IT reseller giant SHI International knocked offline by cyberattack
- Reference: 1657196110
- News link: https://www.theregister.co.uk/2022/07/07/shi_outage/
- Source link:
Described by the company as "a coordinated and professional malware attack," the incident happened over the US holiday weekend and resulted in the company pulling the plug on much of its public presence (including email and websites) while security and IT staff assessed the situation.
Email, according to SHI, came back yesterday and "the IT teams at SHI continue to work on bringing other systems back to full availability in a secure and reliable manner."
[1]
At the time of writing, the privately-owned company's home page consisted only of the latest security update.
[2]
SHI said "there is no evidence to suggest that customer data was exfiltrated during the attack" and that it was liaising with the FBI and CISA regarding the incident. It also stated that no third-party systems in the SHI supply chain had been affected.
[3]Cyberattack shuts down unemployment, labor websites across the US
[4]California state's gun control websites expose personal data
[5]Carnival Cruises torpedoed by US states, agrees to pay $6m after wave of cyberattacks
[6]Israeli air raid sirens triggered in possible cyberattack
The incident is an embarrassment for an IT services giant such as SHI. One would have thought the company would have had defenses against such an attack as well as a disaster recovery plan ready to pull out at a moment's notice, but here we are.
As it is, SHI appeared to lack even a cogent communications plan as its social media voicebox offered up a "Happy Independence Day" [7]tweet before increasingly panicked customers [8]reported that both email and phone lines were down. It took until July 6 for the company to [9]post an update .
[10]
The Register contacted SHI to learn more about the nature of the attack, what the company had done to recover, and what disaster recovery planning was in place. SHI has yet to respond.
The outage is significant. SHI is a major supplier to US government and commercial enterprise customers, and notched up $12b in revenue in 2021. Its slogan is "Ridiculously Helpful." To miscreants as well as customers, judging by recent events. ®
Get our [11]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YscDHzw5k5PiNgfP3MNKwAAAAME&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://regmedia.co.uk/2022/07/07/shi_incident.jpg
[3] https://www.theregister.com/2022/07/01/gsi-cyberattack-state-unemployment/
[4] https://www.theregister.com/2022/06/30/california_websites_expose_personal_data/
[5] https://www.theregister.com/2022/06/28/carnival-cybersecurity-fines/
[6] https://www.theregister.com/2022/06/22/israeli_air_raid_sirens_iran/
[7] https://twitter.com/SHI_Intl/status/1543912582985224194
[8] https://twitter.com/MadamVP_IT/status/1544352498781233153
[9] https://twitter.com/SHI_Intl/status/1544713426953539586
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YscDHzw5k5PiNgfP3MNKwAAAAME&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[11] https://whitepapers.theregister.com/
Re:
"a coordinated and professional malware attack"
Re:
state-backed hackers
sofisticated attack
we've notified the few affected customeres
Embarrassment ?
"The incident is an embarrassment for an IT services giant such as SHI. One would have thought the company would have had defenses against such an attack as well as a disaster recovery plan ready to pull out at a moment's notice, but here we are."
Well, seeing only 2 days after a bank holidays to 1) restore email 2) post an update hardly looks like an embarrassment to me, if one recent customer incident is to be taken as an example (maybe is not, customer is clueless beyond imagination, but the incident looks similar): they only announced "systems off" and took 2+ months to recover fully ! There was never any explanation nor any public date of recovery.
But those were completely and seriously unprepared. And un-patched.
Re: clueless
Go on then. Who was it? We need to know.
No reason for embarassment
QUOTE: The incident is an embarrassment for an IT services giant such as SHI.
If even the Russian bears can penetrate the Pentagon, DHS and others - and I mean, those guys have billions of budget and their daily job is to kill people for a living - there is no reason to be ashamed for having your systems compromised by an skilled adversary.
* no evidence ... customer data was exfiltrated
* we take the security of customer data extremely seriously *snicker*
Did I miss anything?