Showing posts sorted by relevance for query ransom*. Sort by date Show all posts
Showing posts sorted by relevance for query ransom*. Sort by date Show all posts

15 September 2020

Australian Cyber Security Centre says: don't pay the crooks to unlock files encrypted during a RansomWare attack!


Paying a ransom does not guarantee decryption of data. Open source reporting indicates several instances where an entity paid the ransom but the keys to decrypt the data were not provided. The ACSC has also seen cases where the ransom was paid, the decryption keys were provided, but the adversary came back a few months later and deployed ransomware again. The likelihood that an Australian organisations will be retargeted increases with every successful ransom payment.

It is generally much easier and safer to restore data from a backup than attempting to decrypt ransomware affected data.


23 August 2019

How to avoid ransomware attacks: 10 tips


Nigerian princes are no longer the only menaces lurking in an employee's inbox. For healthcare organizations, schools, government agencies and many businesses, ransomware attacks—an especially sinister type of malware delivered through spear phishing emails that locks up valuable data assets and demands a ransom to release them—are a rapidly-growing security threat.

"We're currently seeing a massive explosion in innovation in the types of ransomware and the ways it's getting into organizations," says Rick McElroy, security strategist for cyber security company Carbon Black Enterprise Response. "It's a big business, and the return on investment to attackers is there—it's going to get worse."

To prevent a ransomware attack, experts say IT and information security leaders should do the following:

  1. Keep clear inventories of all of your digital assets and their locations, so cyber criminals do not attack a system you are unaware of.
  2. Keep all software up to date, including operating systems and applications.
  3. Back up all information every day, including information on employee devices, so you can restore encrypted data if attacked.
  4. Back up all information to a secure, offsite location.
  5. Segment your network: Don't place all data on one file share accessed by everyone in the company.
  6. Train staff on cyber security practices, emphasizing not opening attachments or links from unknown sources.
  7. Develop a communication strategy to inform employees if a virus reaches the company network.
  8. Before an attack happens, work with your board to determine if your company will plan to pay a ransom or launch an investigation.
  9. Perform a threat analysis in communication with vendors to go over the cyber security throughout the lifecycle of a particular device or application.
  10. Instruct information security teams to perform penetration testing to find any vulnerabilities.

09 August 2018

PGA Championship servers hacked and files locked - crooks demand Bitcoin ransom!


Hackers have broken into servers belonging to PGA of America, which runs the PGA Championship golf tournament.

Files containing marketing materials for that competition as well as the Ryder Cup in France have been locked, pending payment of a ransom.

A Bitcoin address was provided, but the hackers did not specify a desired amount, according to sports magazine Golfweek.

A PGA spokesman told BBC News he had no comment as the incident was ongoing.

He did add, however, that the PGA Championship would not be affected.

This dear readers is why it's important to have offline backups
Contact Donline if you need assistance with this.


20 June 2017

South Korean hosting company pays $1m ransom to end eight-day outage


A South Korean web hosting company is forking out just over US$1 million to ransomware crooks after suffering more than eight days of nightmare.

Nayana first announced the attack on June 10, saying customer video files and its database had been encrypted, and promising to work to recover the data.

More than 150 servers were hit, hosting the sites of more than 3,400 mostly small business customers.

After a lengthy negotiation with the hackers, a demand for Bitcoin worth 5 billion won (nearly $4.4 million) was trimmed to around $1 million (397.6 Bitcoin), and the company paid up. The ransom was demanded in three instalments; so far, two have been made.

This dear readers is why you should backup your data!
Contact Donline if you need advice on protecting your data.


18 July 2025

Police dismantle DiskStation ransomware gang targeting NAS devices, arrest suspected ringleader


"Operation Elicius", a joint international law enforcement operation involving Europol and police forces in Italy, France, and Romania, has successfully dismantled a Romanian ransomware gang that targeted network-attached storage (NAS) devices and arrested its suspected leader.

The so-called "DiskStation Security" ransomware group has targeted and compromised NAS devices - particularly those manufactured by Synology - since 2021, leaving the data of businesses and non-profit organisations encrypted, and demanding a ransom for its recovery...

...Synology has been advising users on how to protect their NAS devices from ransomware attacks for several years.  Much of the advice revolves around minimising the exposure of NAS devices to the internet, hardening password security, and ensuring that regular backups are made of critical data.

The accounts used to secure NAS devices are no different from any other when it comes to security - you should ensure that passwords are unique, and not easy-to-crack.  Attackers will often use automated tools to brute force their way into poorly-secured devices, or take advantage of users who have used easy-to-guess, predictable passwords.

Donline supports dozens of business & home clients in specifying, building, deploying & ongoing management of Synology NAS devices. They are excellent, reliable, cost effective devices to manage your network & data. HOWEVER, as with all IT: internet connectivity, credentials, patching, etc - MUST be carefully managed. Got questions about IT? Contact Donline.

www.fortra.com


11 November 2019

Top five (six!) classic bikes to buy now before they increase in value


Here is a great article from Bennetts - BikeSocial with recommendations as to what to look for if you are in the market for a modern classic motorcycle. I'm glad to see that prices are much more reasonable than they were a couple of years ago - when a bag of bolts would cost a king's ransom! 

This is their shortlist - & I'd pretty much agree:
1996 Suzuki GSF1200 Bandit
2005 Suzuki GSX-R1000K5
1985 Yamaha V-Max
1993 Ducati M900 Monster
1994 BMW R 1100 GS

For my money - I'd add this to the list: 1983 Honda VF750 SC (Sabre). This was one of my fave big bikes in the day. Now a minter (like these: Bike1 or Bike2) is £2.5 to 3.5k. Doer-uppers start @ £600! They did have their issues (OK, major issues - camshafts!), but when sorted (& they invariably are - or they wouldn't be around 30+ years later) they are cracking bikes. Santa - please take note... ;0)


09 December 2018

Reading for today: Imitate the Shepherds


We must not cease to wonder at the great marvels of our God. It would be very difficult to draw a line between holy wonder and real worship; for when the soul is overwhelmed with the majesty of God's glory, though it may not express itself in song, or even utter its voice with bowed head in humble prayer, yet it silently adores.

Our incarnate God is to be worshipped as "the Wonderful." That God should consider his fallen creature, man, and instead of sweeping him away with the besom of destruction, should himself undertake to be man's Redeemer, and to pay his ransom price, is, indeed marvellous! But to each believer redemption is most marvellous as he views it in relation to himself. It is a miracle of grace indeed, that Jesus should forsake the thrones and royalties above, to suffer ignominiously below for you. 

Let your soul lose itself in wonder, for wonder is in this way a very practical emotion. Holy wonder will lead you to grateful worship and heartfelt thanksgiving. It will cause within you godly watchfulness; you will be afraid to sin against such a love as this. 

Feeling the presence of the mighty God in the gift of his dear Son, you will put off your shoes from off your feet, because the place whereon you stand is holy ground. You will be moved at the same time to glorious hope. If Jesus has done such marvellous things on your behalf, you will feel that heaven itself is not too great for your expectation. Who can be astonished at anything, when he has once been astonished at the manger and the cross? What is there wonderful left after one has seen the Saviour?

Dear reader, it may be that from the quietness and solitariness of your life, you are scarcely able to imitate the shepherds of Bethlehem, who told what they had seen and heard, but you can, at least, fill up the circle of the worshippers before the throne, by wondering at what God has done. 

Today's reading is taken from Charles Spurgeon's Morning and Evening devotional.

30 September 2021

In RansomWare news: crooks complain that crooks are acting like... crooks!

Security intelligence vendor Flashpoint claims to have found forum comments from customers of the REvil ransomware-as-a-service gang, and they’re not happy. The gang's malware may contain backdoors that REvil uses to restore encrypted files itself.

REvil's modus operandi is to rent its malware to other evildoers, in return for a hefty cut of any ransoms paid by victims.

Flashpoint writes that the "Exploit" forum has recently featured posts from a threat actor complaining about the backdoor, and the fact its presence meant that REvil could let its customers do all the hard work of arranging an infection, then subvert communications with victims and keep the entire ransom for itself.

Other chat in the forum, Flashpoint asserts, includes complaints about REvil's behaviour, and the futility of attempting to negotiate with the gang.

www.theregister.com


12 January 2022

Hotel chain switches from Windows and Mac to Chrome OS to recover from ransomware attack

A Scandinavian hotel chain that fell victim to a ransomware attack last month said it took a novel approach to recover from the incident by switching all affected systems to Chrome OS.

Nordic Choice Hotels, which operates 200 hotels across Northern Europe, fell victim to a ransomware attack on December 2, when hackers encrypted some of its internal systems using the Conti ransomware strain.

The attack prevented staff from accessing guest reservation data and from issuing key cards to newly arriving guests, as one of the hotel’s guests told The Record in an interview last month.

But in a press release, Nordic Choice said that instead of contacting the hackers and negotiating a ransom for the decryption key that would have unlocked the infected devices, the hotel chose to migrate its entire PC fleet from Windows to Chrome OS.

Nordic Choice said they used a tool called CloudReady, which can prepare and port old Windows and macOS computers to Chrome OS setups.

www.therecord.media


11 April 2023

Western Digital confirms breach, affects My Cloud and SanDisk users

Western Digital, a big brand in digital storage, says it has suffered a "network security incident" - potentially ransomware - which resulted in a breach and some system disruptions in its business operations.

The company identified the incident on March 26 and said an unnamed third party unlawfully accessed several computer systems to steal data. The investigation is ongoing and Western Digital has yet to learn how much was taken. 

Since the incident, Western Digital's consumer cloud and backup service My Cloud has experienced outages, preventing customers from accessing their files. My Cloud Home, My Cloud Home Duo, My Cloud OS5, SanDisk ibi, and SanDisk Ixpand Wireless Charger all experienced service interruptions. 

UPDATE from techcrunch 14 April 2023: The hackers who breached data storage giant Western Digital claim to have stolen around 10 terabytes of data from the company, including reams of customer information. The extortionists are pushing the company to negotiate a ransom - of a “minimum 8 figures” - in exchange for not publishing the stolen data. READ MORE...

www.malwarebytes.com


03 September 2021

UK VoIP providers under attack from Ruskie cyber crooks


Two UK VoIP operators have had their services disrupted over the last couple of days by ongoing, aggressive distributed denial-of-service (DDoS) attacks.

South Coast-based Voip Unlimited has confirmed it has been slapped with a "colossal ransom demand" after being hit by a sustained and large-scale DDoS attack it believes originated from the Russian cybercriminal gang REvil. This morning, it confirmed that "services are operational ... however the attacks are still ongoing."

Separately, London-based Voipfone (see status page here) said it is still suffering outages on voice, inbound and outbound calls, and SMS services. It told customers on Tuesday in a status update that it had been hit by "a further DDoS attack" after the initial attack, revealed to customers via email as having taken place over the Monday bank holiday.

At this stage it's not clear if any other UK Internet Telephony Service Providers (ITSP) have been affected. However, UK Comms Council – the industry body that represents ITSPs – has informed members of the industry group about the attacks and issued a reminder to adopt "appropriate DDoS mitigation strategies."

www.theregister.com


17 December 2018

Received an email claming that your PC has been hacked & they have your passwords? It's probably a scam...


Here’s a clever new twist on an old email scam that could serve to make the con far more believable. The message purports to have been sent from a hacker who’s compromised your computer and used your webcam to record a video of you while you were watching porn. The missive threatens to release the video to all your contacts unless you pay a Bitcoin ransom. The new twist? The email now references a real password previously tied to the recipient’s email address.

The basic elements of this sextortion scam email have been around for some time, and usually the only thing that changes with this particular message is the Bitcoin address that frightened targets can use to pay the amount demanded. 

But how did they get your password? Chances are, from an already compromised site & not from a direct hack on your PC. Check if your credentials are available online HERE. As always: DO NOT REUSE PASSWORDS!!! 

If you have received one of these emails & are worried / unsure what to do next - contact Donline.


26 January 2022

DeadBolt ransomware targets QNAP NAS (Network Attached Storage) devices

A new DeadBolt ransomware group is encrypting QNAP NAS (Network Attached Storage) devices worldwide using what they claim is a zero-day vulnerability in the device's software.

The attacks started today, January 25th, with QNAP devices suddenly finding their files encrypted and file names appended with a .deadbolt file extension.

Instead of creating ransom notes in each folder on the device, the QNAP device's login page is hijacked to display a screen stating, "WARNING: Your files have been locked by DeadBolt"

What should any computer user (including NAS) do to protect themselves & their irreplaceable data from crooks? Two little words: UPDATES & BACKUP!

www.bleepingcomputer.com


11 March 2020

Backup and protect your important data with a Synology NAS


Malicious software that uses encryption to hold your data for ransom has been on the rise over the last few years. Not only is it making its way into high profile businesses, but it’s also managed to weave its way into schools and hospitals. Synology provides many award-winning tools to help you combat ransomware. 

Solutions
Synology offers a range of tools to help you combat against ransomware and ensure your data is backed up securely: Take a closer look at Synology Active Backup suite, and see where it fits in Synology's Backup and Disaster Recovery app offering.
Active Backup
Centralises backup tasks for: Windows endpoints, Office 365 and G Suite to Synology NAS – and lets you manage from one simple console. Fast and reliable recovery delivered to keep running services and files instantly available.
Hyper Backup
Lets you enjoy a full range of multi-version backup destinations from local shared folders, expansion units, and external hard drives, to network shared folders, rsync server, and public cloud services.
Contact Donline to find out how Synology Network Attached Storage can be a great tool to help protect your critical data - on premise, device & in the cloud.

22 December 2020

Microsoft and McAfee headline newly-formed 'Ransomware Task Force'

A group made up of 19 security firms, tech companies, and non-profits, headlined by big names such as Microsoft and McAfee, have announced on Monday plans to form a new coalition to deal with the rising threat of ransomware.

Named the Ransomware Task Force (RTF), the new group will focus on assessing existing technical solutions that provide protections during a ransomware attack.

The RTF will commission expert papers on the topic, engage stakeholders across industries, identify gaps in current solutions, and then work on a common roadmap to have issues addressed among all members.

The end result should be a standardized framework for dealing with ransomware attacks across verticals, one based on an industry consensus rather than individual advice received from lone contractors.

In other news: The US Federal Bureau of Investigations says it is aware of incidents where the DoppelPaymer ransomware gang has resorted to cold-calling companies in order to intimidate and coerce victims into paying ransom demands.

www.zdnet.com