Brooks County TX pays off hacker with tax dollars after ransomware attack
kztv10.com
kztv10.com
The number of people involved in government, and the resources available for professional support staff (and solution products) are probably modest to say the least.
A lot of you probably went to high schools that were bigger and more funded.
Really the federal government should be publishing and distributing guidance to local governments about how to run IT.
I am wondering about how the ransom payout is going to show up in next year's budget. "Miscellaneous"?
Off topic, but there is a documentary about migration through Brooks County and the perils faced by people trying to migrate: https://en.wikipedia.org/wiki/Missing_in_Brooks_County
I think people from other countries don’t understand that Americans don’t want (federal) government knowing anything about them besides taxes. There’s a whole bunch of reasons why, but for the most part it boils down to various forms of liberty - and tales of the mark of the beast.
… but it’s usually fine when your state or a corporation is doing it.
I'm not American, I know that, have heard various reasons for it, and i consider it to be profoundly stupid. It might have made sense in the 19th century, but today? Your federal government already knows all there is to know about you. They can tap in healthcare, financial, state government information, all that online stuff. The cat is out of the bag, why not use it for something practical? A common unified ID which gives access to e-government services is the norm across the EU, and it's pretty cool and practical.
That sounds profoundly stupid. You mean like the credit rating agencies that provide credit worthiness identity, but where you have no control of how and with whom they store your data? So how would that work, how would the companies providing that service make money and how could they prove your identity? They'd still need to use government info like birth certificate/drivers license to verify who you are, but they'd have a profit motive. Of course that sounds better than the government, which doesn't need to sell who you are, providing an identity service.
Why have a useless middleman trying to make money off you?
So fuck any homeless, people living alone, orphans, etc. ? Not to mention the utter unreliability of relying on random people (who claim they know you) for information like place/date of birth, etc.
At the same time they don’t have any issues with commercial companies knowing everything about them, without any kind of control or oversight.
https://constitution.congress.gov/constitution/amendment-10/....
Or even running the IT for them. Lots of smaller municipalities and counties, even with all the guidance on the world, wouldn't have the resources to properly manage everything. Not to mention what a colossal waste it is, financially or practically, for every single administrative entity to reinvent the wheel for each of their IT needs.
Maybe they should learn from Zambia and restore their data from their backup, and tell the ransomware guys some nice things, just as the central bank of Zambia did.
> “We had determined if we didn’t, then it would take us anywhere from six months to a year to reconstruct our software program,” Ramos said.
How much would it have cost for 6-12 months of engineer time plus the court system slowing to a crawl in the meantime? Thank god these hackers don't know how to negotiate.
> Thank god these hackers don't know how to negotiate.
I think that's a feature, not a bug. They have exemplified that if they get paid, you get your data back. No negotiating, no games, just a hard time limit with consequences and a relatively low payout cost to avoid them.Buying new software is one thing you could price out. Losing historical financial data is the one that’s tricky to price.
Source: worked for a Texas municipality in a previous career life, but definitely not Brooks County
So I'm not an expert by any means, but I can't picture how that is an effective protection. Either the detection can catch it before infection, in which case why shut down? Or it catches it after infection when it could have already spread.
Setting up that last backup sounds like a better use of money.
But I guess they thought it was worth buying to appease the public.
Why don't businesses (or systems) seed their drives with files with known text / content and then use those files to reverse the method used to encrypt? It seems like having an adversary encrypt a set of known "canary" files should provide information to reverse the encryption?
Again, there may be a good reason (or many many good reasons) why this would not be a good solution, especially since I'd expect most OS installations have enough standard files to do this if it worked, but I am curious if someone knows.
Edit: From the helpful comments, this is a known class of attack on a cryptosystem called a plaintext attack. Using that information, I looked into how ransomware systems address this attack, and several, apparently, use per-file keys as, in part, a defense against this type of attack.
> “The only data that we had that wasn’t backed up was in our auditor's office, where we have our financial software,” Ramos said.
Seems like it should’ve been a priority.
(a component of my work in risk mgmt is business continuity and disaster recovery, excuse my saltiness)
Given the usual IT chops of a small local government, I give them points for having backups at all. Funding from higher levels of government (either state/provincial or federal depending on the region) earmarked for anti-ransomware initiatives, could help mitigate this sort of disaster in the future.
A 16T drive costs around $400. Shouldn't be so expensive to copy the contents of the disk to it now and then. No special software is needed, either.
Because they're government records, there's the very good chance that there are compliance/certification requirements, plus there's infrastructure you have to put in to make it auditable while mitigating the risk of a ransomware attack affecting backups, too.
Setting up total, compliant, and working backups for a small county can reasonably require a small headcount and some specialized long-term planning.
E: that's not to mention that in some lower-population, lower-income counties, $400 isn't trivial to spend. There are definitely places in the States where deciding whether to upgrade a single computer from 2006 for $800 is a long conversation.
As for spending $800, how is spending $37,000 more feasible?
I find these sorts of exchanges astonishing. A 1Tb drive can be bought for $30 on ebay. Backing up to it is a simple xcopy or rsync command. Then put the drive in the safe.
It's as simple as that.
How's access to the safe managed? What happens if you get a vindictive (ex-)employee with access to it? If the person with access to the safe loses the key, or gets in an accident and can't open it anymore, what do you do?
How do you audit access to the safe to make sure nobody's pulling down data and selling it for profit on the side?
How do you make sure you don't lose all your backups by having a butterfingers IT person drop the drive?
How sure are you that the latest backup doesn't contain files hit by ransomware, or worse yet, the ransomware itself?
If you're storing financial or medical data about the county's citizens, how are you going to handle the possibility of being legally challenged down the line about data storage practices?
Handling any data in an org of almost any size is surprisingly complicated, especially if it's other peoples' data. Most people don't realize the scale of the issue because they're coming from a place of mostly working with at-home backups.
In terms of spending feasibility: really depends on how funding gets allocated by the state. Like I said in another comment, the solution would be for the state to subsidize the fixed costs of putting this kind of infrastructure in place.
Perhaps ransomware is evolving to fine just right price point niche?
And that is 90% of the actual demand for bitcoin. The rest was speculation, and that is going away as prices fall. So imagine how bitcoin would crash if people stopped paying these ransoms.
Seems to me that in modern times failing to back things up is incompetence and dereliction of duty. The auditor should be billed for at least part of the payment.
Maybe /this/ is the real web3.
If you hire incompetent people, you can't reasonably expect them to do their jobs properly. You may save some money and avoid some inconvenience that way, but you may also have to face crises that would have been avoidable. Alternatively, you can spend more money proactively and hire more competent people. Either way, taxpayers will pay the price.
This county, by the way, was bankrupted from having to deal with the corpses of dead migrants who were desperate enough to try to sneak in through it.
We did end up restoring some large percentage of machines from backup, eventually, then after retrieving/reviewing data we trashed those machines and rebuilt them. We also ended up paying - some of the backups didn't work, and some were taking so long to restore it didn't make sense to wait for them - and we rebuilt those as well.
At least for us, we probably could have done a better job with testing backups. The behavior we saw with individual test restores was not the same as the what happened with mass restores, and we were surprised by that. Also, beyond just restoring from backup, we spent a lot of time rebuilding machines; if you get compromised, your backup might be clean, but the restored state is probably ready to be compromised again. I don't remember how long it was before our security people said they figured out how we got compromised in the first place.