TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

US city rejects $5.3M ransom demand and restores encrypted files from backup

467 pointsby GiulioSover 5 years ago

25 comments

rsyncover 5 years ago
ZFS snapshots are immutable (read-only) for normal users.<p>So, if you had your data stored on a cloud storage platform that created and maintained ZFS snapshots, Mallory could gain <i>all of the credentials</i> and still not be able to touch your daily&#x2F;weekly&#x2F;monthly snapshots.<p>Now, if only there were a cloud backup platform that included zfs snapshots ...
评论 #20893474 未加载
评论 #20894316 未加载
评论 #20893753 未加载
评论 #20895719 未加载
hartatorover 5 years ago
&gt; &quot;I decided to make a counter-offer using insurance proceeds in the amount of $400,000, which I determined to be consistent with ransoms recently paid by other municipalities,&quot;<p>They didn&#x27;t say no. It&#x27;s odd there is so little recourse against things like this.
评论 #20891112 未加载
评论 #20892963 未加载
评论 #20894336 未加载
评论 #20894541 未加载
wmfover 5 years ago
I don&#x27;t understand what I&#x27;m reading here. Why did they offer to pay $400K to recover ~100 PCs if they had backups? Was it so expensive to restore those PCs?<p>I guess the good news is that we can now sell backups as &quot;anti-ransomware&quot; cybersecurity.
评论 #20891191 未加载
评论 #20891575 未加载
评论 #20891157 未加载
评论 #20891888 未加载
评论 #20893359 未加载
评论 #20892394 未加载
quickthrower2over 5 years ago
Why not make it a crime to pay the ransom demand for cryptolocker attacks? This way the flow of money to these gangsters will stop.<p>If you get hit with a cryptolocker and you have no backup you simply lose that data. Or you can pay the ransom, get your data back and go to jail.<p>While this might seem unfair, it might stop 1000 other attacks because there will be no money in it. It would be for the greater good.
评论 #20891467 未加载
评论 #20891470 未加载
评论 #20891558 未加载
评论 #20891505 未加载
评论 #20892375 未加载
评论 #20891606 未加载
评论 #20891767 未加载
评论 #20891686 未加载
评论 #20892392 未加载
评论 #20891916 未加载
评论 #20891463 未加载
评论 #20891844 未加载
评论 #20892655 未加载
评论 #20893787 未加载
评论 #20892018 未加载
评论 #20891539 未加载
pilifover 5 years ago
Do I read this right? They offered to pay $400K even though they had backups to restore their data from? Does this mean that the restore operation cost more than 400K or was this an incredible sample of laziness?<p>They&#x27;d rather pay the ransom to a criminal than invest the time it takes to restore backups?
评论 #20893941 未加载
jumellesover 5 years ago
&quot;Restore from backup&quot; really ought to be the default response to ransomware. That will probably never happen though...
评论 #20891148 未加载
H8crilAover 5 years ago
See also Matt Levine&#x27;s take on ransoms (scroll down):<p><a href="https:&#x2F;&#x2F;www.bloomberg.com&#x2F;opinion&#x2F;articles&#x2F;2019-08-27&#x2F;the-libor-change-is-coming" rel="nofollow">https:&#x2F;&#x2F;www.bloomberg.com&#x2F;opinion&#x2F;articles&#x2F;2019-08-27&#x2F;the-li...</a><p>And the linked article:<p><a href="https:&#x2F;&#x2F;www.propublica.org&#x2F;article&#x2F;the-extortion-economy-how-insurance-companies-are-fueling-a-rise-in-ransomware-attacks" rel="nofollow">https:&#x2F;&#x2F;www.propublica.org&#x2F;article&#x2F;the-extortion-economy-how...</a><p>Tl;dr: perverse incentives, paying some ransoms is in the interest of cyber crime insurers, as it expands the cyber crime insurance market. Also there&#x27;s more ransomware crime now that the word is out that insurers do pay out ransoms.
Gustomaximusover 5 years ago
I wonder if a law that you can&#x27;t pay ransom money for files should be passed.<p>This should work to take any government and larger companies off the target of these groups as they are likely to obey these laws. Kinda like the we dont negotiate with terrorists approach.
评论 #20892964 未加载
评论 #20893081 未加载
avivdegover 5 years ago
NetApp has a solution for all of that: Cloud Volumes ONTAP is a virtualized storage platform running on AWS, Azure, and Google,it consumes native cloud resources and it provides NFS&#x2F;CIFS&#x2F;iSCSI.<p>Cloud Volumes ONTAP has the best snapshots out there, immutable and without any resource penalty. you can take any size snapshots (or restore) in seconds. you can also create clones out of these snapshots, so you can check if that data been affected or not, again in seconds. Adding to that Cloud Manager&#x27;s Ransomeware protection that blocks known Ransomware files.<p>In short- this is the best solution out there for any hybrid&#x2F; cloud and it can actually be cheaper than free, if you have enough capacity, due to all of its storage efficiencies like dedup, compressions and compaction, with auto-tiering of unused blocks to the checper object storage,.
iandinwoodieover 5 years ago
So they offered $400,000 for restoring what was most likely a week of lost work for 158 employees. That works out to $2,531.65 per employee for that week. Is the average salary of the compromised employee $131,645.57 ($2,531.65*52)? It sounds like the town was just willing to throw a lump of cash at the attacker based on what other victims had paid with no regard to what the lost work was actually worth. I know the attacker did not accept and it allowed them to strengthen their security and etc., but it bothers me that the attacker could have just gotten a $400,000 payout. It’s almost as if the moral of the story is “even if a town government had backup system in place, you can still pull in a few years of income with a ransomware attack!”
评论 #20894667 未加载
评论 #20896185 未加载
评论 #20894609 未加载
tastroderover 5 years ago
Could somebody contextualize how targeted this particular attack really was?<p>According to random Google result #1: <a href="https:&#x2F;&#x2F;www.2-spyware.com&#x2F;remove-ryuk-ransomware.html#qm-h2-4" rel="nofollow">https:&#x2F;&#x2F;www.2-spyware.com&#x2F;remove-ryuk-ransomware.html#qm-h2-...</a> the specific malware distribution is unclear but likely involves email attachments and&#x2F;or vulnerable and exposed RDP.<p>While reporting on ransomware cases often sounds like targeted APTs, more often than not the details in these stories read like &quot;we didn&#x27;t bother to pay enough admins to actually patch and secure our systems&quot; and &quot;we didn&#x27;t train our users not to click on every random attachment&quot;.
msmerberryover 5 years ago
It sounds like they played every card right, and that&#x27;s probably not by accident. I&#x27;d be fascinated to see a case study made out of this - especially with a breakdown of how they performed against their CSIRP - because there&#x27;s no way they didn&#x27;t tabletop that plan at some point, and it paid off in the end. Sort of like insurance, eh?
shameshameover 5 years ago
The city was extremely lucky the attackers played their hand too early. If servers had been encrypted it could have a lot worse.
peter_retiefover 5 years ago
Restore from backup isn&#x27;t as easy as it sounds, well done to a disaster recovery plan that actually works
olliejover 5 years ago
Honestly this success might encourage city governments to make sure their backup systems work better.<p>The counter offer of 400k was presumably the break even point for the cost of losing X days of work (depending on what was lost that could involve manually recovering things like tax payments, billing, tickets, etc)
auslanderover 5 years ago
Great read: <a href="https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;notpetya-cyberattack-ukraine-russia-code-crashed-the-world&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;notpetya-cyberattack-ukraine-rus...</a>
zellyover 5 years ago
The real solution is for them to hire out for their ops. No reason these rag tag city governments should store their stuff on-prem. Until then these okie dokie city bureaucrats will keep getting pwned.
评论 #20891845 未加载
评论 #20891893 未加载
评论 #20891880 未加载
CryptoPunkover 5 years ago
Cryptocurrency is hardening IT infrastructure.
ashelmireover 5 years ago
Paying hundreds of thousands to restore 158 backed up machines would be absurd. Surely a week of work for those 158 employees isn&#x27;t worth that. They&#x27;ve gotta put a financial analyst on these issues, and not leave it up to panicking executives.<p>And look at how greedy the attacker was. Missed out on a 400k payday.
评论 #20895039 未加载
hello_tylerover 5 years ago
Why is a backup system so hard for people (especially businesses) to understand????
评论 #20892132 未加载
aitchnyuover 5 years ago
&gt; Because the attack happened at night, most of the city&#x27;s systems were turned off and the ransomware was unable to spread.<p>I used to complain Indian banks used to allow fund transfers only during working days and office hours. Now I see why it was useful.
elchinover 5 years ago
Why isn&#x27;t it mandatory for government orgs to use cloud?
评论 #20895809 未加载
评论 #20905648 未加载
gesmanover 5 years ago
Key: backup<p>Do you ... backup?
mxuribeover 5 years ago
Kudos to the city of New Bedford!
auslanderover 5 years ago
No Windows no cry :) Seriously, how can one compromised machine (inevitable) infect all others? Isn&#x27;t there host firewalls on every machine?
评论 #20894402 未加载
评论 #20895343 未加载