Showing posts with label Cyberattack. Show all posts
Showing posts with label Cyberattack. Show all posts

Thursday, April 19, 2018

Russia Warns Of ‘Precise And Painful’ Response To Any Future US Sanctions


Russia is continuing to warn the West of further attacks against Russia. Whether it be in the form of missiles or sanctions, the former Soviet Union doesn’t seem like they wish to play “war games” any longer.


The United States this month added several Russian firms and officials to a sanctions blacklist in response to what it said were the Kremlin’s “malign activities.” Moscow says those sanctions are unlawful and has warned that it will retaliate in a “painful” manner.


“No one should be under any illusions,” said Valentina Matvienko, who is closely aligned with the Kremlin, was quoted as saying by the Interfax News Agency. Matvienko, the speaker of the Russian upper house of parliament, said on Wednesday that Moscow’s response to any United States sanctions will be targeted and painful, Russian news agencies reported.


“Russia’s response to the sanctions, our so-called counter-sanctions, will be precise, painful, and without question sensitive for exactly those countries that imposed them [the sanctions] on Russia,” she was quoted as saying, according to Reuters.   “Sanctions are a double-edged sword and those who impose them should understand that sanctions against countries, especially those like Russia, will carry with them risks of serious consequences for those who impose them,” Matvienko added.


Lawmakers in the lower house of the Russian parliament have drawn up legislation that would give the government powers to ban or restrict imports of U.S. goods and services ranging from medicines to software and rocket engines. However, the Kremlin has not yet said if it backs such measures.


U.S. President Donald Trump mentioned the joint U.S., French, and British military operation last weekend that struck several sites in Syria to punish the Russian-backed government of President Bashar Assad for an apparent chemical attack that killed civilians. Trump said the strike was “absolute precision.”


A senior U.S. administration official said on Monday  Trump has delayed imposing additional sanctions on Russia and is unlikely to approve them unless Moscow carries out a new cyber attack or some other provocation that would warrant sanctions.

Wednesday, December 13, 2017

Cyberattacks: The Biggest Threat To OPEC

Authored by Irina Slav via OilPrice.com,


Oil and cybersecurity in one sentence certainly makes for a thrilling read, and there will be an increasing amount of information on the topic as the Internet of Things expands and the global oil industry adopts automation and digital technology.



OPEC is no exception in this digitalization drive, but unlike its non-OPEC counterparts, the cartel has emerged as much more vulnerable to cybersecurity threats.


An analysis of data collected from 134 countries by the International Telecommunication Union has revealed that some of the world’s biggest oil producers, including Iraq, Saudi Arabia, Venezuela, Iran, and the UAE, are lacking in the cybersecurity department. This means that, compared to European producers and the United States, OPEC members are pretty much unprepared for a major cyberthreat.


What is the likelihood of such a threat actually materializing? Well, the general opinion in cybersecurity circles is that everything that can be hacked will be hacked at some point. Saudi Arabia’s oil and gas industry, for example, has been a favorite target for numerous attacks over the last few years, including the Shamoon virus, which in 2012 wiped clean the disks of more than 30,000 computers at Aramco, and according to reports from the cybersecurity industry, reared its ugly head again in 2016.


Overall, about half of all cyberattacks in the Middle East target the oil and gas industry, which suggests the answer to the above question is “Pretty high,” but the worse thing is that this likelihood is only going to get higher in the future. Related: Brent Spikes As This Major Pipeline Breaks Down


Middle Eastern producers are following in the footsteps of their non-OPEC counterparts in adopting digital technology and automation to improve efficiencies in the post-2014 world, where efficiency has come to the fore in oil and gas. The problem, of course, is that the more you digitalize, the more vulnerable you become to attacks through digital channels.


A recent study from Siemens and Ponemon Institute found that as digital tech adoption in the Middle East oil industry rises, so does cyber risk. What’s more, this risk is no longer limited to IT operations: the operational technology area is gaining prominence as a preferred target for cybercriminals.


The reason, according to Siemens and Ponemon Institute, is the convergence between IT and OT in the oil and gas industry. “Attackers have identified this convergence of IT and OT as a key opportunity to penetrate an organisation. As a result, an emerging trend of cyberattacks is designed to disrupt physical devices or processes used in operations. In a digital environment, industrial cyber is the new risk frontier,” says Siemens’ Vice President and Global Head of Industrial Cyber, Leo Simonovich.


The cybersecurity industry is sounding an alarm and it seems those in the Middle East that can afford it are hearing it and heeding the warning to improve their cybersecurity capabilities.


The UAE has a Dubai Cyber Security Strategy. Earlier this year, Saudi Arabia launched a National Cyber Security Center, and last month announced the set-up of a National Authority for Cyber Security, seeking to utilize international expertise and best practices to prop up government and critical infrastructure defenses. Iraq is seriously lagging behind and Iran is seen by cybersecurity insiders as more a source of cyberthreats than as a potential victim.


This sounds all well and good, but the trends in cybercrime point to a desperate need to do more. Cybercriminals do not sit on their hands while potential victims work to improve their defenses. While cybersecurity service providers continue to warn businesses and other organizations that they need to become more pro-active with regard to their cybersecurity measures, the hackers are coming up with new ways to undermine existing defenses. This is true for all industries, but it is especially true for oil and gas in the Middle East—national energy infrastructures are called critical for a reason, after all.









Monday, October 2, 2017

Russia Provides New Internet Connection To North Korea

Authored by Martyn Williams via 38North.org,


A major Russian telecommunications company appears to have begun providing an Internet connection to North Korea. The new link supplements one from China and will provide back-up to Pyongyang at a time the US government is reportedly attacking its Internet infrastructure and pressuring China to end all business with North Korea.


The connection, from TransTeleCom, began appearing in Internet routing databases at 09:08 UTC on Sunday, or around 17:38 Pyongyang time on Sunday evening. Internet routing databases map the thousands of connections between telecom providers and enable computers to figure out the best route to a destination.


Until now, Internet users in North Korea and those outside accessing North Korean websites were all funneled along the same route connecting North Korean ISP Star JV and the global Internet: A China Unicom link that has been in operation since 2010.



Global Internet connectivity to Star JV. The orange denotes the China Unicom connection and blue the TransTeleCom. The graphic shows the Russian connection coming online around 0900 UTC, a short period of instability then a stable connection with two networks. (Dyn Research)


“The addition of Russian transit would create new internet path out of the country, increasing its resilience and international bandwidth capacity,” said Doug Madory, who analyzes global Internet connectivity at Dyn Research.


The new link comes at an interesting time.


On Saturday, The Washington Post reported that US Cyber Command has been carrying out denial of service attacks against North Korean hackers affiliated with the Reconnaissance General Bureau. The attacks attempt to overwhelm their computers and the Internet connection with traffic making them slow or impossible to use.


The US cyber attack was due to end on Saturday, reported the Post. That means the new Russian connection went online just after the US Cyber Command attack ended.


TransTeleCom, or TTK, is one of Russia’s biggest telecommunications companies and a subsidiary of the Russian railway operator. Fiber optic lines are laid alongside the railway and, according to a map on its website, on a route from Vladivostok right up to the North Korean border. 



A map of the TTK network shows a link running right up to the North Korean border.


That’s presumably at the Friendship Bridge, a railway crossing over the Tumen River that connects Khasan in Russia with Tumangang in North Korea. It’s the only connection between the two countries.



The Friendship Bridge connecting Russia (right) and North Korea (left). Photo: GoogleEarth.


This isn’t the first time North Korea has had alternate routes for Internet connectivity.


From 2012 for about a year, a second link to Star JV existed via Intelsat, an international satellite telecommunications operator, but in recent years the Chinese link has been the sole connection to Star JV.


Relying on one Internet provider has always left North Korea in a precarious situation.


More than once the link has been the target of denial of service attacks. Most were claimed by the “Anonymous” hacking collective, but on at least one previous occasion, many wondered if US intelligence services had carried out the action.


North Korea has few Internet users, but access to the network is available at major universities, to foreigners via smartphone, at government departments and major companies. Elite families are also suspected of having access. The cyber units of North Korea’s military also enjoy access.


The link is also vital for overseas researchers and academics who rely on access to North Korean state media websites for information.

Sunday, July 2, 2017

Here’s How a DELIBERATE Cyberattack Could Happen To Us

The Petya Ransomware attack hit globally, but one country, in particular, was devastated by it. The Ukrainian infrastructure was brought down by the attack, where the epicenter occurred, and now, experts are suggesting that it may have been deliberate and state-sponsored.


This is not the first time Ukraine has been under siege by cyberattack. In fact, the battle has been nearly constant for quite some time.



 As for whether that state sponsor was Russia, “It’s difficult to imagine anyone else would want to do this,” Boyarchuk says.


Boyarchuk points to the timing of the attack, just before Ukraine’s Constitution Day, which celebrates the country’s post-Soviet independence…


More technical clues support that theory, some Ukrainian security researchers say. Kiev-based Information Systems Security Partners, which has acted as a first responder for several recent waves of cyberattacks on Ukrainian companies and government agencies, says it has found evidence that sophisticated hackers quietly infiltrated the networks of at least some Ukrainian targets two to three months before they triggered the ransomware that paralyzed those organizations. (source)



Security specialist Matthieu Suiche said in a blog post that it wasn’t a “ransomware” attack intended to make money, and is instead a “wiper” sent to eradicate data.



The fact of pretending to be a ransomware while being in fact a nation state attack — especially since WannaCry proved that widely spread ransomware aren’t financially profitable — is in our opinion a very subtle way from the attacker to control the narrative of the attack. (source)



Forensic analyst Oleksii Yasinsky told Wired that the intent was not money, even though this presented as a ransomware attack.




Rather than just encrypting infected hard drives and demanding $300 in Bitcoin for the decryption key, in some cases it simply wiped machines on the same network, deleting a victim computer’s deep-seated master boot record, which tells it how to load its operating system. Yasinsky argues that this behavior indicates the attackers weren’t, in fact, trying to extort payments from those victims but instead wanted to cause maximum disruption. (source)



They wanted to cause maximum disruption. Now, isn’t that just about the scariest thought ever?


What if the US was hit by a similar cyberattack?


Let’s go a little further down this rabbit hole and imagine such an attack happening in the United States. Because, really, is it that far-fetched? In fact, is it possible that this is a dry run for a massive attack on the American infrastructure? Maybe they want to see what happens when they take down the essential systems of a modern country on a smaller scale first, in order to maximize the effects on a larger target.


Scary, but possible.


Everything we do revolves around computers these days.


Businesses keep their records there. Systems are automated there. It goes on and on. And with this particular virus, one expert said, “There IS NO KILL SWITCH.” It’s virtually unstoppable once it gets into a system and it eradicates everything.


You know how I’m always encouraging you to watch survival movies and read survival fiction to enhance your prepared mindset? Let’s use this real life scenario and wargame the situation based on the systems that were damaged in Ukraine and think this through.


Banking would be disrupted.


Many banks in Ukraine were hit by the attack, which means that people suddenly had no access to their money. Their credit and debit cards wouldn’t work and the ATMs were down.


In the United States, most folks use credit or debit as they go throughout their days. Gas pumps are set up to pay at the pump with your bank card. We think nothing of swiping our card at the grocery store or at lunch. We know we have money in there, and it’s less risky than carrying cash, in most folk’s minds.


But what if suddenly you couldn’t use your credit cards and debit cards? What if the ATM machines went dark and you couldn’t get any cash from them?


Imagine this happened when you were traveling on business, miles from home with a half empty gas tank. You wouldn’t be able to get a hotel room, get more fuel, get food – nothing at all unless you had cash on hand – and even if you DID have enough cash, there’d be other problems as you’ll see below.


You should always have enough cash and supplies on hand to manage for quite a while if commerce were to cease.


Gas stations would close.


In Ukraine, getting fuel was difficult.


Of course, it makes sense that getting gasoline would be pretty tricky. Most gas stations are set up as pay-at-the-pump, and if you have cash, you have to go inside, pay, and they reset the pump to allow you the allotted amount of fuel…on a computer.


As well, the gas pumps themselves are digital in just about every place I’ve been in the past few years. Unless you manage to find some anomaly of a gas station where everything is still manual, the fuel you had would be all you’d have until things reverted to normal.


Even if you could buy stuff, there might not be stuff to buy.


It wouldn’t take more than a day or two for the transport trucks to stop running, since the fuel wouldn’t be readily available. Since our stores use “just-in-time” inventory restocking, pickings would be thin within a week.


Here’s a breakdown of what would happen – and how fast it would happen – if the trucks stopped running.


Like I said, be prepped for this.


Business would be disrupted.


In Ukraine, the banks are offline, which means payment systems are also offline.


Most businesses link to banks to be able to take payments by debit or credit. Most people no longer carry around pockets full of cash, and even if they did, some businesses aren’t entirely equipped to take cash payments.


When I worked at a car dealership service department, half a lifetime ago, I recall getting the day off because we were utterly at a standstill when our systems went down. The technicians couldn’t do any kind of electronic repair (and let’s face it, these days, there’s a computer in your car controlling just about every aspect of its function), the advisers couldn’t invoice, no one could check to see if a job was covered under warranty…I’m sure that many other businesses are equally dependent.


Most retail businesses rely on the ability to scan items for the price and to track SKU numbers for inventory purposes. Their cash registers are inextricably linked to computers for both payment options, pricing, and inventory options. Commerce could grind immediately to a halt, which means, what you have on hand would be all you had until things were resolved. You could forget about getting goods or services.


With the banking systems inoperable, other systems would soon go down too.


Think about our day-to-day business. Most of us have things on autopay, like our mortgages, car payments, and other monthly recurring bills.


If the banking systems are completely shut down, then our automatic payments would also cease to work. This means that the businesses relying on those payments would immediately have a shortfall, something that could have long-term ramifications if the issue lasted for more than a few days. Once things came back online, there would be massive confusion and congestion as people tried to straighten out payments that didn’t go through.


Chaos.


Transportation could shut down.


In Ukraine, both the major airport in the capital and the national railway system were shut down.


An attack like this could hit travelers the hardest. Imagine being at an airport to catch a connecting flight, and then discovering all flights had been canceled. If the computer systems were all down, you wouldn’t be able to rent a car to drive the rest of the way, and you wouldn’t be able to get a hotel room without cash, and you wouldn’t be able to buy any food unless you had cash on hand for that.


Commuters who rely on transit like trains to get back and forth to work would be stranded and without ATM access, most would be without any options. This is why you must always have a Plan B to get home when you’re traveling, along with the appropriate gear and footwear to walk if necessary.


The grid would fail.


In Ukraine, the power grid went down across a broad swath of the country.


In an event like this, it isn’t out of the ordinary for the power to go out. Our grid is extremely susceptible to a malware attack and something called “cascading failure.”



…malware can induce what’s often referred to as a cascading failure. This is what caused the massive blackout that occurred in the Northeastern US and Canada back in 2003. An overgrown tree branch in Ohio touched a power line, which caused that section of the grid to overload and shut down. The electricity had to be transferred to other power lines, which in turn also became overloaded. This chain reaction continued until 55 million people were without power. (source)



This can begin to have broad ramifications very quickly:


  • Most homes are reliant on the grid for heat or cooling.

  • No lights.

  • No hot water.

  • Food in the refrigerator or freezer would begin to spoil.

All the basics of a long-term power outage would apply, multiplied by all of the other things going wrong at the same time. Always be ready for a two-week power outage at the bare minimum.


Water could become contaminated.


Without the systems that keep municipal water supplies treated and distributed, it wouldn’t take long for the water from the taps to become contaminated and unsafe to drink – if it still flowed at all. Buying water at the store would be difficult, if not impossible, for all the reasons mentioned above, and even if you could buy it, the supplies would run out very quickly as others realized the tap water was unsafe to consume.


Always be prepared with water storage, a plan to acquire more water, and a way to purify water.


Dangerous infrastructure systems could be at risk.


The Chernobyl nuclear plant lost its ability to monitor radiation with the usual computerized systems.


Because Chernobyl hasn’t already had enough issues. The plant is still not fully decommissioned after the horrible disaster in the 80s, and some people are still working there monitoring for radiation leaks. All systems have had to revert to manual ones due to the cyberattack.


The United States has 99 nuclear reactors in 30 states.  99 Chernobyls waiting to happen?



Here’s How a DELIBERATE Cyberattack Could Happen To Us | power-reactors-operating | Science & Technology Special Interests


Photo Credit: USNRC



 Hospitals could be affected.


In the US, two hospitals in Pennsylvania were forced to cancel surgeries due to the Petya cyberattack.


During a widespread attack in the United States, there is potential for our medical system to be severely affected. Without access to patient records, terrible mistakes could occur. Many patient monitoring systems are computerized. Some life support machinery is tied into the grid. And what happens if the grid-down situation outlasts the fuel for the generators?


In a situation like that, there wouldn’t be much medical help available for incidents that occur during the disaster. You must keep some first aid and longer-term care supplies on hand, as well as informational guides to help you deal with health issues and emergencies as they arise. Know how to back this up with natural remedies in the event the situation outlasts your commercial supplies.


With all of this, unrest would erupt fairly quickly.


If the situation only lasted for a few days, society certainly wouldn’t break down. But if it stretched into weeks and more people began running out of the basics, we’d begin to see unrest on a massive scale. Think about it – what wouldn’t YOU do to take care of your hungry children?  Add to this the now-refugees stranded in airports and other travel centers across the country, with no supplies and no way to get home. It wouldn’t take long for the need to outstrip any governmental efforts to supply aid.


Long before such a thing ever occurs, you should protect yourself by keeping your mouth shut. No one needs to know that you’re stocked to the rafters and ready for a situation like this. Secondly, you need to be prepared to protect your home and family should things go sideways. Here’s an article I wrote about why preppers must be armed and ready for unrest.


Are you prepped for something like this?


Prepping is prepping is prepping.


This, like any other disaster, assumes certain things.


  • The grid could go down.

  • Emergency services and first responders may not be there.

  • What you have on hand is what you have with which to survive,

  • If you’re away from home, the trip back could be difficult.

Have you thought this through?


An attack like this could have very longterm effects because, as I mentioned above, once it gets into a system, it’s unstoppable. It wipes clean all the date, the information stored, the functions. It would take a long time to come back from that.


What are some other things that could be affected by a massive cyberattack on the US? How would you prepare for something like this? Share your thoughts in the comments section below.




Wednesday, June 28, 2017

3 Out Of 4 US Energy Firms Were Hacked In 2016

Authored by Zainab Calcuttawala via OilPrice.com,



Hackers have targeted Russian oil giant Rosneft, the company said on Tuesday, just as Deloitte released a report on cyber-attacks targeting U.S. oil companies.


A “powerful hacker” attacked the company’s server in an assault that, according to TASS news agency, could be related to ongoing legal proceedings.


A Russian court recently froze assets of a holding company called Sistema as part of a suit lodged by Rosneft and Bashneft. The two companies are trying to recover $2.9 billion lost during Sistema’s 2014 restructuring.


Russian companies are not the only ones facing the new frontier in corporate espionage. U.S. consulting major Deloitte released a report on Monday that said American energy companies showed “limited strategic appreciation” for cyber-threats.



Analysts said three of every four U.S. oil and gas companies experienced a cyber-attack in 2016, but only a few firms said the computerized attacks posed a major security risk.





"Whether hackers use spyware targeting bidding data of fields, malware infecting production control systems, or denial of service that blocks the flow of information through control systems, they are becoming increasingly sophisticated and, specifically alarming, launching coordinated attacks on the industry," the report said.



Low crude prices have caused energy companies to focus their spending on operations that maximize value for shareholders, instead of investing in protective cyber security measures.



On the most vulnerable aspects of the oil and gas supply chain, Deloitte wrote:





Among the upstream operations, development drilling and production have the highest cyber risk profiles; while seismic imaging has a relatively lower risk profile, the growing business need to digitize, e-store, and feed seismic data into other disciplines could raise its risk profile in the future.”


Tuesday, June 27, 2017

"Massive Cyberattack" Spreads Across Europe, Hits Ukraine, Russia, UK, Denmark

Update 3: Germany"s Merck also confirms it has been affected by the cyberattack:




* * *


Update 2: RUSSIAN CENBANK SAYS AS A RESULT OF ATTACKS THERE HAVE BEEN ISOLATED CASES WHERE IT SYSTEMS INFECTED


* * *


Update: in addition to the below listed companies, all of which appear to have been targeted in the global cyberattack including Russia"s Rosneft and metals giant Evraz, Danish shipper Maersk, UK ad company WPP, the Ukraine central bank, government and airport, more targets are emerging including Norway"s national security authority which has said that a Ransomeware attack is ongoing in Norway "similar to the attack on Maersk", while Russia"s Home Credit Bank said all domestic branches are closed because of the cyber attack.


As the Spectator adds, companies in Spain are also now affected by the cyberattack which appears to be a modification of the "WannaCry" virus, and has been named "Petya."


A Moscow-based cyber security firm, Group-IB, said it appeared to be a coordinated attack simultaneously targeting victims in Russia and Ukraine, according to Reuters.


* * *


Now that CNN is officially out of the "Russia hacking" fake news business, the Ukraine has decided to fill in the void, and moments ago Ukraine"s Deputy Prime Minister Pavlo Rozenko said that the government"s computer network was down, in what he claimed was a "massive cyberattack", one which has also impacted the central bank, power plant and airport, and promptly blamed Russia for being behind the attack without a shred of evidence. To "prove" the accusation, he posted a picture on Twitter of a computer screen showing an error message.


“We also have a network "down",” he wrote. “This image is being displayed by all computers of the government.” The photo showed his PC displaying a message claiming a disk “contains errors and needs to be prepared”, urging the user not to turn it off.



According to local press, numerous Ukrainian institutions were hit by a wave of cyber attacks earlier in the day, including banks, the state energy distributor and Kiev"s main airport. "We also have a network "down"," Rozenko said on Facebook.


Ukrainian state-run aircraft manufacturer Antonov was among the companies hit, along with state power distributor Ukrenergo, which said the attack did not affect power supplies.


According to Bloomberg, Kievenergo, a Ukrainian utility, switched off all computers after the hack, while another power company, Ukrenergo, was also affected, though “not seriously,” the Interfax news service reported. Ukrainian airports and railways are operating as usual, according to the Russian news service.


Ukrainian delivery network Nova Poshta halted service to clients after its network was infected, the company said on Facebook. Ukraine’s Central Bank warned on its website that several banks had been targeted by hackers.


After the attack, Ukraine quickly went for the empathy points, tweeting a meme from its official Twitter account.


“Some of our gov agencies, private firms were hit by a virus. No need to panic, we’re putting utmost efforts to tackle the issue,” the account tweeted. Attached was an infamous "this is fine" gif.



* * *


So who"s to blame? Why Russia of course.


Speaking to Interfax,the advisor to the Interior Minister of Ukraine, MP Anton Gerashchenko said that "a huge cyber-attack at Ukrainian companies on Tuesday has been organized by Russian intelligence services and it is one of the elements of the hybrid war against Ukraine,


"The intrusion is the biggest in Ukraine’s history,” Gerashchenko wrote on Facebook. The goal was “the destabilization of the economic situation and in the civic consciousness of Ukraine,” though it was “disguised as an extortion attempt,” he said.


"A huge cyber-attack has been started against Ukraine. It was done under the disguise that it is allegedly a virus… According to the preliminary information, this is an organized system, a kind of training by the Russian intelligence services. The attack aims at banks, media and transport communications," he said on 112.Ukraine TV Channel on Tuesday.


One wonders if that preliminary information came from the same FBI that incorrectly claimed the Qatar hack was organized by Russia, when Qatar itself later blamed the "blockade" countries as being behind it.


Gerashchenko said that the virus reached computers during several days and even weeks via getting mails. "Today, at 11:00 [the computers] that were affected by the virus in advance were activated. Thus, this is another example of using cyber-attacks in the hybrid war against our country," he said.


"I think that soon officers of the SBU, the cyber security department of the National Police will unveil the ways how this virus reached the targets and they propose the options to tackle the problem," he said.


* * *


Meanwhile, the fall out in Ukraine, which claimed the cyberattacks are a modified version of the "WannaCry" virus, has been extensive with Ukrainian state-run aircraft manufacturer Antonov among the companies reportedly hit, along with state power distributor Ukrenergo, which said the attack did not affect power supplies. The National Bank of Ukraine said an “unknown virus” was to blame, saying several unnamed Ukrainian banks were affected  along with financial firms.


“As a result of cyber attacks, these banks have difficulties with customer service and banking operations,” a statement said.


“The National Bank bank is confident that the banking infrastructure"s defense against cyber fraud is properly set up and attempted cyber attacks on banks" IT systems will be neutralised.”


Oschadbank, one of Ukraine"s largest state-owned lenders, said some of its services had been affected by a “hacking attack” but guaranteed that customer data was safe.


Computers and departure boards at Boryspil International Airport in Kiev – the largest in Ukraine – were also down. “The official site of the airport and the scoreboard with the schedule of flights aren"t working!” the airport’s acting director, Pavel Ryabikin, wrote on Facebook.



* * *


It wasn"t just Ukraine however. As The Independent writes, Danish shipping giant Maersk said its IT systems were down across “multiple sites and
businesses due to a cyber attack”, although it was unclear whether it
was related to the situation in Ukraine. The congolmerate is the largest container shipping
company in the world and also operates in the oil and gas sectors.


Russia"s Rosneft, a government-owned oil firm, also said it was targeted by a “massive hacker attack” on its servers, as was steel maker
Evraz. "The cyber attack could lead to serious consequences, however, due to
the fact that the Company has switched to a reserve control system,
neither oil production nor preparation processes were stopped,” a
statement from Rosneft said.


British advertising company WPP also said several units were affected by a suspected cyber attack.


Or, as Reuters summarizes:


  • SWISS GOV"T AGENCY SAYS UKRAINE, RUSSIA, ENGLAND AND INDIA ARE MOST AFFECTED BY VIRUS, NO INDICATION THAT SWISS COMPANIES AFFECTED

  • SWISS GOV"T AGENCY SAYS THERE ARE INDICATIONS THAT PETYA RANSOMWARE VIRUS IS CIRCULATING AGAIN

It was not clear how and why Russian hackers would be able to hack the entire world, Russia included, but that probably does not matter: Ukraine has blamed Russia for repeated cyber attacks targeting
crucial infrastructure during the past three years, including one on its
power grid that left part of western Ukraine temporarily without
electricity in December 2015. Today was just a continuation, and after all the world still demand Russia hacking narratives.

Monday, May 15, 2017

Cyberattacks expected to spread Monday as Europol fears computer systems simply won’t start

Update: confirming our earlier report that Monday could get ugly for global computer system, the WSJ writes on Sunday afternoon that Cybersecurity experts are expecting another wave of computer-system attacks that encrypt files and demand ransom to unlock them on Monday, as companies and government agencies are seeking to restore normal operations and figure out the roots of the attack.



The attacks, which made over 200,000 victims in at least 150 countries, affect only computers running Microsoft Corp.’s Windows that haven’t installed the security patch that the company released in March, or the emergency patch it released for older Windows systems over the weekend. The problem is that it can take organizations, especially large ones, a long time to install these patches.


“I think there’s going to be a lot of infections Monday morning,” said Ofer Israeli, chief executive of Tel Aviv-based cybersecurity firm Illusive Networks.



“Time will tell how quickly people are going to patch their systems.” If the answer is “not fast enough”, what started off as a modest crippling of global Windows-based system, could become a full-blown global paralysis.


Earlier


There was a silver lining in what has been dubbed the “world’s biggest ransomware attack” – it struck on Friday mid-afternoon (in Europe), just as businesses were winding down for the weekend, and as a result the full impact of the forced system shutdowns would not be fully felt over the weekend when businesses and infrastructure are generally operating at a subdued pace. However, with the weekend coming to a close, the full extent of the inflicted damage may become apparent in just a few hours.


That was the warning by Europol Executive Director Rob Wainwright who on ITV’s “Peston on Sunday” broadcast, said that additional disruptions are likely as people return to work Monday and turn on their desktop systems, and as a result the “unrivaled” global cyberattack is poised to continue claiming victims.


Speaking to ITV’s, Wainwright added the attack was indiscriminate across the private and public sectors.


At the moment we are in the face of an escalating threat, the numbers are going up, I am worried about how the numbers will continue to grow when people go to work and turn their machines on Monday morning.”


“The latest count is over 200,000 victims in at least 150 countries. Many of those will be businesses including large corporations.”


“We’ve seen the rise of ransomware becoming the principal threat, I think, but this is something we haven’t seen before — the global reach is unprecedented,” Wainwright also said. He also said that organisations across the globe, including investigators from the National Crime Agency (NCA), are now working non-stop to hunt down those responsible for the ransomware.


As we reported on Saturday, the initial attack was halted when a security researcher disabled a key mechanism used by the worm to spread, but experts said the hackers were likely to mount a second attack because so many users of personal computers with Microsoft operating systems couldn’t or didn’t download a security patch released in March that Microsoft had labeled “critical.” Microsoft said in a blog post Saturday that it was taking the “highly unusual“ step of providing the patch for older versions of Windows it was otherwise no longer supporting, including Windows XP and Windows Server 2003.


As the WSJ confirms, the attacks could worsen on Monday morning because of how the virus works.



The virus contains two parts. One is the ransomware, which locks the computer files and displays a message saying that the files will be locked and eventually destroyed unless the user sends payment over the internet to the hacker.


The other part is known as the “spreader.” Once the virus makes its way onto one computer–perhaps when a user opens an infected email attachment–the spreader transmits itself to other computers on the network.


The British researcher, who wishes to be identified only as MalwareTech, found a kill switch in the spreader. The spreader was designed to contact a web address to see whether it should further spread itself, but hackers hadn’t bought that web address. So MalwareTech did, and effectively stopped the virus’s spread. It meant that one computer in a network could be infected, but the worm wouldn’t spread to the rest of the network.


Cybersecurity experts expect the latest versions of the worm to have no kill switch for the spreader. So when workers return to the office Monday morning and turn on their computers, they might open an infected email attachment or connect an already-infected laptop to their organization’s non-security-patched network and spread the worm.



There was some good news: having tipped their hand on Friday, and allowing hacking countermeasures to be implemented, about 97% of U.K. facilities and doctors disabled by the attack were back to normal operation, Home Secretary Amber Rudd said Saturday after a government meeting. As reported on Friday, at the height of the attack Friday and early Saturday, 48 organizations in the NHS were affected, and hospitals in London, North West England and Central England urged people with non-emergency conditions to stay away as technicians tried to stop the spread of the malicious software.


“There will be lessons to learn from what appears to be the biggest criminal cyber-attack in history,” Rudd said cited by Bloomberg in response to a letter from Jonathan Ashworth, the shadow secretary of state for health.


Meanwhile, according to Tom Robinson, chief operating officer and co-founder of Elliptic Enterprises Ltd., a ransomware consultant that works with banks and companies, victims have already paid about $30,000 in ransom so far, with the total expected to rise substantially next week, said . Robinson, in an interview by email, said he calculated the total based on payments tracked to Bitcoin addresses specified in the ransom demands. The number, which is likely a conservative estimate, will only embolden the hackers to become even more aggressive in their next attack.



Ransomware is a particularly stubborn problem because victims are often tricked into allowing the malicious software to run on their computers, and the encryption happens too fast for security software to catch it. Some security expects calculate that ransomware may bring in as much as $1 billion a year in revenue for the attackers.



According to Bloomberg, last year an acute-care hospital in Hollywood paid $17,000 in bitcoin to an extortionist who hijacked its computer systems and forced doctors and staff to revert to pen and paper for record-keeping.


On one hand, it is probable that the weekend gave many companies the opportunity to prepare for the next ransomware attack: “While any sized company could be vulnerable, many large organizations with robust security departments would have prioritized the update that Microsoft released in March and wouldn’t be vulnerable to Friday’s attack.”


Even so, it does not explain why some of the world’s biggest corporations were so strikingly unprepared for Friday’s events.



A spokesman for Spain’s Telefonica SA said the hack affected some employees at its headquarters, but the phone company is attacked frequently and the impact of Friday’s incident wasn’t major. FedEx said it was “experiencing interference,” the Associated Press reported.


Renault halted production at some factories to stop the virus from spreading, a spokesman said Saturday, while Nissan’s U.K. car plant in Sunderland, in northeast England, was affected without causing any major impact on business, an official said.


In Germany, Deutsche Bahn faced “technical disruptions” on electronic displays at train stations, but travel was unaffected, the company said in a statement on its website. Newspaper reports showed images of a ransomware message on display screens blocking train information.


Russia’s Interior Ministry, with oversight of the police forces, said about “1,000 computers were infected,” which it described as less than 1 percent of the total, according to its website.


Indonesia’s government reported two hospitals in Jakarta were affected.



Meanwhile, the latest anti-Russia narrative is growing.


“There is a high probability that Russian-language cybercriminals were behind the attack” said Aleks Gostev, chief cybersecurity expert for Kaspersky Labs. “Ransomware is traditionally their topic,” he said. “The geography of attacks that hit post-Soviet Union most also suggests that.” In retrospect, what more convenient confluence of events could there be than having a handy justification for Q2 GDP missing again – just blame it on the computer virus – and accusing Russia of being responsible for the latest global slowdown.


Via Zero Hedge


(Photo Credit: photosteve101/Flickr)

Wednesday, January 11, 2017

Gov’t Report Warns: Power Grid In ‘Imminent Danger’ Of Cyberattack Impacting ‘Millions’

Gov’t Report Warns: Power Grid In ‘Imminent Danger’ Of Cyberattack Impacting ‘Millions’


Jan. 11, 2017


The U.S. power grid is in constant danger of a cyberattack that could cause widespread blackouts and impact millions of citizens, according to a new 492-page report from the Department of Energy that warns if nothing is done to protect the system, the nation likely will suffer.


“The U.S. grid faces imminent danger from cyberattacks,” the report, released Jan. 6, states. “Widespread disruption of electric service because of a transmission failure initiated by a cyberattack at various points of entry could undermine U.S. lifeline networks, critical defense infrastructure, and much of the economy; it could also endanger the health and safety of millions of citizens.”


The report, titled “Transforming the Nation’s Energy System,” notes that the electric grid in the 48 contiguous states is comprised of 21,500 substations and about 700,000 miles of power lines.


It points to the 2015 cyberattack on the Ukrainian electric grid as an example of what is possible in the U.S. That attack — the “most sophisticated cyber incident on a power system to date” – took out electricity for 225,000 customers “after malicious actors remotely manipulated circuit breakers across multiple facilities.”


Are You Prepared For A Long-Term Blackout? Get Backup Electricity Today!


One problem America faces, the report says, is that while cyberattacks are rapidly evolving, power grid officials are slow to deploy defensive measures.


“This gap is exacerbated by difficulties in addressing vulnerabilities in operational technologies that cannot easily be taken offline for upgrades, and the presence of significant legacy systems, as well as components that lack computing resources to incorporate new security fixes,” the report says.


For a fix to be successful, the report notes, it “must be implemented by the thousands of private companies that own and operate electricity infrastructure.”


“While cyberattacks on the U.S. grid and affiliated systems have had limited consequences to date, attacks elsewhere in the world on energy systems should be seen as an indicator of what is possible,” the report says. “Threats can emerge from a range of highly capable actors with sufficient resources, including individuals, groups, or nation-states under the cloak of anonymity.”


“There’s the weak-link issue for the whole system,” Energy Secretary Ernest Moniz said in an interview, according to The Washington Post. “The reality is, for a lot of rural, smaller utilities, it’s a very difficult job to have the kind of expertise that will be needed in terms of cyber, so we suggest for example, grant programs to help with training, to help with analytical capacity in these situations.”


The economy would “just take an enormous hit” from a successful cyberattack, Moniz added.


Do you believe the power grid is vulnerable to a cyberattack? Do you think President Trump can or will fix it? Share your thoughts in the section below:  


Sunday, October 23, 2016

Massive Cyberattack Hits America – Will Russia Take Down The Entire Internet If We Go To War?

computer-code


We just learned a very important lesson about how exceedingly vulnerable our Internet truly is. On Friday, three massive waves of cyberattacks took down some of the biggest websites on the entire Internet. Amazon, Twitter, Netflix, Reddit, Etsy, Business Insider, Github, Spotify, the New York Times and the Boston Globe were among the prominent websites affected. Security experts tells us that with each passing month these kinds of attacks are becoming larger and more sophisticated. And most Americans don’t realize this, but nations such as Russia, China and North Korea have been feverishly developing extremely advanced cyberwarfare capabilities. So could a day come when one of our enemies takes down our Internet completely for an extended period of time?


According to CNBC, the primary target of the attacks on Friday was a hosting company known as Dyn, and these attacks came from “tens of millions” of IP addresses simultaneously…



Internet traffic company Dyn on Friday warned of another cyberattack after websites and services across the East Coast were shut down earlier in the day.


Dyn told CNBC Friday afternoon the attacks are “well planned and executed, coming from tens of millions IP addresses at same time.”


“We have begun monitoring and mitigating a DDoS attack against our Dyn Managed (Domain Name System) infrastructure. Our Engineers are continuing to work on mitigating this issue,” Dyn said on its website at 11:52 a.m. ET.



Specifically, the types of attacks that we witnessed on Friday are known as “denial of service” attacks. If you are not familiar with denial of service attacks, the following is a pretty good explanation from Business Insider



It appears to have been caused by a large digital denial of service (DDoS) attack leveled at the servers of the domain name system (DNS) host Dyn. A DDoS attack typically overwhelms a server with data requests in order to prevent normal users from having their own queries answered. The DNS is a large database that, among other things, converts a simple domain name into a more complex IP address from which data can be retrieved. Taking down a DNS server means that a user’s browser can’t use it to resolve which IP address to fetch the files of a web page from.



These attacks were so big that the Department of Homeland Security is looking into them. It is being reported that North Korea has been ruled out as a suspect so far, but nothing has been said about Russia or China.


As I mentioned above, countries such as Russia, China and North Korea have been working very hard to develop extremely advanced cyberwarfare capabilities in recent years. In particular, Russia has been heavily investing in this area since at least 2007



Russia’s intelligence services decided years ago to make cyber warfare a national defense priority, said Dr. David Stupples, director of the Centre for Cyber Security Sciences at City University London. They have become increasingly proficient in cyber operations as a result.


From around 2007, Russia decided that information warfare was key to winning any world conflict, and that it was this area of capability and technology they decided would benefit from vastly increased military investment,” Stupples said. “What made this decision easier was that Russia was also home to the largest numbers of some of the world’s best hackers.”



For almost a decade, the Russians have been preparing to fight a cyberwar with the United States.


And at this point many analysts believe that they are far better equipped to fight a cyberwar then we are.


So it would seem to be incredibly foolish to provoke an enemy into a fight that we could not possibly win. Unfortunately, that is precisely what Barack Obama is doing. According to a stunning report from NBC News, the Obama administration is actually threatening Russia with “an unprecedented cyber covert action”…



The Obama administration is contemplating an unprecedented cyber covert action against Russia in retaliation for alleged Russian interference in the American presidential election, U.S. intelligence officials told NBC News.


Current and former officials with direct knowledge of the situation say the CIA has been asked to deliver options to the White House for a wide-ranging “clandestine” cyber operation designed to harass and “embarrass” the Kremlin leadership.


The sources did not elaborate on the exact measures the CIA was considering, but said the agency had already begun opening cyber doors, selecting targets and making other preparations for an operation.



I can’t even begin to describe how foolish this is.


Yes, without a doubt we could do some damage to the Russians. But the Russians believe that when they get hit by an enemy that they should hit back even harder.


Considering how important the Internet has become to the U.S. economy, do we really want to invite the Russians to attack it?


Talk about an event that could crash our economy almost overnight. This year alone “the Internet economy” will account for more than a trillion dollars. Without the Internet, vast numbers of businesses would not be able to function normally, and an extended outage would cause financial markets all over the planet to start crashing.


And many experts believe that it was the Russians that took down the Ukrainian power grid a while back. So do we really want to invite the Russians to attack our power grid?


Anyone out there that believes that our power grid is “secure” is dead wrong. We are exceedingly vulnerable, and the Russians know this.


Could you imagine the chaos that would happen if our power grid suddenly went down in the middle of the winter? An extended outage would potentially be life-threatening for millions of people that live in our coldest areas.


And what about our banks and financial systems? Do we really want to invite the Russians to shut those down?


It really is in our best interest to try to find a way to develop a better relationship with Russia. Unfortunately, we are about to elect a crazy woman as our next president that has a fierce vendetta against the Russians, and Russian politicians are very open about the fact that if Hillary Clinton is elected in November that the odds of World War 3 happening will go up dramatically.


You may wake up one day only to discover that a massive cyberattack has completely changed life in America overnight.


When that happens, you won’t be able to say that you weren’t warned in advance.


Print Friendly