UK blames North Korea for WannaCry attacks
The United Kingdom released its final report Friday on the WannaCry ransomware attacks that caused mass disruption in its hospital system, with a U.K. official saying the country believes the attacks originated in North Korea.
"This attack, we believe quite strongly that it came from a foreign state," Ben Wallace, a junior minister for security, told BBC 4 Radio, adding that the government was "as sure as possible" that nation was North Korea.
NHS 'could have prevented' WannaCry ransomware attack
The report said NHS trusts had not acted on critical alerts from NHS Digital and a warning from the Department of Health and the Cabinet Office in 2014 to patch or migrate away from vulnerable older software.
The Department of Health also lacked important information, the report said. "Before 12 May 2017, the department had no formal mechanism for assessing whether NHS organisations had complied with its advice and guidance."
Organisations could also have better managed their computers' firewalls - but in many cases they did not, it said.
NHS organisations have not reported any cases of harm to patients or of their data being stolen as a result of WannaCry.
Also at NPR.
Related Stories
A derivative of Microsoft Windows ransonware, Wannacry, has hit a Boeing production plant in Charleston, South Carolina. An internal memo from Mike VanderWel, chief engineer of Boeing Commercial Airplane production engineering, warned that the company's production systems and airline software were "at risk".
Wannacry was based on Microsoft Windows' CVE 2017-0144 which is used in the EternalBlue exploit kit. EternalBlue was initially utilized in apparent coordination with Microsoft's long delay in patching. Despite massive media spin, Wannacry was found to have hit all recent versions of Microsoft Windows.
From:
The Verge: Boeing production plant hit with WannaCry ransomware attack
The New York Times: Boeing Possibly Hit by ‘WannaCry’ Malware Attack
The Daily Express: Vital Boeing computer network INFECTED with WannaCry VIRUS - is it safe to fly?.
Previously: UK Blames North Korea for WannaCry Attacks, Says NHS Didn't Follow Cybersecurity Guidelines
WannaCry Ransomware Attack Linked to North Korea by Symantec
(Score: 4, Insightful) by Whoever on Sunday October 29 2017, @10:40PM (10 children)
Instead of blaming poor security, blame North Korea instead.
What has NK got to gain from hacking the NHS? Nothing, except in the fevered imaginations of the war hawks.
(Score: 1, Insightful) by Anonymous Coward on Sunday October 29 2017, @10:47PM
I think you mean chicken hawks instead of war hawks. War hawks may fight but chicken hawks get bone spurs.
(Score: 4, Informative) by takyon on Sunday October 29 2017, @11:08PM (7 children)
Your info is sadly years out of date:
The World Once Laughed at North Korean Cyberpower. No More. [nytimes.com]
Maybe the attribution is incorrect, but your idea that "war hawks" are falsifying it doesn't make any sense. UK doesn't want to go to war with North Korea, and the U.S. probably doesn't (who knows what Trump wants?). The idea that NK has nothing to gain is also false. They don't call it "ransomware" for nothing, and some state-sponsored hacking is done for the data rather than money. If NK has no use for the data (except blackmail and phishing can be a great use), then they know who does: China.
[SIG] 10/28/2017: Soylent Upgrade v14 [soylentnews.org]
(Score: 0) by Anonymous Coward on Sunday October 29 2017, @11:11PM (3 children)
Doesn't change the fact that N Korea has nothing to gain by hacking the UK's NHS. What would they gain?
(Score: 3, Interesting) by takyon on Sunday October 29 2017, @11:18PM (1 child)
Money. It's ransomware. Some people did pay out.
You are also forgetting that the NHS was far from the only target:
https://en.wikipedia.org/wiki/WannaCry_ransomware_attack [wikipedia.org]
Affected organizations:
[SIG] 10/28/2017: Soylent Upgrade v14 [soylentnews.org]
(Score: 1, Insightful) by Anonymous Coward on Monday October 30 2017, @08:15AM
https://www.cnbc.com/2017/05/15/wannacry-ransomware-hackers-have-only-made-50000-worth-of-bitcoin.html [cnbc.com]
https://www.thesslstore.com/blog/wannacry-ransom-total/ [thesslstore.com]
You really believe the North Koreans wrote Wannacry which has such an easy killswitch in the code? When North Koreans screw up it's not just them who get executed. Their families get executed or imprisoned too. All to make less than USD100,000 for the North Korean Government in traceable Bitcoin?
Just because some code matches doesn't mean much.
Quote the NY Times:
Now if you can link the "Patient Zero"(s) to North Korea then I'll put more weight on the NK accusations. Till then you've really got nothing except hearsay and propaganda.
(Score: 3, Insightful) by frojack on Monday October 30 2017, @07:31AM
You hack where you can, where its easy. Where people are unprepared. You don't even know your targets, and you certainly don't pick them
You don't set out to hack any specific place.
You accept any low hanging fruit that comes your way.
The NHS apparently hired people with your mind set. No doubt graduates of the Alfred E Newman school of network security.
No, you are mistaken. I've always had this sig.
(Score: 2) by Whoever on Monday October 30 2017, @01:24AM (2 children)
... because the Western powers don't have a record of over-stating the capabilities of their adversaries, do they?
(Score: 2) by takyon on Monday October 30 2017, @01:46AM (1 child)
Yeah, we hear you, you're skeptical and a cynic like everyone else here. Just don't let it cloud your vision.
North Korean Hack of U.S. War Plans Shows Off Cyber Skills [bloomberg.com]
https://en.wikipedia.org/wiki/Internet_in_North_Korea#Hackers [wikipedia.org]
In North Korea, Hackers Are a Handpicked, Pampered Elite [soylentnews.org]
North Korea 'Hacks South's Military Cyber Command' [soylentnews.org]
South Korean Government Report Suggests North Koreans Hack for Cash, Not Secrets [soylentnews.org]
New US Sanctions for North Korea Following Sony Hack [soylentnews.org]
[SIG] 10/28/2017: Soylent Upgrade v14 [soylentnews.org]
(Score: 1, Insightful) by Anonymous Coward on Monday October 30 2017, @11:09AM
The hack of military stuff is believable but the other stuff and wannacry? All that "evidence" has just been from the US Gov or other non-credible sources.
http://www.businessinsider.com/north-korea-sony-hack-2016-6/ [businessinsider.com]
Just like the claims that NK was behind the Bangladesh Bank hack. It's just as likely or more that some Filipino hackers did it - the money went to a bank in Philippines and then vanished into their casinos:
http://fortune.com/2016/12/13/swift-bangladesh-2/ [fortune.com]
The US Gov has lied so many times about such stuff why believe them on this? They're not a credible witness at all.
(Score: 4, Insightful) by Snotnose on Sunday October 29 2017, @11:54PM
Horse hockey. Fix your damned security. If it wasn't the Norks it would have been someone else.
It's just a fact of life that people with brains the size of grapes have mouths the size of watermelons. -- Aunty Acid
(Score: 1, Insightful) by Anonymous Coward on Monday October 30 2017, @04:07AM
Sounds like some bigwig should spend some time thinking in the cooler to avoid making such colossal fuckups in the future.
But of course nobody will take the blame. Responsibility of for the little people.