Ransomware Attack On Accenture

The global business consulting firm Accenture has confirmed that it has become a victim of a LockBit ransomware attack. According to the company, LockBit was used in attempt to freeze various corporate databases, although the firm says that it has recovered all its data using backups. 

The LockBit ransomware-as-a-service (RaaS) gang has published the name and logo of Accenture, with a mischievous message and an implied threat to the security of even some of the world’s biggest, most powerful companies.

Ransomware Background

Ransomware is a subset of malware in which the data on a victim's computer is locked, typically by encryption, and payment is demanded before the ransomed data is decrypted and access is returned to the victim. The motive for ransomware attacks is usually monetary, and unlike other types of attacks, the victim is usually notified that an exploit has occurred and is given instructions for how to recover from the attack. Payment is often demanded in a virtual currency, such as bitcoin, so that the cyber criminal's identity is not known.

In May this year Colonial Pipeline paid almost $5 million to restore its systems after DarkSide used encryption to hold hostage the pipeline, which supplies nearly half of the East Coast’s fuel to 50 million people. 

The cybersecurity industry is stretched thin. Ransomware attacks are now so prolific that some companies simply cannot help every newly hacked victim get back online and a shortage of workers means no immediate help in sight. One of the biggest problems that organisations face in the battle against ransomware is a lack of expert guidance and attacks have become so prolific that organisations don’t have the internal expertise to address the risk and are unable to seek assistance from third parties.

The pace of attacks is seemingly relentless. President Biden has spoken about  the issue, stressing how much ransomware activity originates from Russia,where cyber criminals seem to work with impunity. In  of the most prolific ransomware gangs, REvil, carried out one of its boldest attacks on the Fourth of July weekend on Kaseya, a n IT services buisness which infected the customer supply chain. Experts say the hack permitted REvil to infect  more than 1,500 corporations in the US and around the world. 

Types of Ransomware

There are three main types of ransomware.

Scareware:   Scareware includes rogue security software and tech support scams. You might receive a pop-up message claiming that malware was discovered and the only way to get rid of it is to pay up. If you do nothing, you’ll likely continue to be bombarded with pop-ups, but your files are essentially safe. A legitimate cyber security software program would not solicit customers in this way. If you don’t already have this company’s software on your computer, then they would not be monitoring you for ransomware infection. If you do have security software, you wouldn’t need to pay to have the infection removed, you’ve already paid for the software to do that very job.

Screen Lockers:   When lock-screen ransomware gets on your computer, it means you’re frozen out of your PC entirely. Upon starting up your computer, a full-size window will appear, often accompanied by an official-looking like police  or Department of Justice seal saying illegal activity has been detected on your computer and you must pay a fine. However, the police would not freeze you out of your computer or demand payment for illegal activity. If they suspected you of piracy, child pornography, or other cyber crimes, they would go through the appropriate legal channels.

Encrypting Ransomware:   The hacking gangs steal your files and encrypt them, demanding payment in order to decrypt and redeliver. The reason why this type of ransomware is so dangerous is because once cyber criminals get ahold of your files, no security software or system restore can return them to you. Unless you pay the ransom, for the most part, they’re gone. Even if you do pay up, there’s no guarantee the cyber criminals will give you those files back.

The Future Of Ransomware 

As ransomware technology continues to advance, the technological margin between attackers and public targets has the potential to grow even wider. Within these targeted public sectors, specifically healthcare, attacks may be more costly in the coming years than ever before.

Predictions also indicate a growing focus on small businesses that run outdated security software. As the number of IoT business devices grows, small businesses can no longer think that they are too small to be attacked. This  attack vector is growing faster than effective the available security measure and the risk is that  domestic devices will become progressively more likely targets, alongside business.

NBC:     IEEE:      Oodaloop:        War on the Rocks:     ITGovernance:    Malwarebytes:      Techtarget:

CRN:        Threatpost:   Infosecurity Magazine:     

You Might Also Read:

No More Ransom Saves Victims:

 

« Suspected Russian Spy Arrested
Norton To Pay $8bn To Buy Avast »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Perimeter 81 / How to Select the Right ZTNA Solution

Perimeter 81 / How to Select the Right ZTNA Solution

Gartner insights into How to Select the Right ZTNA offering. Download this FREE report for a limited time only.

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

North Infosec Testing (North IT)

North Infosec Testing (North IT)

North IT (North Infosec Testing) are an award-winning provider of web, software, and application penetration testing.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Promon

Promon

Promon is an application security vendor providing Self-Protection abilities to Mobile apps and Desktop applications.

DTEX Systems

DTEX Systems

DTEX Systems is the global leader for insider risk management. We empower organizations to prevent data loss by proactively stopping insider risks from becoming insider threats.

Alert Logic

Alert Logic

Alert Logic delivers unrivaled security for any environment, delivering industry-leading managed detection and response (MDR) and web application firewall (WAF) solutions.

Brinqa

Brinqa

Brinqa is a leading provider of unified risk management and security analytics.to manage IT governance and technology risk.

Ground Labs

Ground Labs

Ground Labs is a security software company dedicated to making sensitive data discovery products that help organisations prevent sensitive data loss.

Italian Association of Critical Infrastructure Experts (AIIC)

Italian Association of Critical Infrastructure Experts (AIIC)

AIIC acts as a focal point in Italy for expertise on the protection of Critical Infrastructure including ICT networks and cybersecurity.

ComCode

ComCode

ComCode provides consulting services and solutions in the area of digitization and cyber security for mid-sized and big businesses.

Science Applications International Corporation (SAIC)

Science Applications International Corporation (SAIC)

SAIC is a premier technology integrator in the technical, engineering, intelligence, and enterprise information technology markets. Services and solutions include Cybersecurity.

Cyber Discovery

Cyber Discovery

Cyber Discovery, the UK Government's Cyber Schools Programme, is a learning programme designed to give young people the opportunity to learn the skills needed to enter the cyber security profession.

Cyber Base

Cyber Base

Cyber Base is an Information Technology company based in Uganda providing software and hardware solutions to clients.

Gradcracker

Gradcracker

Gradcracker is THE careers website for Science, Technology (including Cybersecurity), Engineering and Maths university students in the UK.

101 Blockchains

101 Blockchains

101 Blockchains is a professional and trusted provider of enterprise blockchain research and training.

PizzlySoft

PizzlySoft

PizzlySoft is a global company that is seeking convergence of network and security / software and hardware. We put our value on creating the best security.

Intrepid Solutions and Services

Intrepid Solutions and Services

Intrepid Solutions and Services provides technology solutions and professional services to key components of the intelligence and national security communities.

Zilla Security

Zilla Security

Zilla combines identity governance with cloud security to deliver comprehensive access visibility, reviews, lifecycle management, and policy-based security remediation.

Phone Monitoring Service

Phone Monitoring Service

Phone Monitoring Service provides cyber security services, ethical hacking services, social media hacking services in the USA, Canada, Europe.