Manufacturing Giant Suffers Major Cyber-Disruption

Manufacturing Giant Suffers Major Cyber-Disruption

A leading global manufacturer of cranes has been hit by what appears to be a ransomware attack disrupting IT operations around the world.

Headquartered in Austria, Palfinger Group is renowned for producing hydraulic lifting and loading systems and runs scores of companies in over 30 countries.

The firm issued a brief statement on Monday revealing it is the target of an ongoing global cyber-attack.

“IT infrastructure is disrupted at the moment (including sending and receiving emails, ERP systems). A large proportion of the group’s worldwide locations are affected,” it continued.

“It is not possible to estimate the precise extent and duration of the attack or its consequences at this time. Work is being carried out intensively on a solution.”

Although no specifics were mentioned about the type of attack, it would seem to fit the MO of ransomware, given the disruption being caused to the firm’s email and ERP systems.

The group’s €1.1bn revenue haul for the first three months of 2020 would certainly be enough to pique the interest of online extortionists, who are increasingly going after “big game” like Palfinger in a bid to extract larger ransom payments.

“In the manufacturing business, time is money, so the disruption of Palfinger’s IT services as well as order processing and shipment delays, translates to lost revenue. The single biggest threat to enterprises today is underestimating and failing to address cybersecurity across all of a company’s cyber and physical systems,” argued Andrea Carcano, co-founder of Nozomi Networks.

“Attackers are going after higher value targets and that includes operational networks. The remediation costs and efforts to repair the operational, financial and reputational damage caused by these attacks put a significant strain on leadership teams.”
 

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

UK Spies Called on to Help in Fraud Fight

UK Spies Called on to Help in Fraud Fight

Fraud has become a serious threat to the UK’s national security, according to a think tank report calling for a major new government-led approach to tackle the issue.

The report from the highly respected Royal United Services Institute (RUSI) argued that, while fraud has received more airtime from media and lawmakers lately, there needs to be a “major systemic shift” in government strategy.

That’s because fraud is increasingly a threat to social and economic stability, and fuels both serious organized crime and terrorism, the report claimed.

Given that two of the UK’s National Security Objectives are to “protect our people” and “promote our prosperity,” the lack of consideration given to fraud as a national security threat is “increasingly perverse,” RUSI continued.

A 2020 report claimed that a fifth of British consumers had suffered financial fraud over the previous 12 months, with a similar number accepting it as the cost of participating in the digital economy. Meanwhile, RUSI cited figures from 2017 claiming that total fraud in the UK may have reached as high as £190bn or 10% of GDP at the time.

RUSI’s 13 recommendations called for a new “whole of system” public–private strategy for tackling fraud, led by the National Security Council and featuring a clearer role for private sector firms, as well as more resources and capabilities to be built-up in the police force.

It also called for a more explicit mandate for GCHQ and long-term resources to fund the National Cyber Security Center Suspicious Email Service. The National Crime Agency and intelligence services should be enlisted to better understand fraud as organized crime, police need to re-prioritize and public-private data sharing around fraud and serious organized crime must improve, it added.

RUSI also urged the government to look at the role digital ID schemes could play in countering fraud, including that used to fund terrorism.

A systemic “responsibility vacuum” in the UK government must be addressed to improve the fight against fraud, the think tank argued.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk

DDoS Attacks Surge in 2020 Due to #COVID19

DDoS Attacks Surge in 2020 Due to #COVID19

Distributed denial-of-service (DDoS) attacks rose substantially last year following the digital shift brought about by COVID-19, according to figures released by NETSCOUT.

The cybersecurity company’s ATLAS Security Engineering and Response Team (ASERT) revealed it observed over 10 million attacks of this nature in 2020, which is around 1.6 million higher than in 2019.

While acknowledging that it is normal for DDoS attacks to increase, the rate of growth suggests that cyber-criminals have sought to exploit the growth of internet use and home working during the COVID-19 pandemic. The analysis found that attack frequency was up 20% across the whole of 2020, but excluding the pre-pandemic months of January, February and most of March, attack frequency grew by 22% year-on-year.

NETSCOUT added that it recorded the largest single number of monthly DDoS attacks it had ever seen in May 2020, at 929,000, with monthly rates regularly exceeding 800,000 from March.

Essential sectors forced to shift to digital during the crisis, such as e-commerce, online learning and healthcare, were particularly heavily targeted by cyber-criminals, according to the analysis. For instance, a 25% increase in DDoS activity in education networks worldwide was observed by ASERT.

Richard Hummel, threat intelligence lead at NETSCOUT, commented: “It is no coincidence that this milestone number of global attacks comes at a time when businesses have relied so heavily on online services to survive. Threat actors have focused their efforts on targeting crucial online platforms and services such as healthcare, education, financial services and e-commerce that we all rely on in our daily lives. As the COVID-19 pandemic continues to present challenges to businesses and societies around the world, it is imperative that defenders and security professionals remain vigilant to protect the critical infrastructure that connects and enables the modern world.”

NETSCOUT added that it expects threat actors to continue targeting vulnerabilities exposed by the pandemic in 2021, as well as using new attack vectors to try and take advantage of weak points of the growing reliance on digital technologies.

Premium Domain Names – transcom.uk
Transcom ISP – The UK’s Best Business ISP
DoubleCheck any website at doublecheck.uk