News: 1638196153

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Wind turbine maker Vestas confirms recent security incident was ransomware

(2021/11/29)


Wind turbine maker Vestas says "almost all" of its IT systems are finally up and running 10 days after a security attack by criminals, confirming that it had indeed fallen victim to ransomware.

Alarm bells rang the weekend before last when the Danish organisation [1]said it had identified a "cyber security incident" and closed off parts of its tech estate to "contain the issue."

Today the business - one of the largest worldwide to design, build, install and maintain wind turbines – said it has undertaken "extensive investigations, forensics, restoration activities and hardening of our IT systems and IT infrastructure."

[2]

Henrik Andersen, president and chief exec of the firm, [3]said in a statement :

[4]

[5]

"We have been through some tough days since we discovered the cyber incident, and executive management and the board of directors are thus very pleased that the incident didn't impact wind turbine operations and almost all of our IT systems are running again."

Manufacturing, construction and services team were unaffected, Vestas said.

[6]

"There is still a lot of work ahead of us to and we must remain extremely diligent towards cyber threats. I would already now like to take this opportunity to thank our customers, employees and external partners for their understanding and extraordinary support in these challenging circumstances."

[7]Kremlin names the internet giants it will kidnap the Russian staff of if they don't play ball in future

[8]The inside story of ransomware repeatedly masquerading as a popular JS library for Roblox gamers

[9]Ukrainian cuffed, faces extradition to US for allegedly orchestrating Kaseya ransomware infection

[10]Labour Party supplier ransomware attack: Who holds ex-members' data and on what legal basis?

[11]REvil gang member identified living luxury lifestyle in Russia, says German media

[12]GCHQ director outlines plan to 'go after' links between ransomware crims and state actors

The deep probing of the incident continues, Vestas said, and there still remains no evidence that the break-in hit customer or supply chain operations, "which is supported by the forensics investigation carried out with the assistance of third-party experts," it said.

The security incident bore all the hallmarks of a ransomware attack, but Vestas last week refused to comment. Today it confirmed what The Register had previously suspected.

"The cyber incident, which our investigations indicate was ransomware, impacted Vestas' internal systems and resulted in data being compromised. The extent to which data has been compromised is still being investigated, but for now it appears that the data foremost relates to Vestas' internal matters."

We asked the company if it paid the ransom but a spokesperson said: "Due to the situation this is not something we are going to comment on." He also refused "at this point" to go into detail about how the digital break-in occurred.

[13]

According to research by Coveware pulbished in January, the average downtime caused by ransomware is [14]16.2 days and Bitcoin is the cryptocurrency favoured most by criminal gangs. The firm also found that ransomware is [15]more lucrative than cocaine trafficking , that the average payment is just shy of $140,000 per attack and the most common strains are [16]Conti V2 , [17]Mespinoza and [18]Sodinokibi . ®

Get our [19]Tech Resources



[1] https://www.theregister.com/2021/11/22/vestas_wind_systems/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YaUHPgLBLsaI9YXZYLmxogAAAFQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.vestas.com/en/media/company-news/2021/second-update-on-cyber-incident-c3462120

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YaUHPgLBLsaI9YXZYLmxogAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YaUHPgLBLsaI9YXZYLmxogAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YaUHPgLBLsaI9YXZYLmxogAAAFQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2021/11/25/tech_offices_russia/

[8] https://www.theregister.com/2021/11/16/nobloxjs_typosquatting_discord/

[9] https://www.theregister.com/2021/11/08/revil_ransomware_operators/

[10] https://www.theregister.com/2021/11/05/labour_party_ransomware_data_breach_questions/

[11] https://www.theregister.com/2021/10/28/revil_member_identified_german_reports/

[12] https://www.theregister.com/2021/10/26/gchq_ransomware_plan/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YaUHPgLBLsaI9YXZYLmxogAAAFQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[14] https://www.coveware.com/blog/2020/1/22/ransomware-costs-double-in-q4-as-ryuk-sodinokibi-proliferate

[15] https://www.coveware.com/blog/2021/10/20/ransomware-attacks-continue-as-pressure-mounts

[16] https://www.theregister.com/2021/11/16/emotet_botnet_rappears/

[17] https://www.theregister.com/2021/07/20/campbell_law_firm_data_breach/

[18] https://www.theregister.com/2021/11/08/revil_ransomware_operators/

[19] https://whitepapers.theregister.com/



How to pay Ransomware requests

Anonymous Coward

Send them the payment details, tell them all they need to do is open the payment spreadsheet and allow the macro to receive the payment ... I'm posting this anonymously because we're processing the malware senders bitcoins at the moment.

"Is it just me, or does anyone else read `bible humpers' every time
someone writes `bible thumpers?'
-- Joel M. Snyder, jms@mis.arizona.edu