Ransomware attack at my job.

  • Thread starter Thread starter Dust2dust
  • Start date Start date
  • Views Views 931
  • Replies Replies 7

Dust2dust

Well-Known Member
Member
Joined
Jun 17, 2010
Messages
2,860
Solutions
1
Reaction score
2,699
Trophies
2
XP
6,113
Country
Canada
So it looks like the computer network at my workplace got hacked. It's just a medium sized business (about a hundred employees), but still got targeted by some thief. The hacker left a lengthy message on every desktop in a plain text file mentioning that data was stolen and encrypted. He's threatening to post this data on the darkweb if a ransom is not paid. He's listing all the advantages of paying the ransom, and also the consequences of not paying. I looked at a few files, and some of them, like jpg, doc, txt and others got encrypted indeed... pure garbage in those files now. I saw a exe file which was untouched. I don't have access to the whole network, I'm not the IT guy. The files which were affected have now the "randombits" file extension at the end of the original filename. The hacker said he's part of a famous ransomware group, and he also mentioned that he is not politically motivated, he just wants money. He only gave an email address to contact him, and he said replies might come a little late because the group is very busy attacking other businesses. So no computers are working at my workplace now, which sucks. Windows 10 Pro was being used. Windows still boots, but it seems kinda broken. Anybody ever seen a similar situation?
 
Aw man, that sucks.

A robust backup system will make short work of the encryption attack, but for the "stolen" (rather copied) data there is nothing that can be done. If an attacker got full access to important and private data and created a copy, then nobody can stop them from publishing it. Even paying ransom wouldn't help. The attacker can ask for more money later. Again and again.

Doing business with criminals is not a good idea in my opinion.

Such assholes have already been everywhere. Companies, authorities, hospitals...

It is hard to say what to do in such a case. I would probably hard shutdown everything (cutting power off for all PCs and servers) and get somebody to analyze the damage and identify the source of intrusion (which might "just" be an E-Mail attachment).
 
  • Like
Reactions: CoolMe
Aw man, that sucks.

A robust backup system will make short work of the encryption attack, but for the "stolen" (rather copied) data there is nothing that can be done. If an attacker got full access to important and private data and created a copy, then nobody can stop them from publishing it. Even paying ransom wouldn't help. The attacker can ask for more money later. Again and again.

Doing business with criminals is not a good idea in my opinion.

Such assholes have already been everywhere. Companies, authorities, hospitals...

It is hard to say what to do in such a case. I would probably hard shutdown everything (cutting power off for all PCs and servers) and get somebody to analyze the damage and identify the source of intrusion (which might "just" be an E-Mail attachment).
Yep, i agree, paying any kind of money to these criminals is just asking for more attacks in the future, because you're such a good (paying) customer. I forgot to mention, in his message, the hacker was mentioning that he can be trusted to respect the deal if ransom is paid, because honor is the most important thing for the group.:rolleyes:
 
Good thing you're not the I.T. guy. I've heard of these situations countless times but have never experienced one.

What changes will the company implement to stop this from happening again or at least mitigate the impact? Daily backups, upgrade to Windows 11, tighter network monitoring, cybersecurity training (like teaching employees not to reuse passwords or open suspicious emails)?

Were the I.T. guys following best practices like keeping Windows up to date and not web browsing on administrator accounts?
 
Good thing you're not the I.T. guy. I've heard of these situations countless times but have never experienced one.

What changes will the company implement to stop this from happening again or at least mitigate the impact? Daily backups, upgrade to Windows 11, tighter network monitoring, cybersecurity training (like teaching employees not to reuse passwords or open suspicious emails)?

Were the I.T. guys following best practices like keeping Windows up to date and not web browsing on administrator accounts?
We're pretty much kept in the dark. I have no idea how they got hacked, or what they're going to do to fix this mess. The computer network is still down 10 days after the event. I don't think they had a backup. I heard rumors that they contacted the hacker with the email address, and he asked for 10 millions. Canadian money, granted, but it's still a lot of dough. I hope they don't pay. Take your loss, learn from your mistakes, start a new system from scratch, and fire this incompetent IT guy.
 
  • Like
Reactions: CoolMe
I don't think they had a backup.
This might sound harsh, but no backups = your data wasn't valuable to you. A TB of storage is like $45 [with 2 redundancies in mind], so I'm baffled as to how a company hiring a hundred people didn't have backups.
 
Last edited by notsu,

Site & Scene News

Popular threads in this forum