15 September 2020
Australian Cyber Security Centre says: don't pay the crooks to unlock files encrypted during a RansomWare attack!
23 August 2019
How to avoid ransomware attacks: 10 tips
- Keep clear inventories of all of your digital assets and their locations, so cyber criminals do not attack a system you are unaware of.
- Keep all software up to date, including operating systems and applications.
- Back up all information every day, including information on employee devices, so you can restore encrypted data if attacked.
- Back up all information to a secure, offsite location.
- Segment your network: Don't place all data on one file share accessed by everyone in the company.
- Train staff on cyber security practices, emphasizing not opening attachments or links from unknown sources.
- Develop a communication strategy to inform employees if a virus reaches the company network.
- Before an attack happens, work with your board to determine if your company will plan to pay a ransom or launch an investigation.
- Perform a threat analysis in communication with vendors to go over the cyber security throughout the lifecycle of a particular device or application.
- Instruct information security teams to perform penetration testing to find any vulnerabilities.
09 August 2018
PGA Championship servers hacked and files locked - crooks demand Bitcoin ransom!
20 June 2017
South Korean hosting company pays $1m ransom to end eight-day outage
18 July 2025
Police dismantle DiskStation ransomware gang targeting NAS devices, arrest suspected ringleader
"Operation Elicius", a joint international law enforcement operation involving Europol and police forces in Italy, France, and Romania, has successfully dismantled a Romanian ransomware gang that targeted network-attached storage (NAS) devices and arrested its suspected leader.
The so-called "DiskStation Security" ransomware group has targeted and compromised NAS devices - particularly those manufactured by Synology - since 2021, leaving the data of businesses and non-profit organisations encrypted, and demanding a ransom for its recovery...
...Synology has been advising users on how to protect their NAS devices from ransomware attacks for several years. Much of the advice revolves around minimising the exposure of NAS devices to the internet, hardening password security, and ensuring that regular backups are made of critical data.
The accounts used to secure NAS devices are no different from any other when it comes to security - you should ensure that passwords are unique, and not easy-to-crack. Attackers will often use automated tools to brute force their way into poorly-secured devices, or take advantage of users who have used easy-to-guess, predictable passwords.
Donline supports dozens of business & home clients in specifying, building, deploying & ongoing management of Synology NAS devices. They are excellent, reliable, cost effective devices to manage your network & data. HOWEVER, as with all IT: internet connectivity, credentials, patching, etc - MUST be carefully managed. Got questions about IT? Contact Donline.
11 November 2019
Top five (six!) classic bikes to buy now before they increase in value
09 December 2018
Reading for today: Imitate the Shepherds
30 September 2021
In RansomWare news: crooks complain that crooks are acting like... crooks!
Security intelligence vendor Flashpoint claims to have found forum comments from customers of the REvil ransomware-as-a-service gang, and they’re not happy. The gang's malware may contain backdoors that REvil uses to restore encrypted files itself.
REvil's modus operandi is to rent its malware to other evildoers, in return for a hefty cut of any ransoms paid by victims.
Flashpoint writes that the "Exploit" forum has recently featured posts from a threat actor complaining about the backdoor, and the fact its presence meant that REvil could let its customers do all the hard work of arranging an infection, then subvert communications with victims and keep the entire ransom for itself.
Other chat in the forum, Flashpoint asserts, includes complaints about REvil's behaviour, and the futility of attempting to negotiate with the gang.
12 January 2022
Hotel chain switches from Windows and Mac to Chrome OS to recover from ransomware attack
A Scandinavian hotel chain that fell victim to a ransomware attack last month said it took a novel approach to recover from the incident by switching all affected systems to Chrome OS.
Nordic Choice Hotels, which operates 200 hotels across Northern Europe, fell victim to a ransomware attack on December 2, when hackers encrypted some of its internal systems using the Conti ransomware strain.
The attack prevented staff from accessing guest reservation data and from issuing key cards to newly arriving guests, as one of the hotel’s guests told The Record in an interview last month.
But in a press release, Nordic Choice said that instead of contacting the hackers and negotiating a ransom for the decryption key that would have unlocked the infected devices, the hotel chose to migrate its entire PC fleet from Windows to Chrome OS.
Nordic Choice said they used a tool called CloudReady, which can prepare and port old Windows and macOS computers to Chrome OS setups.
11 April 2023
Western Digital confirms breach, affects My Cloud and SanDisk users
Western Digital, a big brand in digital storage, says it has suffered a "network security incident" - potentially ransomware - which resulted in a breach and some system disruptions in its business operations.
The company identified the incident on March 26 and said an unnamed third party unlawfully accessed several computer systems to steal data. The investigation is ongoing and Western Digital has yet to learn how much was taken.
Since the incident, Western Digital's consumer cloud and backup service My Cloud has experienced outages, preventing customers from accessing their files. My Cloud Home, My Cloud Home Duo, My Cloud OS5, SanDisk ibi, and SanDisk Ixpand Wireless Charger all experienced service interruptions.
UPDATE from techcrunch 14 April 2023: The hackers who breached data storage giant Western Digital claim to have stolen around 10 terabytes of data from the company, including reams of customer information. The extortionists are pushing the company to negotiate a ransom - of a “minimum 8 figures” - in exchange for not publishing the stolen data. READ MORE...
03 September 2021
UK VoIP providers under attack from Ruskie cyber crooks
South Coast-based Voip Unlimited has confirmed it has been slapped with a "colossal ransom demand" after being hit by a sustained and large-scale DDoS attack it believes originated from the Russian cybercriminal gang REvil. This morning, it confirmed that "services are operational ... however the attacks are still ongoing."
Separately, London-based Voipfone (see status page here) said it is still suffering outages on voice, inbound and outbound calls, and SMS services. It told customers on Tuesday in a status update that it had been hit by "a further DDoS attack" after the initial attack, revealed to customers via email as having taken place over the Monday bank holiday.
At this stage it's not clear if any other UK Internet Telephony Service Providers (ITSP) have been affected. However, UK Comms Council – the industry body that represents ITSPs – has informed members of the industry group about the attacks and issued a reminder to adopt "appropriate DDoS mitigation strategies."
17 December 2018
Received an email claming that your PC has been hacked & they have your passwords? It's probably a scam...
26 January 2022
DeadBolt ransomware targets QNAP NAS (Network Attached Storage) devices
A new DeadBolt ransomware group is encrypting QNAP NAS (Network Attached Storage) devices worldwide using what they claim is a zero-day vulnerability in the device's software.
The attacks started today, January 25th, with QNAP devices suddenly finding their files encrypted and file names appended with a .deadbolt file extension.
Instead of creating ransom notes in each folder on the device, the QNAP device's login page is hijacked to display a screen stating, "WARNING: Your files have been locked by DeadBolt"
11 March 2020
Backup and protect your important data with a Synology NAS
22 December 2020
Microsoft and McAfee headline newly-formed 'Ransomware Task Force'
A group made up of 19 security firms, tech companies, and non-profits, headlined by big names such as Microsoft and McAfee, have announced on Monday plans to form a new coalition to deal with the rising threat of ransomware.
Named the Ransomware Task Force (RTF), the new group will focus on assessing existing technical solutions that provide protections during a ransomware attack.
The RTF will commission expert papers on the topic, engage stakeholders across industries, identify gaps in current solutions, and then work on a common roadmap to have issues addressed among all members.
The end result should be a standardized framework for dealing with ransomware attacks across verticals, one based on an industry consensus rather than individual advice received from lone contractors.
In other news: The US Federal Bureau of Investigations says it is aware of incidents where the DoppelPaymer ransomware gang has resorted to cold-calling companies in order to intimidate and coerce victims into paying ransom demands.









