News: 1600352828

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

GCHQ agency 'strongly urges' Brit universities, colleges to protect themselves after spike in ransomware infections

(2020/09/17)


GCHQ offshoot the National Cyber Security Centre has warned Further and Higher Education institutions in the UK to be on their guard against ransomware attacks as the new academic year (sort of) gets under way.

NCSC sent advice to places of learning "containing a number of steps they can take to keep cyber criminals out of their networks, following a recent spike in ransomware attacks," it said in [1]an advisory note published this morning.

A recent spike in ransomware attacks in August included [2]infections of Newcastle and Northumbria Universities , seemingly among others.

"While these have been isolated incidents, I would strongly urge all academic institutions to take heed of our alert and put in place the steps we suggest, to help ensure young people are able to return to education undisrupted," thundered Paul Chichester, the NCSC's director of ops.

Where China leads, Iran follows: US warns of 'contract' hackers exploiting Citrix, Pulse Secure and F5 VPNs [3]READ MORE

Attackers typically target the Remote Desktop Protocol (RDP) as a way of extracting data from targeted organisations. The usual modus operandi of larger groups is to gain access to a target network, deploy an encryptor, steal data from the network and then drip-feed it out to wind up pressure on victims to pay a ransom to decrypt their files, [4]as the Maze ransomware gang does . Demands usually range between six and eight figures.

Smaller operators typically engage in drive-by attacks, relying on automated encryption and emails from victims desperate to regain control over their corporate networks.

Infection vectors are most commonly staffers connected to corporate networks opening infected email attachments, triggering embedded malware. Occasionally targeted attacks manage to find easy-to-crack passwords, as NCSC said, and unpatched enterprise software also provides a relatively common way in – as the US [5]has been repeatedly warning .

Adenike Cosgrove, cybersecurty strategist at email security provider Proofpoint said in a statement: "Education institutions hold masses of highly sensitive data on individuals, perhaps more so than any industry outside healthcare. Along with personal information such as name, address, DOB, there's also the potential to hold payment details, ID, health records, and much more. This trove of information puts a target on the back of every good-sized school, college, or university."

She added: "Universities should ensure that all staff and students are aware of basic security hygiene and the mechanics of common threats. This awareness training must be in context. All users must know how they are likely to encounter an attack and the role they play in defending against it."

Mark Nicholls, CTO of infosec biz Redscan, agreed, saying: "The fact that such a large number of universities don't deliver cyber security training to staff and students, nor commission independent penetration testing, is concerning. These are foundational elements of every security program and key to helping prevent data breaches." ®

Get our [6]Tech Resources



[1] https://www.ncsc.gov.uk/news/alert-issued-following-rising-attacks-on-uk-academia

[2] https://www.theregister.com/2020/09/08/newcastle_northumbria_universities_cyber_attack/

[3] https://www.theregister.com/2020/09/16/iran_targets_citrix_pulse_secure_f5_vpns/

[4] https://www.theregister.com/2020/06/24/maze_ransomware_gang_vt_aerospace_rant/

[5] https://www.theregister.com/2020/09/16/iran_targets_citrix_pulse_secure_f5_vpns/

[6] https://whitepapers.theregister.com/

GCHQ says protect yourself

Yet Another Anonymous coward

But don't use encryption; because only terrorists, people-traffickers and (looksup list of today's official daily hate) Eu Brexit negotiators use encryption

Arachnoid

Yea but theres back doors in that encryption if its to US standards, init bro.

Which do you Prefer? The Juicy Lucy Carrot or the Blunt Cleft Stick?

amanfromMars 1

Is GCHQ fully protected against phisher men and women .... or are they just as incredibly vulnerable and addictively attracted to exotic and erotic temptations as would everyone else be?

And are they suitably practised and remarkably expert in ....... well, let us venture they have an ardent interest in Pornographic Steganography, in multiple degrees of excessive order and participation, in order to ensure communications are able to be kept personal and private rather than exposed for simple pirating and renegade exploitation ‽ .

It has many ardent enthusiastic fans .... for all of the really basic reasons which any hot blooded being would immediately fundamentally understand and encourage demonstration of. :-)

Doctor Syntax

"This trove of information puts a target on the back of every good-sized school, college, or university."

Just an idea but how about putting that trove on its own isolated network? Yes, inconvenient when somebody has to answer a query that came in by email. But look on it as a choice of that inconvenience vs the inconvenience of an attack on that trove and at best having to rebuild it from backups and at worst seeing it copied off and sold to the highest bidder - or all bidders.

Chris G

" its own isolated network"

It may be a little inconvenient but still less so than digging out a ledger as in the old days.

Password security?

Anonymous Coward

What's password security? I've worked at a Russell Group university for the last 4 years without having to change my password. (Yes, basic complexity is enforced, but no changes). Rather different from my time at the NHS...

AC, because I need to stay working there a bit longer yet.

<Valkyrja> java, hon, sometimes I really want to smack you.
<Knghtbrd> Valkyrja - he'd enjoy it too much
<Reteo> Valkyrja: yah, go ahead and do it... beat java into cappuccino! :-)