4 ms·
Yes. They are often targeting IT providers of SMBs by phishing/otherwise compromising their credentials, and deleting backups before encrypting. It works someti
by emmp 7y ago
Yes. They are often targeting IT providers of SMBs by phishing/otherwise compromising their credentials, and deleting backups before encrypting. It works sometimes, 2FA hygiene and secondary site redundancy are usually good enough to protect you.
- ev0lv 7y ago2FA is so overrated. You can so easily do a sim swap to get access to a particular phone number and bypass 2FA.
- therealrootuser 7y agoThe problem isn't with 2FA, the problem is with SMS-based 2FA.
- bonestamp2 7y agoTrue, and that's why you shouldn't use SMS 2FA. The unfortunate part is when that's the only method offered.
- parliament32 7y agoTOTP and HOTP 2FA are unbreakable and supported by literally everyone. Who still does SMS 2FA anymore?
- out_of_protocol 7y agoLots, unfortunately. With no way to opt out
- i_cant_speel 7y agoIf you inject the ransomware into a system that is subsequently backed up and wait a significant period of time, you could potentially lock all backups as they are restored. Then people have to decide between paying up or restoring to a time before the ransomware was injected. I'm not sure if it's feasible to have ransomware lock backups as they're restored, however.