one brand's information technology systems. The unauthorized access also included the download of certain of our data files."
UCSF had data protection but didn't use it on affected systems, and had to pay ransomware attackers $1.14m
In other ransomware news, sister site Blocks & Files has revealed that the University of California San Francisco paid attackers $1.14m in Bitcoin to recover encrypted files, despite having data protection provided by Rubrik.
B&F understands the ransomware took root in the School of Medicine's IT environment, but that Rubrik's product wasn't covering the affected servers at the time. [2]Full story here .
The filing also reveals that the company expects "that the security event included unauthorized access to personal data of guests and employees, which may result in potential claims from guests, employees, shareholders, or regulatory agencies". The filing also said Carnival can't be completely sure that the incident did not hit more than one of its brands (it has at least 10).
The company was at least able to act quickly and did not cover things up, as shown by the statement emerging two days after the attack was detected and detailing containment and remediation efforts. The document also said Carnival has called the cops, hired lawyers, and brought in white hats to get to the bottom of the mess.
Perhaps ironically, the filing includes a section titled "Cautionary Note Concerning Factors That May Affect Future Results", which includes the boilerplate observation: "Breaches in data security and lapses in data privacy as well as disruptions and other damages to our principal offices, information technology operations and system networks... may adversely impact our business operations, the satisfaction of our guests and crew and lead to reputational damage."
Which, like a stopped watch, has now been proven correct. ®
Get our [3]Tech Resources
[1] https://www.carnivalcorp.com/static-files/4560bf11-dbfd-4224-9251-cafa5d17d9f1
[2] https://blocksandfiles.com/2020/08/18/ucsf-ransomware-attack-data-protection/
[3] https://whitepapers.theregister.com/
Cunard
That explains why Cunard has been unable to answer phones etc for the last few days. At least all the ships are parked up at the moment - imagine if several thousand people were trying to board one right now.