Dish confirms 300,000 people's data was exposed in February's attack
- Reference: 1684860189
- News link: https://www.theregister.co.uk/2023/05/23/dish_networks/
- Source link:
Dish customers can rest easy, at the very least, as the company [1]said in a sample letter posted to the Maine Attorney General's breach notification website that customer databases weren't accessed and the stolen data belonged instead to employees both past and present, their family members, "and a limited number of other individuals" that Dish didn't specify.
The satellite TV company also didn't say what sorts of personal information was stolen from 296,851 employees in the attack, aside from driver's license and non-driver ID card numbers.
[2]SpaceX: 5G expansion could kill US Starlink broadband
[3]Dish Network hit with $280 MEEELLION fine for relentless robocalling
[4]T-Mobile has a network, Dish has spectrum it can't use. Oh, HELLO
[5]Dish and DirecTV deal: Damned if they merge, damned if they don't
Dish has been generally quiet about the attack since [6]late February , when it admitted there was an incident, filed a [7]form with the Securities and Exchange Commission to notify it of the breach, and admitted that some internal data had been stolen without confirming what it was or from where.
Dish never went on the record to publicly state the attack was caused by ransomware, though internal sources who contacted The Register, did report that ransomware was involved. Dish also made mention of ransomware in its SEC filing.
[8]
Reports from February [9]citing internal Dish sources claim the [10]Black Basta ransomware gang was behind the break-in at Dish, and in its [11]template letter [PDF] notifying affected individuals of the incident, the company sought to reassure recipients that there's no evidence the extracted data has been misused, and that it believes the data has been deleted.
Er, who confirmed that again?
"We have received confirmation that the extracted data has been deleted," Dish said, adding that it has been monitoring the dark web and criminal forums for signs the data is available online. "The results of the monitoring are consistent with the confirmation that the extracted data has been deleted," it added.
That, as Emsisoft security analyst Brett Callow has pointed out, could be interpreted as an admission that Dish paid whatever ransom was demanded of it because "totally untrustworthy cybercriminals assured us the data would be deleted if we paid the ransom," Callow [12]tweeted .
[13]
As numerous security researchers and publications have [14]pointed out since ransomware became the hot thing in cybercrime, there is absolutely no reason to believe that a threat actor will follow through on its claims not to retain or eventually leak data.
Dish said it is offering two free years of single-bureau credit monitoring to those impacted, but with an enrollment deadline of August 31.
[15]
We still have a lot of questions for Dish, which hasn't responded to us, and will update this story if we hear back. ®
Get our [16]Tech Resources
[1] https://apps.web.maine.gov/online/aeviewer/ME/40/ec8cf5c5-3048-4b22-baa9-10438a51e6f5.shtml
[2] https://www.theregister.com/2022/06/23/starlink_dish_satellite_internet/
[3] https://www.theregister.com/2017/06/06/dish_network_280m_fine_robocalling/
[4] https://www.theregister.com/2015/06/04/tmob_and_dish_to_marry/
[5] https://www.theregister.com/2014/03/31/dish_directv_merger/
[6] https://www.theregister.com/2023/02/27/dish_outage_ransomware/
[7] https://dish.gcs-web.com/node/34511/html
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZG03ih72toeC94@@JBWpggAAAE8&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[9] https://www.bleepingcomputer.com/news/security/dish-network-confirms-ransomware-attack-behind-multi-day-outage/
[10] https://forums.theregister.com/forum/all/2023/04/18/capita_breach_gets_worse/
[11] https://regmedia.co.uk/2023/05/23/v.pdf
[12] https://twitter.com/BrettCallow/status/1659598960695336960
[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZG03ih72toeC94@@JBWpggAAAE8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[14] https://www.coveware.com/blog/q3-2020-ransomware-marketplace-report
[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZG03ih72toeC94@@JBWpggAAAE8&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[16] https://whitepapers.theregister.com/
Quote
"We have received confirmation that the extracted data has been deleted," Dish said, adding that it has been monitoring the dark web and criminal forums for signs the data is available online. "The results of the monitoring are consistent with the confirmation that the extracted data has been deleted," it added.
The only people who could possibly delete it are the people who stole it in the first place, and DISH believes them, OK well, stranger things have happened, no?
And that assumes that said actors didn’t sell what they had extracted to another party before deleting it, no?
I’ll give it 18 months at most before this data starts appearing all over the place; prime phishing material, no?
OK now what actually needs to happen in cases such as this?* Firstly senior management at DISH (or any other company), need to be looking at jail time, not company fines, not half felt apologies, but whoever was CTO and CEO at DISH at the time, needs to be handcuffed and dragged out of their home (ideally with the world’s press in attendance to record it), on the grounds that they were, well, fucking incompetent and as such compromised the details for a lot of people.
In fact maybe every single investor in DISH needs to be hit with a (small) fine, On the grounds that you want the rewards when it works, (fair enough), take the rap when the people in charge (which as investors, you are responsible for), fuck up!
*Yes, of course I know this won’t ever happen, it not being the way the system works. One day though, maybe?
Oh goody, more free credit monitoring! Hooray!
I'm starting to wonder if there's any backroom deals between TransUnion/Equifax/Experian and some of these ransomware gangs, but that gives me flashbacks to when we wondered similarly semi-cynical thoughts about AV vendors secretly generating and propagating malware.