City in Florida pays hackers ransom

tedjamestedjames Member Posts: 1,182 ■■■■■■■■□□

Comments

  • mikey88mikey88 Member Posts: 495 ■■■■■■□□□□
    Ouch, that is one expensive click of an email link.
    Certs: CISSP, CySA+, Security+, Network+ and others | 2019 Goals: Cloud Sec/Scripting/Linux

  • Johnhe0414Johnhe0414 Registered Users Posts: 191 ■■■■■□□□□□
    That was an interesting read...thanks
    Current: Network+ | Project+ 
    Working on: PMP
  • LonerVampLonerVamp Member Posts: 518 ■■■■■■■■□□
    Yeah, I've been looking to see where this may have been covered in the past, as I really would like to use it as an example of the risks of phishing attacks. The wave of news bits about it today and last night are all high-level mainstream pieces.

    I found a small regional piece from June 1st: https://www.wpbf.com/article/riviera-beach-computer-shut-down-due-to-hacking-fix-may-cost-dollar1-million/2770640. Otherwise, absolutely nothing more detailed.
    "An email got in. Someone clicked on an email. There was an intrusion. As soon as we became aware of it, we went and locked everything down," said Williams in answer to a councilman's question.




    Security Engineer/Analyst/Geek, Red & Blue Teams
    OSCP, GCFA, GWAPT, CISSP, OSWP, AWS SA-A, AWS Security, Sec+, Linux+, CCNA Cyber Ops, CCSK
    2021 goals: maybe AWAE or SLAE, bunch o' courses and red team labs?
  • LonerVampLonerVamp Member Posts: 518 ■■■■■■■■□□
    "Someone in the police department on May 29 opened an email that unleashed a virus that paralyzed the city’s computer system, sending all of the city's operations offline."

    Security Engineer/Analyst/Geek, Red & Blue Teams
    OSCP, GCFA, GWAPT, CISSP, OSWP, AWS SA-A, AWS Security, Sec+, Linux+, CCNA Cyber Ops, CCSK
    2021 goals: maybe AWAE or SLAE, bunch o' courses and red team labs?
  • tedjamestedjames Member Posts: 1,182 ■■■■■■■■□□
    OK, it happened again...to another Florida city.
    https://www.zdnet.com/article/second-florida-city-pays-giant-ransom-to-ransomware-gang-in-a-week/

    Again, I say to back up regularly. Don't pay ransoms.
  • jeremy_dfirjeremy_dfir Member Posts: 23 ■■■□□□□□□□
    +1 to what @tedjames said.

    You may not avoid a breach, but for crying out loud BACK UP!
  • tedjamestedjames Member Posts: 1,182 ■■■■■■■■□□

    Their CISO was the keynote at a conference I attended earlier this year. Her talk, which focused on how they handled the problem, was really eye opening and inspiring.


Sign In or Register to comment.