Scottish enviro bods shrug off ransomware gang's extortion attempt as 4,000 files dumped online, saying it's nothing big
- Reference: 1611342006
- News link: https://www.theregister.co.uk/2021/01/22/sepa_ransomware_failure/
- Source link:
The move was predicted by the agency itself following the Conti criminal gang’s malware attack against SEPA earlier this month.
[1]
SEPA had, quite correctly, [2]refused to pay the extortionists to prevent disclosure. It had even predicted how many files the crims would dump online, saying on 14 January: “Nevertheless, it still means that at least four thousand files may have been stolen by criminals.”
The effects of the attack were to knock a few of SEPA’s services offline, although it insisted that its flood forecasting and warning functions were able to continue operating regardless of the disruption.
[3]
Scottish Environment Protection Agency refuses to pay ransomware crooks over 1.2GB of stolen data [4]READ MORE
Ransomware is malicious software deployed by criminals that encrypts files on a targeted computer network. The criminal operators then demand a ransom in exchange for the decryptor, and enterprising crims target backups as well as production networks, in the hope of destroying the ability for targeted firms to ignore ransom demands.
Some ransomware gangs give themselves nicknames and cultivate a certain public status, in the hope that their marks will, in terror, roll over and pay out with minimal fuss. Some have even gone as far as to issue “press releases” and communicate directly with the press as a means of boosting their notoriety, something infosec blogger Brian Krebs [5]commented on last summer.
Ransoms vary widely but sums measured in millions or tens of millions of pounds are becoming more common, especially as larger and more high profile companies are compromised.
[6]
Destroying their business model is the only way to stop ransomware gangs, and SEPA unquestionably did the right thing in refusing to pay. It is also illegal to give money to individuals or organisations on international sanctions lists – certainly in the US and UK. ®
Get our [7]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YAtZBjqdzKDj1GLVHYP9gQAAAMY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2021/01/18/scottish_environment_protection_agency_refuses_to_pay_ransom/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YAtZBjqdzKDj1GLVHYP9gQAAAMY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://www.theregister.com/2021/01/18/scottish_environment_protection_agency_refuses_to_pay_ransom/
[5] https://krebsonsecurity.com/2020/07/ransomware-gangs-dont-need-pr-help/
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YAtZBjqdzKDj1GLVHYP9gQAAAMY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://whitepapers.theregister.com/
Re: Thank you
I've sometimes wondered what would happen if a country made it a criminal offence to pay ransoms for cybercrime attacks like this. I wounder whether the crims give up cos they know they wouldn't get paid or would they assume that because they are happy to be crims then everyone else will be and pay up any way.
Let me guess..
.. they were running Windows?
I'm just posting to up my downvote count, because stating the bleedin' obvious tends to seriously offend Redmond & friends.
Bile yer heid
...is actually a very mild Scottish rebuke. Bear in mind our top veterinary college is called the Dick Vet, or the 'Royal (Dick) School of Veterinary Studies'. It was the Royal School of Veterinary Studies in 1823, but then someone drew a penis on their sign after Royal, and they reckoned, 'aye, we're having that'.
[1]Disclaimer: Actual history may no be as guid.
[1] https://en.wikipedia.org/wiki/Royal_(Dick)_School_of_Veterinary_Studies#Clyde_Street
Open Environment Initiative
4000 files containing what?
How long, I wonder
Before files are encrypted as a matter of course? The only time it should be decrypted is when it's being worked on... There's a certain amount of satisfaction, I feel, in saying 'publish and be damned' in the knowledge that what is published is still invisible to most.
Certainly some (many?) companies these days require that files are stored on central servers - on premise or cloudy - if only for compliance or backup reasons. How difficult to encrypt on write?
(I'm probably missing something stunningly obvious; this sort of thing isn't my day job. I'm happy to be educated.)
Re: How long, I wonder
Disclaimer: I work for a company active in this area.
Filesystem encryption is common these days - bitlocker on Windows, or Veracrypt, or the Linux alternatives, etc. But that's not going to help if scumbags are logged into your system because they then see the same view of the files as you do, they're inside the file system.
There are also ways to do application level encryption, which is what you're suggesting. There are tools that will plug into Word, for example, and encrypt/decrypt stuff between Word and the disk. The problem is that this needs to be implemented on a per application basis - if your favourite CAD software doesn't have a plug-in for your chosen encryption software, you're short on luck. You also need to be careful with configuration - for example, ensuring temporary backup files created by the application are also encrypted.
Depending on your paranoia level, you also need to worry about swap files, which can contain unencrypted snapshots of files resident in your application's memory.
Finally, there's a kind of middle ground where you manually encrypt / decrypt files as needed - either on a per-file basis or in a container like Veracrypt. But that is less convenient for day-to-day workflow.
Re: How long, I wonder
This was kind of what I wondered. Thanks for the explanation.
As always, the convenience vs security tradeoff. Might one expect this sort of data grab for ransom to be mostly via compromised (senior) user accounts? Or are we looking at 'oops, left the database world+dog visible'? Or a combination?
Hey if it were easy...
Thank you
For doing the right thing and not paying the scumbags.