The Trillion dollar industry
At the time of writing, the Waikato DHB cyber-attack is ongoing. The government is refusing to pay the ransom as a point of principle, and it looks like every possible tool at their disposal is being used to try to recover the situation.
Should they just pay the ransom? Or should the government go further and make it illegal to pay ransoms in New Zealand? That’s the question that Minister Kris Faafoi is having to assess at the moment. DHB attack: Why Justice Minister Kris Faafoi won’t make it illegal to pay a cyber-ransom – NZ Herald
Cyber crime is big business. We’ve called it organised crime in previous articles and we’re happy to stick with that. These organisations recruit the best and brightest out of the top universities, and give them both the latest tools and time to wreak havoc. Their recruits are paid astronomical sums to work for them, overcoming any moral objections with immorally large pay checks. These paychecks are funded by the proceeds of previous hacks. Every time they are paid, their war chest is strengthened. For example, we recently saw the Colonial Pipeline in the eastern US get hacked for 75 bitcoins (just under US$4M) which went to a criminal group called ‘Darkside”.
So, will cutting off payments stop their attacks by removing the incentive?
These criminals are smart and highly motivated. They seem to have no conscience but plenty of greed. Waikato is not only the hospital being brought down – there was a huge wave of hospital attacks in the US in October, just a few months ago – Several hospitals targeted in new wave of ransomware attacks – CNNPolitics.
I don’t know how Waikato DHB got infected, but the rumour is that it was from phishing attacks onto machines that weren’t fully patched up to date. We don’t know if that is true, but it is a common attack vector. Once a hacker gets into a system, they often hold back and try to dig further looking for more vulnerabilities they can exploit. The more damage they can cause, the more ransom they can demand, so they will often use one vulnerability to find the next, and so on until they finally have enough to bring the house down.
Security is all about layers. There is NO way to prevent attacks, and it is impossible to guarantee that any system is invulnerable. We saw that with the recent Hafnium attack where a vulnerability was exploited before patches were available to block it. But the more layers of security, the harder you make it, and you reduce the scope of any harm.
Today, even if you have the best backups and can recover the system, the hackers then threaten to release the data you hold to media or competitors. In the case of the Waikato DHB, it is being reported that personal data is being released to media by the hackers to increase pressure, even as they fail to stand their systems up.
As to paying the ransom, I suspect your perspective changes when your business, your job or livelihood is threatened. Not an easy decision and hopefully one we can avoid by being paranoid.
The best solution we can recommend is to check your cyber insurance and to apply the best security you can reasonably afford, which should be more than you had last year. Expect it to be more again next year as new tools and new threats emerge. Consider managed security solutions like our KARE Plans.
We don’t know where this will end, or if it will end, but let’s hope so. It is such a drain on our resources and holds us back from investing in tools that make us more productive.
Security Training and Awareness offer
We are deploying some new tools for our KARE for Security clients. For a limited time we can share these with all our clients to give you and your colleagues some great e-security awareness training. The holiday season is targeted by scammers, they know that employees...
Zero-Trust Networking for real business?
Zero-trust sounds extreme Humans like to trust. We trust everyday as we drive down the street that the people coming the other way will stay in their lane. We trust that the restaurants we visit prepare our food properly and hygienically. We trust that our doctor...
Fact or Fiction? My files are in the cloud, I don’t need to worry about security any more!
If only life were so simple! We have some clients that ask us about file security in the cloud as if the answer is an absolute. Of course it isn't. The cloud is more secure than an on-premise system Assuming we’re talking about a reputable mainstream cloud, the...
Are your back ups keeping up?
Why do we need offsite, air-gapped backups? About ten years ago the age of the tape ended. USB 3 was the nail in the coffin for tapes. Finally we had something that was just as fast, but supported random access. At about the same time, we moved from data backups, to...
Deepscan Antivirus and AntiMalware
We've warned before about vulnerabilities like Spectre and Meltdown. The basic precautions are to keep your Windows, Office and other software completely up to date, and of course keeping your anti-virus current. That’s going to stop most things but lately we’ve seen...
One charging cable to rule them all?
How many old phone chargers do you have tucked away at the back of cupboards? It is such a waste of resources to have all those plastic and metal boxes that you don’t want to throw way, but can’t be sure you will ever use again. Just to make things slightly worse,...
Helping you with Cyber Insurance Audit Forms
Cyber Security Audits are increasingly common. One cause is that we're seeing more boards ask about cyber security posture, and frankly every board needs to be asking about that. The other major prompt we see is when our clients are applying for cyber security...
The 5 questions you will asking about Windows 11
1. What is it? We’ve mentioned before that Microsoft had stated that Windows 10 would be the last version of Windows and it would simply keep being updated. That’s played out well over the last many years, but now we do have a new version – Windows 11. New Windows 11...
Don’t be in the 67,500
It might be our nearest neighbour, rather than us, but its still a good indicator of the trends that we're also seeing in New Zealand. We have to remember that much cyber-crime is still not reported. Whether it's out of embarrassment or commercial sensitivity, we...
Print NIGHTMARE
If you suddenly can't print at work, it might NOT be you! It could be the "PrintNightmare" problem For months Microsoft has been battling to release a reliable update for a problem called “PrintNightmare” that’s been happening since Microsoft released an...








