Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

jpak

(41,756 posts)
Tue Aug 20, 2019, 11:57 AM Aug 2019

23 Texas Towns Hit With Ransomware Attack In 'New Front' Of Cyberassault

Source: NPR

Texas is the latest state to be hit with a cyberattack, with state officials confirming this week that computer systems in 23 municipalities have been infiltrated by hackers demanding a ransom.

The Federal Bureau of Investigation and state cybersecurity experts are examining the ongoing breach, which began Friday morning and has affected mostly smaller local governments. Officials have not disclosed which specific places are affected.

Investigators have also not yet identified who or what is behind the attack that took the systems offline, but the Texas Department of Information Resources says the evidence so far points to "one single threat actor."

Elliott Sprehe, a spokesman for the department, said he was "not aware" of any of the cities having paid the undisclosed ransom sought by hackers. He said the areas impacted are predominantly rural.

<more>

Read more: https://www.npr.org/2019/08/20/752695554/23-texas-towns-hit-with-ransomware-attack-in-new-front-of-cyberassault

12 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies

ancianita

(35,932 posts)
1. For the same amount of ransom paid, these towns could get all new computers & firewall their govts.
Tue Aug 20, 2019, 12:13 PM
Aug 2019

Like Atlanta, they either make the upfront high cost investment or pay more in ransom in the long run.

The FBI has its hands full. It has confirmed that 1,493 ransomware attacks were reported last year, for a total of $3.6 million being paid to hackers—about $2,400 per attack.

bluedigger

(17,085 posts)
3. It's not their hardware they are worried about, it's their data.
Tue Aug 20, 2019, 12:36 PM
Aug 2019

All the assessor's tax info in particular.

ancianita

(35,932 posts)
5. Interesting.It could be an anti-tax extremist, since the real money lies in hitting up wealthy corps
Tue Aug 20, 2019, 12:46 PM
Aug 2019

SpankMe

(2,956 posts)
2. There should be a special place in hell for ransomeware attackers.
Tue Aug 20, 2019, 12:24 PM
Aug 2019

We've been hit by it. It's devastating.

bluedigger

(17,085 posts)
4. They are either very confident, or very stupid.
Tue Aug 20, 2019, 12:38 PM
Aug 2019

With some luck, both. I expect this just shot up to the top of the FBI's priorities.

in2herbs

(2,944 posts)
6. Isn't it the rural areas that polls are predicting may go blue? Is the hacking a test before the
Tue Aug 20, 2019, 01:20 PM
Aug 2019

election?

matt819

(10,749 posts)
8. WTF?
Tue Aug 20, 2019, 01:52 PM
Aug 2019

Okay, all I have are my couple of computers. But I have BitDefender, which is supposed to protect against that. I would guess that there are more powerful firewalls for the sorts of systems being attacked. If they were in place, why didn't they work. And if they weren't, why?

I read online the other day that a non-profit tech group - can't remember the name - that has tools to identify and in some cases resolve the problem. At the very least, the tools help narrow down the details on the attack.

And, third, if they were properly backed up, the data isn't lost, and insurance will pick up the tab for new computers. And if not, why not?

Igel

(35,274 posts)
11. Here's speculation.
Tue Aug 20, 2019, 06:20 PM
Aug 2019

At least some of these kinds of take-over attacks result from phishing. It's what nailed the DNC in summer 2016, and what didn't nail hundreds or thousands of other organizations who received the same spear-phish attack at the same time.

You're sent email. "Somebody has tried to access your ______ account." Perhaps cell phone, perhaps Google drive, perhaps your Ebay or Amazon account. It's a case of "fill in phish-bait here." Recently I've been spammed with fake Fedex deliveries, USPS information, and Google account mail.

Cursor over it and often at the bottom you'll see link addresses like "screwyoubitch.ru" or "youreasucker.ru". Sometimes random stuff, "4k3hjgf0239.tv" or "38cjdhhheii.ch".

Click, and you've granted permission for a lot of things to attack your computer. What, exactly, depends on your software, your config settings, and how nasty the malware is. How far-reaching the damage is also depends on your system and their malware. It may just knock out your computer; it may propagate through the system and take out computers or perhaps the server.

Where I work has entire country domains blocked.

Jokerman

(3,518 posts)
12. "They got into our software provider, the guys who run our IT systems,"
Wed Aug 21, 2019, 08:37 AM
Aug 2019

There you go.

All the firewalls and security in the world won't help you when you give the keys to a third party and they don't keep them secure.

My money is on someone inside the provider either fucked up or is complicit.

"A lot of folks in Texas use providers to do that, because we don't have a staff big enough to have IT in house."

Latest Discussions»Latest Breaking News»23 Texas Towns Hit With R...