White House Issues Open Letter on Ransomware

White House Issues Open Letter on Ransomware

The White House has sent an open letter to companies in the United States entreating them to urgently act against the threat of ransomware.

Corporate executives and business leaders received a memo on Thursday morning from Anne Neuberger, the National Security Council’s top cyber official. In the missive, Neuberger underscored the sweeping danger of ransomware to the private sector.

“All organizations must recognize that no company is safe from being targeted by ransomware, regardless of size or location,” wrote Neuberger. “We urge you to take ransomware crime seriously and ensure your corporate cyber defense match the threat.”

Neuberger, who is deputy national security adviser for cyber and emerging technology, called for swift action from corporations and businesses, which she stated have “a distinct and key responsibility” when it comes to America’s cybersecurity.

“All organizations must recognize that no company is safe from being targeted by ransomware, regardless of size or location,” wrote Neuberger in the letter dated Wednesday. “But there are immediate steps you can take to protect yourself, as well as your customers and the broader economy.” 

She added that the impact of ransomware upon a company was directly linked to that company’s attitude toward the threat.

“The most important takeaway from the recent spate of ransomware attacks on U.S., Irish, German and other organizations around the world is that companies that view ransomware as a threat to their core business operations rather than a simple risk of data theft will react and recover more effectively,” wrote Neuberger.

The letter follows a recent string of ransomware attacks on American companies. Last month’s cyber-assault on the Colonial Pipeline was followed by attacks on global meat supplier JBS and on ferry service the Steamship Authority of Massachusetts.

A threat group known as both REvil and Sodinokibi, believed to have ties with Russia, has been blamed for the cyber-attacks on the Colonial Pipeline and JBS.

“More than any other threat, non-technical executives are familiar with ransomware by name and are already looking for solutions,” commented John Bambenek, threat intelligence advisor at Netenrich. “A letter from a White House official isn’t going to change the game in the slightest.” 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Fujifilm Shuts Down Servers to Investigate Possible Ransomware Attack

Fujifilm Shuts Down Servers to Investigate Possible Ransomware Attack

Fujifilm is investigating a potential ransomware attack that resulted in the company closing down part of its network.

The company is investigating “possible unauthorized access” to its server, it said in a statement. 

The company first noticed the “possibility” of a ransomware attack on June 1 and took swift action to discontinue all compromised systems. 

“We are currently working to determine the extent and the scale of the issue,” it said on its website, and that it “apologises to its customers and business partners for the inconvenience this has caused.

“For some entities, this affects all forms of communications, including emails and incoming calls, which come through the company’s network systems,” said the company.

In an earlier statement, Fujifilm confirmed that the cyber-attack is preventing the company from accepting and processing orders. 

Japanese organizations have experienced other notable breaches in recent months. In March, Yamabiko, a Tokyo-headquartered manufacturer of power tools and agricultural and industrial machinery, was apparently added to the data leak site used by the Babuk group. 

In May, a subsidiary of Japanese tech giant Toshiba admitted to suffering a cybersecurity breach, reportedly caused by the DarkSide ransomware gang.

Ransomware hackers have gone after larger targets in 2021. This month saw a ransomware attack on the world’s largest meat processing company and May saw a sophisticated ransomware attack on Bose, which resulted in the unauthorized access of personal information on current and former employees.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Mandiant to Re-Emerge After $1.2 Billion FireEye Sale

Mandiant to Re-Emerge After $1.2 Billion FireEye Sale

FireEye has agreed to sell its FireEye Products business and brand name to a private equity firm in a deal that will see the Mandiant business it bought several years ago become a standalone company again.

The $1.2 billion all-cash sale to a consortium led by Symphony Technology Group (STG) is expected to close by the end of Q4 2021.

It will see STG acquire FireEye’s network, email, endpoint and cloud security products — alongside its related security management and orchestration platform.

After its acquisition by FireEye in 2014, Mandiant and founder Kevin Mandia were instrumental in expanding the new company’s focus from web, email and data center security to threat intelligence and incident response services.

Over the intervening years, the company has been busy dealing with the aftermath of countless breaches at big-name firms and government organizations.

FireEye’s work investigating an audacious attack on its own systems uncovered the infamous SolarWinds attacks, which subsequently found that at least nine US government agencies were compromised.

FireEye CEO, Kevin Mandia, argued that the separation of the two businesses again would enable the high-growth Mandiant to thrive.

“After closing, we will be able to concentrate exclusively on scaling our intelligence and frontline expertise through the Mandiant Advantage platform, while the FireEye Products business will be able to prioritize investment on its cloud-first security product portfolio,” he added.

“STG’s focus on fueling innovative market leaders in software and cybersecurity makes them an ideal partner for FireEye Products. We look forward to our relationship and collaboration on threat intelligence and expertise.”

William Chisholm, managing partner at STG, argued that FireEye’s cloud-first XDR platform would play a mission-critical role for current and prospective customers.

“We believe that there is enormous untapped opportunity for the business that we are excited to crystallize by leveraging our significant security software sector experience and our market leading carve-out expertise,” he said.

The private equity firm in March agreed to buy McAfee’s enterprise business for $4 billion.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Secureworks Appoints Wendy Thomas as CEO as Michael Cote Announces Retirement

Secureworks Appoints Wendy Thomas as CEO as Michael Cote Announces Retirement

Cybersecurity firm Secureworks has announced the appointment of Wendy Thomas as its next president and CEO. Thomas will take up the reigns from current CEO Michael Cote from September 3, 2021, when he will retire following nearly 20 years at the company.

Thomas, who is currently president of customer success at Secureworks, has more than 25 years’ experience in strategic and functional leadership roles across multiple organizations, including FirstData, Bell South and Internap Network Services.

During her career at Secureworks, which began in 2008 in its finance team, she has worked alongside Cote to successfully conclude a number of high profile business transactions, such as the acquisition of Verisign’s Managed Security Services (MSS) business and DNS and the company’s acquisition by Dell Technologies back in 2011. Prior to becoming president of customer success at Secureworks, she was its chief product officer, where she led the development of numerous solutions, such as its first security analytics product, Secureworks TaegisTM XDR.

Commenting on her appointment, Thomas said: “I know that I speak for everyone at Secureworks in thanking Mike for his leadership and tireless dedication to the company. I appreciate the support of Mike and the Board, and I am proud to work with an exceptional team that is focused on taking decisive actions to transform cybersecurity.”

Cote will leave the organization after almost 20 years, having joined in February 2002 as chairman, president and CEO. Since that time, Secureworks has grown from generating less than $1m in annual revenue to in excess of $550m, with a global presence in over 60 countries.

Cote stated: “Wendy is a proven and respected leader who has been the driving force of our company’s transformation. Her deep knowledge of our business has made her a valued strategic partner for many years, and throughout her tenure she has delivered strong operating results and innovative solutions through a relentless commitment to our customers, our purpose, and our people. I am confident she will lead Secureworks well into the future and I am proud to have her succeed me. I know she will make an outstanding CEO.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Ransomware Disrupts Largest Ferry Service in Massachusetts

Ransomware Disrupts Largest Ferry Service in Massachusetts

Ransomware actors have disrupted the largest ferry service operating out of Massachusetts, disrupting passengers and commercial traffic.

The Steamship Authority, which runs to Martha’s Vineyard and Nantucket, revealed on Twitter that the attack struck early on Wednesday morning, local time.

The outage meant that customers were unable to book or change vehicle reservations online or by phone. However, existing bookings would be honored, and rescheduling or cancellation fees waived, it said.

“There is no impact to the safety of vessel operations, as the issue does not affect radar or GPS functionality. Scheduled trips to both islands continue to operate, although customers may experience some delays during the ticketing process,” the firm said.

“If traveling with the Authority today, cash is preferred for all transactions. The availability of credit card systems to process vehicle and passenger tickets, as well as parking lot fees, is limited.”

In an update late last night, the Steamship Authority said it expected the disruption to continue throughout Thursday June 3. The firm’s website was also down at the time of writing.

“The Steamship Authority continues to work with our team internally, as well as with local, state, and federal officials externally, to address today’s ransomware incident. At this point, we are unable to release or confirm specific details of what occurred,” it said.

Although the target for this attack is relatively minor compared to the recent incidents at Colonial Pipeline and JBS, it proves that no organization is safe from ransomware.

Charles Herring, CTO of WitFoo, argued that poor cyber-hygiene and a lack of coordination between law enforcement and private organizations had enabled cyber-criminals to get ahead in this particular arms race.

“The outer layer of the broken system is that national security and intelligence agencies need access to data collected by law enforcement to inform military and diplomatic strategy and campaigns,” he added.

“We are quickly learning that safely sharing information, while protecting liberties and privacy, is as important to thwarting evolving cybercrime as it was in combating terrorism after 9/11.”

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

Three-Quarters of Security Leaders Report Increase in Cyber-Attacks in Past Year

Three-Quarters of Security Leaders Report Increase in Cyber-Attacks in Past Year

More than three-quarters (76%) of security leaders have reported an increase in cyber-attacks over the past 12 months, according to VMware’s Global Security Insights Report 2021.

The report also found that the volume of attempts rose by a significant 52% across all affected organizations, emphasizing how accelerated digitization during the COVID-19 pandemic has expanded the attack surface. Indeed, over three-quarters (78%) of those experiencing a cyber-attack pointed to the rise in remote working as the reason for the increase in volume.

Additionally, four out of five (81%) of the 3542 CIOs, CTOs and CISOs surveyed for the research revealed they had suffered a breach in the past 12 months, with 82% of incidents considered material. Despite this, it appears there may be some complacency on the part of many security leaders: only 56% said they fear a material breach in the coming year, while just 41% have updated their security policies and approaches to tackle the extra risks to their organization.

The vast majority (79%) of security leaders noted that attacks have become more sophisticated in the past year, and the leading causes of breaches were reported to be third-party apps (14%) and ransomware (14%). Applications and workloads were seen as the most vulnerable points on the data journey, and 63% of respondents said there is a need for greater visibility over data and apps to pre-emptively detect attacks.

Encouragingly, close to two-thirds (61%) of security leaders agreed they need to adapt their security in light of the expanded attack surface. Securing the cloud looks to be a particular priority, with almost all (98%) respondents either already use, or are planning to shift to, a cloud-first security strategy.

Commenting on the findings, Rick McElroy, principal cybersecurity strategist, VMware said: “The race to adopt cloud technology since the start of the pandemic has created a once-in-a-generation chance for business leaders to rethink their approach to cybersecurity.

“Legacy security systems are no longer sufficient. Organizations need protection that extends beyond endpoints to workloads to better secure data and applications. As attacker sophistication and security threats become more prevalent, we must empower defenders to detect and stop attacks, as well as implement security stacks built for a cloud-first world.”  

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

FBI: REvil Ransomware Group Behind JBS Attack

FBI: REvil Ransomware Group Behind JBS Attack

The FBI has attributed a major ransomware attack on the world’s largest meat processing company to a notorious group believed to be Russian in origin.

In a brief statement, the Feds blamed REvil (aka Sodinokibi) for the attack on Sao Paolo-headquartered JBS.

“We continue to focus our efforts on imposing risk and consequences and holding the responsible cyber actors accountable. Our private sector partnerships are essential to responding quickly when a cyber intrusion occurs and providing support to victims affected by our cyber-adversaries,” read the statement.

“A cyber-attack on one is an attack on us all. We encourage any entity that is the victim of a cyberattack to immediately notify the FBI through one of our 56 field offices.”

The FBI said it would be working to bring the REvil group to justice for the hack on JBS.

REvil is one of the most prolific and successful groups around today, having targeted organizations as diverse as Apple, Jack Daniels, Travelex and even a law firm linked to Donald Trump.

The ransomware variant was responsible for over 14% of attacks in Q1 2021, remaining at the top of the global list, according to Coveware.

However, it operates as most do today via an affiliate model, so it’s unclear who actually used the malware to attack JBS.

There’s still no word from the meat processing giant on any of its public-facing websites about the attack.

Although, as Infosecurity reported on Tuesday, it appears to have impacted the firm’s servers supporting its North American and Australian operations, which could have significant knock-on effects for the meat supply chain in those regions.

Ronnen Brunner, VP of EMEA at ExtraHop, argued that food supplies could be considered critical national infrastructure.

“Businesses can’t be protected all the time, but these attacks succeed due to outdated systems and because many organizations still rely on perimeter defence and signature detection tools. This means once the attacker is inside the network, that organization is completely vulnerable,” he added.

“Businesses must learn from the downfall of others. Visibility is crucial for detecting ransomware quick enough to respond before it’s too late.”  

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk