News: 1637590214

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Turbine maker Vestas Wind Systems admits to cyber incident, refuses to confirm if ransomware is at play

(2021/11/22)


Vestas Wind Systems, one of the world's largest makers of wind turbines, today confirmed company data has been compromised in a "cyber security incident" that forced the firm to isolate parts of its IT infrastructure.

The alarm bells rang on Saturday when [1]Vestas admitted : "To contain the issue, IT systems are shut down across multiple business units and locations."

It has pulled in external help to get on top of things.

[2]

In the [3]latest update , Vestas – which designs, makes, installs and services wind turbines – said that according to preliminary findings, the incident "impacted all parts of Vestas' internal IT infrastructure and that data has been compromised."

[4]

[5]

Investigations continue, it added, but at this stage there is "no indication" that third-party operations, including customer and supply chain, were caught up.

"Vestas' manufacturing, construction and services teams have been able to continue operations, although several operational IT systems have been shut down as a precaution. Vestas has already initiated a gradual and controlled reopening of all IT systems," it said a statement.

[6]Boat biz breaches itself: Brittany Ferries 'fesses up to leaks caused by routine website update

[7]Shotgun targeting of malware attacks will be the defining infosec theme of 2022, reckons Sophos

[8]Labour Party supplier ransomware attack: Who holds ex-members' data and on what legal basis?

[9]REvil gang member identified living luxury lifestyle in Russia, says German media

The attack bears the hallmarks of ransomware, but a spokesperson at the Vestas refused to be drawn on the specific nature of the attack at this stage.

"One of the key priorities is to keep stakeholders well informed without releasing information that could compromise the handling of the situation," he told The Register , refusing to confirm or deny whether a ransom was under demand.

[10]

Vestas, which employs 29,000 people globally, says it has installed more than 145GW of wind turbines in 85 countries, and that its sustainable energy solutions have prevented 1.5 billion tonnes of CO 2 from being released into the atmosphere.

Ransomware attacks have proliferated in recent years, with other critical infrastructure also popping up on the radar of criminals, [11]including Colonial Pipeline . As yet, none of the major ransomware gangs have admitted being behind the Vestas incident. ®

Get our [12]Tech Resources



[1] https://www.vestas.com/en/media/company-news/2021/vestas-impacted-by-cyber-security-incident-c3457473

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YZvMxrwn84RFwPQvlmRrrgAAAI0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.vestas.com/en/media/company-news/2021/update-on-cyber-security-incident-c3457795

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZvMxrwn84RFwPQvlmRrrgAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YZvMxrwn84RFwPQvlmRrrgAAAI0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2021/11/10/brittany_ferries/

[7] https://www.theregister.com/2021/11/09/sophos_infosec_predictions_2022_linux_targeting/

[8] https://www.theregister.com/2021/11/05/labour_party_ransomware_data_breach_questions/

[9] https://www.theregister.com/2021/10/28/revil_member_identified_german_reports/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YZvMxrwn84RFwPQvlmRrrgAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[11] https://www.theregister.com/2021/05/10/colonial_pipeline_ransomware/

[12] https://whitepapers.theregister.com/



Korev

I guess the company has a Vestas interest in getting their infrastructure up again...

Jellied Eel

Let's see how they spin this one.

MiguelC

Let's just hope it's not all gone with the wind

David Halko

Glad they were not blown away during the attack

Clausewitz 4.0

This hole business of breaking Wind Systems smells bad

Anonymous Coward

This is the Vestas who had a printed list of their corporate licence keys blutacked to the wall and clearly visible to anyone walking around the business park?

Definitely not very crispy noodles.

Hopefully it was

LordHighFixer

Ransomware, the company decided not to pay and just restore from 'gold masters.' I would really like to see a company actually handle this correctly instead of paying.

Her locks an ancient lady gave
Her loving husband's life to save;
And men -- they honored so the dame --
Upon some stars bestowed her name.

But to our modern married fair,
Who'd give their lords to save their hair,
No stellar recognition's given.
There are not stars enough in heaven.