Return to flip book view

Ransomware Response Playbook

Page 1

Ransomware attackers demand 70 million claiming they infected over a million devices We have included the supply chain attack timeline our best practice response plan we have circulated to support businesses affected HOW TO RESPOND TO A RANSOMWARE 9 STEPS ATTACK IN Swipe Think Cloud In Ltd 2021 Think Cloud In Ltd 2021 Success Through Cyber Security

Page 2

ATTACK TIMELINE Supply Chain Attack April 2021 Kaseya notified by DVID of vulnerabilities Fri 2nd July 3pm 5pm GMT June 2021 FBI Warn of further attacks Kaseya VSA Servers attacked triggering ransomware 5 30pm GMT 5 45pm GMT Exploit kicked off on scheduled ransomware attack Huntress alerted to multiple incidents 6 50pm GMT Huntress connects with Kaseya to share intel 7 05pm GMT 8 00pm GMT Kaseya take down SAAS Service Kaseya recommend the IMMEDIATE shutdown of VSA servers Think Cloud In Ltd 2021 Success Through Cyber Security

Page 3

Finding Ransom Notes Files encrypted by most ransomware typically have no way of being decrypted Think Cloud In Ltd 2021 Think Cloud In Ltd 2021 Success Through Cyber Security

Page 4

The Swedish Coop grocery store chain closed all its 800 stores on Saturday after a ransomware attack Think Cloud In Ltd 2021 Success Through Cyber Security

Page 5

ITS HAPPENING LOCALLY TO A cyber attack has crippled Spar shops across the north of England and outlets in Hull and the East Riding continue to be affected The attack on Sunday targeted James Hall and Company in Preston which operates Spar s tills and IT systems which has left stores unable to accept card payments he affected stores include the SPAR In the Hull University Student s Union the store on Hessle Road the store in Willerby the store attached to the Long Riston petrol station As of this morning the Spar at Long Riston was not accepting card payments in store but you can pay for fuel at the pumps The Spar in the Hull University Students Union wrote on Facebook on Monday Due to the ongoing network problems that we are experiencing that is affecting our tills card machines and back office systems we have taken the decision to remain closed for the remainder of today How one Yorkshire business lost 70 000 to online scammers When Simon s business advisory consultancy suffered a ransomware cyber attack in September it almost cost him everything When Simon s business advisory consultancy suffered a ransomware cyber attack in September it almost cost him everything UK businesses are now 15 times more likely to suffer a hacking incident rather than a fire or theft with one firm paying out 71 million One in six firms paid ransoms to meet the demands of hackers last year according to the chilling findings of a report on cyber crime The annual Hiscox Cyber Readiness Report revealed that six per cent of the 5 569 firms polled and one in six of those attacked had surrendered by paying out following a cyber attack UK firms are now 15 times more likely to suffer a cyber attack than a fire or theft the report suggests It revealed the biggest reported cyber loss among firms in the eight countries surveyed was suffered by a UK financial services firm at 71 million The business employed 25 staff across offices in Yorkshire and the North East That Wednesday was just like any normal day nothing unusual until his staff started to report that emails weren t getting through and then access to the server started to be denied Think Cloud In Ltd 2021 Success Through Cyber Security

Page 6

Attack Teardown Geography of attempted attacks resulting from the original breach CreditMailonline abc News Think Cloud In Ltd 2021 Think Cloud In Ltd 2021 Success Through Cyber Security

Page 7

Revil hackers continue to wrack up targets with ransomware attacks REVIL HAPPY BLOG Think Cloud In Ltd 2021 Think Cloud In Ltd 2021 Success Through Cyber Security

Page 8

Files encrypted by most ransomware typically have no way of being decrypted Think Cloud In Ltd 2021 Success Through Cyber Security

Page 9

Steps to take if your organisation is already infected Think Cloud In Ltd 2021 Success Through Cyber Security

Page 10

STEP ONE Immediately disconnect the infected computers laptops or tablets from all network connections whether wired wireless or mobile phone based Think Cloud In Ltd 2021 Success Through Cyber Security

Page 11

STEP TWO Turn off your Wi Fi disabling any core network connections switches disconnecting from the internet Think Cloud In Ltd 2021 Success Through Cyber Security

Page 12

STEP THREE Reset credentials including all passwords especially for admin system accounts Verify clarify that you are not locking yourself out of systems that are needed for recovery Think Cloud In Ltd 2021 Success Through Cyber Security

Page 13

STEP FOUR Safely wipe the infected devices and reinstall the OS Think Cloud In Ltd 2021 Success Through Cyber Security

Page 14

STEP FIVE Before you restore from a backup verify that it is free from any malware You should only restore from a backup if you are confident that the backup and the device you re connecting it to are clean from the ransomware Think Cloud In Ltd 2021 Success Through Cyber Security

Page 15

STEP SIX Connect devices to a clean network in order to download install and update the OS and all other software Think Cloud In Ltd 2021 Success Through Cyber Security

Page 16

STEP SEVEN Install Essential Cyber Protection If you have concerns for your cyber security safety please download our free Value Protection Framework Ransomware Recovery Playbook Our diagnostic tool was developed to support businesses across the Humber Cumbria region through the GROWMYSME Humber Growth Hub Digital Tech Cumbria Digital Catalyst Scheme In response to the Global Cyber Attack that hit businesses over the 4th of July weekend we have made this available for free to support the business community ASSOC Visit The Link below digital think cloud co uk 15ways Think Cloud In Ltd 2021 Success Through Cyber Security

Page 17

STEP EIGHT Reconnect to your network Think Cloud In Ltd 2021 Success Through Cyber Security

Page 18

STEP NINE Monitor network traffic and run advanced threat detection scans to identify if any infection remains Think Cloud In Ltd 2021 Success Through Cyber Security

Page 19

TAKE THE CYBER SECURITY CHALLENGE It is our company s mission to up skill and make our local business community stronger with our free Cyber Security Challenge We ve put together a brief piece of online training for all busy business owners and senior leadership teams This quick expert training guide also includes a must see video report by the BBC and we have included details of our free framework on how to tackle the silent killer that UK Businesses are facing right now Scan the QR Code or head to www digital think cloud co uk challenge Think Cloud In Ltd 2021 Success Through Cyber Security

Page 20

| Success Through Cyber-SecurityATTACK IN 9 STEPSHOW TO RESPOND TO A RANSOMWARE © Think Cloud In Ltd 2021© Think Cloud In Ltd 2021SwipeRansomware attackers demand $70 million, claiming they infected over a million devices+ We have included the supply chain attack timeline & our best practice response plan we have circulated to support businesses affected.