14 ms·
Hit by Ransomware Attack, Florida City Agrees to Pay Hackers $600k
- nyolfen 7y agomaybe state governments should preempt this and make it illegal for municipalities or state agencies to pay ransoms, so they are less attractive targets
- pergadad 7y agoThen there'll be workarounds such as those intermediary companies that claim to unlock it but in reality just pay off the cryptolocker guys and keep a part of the fee for themselves. That said, this city could have used some negotiation help.
- Shivetya 7y agoI would be more impressed if government at every level were held to higher standards than they impose on businesses. the hoops we jump through for SOX compliance which includes cybersecurity since 2017 [1] why aren't local, city, and state, officials, if not Federal, held accountable for the same? Similar to the story we had recently where state colleges across New York and elsewhere were not complying with the ADA and costing the tax payers millions. [1] https://www.congress.gov/bill/114th-congress/house-bill/5069/text https://www.congress.gov/bill/114th-congress/house-bill/5069...
- AnIdiotOnTheNet 7y agoThe competing pressure is to drive down costs because no one wants to pay taxes.
- pjc50 7y agoOnly if that comes with funding to defend against attacks and restore services. Otherwise, congratulations, you've turned off a city and it won't be working again for six months.
- throwaway13337 7y ago"We never pay any-one Dane-geld, No matter how trifling the cost; For the end of that game is oppression and shame, And the nation that plays it is lost!" But the problem is that those that don't pay hurt even more. The US makes it illegal to pay kidnapper ransom and, as a result, US citizens have much worse outcomes (often murdered) when they are ransomed abroad. The theory that it makes US citizens less attractive targets is confounded by the fact that some families/friends of the victims can and do pay anyway (illegally). Planet money did a podcast on it. https://www.npr.org/sections/money/2017/09/01/548032302/episode-792-the-ransom-problem https://www.npr.org/sections/money/2017/09/01/548032302/epis...
- dagw 7y agoAnother interesting podcast on the topic of kidnapping: http://www.econtalk.org/anja-shortland-on-kidnap/ http://www.econtalk.org/anja-shortland-on-kidnap/ Goes into the details of kidnapping as a business venture from the kidnappers perspective, and how a price equilibrium is found between 'buyers' (ransom payers) and 'sellers' (kidnappers). On interesting story was when the partner of a small business owner got kidnapped as punishment for failing to pay some protection money. When the business owner went to negotiate the ransom, the kidnappers had had an accountant already go through the businesses fiances so they knew exactly how much they could ask for, without it bankrupting the business owner (so that the owners company could keep thriving and thus could keep paying protection money).
- woodrowbarlow 7y ago> The theory that it makes US citizens less attractive targets is confounded by the fact that some families/friends of the victims can and do pay anyway (illegally). but this wouldn't be true of governments, compared to private citizens, since government spending is a matter of public record.
- Buttons840 7y ago> The US makes it illegal to pay kidnapper ransom What? I read the book "Never Split the Difference" written by a former FBI hostage negotiator, and it had stories of him helping with some kidnapping cases and offering a ransom. If I remember correctly his goal was not to avoid paying a ransom, but to make it as small as possible. Good book by the way.
- blotter_paper 7y ago>On Monday, Councilwoman KaShamba Miller-Anderson, the chairwoman of the board, asked Justin Williams, the interim information technology manager, for something seemingly simple. Could the elected officials’ new email addresses be posted online for the public to get in touch with them? >Underscoring the enormity of the city’s troubles, Mr. Williams explained that the webmaster hoped to get to that soon. >“He’s been working very feverishly to get that done,” Mr. Williams said. ...the webmaster is working feverishly to post a static piece of text to a website? I guess it really is hard to fire government workers.
- crummy 7y agoThat's easy to say, but if the deployment server is down you might not be able to do it easily, and if you try to do it manually you need credentials which were stored on in a text file on another server that's down... etc.
- scarejunba 7y agoIt's the government. He probably needs to find long lost keys to SSH in, file four forms (each in triplicate), and receive approval from each person to get it out.
- jlgaddis 7y agoIt's municipal government. There almost certainly were no SSH keys. The problem is that the credentials that the webmaster needs likely only exist in an Excel spreadsheet that was saved on the desktop of the "Administrator" user account on one of the machines that got hit.
- bryanrasmussen 7y agoMost City websites are going to be some sort of CMS and it might not be as simple as putting a text file in the public folder and linking to it. Add to that all sorts of other things that might be getting in the way and you can have someone working feverishly to get it done.
- dillonmckay 7y ago
- dbg31415 7y agoLook, virtually nowhere in the public sector is security taken seriously. And nowhere in local government is security taken seriously. City governments might as well be pinatas... the way their budgets work, they'd never be able to replace large systems that were compromised. Without legislation banning them from paying, paying the ransom is likely really appealing to them. Security should be bumped up, but let's face it... that's not going to happen given how nobody who knows anything about tech would be caught dead working for local government. So many things have to change.
- hanniabu 7y agoIt really doesn't make sense to me that software isn't created at the government level for cities and states to use. This way it's easier to make sure everything is functioning properly and the cost is only paid once.
- deleted 7y ago[deleted]
- furi 7y agoDo we know the problem is in the software? There's a lot of other things that go into securing a large system like this, training and testing staff to resist phishing attacks, apply security patches promptly, maintaining least privilege as requirements, hardware and staff change, etc. It seems to me that unless your software package encapsulates every use case and enforces the security protocols itself the only defense is an on-site security professional who is listened to.
- dillonmckay 7y agoWith full SCADA integration for any type of system (water, sewer, electric)? Might be some problems with the competitive bidding aspect of things, as well.
- dragonwriter 7y ago> It really doesn't make sense to me that software isn't created at the government level for cities and states to use. What government level? The federal government? > This way it's easier to make sure everything is functioning properly and the cost is only paid once. The federal government is no paragon of software virtue, nor is it likely to produce software adapted all that well to all of the needs of various states and cities, so what you'd end up with is software less fit for purpose, not particularly free from vulnerability, and where all of the vulnerabilities expose every state and local government in the country rather than just one jurisdiction. And that's still assuming good intent, but in many cases the state and federal government have adversarial relations on particular issues, which might lead to the federal government actively designing software in a way to frustrate the needs of particular states.
- xupybd 7y agoGreat, now they have encouragement to do it again.
- mysterypie 7y agoCould they have avoided the ransom by having daily (or hourly) backups to non-rewritable (write once) media? So the malware won’t encrypt the backups, obviously. I think that the last day’s work (or last hour’s work) will be lost or will require a lot of manual fixing regardless of whether they pay the ransom. If they pay, they’ll still have to fix partial database transactions, corrupt files, etc., for the attack date. If they don’t pay, they can recover from earlier good backups and reconstruct that one day’s worth. My reasoning is that the attack date’s data is going to be corrupt and untrustworthy in either case, and it’ll be equal work either way. (Or at least it’ll be less than $600,000 of work to fix that one day.) I imagine that they either weren’t doing backups at all, or their backups were directly accessible and writable by the malware.
- moksly 7y agoI work for the city of Skanderborg in Denmark and we do a few things to avoid it. One is to monitor our entire storage for malicious code and automatically isolate suspicious activity. Another is to do frequent backups of everything on our network shares and one drive for business which is where most employee data that doesn’t belong in a specific system lives. Our servers, database clusters and vital systems are all isolated from the employee network and also frequently backed up. When we get hit, it’s usually employees reading private email and we’re typically able to isolate the ransomware before it spreads from that specific employees network share. Once we kill it, we restore files to the most recent backup and roll their machine. It’s worked well so far, but we do have an IT crew that would make most places jealous and IT is an area that is notoriously undervalued in the public sector.
- skribbj 7y agoSee this seems to be a really fun and challenging part of IT.. the part that I don't want to have to deal with is the helpdesk, guiding a 60 year old lady to login onto her system or configure her company iPhone. Maybe there is a job where you do only the former, I just haven't found it yet.
- 7y ago
- technion 7y agoNote the specific detail here: the City Council unanimously agreed to have its insurance carrier pay
- Macross8299 7y agoSeems like a classic case of moral hazard here. I'm surprised cybersecurity insurance doesn't mandate best-practice auditable backups as part of the process to grant a policy.
- onetimemanytime 7y agoProbably they haven't been hit hard so far...
- bayouborne 7y agohttps://arstechnica.com/information-technology/2016/04/maryland-hospital-group-denies-ignored-warnings-allowed-ransomware-attack/ https://arstechnica.com/information-technology/2016/04/maryl...
- mruts 7y agoI mean, do health insurance companies mandate best health practices in order to get health insurance? Of course not, they just charge premiums commensurate with the risk they're taking on.
- dredmorbius 7y agoDepends on the carrier and plan. Fully-integrated HMOs (think Kaiser) have extensive tracking and best practices that reduce future risk and liabilities: well mother / we'll baby care and training, vaccinations and nutrition, preventive chechups, monitoring of dangerous conditions, ob/gyn checkups, breast, colon & prostate exams, etc. There's only so much that individual initiative can accomplish, but systemic measures really can move the needle.
- noahl 7y ago
- iliketosleep 7y agoThe laxness of infosec in government continues to astonish me. It's not like these types of attacks are new either. I can only assume that the people in charge of infosec in such situations are bureaucrats without much technical knowledge.
- philpem 7y agoMore likely bean-counters unwilling to pay for experienced IT staff.
- Chirael 7y agoI think it’s basically the same problem as small businesses, people have this psychological expectation that I’m too small to target. They don’t realize that they are just another IP address or email address in a sea of IP/email addresses that is being automatically targeted every hour of every day.
- dillonmckay 7y agoThe decision makers are the city council and the mayor. If none of these people have the knowledge to make an informed decision, they will defer to either internal IT staff (if that even exists), or their contracted MSP. I seriously doubt there is much, if any, proactive coordination between the council and IT.
- Dirlewanger 7y agoIt's a failing of the American condition. The country was founded by radical conspiracy theorist farmers that didn't want to pay taxes. Distrusting government is in our national ethos. It pervades to this day in the form of governments generally being staffed with people too incompetent for private sectors. The pay sucks. It's hard to get raises. It's hard to do anything because Americans hate taxes; they'll help their neighbors, but they won't help those they can't see beyond their porch. There's little personal incentive to work in local/state governments. And that's partly how we end up with events like this.
- 7y ago
- billpg 7y agoWill the attackers restore the attacked machines once the payment is made? They are just as likely to take the ransom and run.
- Consultant32452 7y agoIf they want the next city to pay, they will restore the attacked machines. Gotta remember, this is a business for the attackers.
- icebraining 7y agoSimilar for ransom for actual lives: http://www.econtalk.org/anja-shortland-on-kidnap/ http://www.econtalk.org/anja-shortland-on-kidnap/
- billpg 7y agoI think that time has passed. I've read about too many people who pay up but don't get their files back.
- AnaniasAnanas 7y agoShouldn't the one responsible personally have to pay for it rather than the city and its taxpayers?
- travolter 7y agoDo you have to pay the damages for every mistake you make at your job?
- tremon 7y agoYou mean the one who wrote the attacking code? Or the one who wrote the vulnerable code? Why do we even assume there is a "one" here?
- AnaniasAnanas 7y agoWhoever made the decision not to take backups for example. The ones who will have to pay for their mistakes will be the taxpayers otherwise.
- albertgoeswoof 7y agoThis is a public service, aren't the voters responsible? They could have voted in competent leaders.
- magduf 7y agoThis is it exactly. The voters are the ones who are ultimately responsible, and they'll be the ones to ultimately pay, just as it should be. They should be voting for competent leaders, and for sufficient taxes to pay decent salaries to attract good IT talent, but they don't, so this is what they get. Every nation gets the government it deserves. - Joseph de Maistre
- AnaniasAnanas 7y agoThe voters are not one person. Sadly democracy ends up being the fascism of the many.
- knorker 7y agoApparently some people do negotiate with terrorists.
- EvanAnderson 7y agoI will continue to smugly assert that backup must include an offline component. Given that total data loss is a non-zero possibility (and, increasingly, more and more likely) the argument that having even a simple offline component (say, some encrypted USB disks for a small business, tape or such for a larger business) is too expensive or cumbersome doesn't make sense to me.
- tjpnz 7y agoSo the US is willing to pay ransoms - just not for people.
- mulmen 7y ago> So the US is willing to pay ransoms - just not for people A city government in Florida is not the US federal government.
- PlasticTank 7y agoWell now the various groups beheading people on YouTube know where to ask.
- vonmoltke 7y agoThose people care about creating a spectacle, not getting paid.
- OrgNet 7y agofor people's data? It would probably be cheaper to resolve citizen's issues directly for all missing data not present in the backup (even if it's not, that was a crazy decision made by the city council)
- PlasticTank 7y agoWhat evidence do they have that the hackers will actually send the keys? seems like a pretty big gamble on trusting proven criminals.
- nkrisc 7y agoWhat reason so they have to not send the keys (apart from not having them)? If they send the keys, all the sooner the can hit them again.
- AnIdiotOnTheNet 7y agoRansomware relies on trust, because if you don't actually hold up your end and decrypt the data then no one will bother to pay you in the future. The entire "market" is best served by playing "fair", in so far as that can be applied here. That doesn't mean some criminals won't just take the money, but it does mean that most of them wont and that the larger players have a vested interest in keeping that behavior to a minimum.
- dredmorbius 7y agoI would very much like to hear from the insurance carrier here, and know what the post mortem and preventive countermeasures will be. Update: The servicer appears to be Gallagher Basset based on the 2018-19 budget and legal cases cited online. City records (CC agendas, minutes) are painful if not impossible to navigate.
- jrochkind1 7y ago> A similar breach recently cost Baltimore $18 million to repair damages. No. $18 million was an estimate somebody gave once, who knows where it came from. In fact, damages have not been repaired in Baltimore. 6 weeks later, most city services are still down. You can't pay a parking ticket or a water bill online. (You can send a check in; I am not sure where they record that you paid when they cash your check, and am not particularly confident they'll actually have a record I paid). We in fact do not know how much money they've spent thus far, there have been no press briefings on this. Estimates of how much they will spend before it's over (will it ever be over?)... we all know how IT estimates work. I think it will probably be quite a bit more than $18 million. And then there's estimating "damage to the economy." (There were two weeks when real estate transfers were frozen, because there was no way to check city liens. They can be done now, using a paper-based system that actually has those involved in the transaction sign an unusual contract agreeing to take on liability for unknown liens in unusual ways (I'm being vague cause I don't totally understand it), that some but not all title companies are willing to use). The Baltimore ransomers only wanted ~$100K. If I were the mayor, yeah I'd pay it. </Baltimore resident>
- behringer 7y agoIf it's that easy to blackmail cities I need to take up hacking...
- jrochkind1 7y agoIf you're looking for ways to make money and aren't concerned about legal risk or ethics, certainly I'd expect hacking to be on your list of possibilities. There wouldn't be so much hacking going on if it wasn't lucrative.
- londons_explore 7y agoIt actually isn't very lucrative. Some of the crypto-blackmailers use public bitcoin addresses, and they don't get as much money as you'd expect. For the fact you'd probably have to move your life to Russia to escape the FBI, it doesn't pay very well.
- Circuits 7y agoLady opens a random email (most likely in her junk folder) from someone she doesn't know and end's up costing the company hundreds of thousands of dollars? In 2019? Something is rotten in the state of Denmark.
- dredmorbius 7y agoCuriously, no open IT / security positions listed: https://rivierabch.applicantpro.com/jobs/ https://rivierabch.applicantpro.com/jobs/
- otakucode 7y agoThe first thing I do when I read a news article that includes any company or organization saying that they are 'serious about security' is go to their website and check their job listings. Sometimes they have openings for security-related positions, but what is actually telling is their software openings. They NEVER so much as mention a single thing about security or knowing how to create secure applications. I've literally not seen a single exception, personally. Most companies do seem to have reached a level of 'caring about security' but it amounts to hiring some people to play Patch Patrol and nothing more. I guess that's better than nothing, but it won't actually help much.
- deleted 7y ago[deleted]
- nwmcsween 7y agoI've noticed outside software or technical companies IT is basically 100% turn key with off the shelf mostly junkware (even 'enterprise') software being used. I attribute this to the mismatch between HR and the position being hired for and what higher education teaches w.r.t IT. Honestly what needs to happen is interviews need to be farmed out to places that understand the respective industry and not just certifications and higher education.
- sjreese 7y agoLet's look at this a bit differently - Ransomware is a type of malicious software designed to block access to a computer system or computer files until a sum of money is paid. Most ransomware variants encrypt the files on the affected computer, making them inaccessible, and demand a payment to restore access. Ransomware is a type of malicious software designed to block access to a computer system or computer files until a sum of money is paid. Most ransomware variants encrypt the files on the affected computer, making them inaccessible, and demand a ransom payment to restore access. Ransomware is rarely individually targeted, but rather a “shotgun” approach where the attackers (Clue I) acquire lists of emails or compromised websites and blast out ransomware. Microsoft used a method to install software giving it superuser rights without a login. (Clue II) Most ransomware is based on this same install job. It is lightweight but identifiable. Ransomware is a tripartite intruder and is based on what's already there on Windows (mscexe) in your compute and a substitution of legit program (outlook encrypt) Once the 3 parts are there your system is theirs and only a windows product key method "EFHST-G6ERT-VXWMT-FF8MB-MYERR" can free it - all thanks to Microsoft's product key methodology. Oh and "backups" & PCmatic won't help and because Microsoft uses the same method to stop you from sharing software. You have seen the screen yourself => you have entered an invalid the product key! Ransomware can be shipped with a NSA crack( EternalBlue ) forced onto the city of Baltimore (Clue III ) but the same code to create a superuser is open to the public is the end to all protection - because it hides using Microsoft's hidden directory method. Well what to do now, pay the BTC? Yes and NO Yes buy BTC and NO this is where we create a pigeon drop for out NSA connected friends - we don't accept the face price and try to keep our BTC keys and Encrypt theirs. For the FBI and NSA the profit from robbing Venezuela, Iran, Russia, Ukraine and Switzerland has been too great for them to stop. As witnessed with Venezuelan money gone and power outage. That said, demand that Microsoft be held liable for product defects and to make all actions visible to the end user community ( no hidden files or directories ).