Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Friday January 17 2020, @02:29AM   Printer-friendly
from the Windows-TCO dept.

The Insurance Journal is asking if the NotPetya Windows worm was an act of war. If so, that would change any potential obligations carried by insurance policies towards claimants, in this case Merck & Co. NotPetya took over Windows computers in 2017 but was apparently originally intended to target Ukrainian Windows computers. The rest of the Windows computers may have just been collateral damage.

By the time Deb Dellapena arrived for work at Merck & Co.’s 90-acre campus north of Philadelphia, there was a handwritten sign on the door: The computers are down.

It was worse than it seemed. Some employees who were already at their desks at Merck offices across the U.S. were greeted by an even more unsettling message when they turned on their PCs. A pink font glowed with a warning: “Ooops, your important files are encrypted. … We guarantee that you can recover all your files safely and easily. All you need to do is submit the payment …” The cost was $300 in Bitcoin per computer.

The ransom demand was a ruse. It was designed to make the software locking up many of Merck’s computers—eventually dubbed NotPetya—look like the handiwork of ordinary criminals. In fact, according to Western intelligence agencies, NotPetya was the creation of the GRU, Russia’s military intelligence agency—the same one that had hacked the Democratic National Committee the previous year.

In all, the attack crippled more than 30,000 laptop and desktop [Windows] computers at the global drugmaker, as well as 7,500 servers, according to a person familiar with the matter. Sales, manufacturing, and research units were all hit. One researcher told a colleague she'd lost 15 years of work. Near Dellapena's suburban office, a manufacturing facility that supplies vaccines for the U.S. market had ground to a halt. "For two weeks, there was nothing being done," Dellapena recalls. "Merck is huge. It seemed crazy that something like this could happen."

Earlier on SN:
Windows 7 and Server 2008 End of Support: What Will Change on 14 January? (2020)
Cyber Insurance claims NotPetya was an act of war (2019)
Original Petya Master Decryption Key Released (2017)


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by hendrikboom on Friday January 17 2020, @02:37PM (3 children)

    by hendrikboom (1125) Subscriber Badge on Friday January 17 2020, @02:37PM (#944525) Homepage Journal

    How easy is it on most popular backup programs to check that a restore is possible without putting your primary data at risk in case the backup was corrupt?

    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2  
  • (Score: 2) by deimtee on Friday January 17 2020, @08:38PM (2 children)

    by deimtee (3272) on Friday January 17 2020, @08:38PM (#944712) Journal

    If you can't restore to alternative hardware then it is not a backup. So the answer is, "as easy as it is to get backup hardware".
    Note that if your equipment is expensive, this might not be easy.

    --
    If you cough while drinking cheap red wine it really cleans out your sinuses.
    • (Score: 2) by hendrikboom on Saturday January 18 2020, @08:12PM (1 child)

      by hendrikboom (1125) Subscriber Badge on Saturday January 18 2020, @08:12PM (#945067) Homepage Journal

      More practical for corporations than for hobbyists. Even one modest laptop can break the budget.

      • (Score: 2) by deimtee on Sunday January 19 2020, @01:40AM

        by deimtee (3272) on Sunday January 19 2020, @01:40AM (#945157) Journal

        Yes, but the average hobbyist doesn't have to restore a working corporate environment either. They are generally only concerned that the files are not lost, they can build a new environment.
        In either case the equipment does not need to be as powerful and expensive as the original, it just needs to be enough to show the files are accessible. Many of the times someone will need a backup are either hardware failure or lost/stolen equipment. In both cases a backup that needs to go on the original hardware is useless.

        --
        If you cough while drinking cheap red wine it really cleans out your sinuses.