Equinix warns it's infected with ransomware, promises it can carry on regardless
(2020/09/10)
- Reference: 1599724327
- News link: https://www.theregister.co.uk/2020/09/10/equinix_ransomware/
- Source link:
Equinix has warned customers it has been infected with ransomware.
A [1]brief “Equinix Statement on Security Incident” issued late on Wednesday night US time said the company was “currently investigating a security incident we detected that involves ransomware on some of our internal systems.”
Just which systems were infected was not specified, but the post said its "Our data centers and our service offerings, including managed services, remain fully operational, and the incident has not affected our ability to support our customers.”
This suggests that perhaps the infection has hit business applications, rather than systems related to data centre operations or the software-defined networks Equinix operates.
Outage: Faulty UPS at data centre housing London Internet Exchange causes grief for ISPs and telcos alike [2]READ MORE
Isolating different kit under one roof is an explicit element of the product offered by the likes of Equinix and the company appears to have done so, as it advised customers that the incident has had “no impact on their operations or the data on their equipment at Equinix.”
The company has called the relevant authorities and the post said the firm will “take all necessary actions, as appropriate, based on the results of our investigation.”
A common script for this sort of incident sees victims drip out info about the extent of any problems, hire a reputable security firm to probe whatever made it possible, apologise profusely and then release an incident report that explains where they went wrong and how they’ve fixed things up so this could never happen again. If Equinix diverts markedly from that template, The Reg will be surprised. ®
Get our [3]Tech Resources
[1] https://blog.equinix.com/blog/2020/09/09/equinix-statement-on-security-incident/
[2] https://www.theregister.com/2020/08/18/outage_london_internet_exchange/
[3] https://whitepapers.theregister.com/
A [1]brief “Equinix Statement on Security Incident” issued late on Wednesday night US time said the company was “currently investigating a security incident we detected that involves ransomware on some of our internal systems.”
Just which systems were infected was not specified, but the post said its "Our data centers and our service offerings, including managed services, remain fully operational, and the incident has not affected our ability to support our customers.”
This suggests that perhaps the infection has hit business applications, rather than systems related to data centre operations or the software-defined networks Equinix operates.
Outage: Faulty UPS at data centre housing London Internet Exchange causes grief for ISPs and telcos alike [2]READ MORE
Isolating different kit under one roof is an explicit element of the product offered by the likes of Equinix and the company appears to have done so, as it advised customers that the incident has had “no impact on their operations or the data on their equipment at Equinix.”
The company has called the relevant authorities and the post said the firm will “take all necessary actions, as appropriate, based on the results of our investigation.”
A common script for this sort of incident sees victims drip out info about the extent of any problems, hire a reputable security firm to probe whatever made it possible, apologise profusely and then release an incident report that explains where they went wrong and how they’ve fixed things up so this could never happen again. If Equinix diverts markedly from that template, The Reg will be surprised. ®
Get our [3]Tech Resources
[1] https://blog.equinix.com/blog/2020/09/09/equinix-statement-on-security-incident/
[2] https://www.theregister.com/2020/08/18/outage_london_internet_exchange/
[3] https://whitepapers.theregister.com/
Well at least it hasn't spread all over the place
As stated in the article, Equinix may have been bitten by social engineering or hacked, but at least the crises was contained to the non-operational side of the business. That does tend to signal that Equinix, unlike many, has planned and put in place proper security procedures, and that planning, at least, has paid off.
In this case, I doubt that we will see much as far as apologies are concerned. Customer data and operations are not impacted, so Equinix does not need to go promising that "the security of our customers is our greatest concern" - they've just proven that it is (contrary to practically every company that has tried to bullshit us with that line since, well, ever).
I do hope we'll get a report on what happened. I'll be interested in learning just how a company that has things so well-planned still managed to get caught out.