Started By
Message

We were hacked today - Ransomware

Posted on 11/19/18 at 6:03 pm
Posted by CHiPs25
ATL
Member since Apr 2014
2894 posts
Posted on 11/19/18 at 6:03 pm
I own an architectural signage company and today we were hacked. We were infested with a ransomware called Ryuk and the bastards want $11,000 (or 2 BTC) to release our files. We know exactly where this originated from, one of our employees opened a file that they shouldn't have about 10 days ago and now here we are. We came into the office this morning and our entire operation was shut down. We ended up sending everyone home as it was going to take all day to backup our files, which luckily about a year ago we spent a small fortune on our backup solution. We spent approximately $7k on a DATTO box and then the upkeep is approximately $600/mo, which at this point is well worth it.

Tomorrow is going to be a new day but our IT company is going to have to essentially clean every computer which means reloading Windows and starting from scratch.

This thread is no more than a make sure that if you own a company or are in a position where technology is your career, to have a backup solution in place. If we didn't have DATTO then we would probably be negotiating with the hackers right now.
Posted by HubbaBubba
F_uck Joe Biden, TX
Member since Oct 2010
45699 posts
Posted on 11/19/18 at 6:18 pm to
My computer has a backup image made every week by IT and images are stored for three months. In addition, I have a local USB backup that is scanned every evening. One of my coworkers got random ware and lost everything until he sent it to IT and they reimaged his computer.
Posted by CHiPs25
ATL
Member since Apr 2014
2894 posts
Posted on 11/19/18 at 6:51 pm to
The one thing that we weren't doing is backing up the individual machines. We have advised everyone in our organization that we were not backing up the machines and not to put anything they didn't want to lose on it. We do not need to backup the machines with the DATTO as that's another couple of hundred bucks per month, but I think we can use a inexpensive or free backup of the machines into the cloud each week.
Posted by foshizzle
Washington DC metro
Member since Mar 2008
40599 posts
Posted on 11/19/18 at 7:17 pm to
quote:

This thread is no more than a make sure that if you own a company or are in a position where technology is your career, to have a backup solution in place.


fricking this. I'll add that it is important to practice a recovery before you need it. Buy new hardware that is bare metal. Now do a complete restore without having any access to your existing machines.

If you can't do it smoothly, you aren't ready.
Posted by oklahogjr
Gold Membership
Member since Jan 2010
36748 posts
Posted on 11/19/18 at 7:53 pm to
anytime we have a customer come to us with this. we only have three options really.


restore backups or
start googling nearest bitcoin atm or
start from scratch(not really an option)

Posted by oklahogjr
Gold Membership
Member since Jan 2010
36748 posts
Posted on 11/19/18 at 7:55 pm to
anytime we have a customer come to us with this. we only have three options really.


restore backups or
start googling nearest bitcoin atm or
start from scratch(not really an option)

Posted by Tigeralum2008
Yankees Fan
Member since Apr 2012
17125 posts
Posted on 11/19/18 at 8:23 pm to
Your IT company should be fired immediately for not using bitlocker and app locker. They are free MS apps and easy to manage

We have had zero instances of malware or ransom ware despite some seriously stupid moves by our employees.
This post was edited on 11/19/18 at 8:25 pm
Posted by CHiPs25
ATL
Member since Apr 2014
2894 posts
Posted on 11/19/18 at 9:07 pm to
We will definitely be discussing this with them after they fix it.
Posted by flyAU
Scottsdale
Member since Dec 2010
24848 posts
Posted on 11/19/18 at 9:38 pm to
This shite is a huge fricking deal in healthcare. We are staring to put fortigate firewalls behind all of our instruments to protect us from the hospital network (and vice versa). If my moms cancer treatment would have been impacted a day because of one of these frickers I would go insane.
Posted by Spock's Eyebrow
Member since May 2012
12300 posts
Posted on 11/19/18 at 9:44 pm to
quote:

Your IT company should be fired immediately for not using bitlocker and app locker. They are free MS apps and easy to manage

We have had zero instances of malware or ransom ware despite some seriously stupid moves by our employees.



I'm not familiar with AppLocker, but Bitlocker is only going to protect drives that are locked (at rest), though the whole Secure Boot apparatus protects against root kits and tampering with boot files. BitLocker's not going to help if someone downloads a program that proceeds to do its own encryption of their Bitlocker-encrypted files on an unlocked volume.
Posted by philabuck
NE Ohio
Member since Sep 2008
10378 posts
Posted on 11/19/18 at 10:23 pm to
quote:

Tomorrow is going to be a new day but our IT company is going to have to essentially clean every computer which means reloading Windows and starting from scratch. 




Microsoft System Center Configuration Management image deployment would help tremendously.

One thing about backups, make sure they are encrypted..
Posted by Hopeful Doc
Member since Sep 2010
14938 posts
Posted on 11/19/18 at 11:28 pm to
quote:

This shite is a huge fricking deal in healthcare.


I worked at a hospital that got hacked. That was not a fun 2 weeks.


It got put on diversion which helped, but taking care of people without computers in a system designed to do away with non-computer charting was awful. Even still when they go down from time to time, that hospital "downtime" plan was not great.



And as for the backups:
Previous life for me was in a state government IT position. We had an off-site server with tape drive backup. We did not have a remote backup, though if I were dealing with an operation like that today, I'd probably argue we need it/would benefit from it.
I had 4 "daily" tapes for Mon-Thurs
I forget the number of weekly tapes, but it was definitely over 30 and I want to say 60. These were made of Friday and the reason I didn't have Friday tapes
I had 11 monthly tapes and then lept a December copy as an "annual" going back a handful of years (I believe from when this backup was implemented. Maybe 5-7 years)
Posted by Chimlim
Baton Rouge, LA
Member since Jul 2005
17712 posts
Posted on 11/20/18 at 8:02 am to
I work in IT and a major part of my job is backups and replication. Not only do I need to verify backups ran, but I need to do a test restore of them every now and then.
Posted by CarRamrod
Spurbury, VT
Member since Dec 2006
57426 posts
Posted on 11/20/18 at 8:14 am to
so what is the best "free" solution for your home computers? Is windows backup sufficient to a spare HDD in my computer? or should it do to an external drive?
Posted by BottomlandBrew
Member since Aug 2010
27057 posts
Posted on 11/20/18 at 8:15 am to
We're a medium sized glass company and we went through this a year or two ago. We had daily backups on tape, but after the attack we hired an actual IT contractor to help us out and they instituted 15 minute backups.

Like you, we did not back up individual machines, which sucked when we had to bring everything back up, but we learned from our mistakes and now backup everything. I even backup files from our CNC machine that I'll likely never need again, but you never know.
Posted by CarRamrod
Spurbury, VT
Member since Dec 2006
57426 posts
Posted on 11/20/18 at 8:24 am to
quote:

our CNC machine
can i have it... i have tons of cool shite i want to route on a CNC.
Posted by BottomlandBrew
Member since Aug 2010
27057 posts
Posted on 11/20/18 at 8:48 am to
It's highly specialized for heavy glass fabrication. I don't think it would do you much good. But yeah, make me an offer. You've got to come pick it up, though.
Posted by TAMU-93
Sachse, TX
Member since Oct 2012
895 posts
Posted on 11/20/18 at 8:54 am to
quote:

so what is the best "free" solution for your home computers? Is windows backup sufficient to a spare HDD in my computer? or should it do to an external drive?


For home, I use Macrium Reflect. All my PCs get backed up to a NAS.

For work, I retain the Windows Deployment Services images I used deploy the workstation for disaster recovery.
Posted by StraightCashHomey21
Aberdeen,NC
Member since Jul 2009
125386 posts
Posted on 11/20/18 at 8:57 am to
quote:

The one thing that we weren't doing is backing up the individual machines. We have advised everyone in our organization that we were not backing up the machines and not to put anything they didn't want to lose on it. We do not need to backup the machines with the DATTO as that's another couple of hundred bucks per month, but I think we can use a inexpensive or free backup of the machines into the cloud each week.


have you ever though about going to a zero client solution aka dumb box so you don't have to worry about backing up every machine.
Posted by GrammarKnotsi
Member since Feb 2013
9313 posts
Posted on 11/20/18 at 9:14 am to
quote:

practice a recovery


x billion...
first pageprev pagePage 1 of 3Next pagelast page

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on Twitter, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookTwitterInstagram