Tuesday, April 3, 2018

Atlanta's Ransomware Situation

Image result for atlanta Atlanta officials are 'working around the clock' to resolve a recent ransomware attack

Federal officials, Microsoft and Cisco are working with the city of Atlanta to resolve the attack, but Atlanta's mayor won't say if the city paid the demand to release the municipality's online services that the attackers are keeping hostage:

  • Send .8 bitcoins for each computer or 6 bitcoins for all of the computers. (That's the equivalent of around $51,000.)
  • After the .8 bitcoin is sent, leave a comment on their website with the provided host name. They’ll then reply to the comment with a decryption software. When you run that, all of the encrypted files will be recovered.
Police officers are once again able to file reports electronically and some investigative databases thought to have been corrupted by the ransomware attack have turned out to be unscathed, the city says. The city's 311 system — which deals with things such as trash pickup and reporting of potholes — is also back in operation.
As a precaution, however, law enforcement is still not using some of its databases and the city's water department can't take any form of payment. Plus, the municipal court continues to push off its caseload, indefinitely.

Atlanta is just the latest target in a long list of victims whose vulnerable cybersecurity has fallen prey to online predators.    The FBI says ransomware attacks have been on the rise for the past three years, particularly against organizations that serve the public. That includes hospitals, school districts, state and local governments and even law enforcement.

Data compiled by BitSight, a cybersecurity ratings company, revealed a 2016 report analyzing government, health care, finance, retail, education and utilities, and concluded that education institutions are most likely to be on the receiving end of a ransomware attack. They are three times as likely to get hit as are the health care sector and more than 10 times as likely as financial institutions.

While there has not been reports of breaches in the information that was encrypted, it is very likely that some or all of this information was compromised. It is unknown what this information is at the moment.

There has yet to be a resolution to this instance but there are some potential resolution options. One option is paying the ransom and hoping that the files actually get decrypted. This is only a short term solution as the information was compromised and there is definitely a hole in the system that needs to be fixed. Another option is to decrypt the files but this will take a long time which would compromise availability even further.

Questions:

1. Are you surprised that ransomware attacks are on the rise? Why do you think that is the case?

2. Why are educational institutions most likely to be on the received end of a ransomware attack?

3. Are you aware of other ransomware attacks that occurred in your workplace or city, or other examples?  What happened?

1 comment:

  1. Personally, I would have never even thought of anyone trying to pull of an attack like ransomware. However, after reading more into all the attacks it is not incredibly surprising that they are become more and more prevalent. I think this has to do with increase in popularity of bitcoin and electronic money systems. When people are introduced to a new technology it is intriguing to see everything it can do. With this I am sure people out there want to learn how they can hack or manipulate it right away. I think educational institutions are on the receiving end of these attack due to the amount of information they hold on people and their financial data. I am not aware of any other attacks but there are probably many more going on that we do not know about.

    ReplyDelete