BradEgeland.com
  • Welcome
  • Blog
  • Expertise
  • Resume
  • Software / Service Reviews
  • Contact
  • Videos
  • Books / White Papers
  • Mentoring Contact Form
  • Awards/Recognition
  • Templates & Downloads
  • Clients
  • Professional Services
  • Past Survey Results

How One Company Survived a Ransomware Attack Without Paying the Ransom

7/18/2022

0 Comments

 
The first signs of the ransomware attack at data storage vendor Spectra Logic were reports from a number of IT staffers about little things going wrong at the beginning of the day. Matters steadily worsened within a very short time and signs of a breach became apparent. Screens then started to display a ransom demand, which said files had been encrypted by the NetWalker ransomware virus. The ransom demand was $3.6 million, to be paid in bitcoin within five days.
Tony Mendoza, Senior Director of Enterprise Business Solutions at Spectra Logic, laid out the details of the attack at the annual Fujifilm Recording Media USA (FRMA) Conference in San Diego late last month.
“We unplugged systems, as the virus was spreading faster than we could investigate,” Mendoza told conference attendees. “As we didn’t have a comprehensive cybersecurity plan in place, the attack brought the entire business to its knees.”
Cyber Insurer Provides HelpThe IT team spent the day assessing systems to see which ones were virus-free. Most had been infected. As Spectra Logic had the foresight to take out cyber insurance, Chubb representatives were professional and helpful, according to Mendoza. Chubb set the company up with Ankura, a cybersecurity recovery specialist that has also trained the FBI on cybersecurity.
Ankura immediately provided security operations center (SOC) services to stop the virus from spreading, protect against further damage, and to begin the process of removing it. Forensic analysis of the breach came to a quick conclusion – a phishing attempt had tricked a user with privileged access into clicking on a malicious link.
“The guys in the SOC discovered that the virus came in via a remote user, had spread over the VPN and then began to look for security flaws,” said Mendoza.
Fortunately, the email system escaped the virus. The team brought that system back online the next morning to enable the company to commence limited operations and to inform employees what had occurred. The IT team worked through the night for many days on intensive remediation efforts.
Also read:
  • Top 8 Cyber Insurance Companies for 2022
  • Best Ransomware Removal and Recovery Services
Backups Wiped Out But Tape, Snapshots SurviveAs the backup account had been compromised and the backup server wiped out, online backups were useless. A detailed check revealed that no data had left the premises, although the criminals behind the hack had been stealing passwords. Instructions were issued to change passwords immediately.
Meanwhile, Spectra Logic got in touch with the FBI. The agency said the virus itself could not easily be undone in the systems that had been infected. At that point, it became a race against time to see if there was some way to recover systems before the ransom deadline arrived.
Although the backup server was useless, the company had retained a copy of all its data on tape. These tape cartridges were not impacted by the hack. Those stored on premises had been kept offline. Further tape copies were available at an offsite location.
“The air gap provided by offline tape cartridges gave us hope that we could actually get the company fully operational again in a reasonable time,” said Mendoza.
IT got to work restoring things from tape. Initial estimates put time to recovery from tape at about 30 days for Tier 1 production and up to six weeks for everything else – slow, but it gave the company the confidence to ignore the ransom request with the FBI’s blessing. Soon afterwards, snapshots on disk were discovered that were immutable and safe from the virus. Those snapshots enabled recovery to be accomplished in a few days.
“We were able to restore everything and paid nothing,” said Mendoza. “Other than a few files, all data was recovered.”
Also read: Best Backup Solutions for Ransomware Protection
Lessons LearnedMondoza advises others that disk snapshots and offsite tape with an air gap are the best way to provide a sound recovery pathway after an attack. In his organization’s case, read-only immutable ZFS-based snapshots were stored on an HPE NAS system. Spectra Logic’s own systems were used for onsite and offsite tape storage.
Tape storage can take time to recover, but given Spectra Logic’s backup failures, tape media was a good additional backup measure to have.
“It took us almost a month to fully recover and get over the ransomware pain,” said Mendoza.
He agrees that threat protection is the first line of defense. But a breach is likely to happen eventually. Threat protection technology must be supported by immutability at the data level via snapshots as well as a tape air gap, he said.
That said, he stresses that security can’t take precedence over productivity. Both factors must be balanced. The company is also in favor of good security awareness education for users, as well as strong ransomware and cybersecurity insurance.
Soon after the attack, the company developed a thorough response and action plan and a cybersecurity plan.
“Our attack happened at the speed of disk and flash and was system-agnostic,” said Mendoza. “Air-gapped tape gave us the confidence to say no to paying a ransom and bought us time to find faster ways to recover.”
Ransomware attacks are happening with greater frequency than ever. A recent study published by Arcserve found that 50% of respondents were hit with ransomware attacks over the past year. More than a third (35%) said their organizations were asked to pay over $100,000 in ransom payments, and 20% were asked to pay between $1 million and $10 million.
Given the high cost of ransom payments and downtime, any company that relies on data would be wise to have a comprehensive plan and solutions in place.
Also read:
  • How to Recover From a Ransomware Attack
  • Best Incident Response Tools and Software
  • Best Disaster Recovery Solutions
0 Comments



Leave a Reply.

    Author:

    Picture

    Brad Egeland


    Named the "#1 Provider of Project Management Content in the World," Brad Egeland has over 25 years of professional IT experience as a developer, manager, project manager, cybersecurity enthusiast, consultant and author.  He has written more than 8,000 expert online articles, eBooks, white papers and video articles for clients worldwide.  If you want Brad to write for your site, contact him. Want your content on this blog and promoted? Contact him. Looking for advice/menoring? Contact him.

    Picture
    Picture
    Picture
    Picture
    Picture
    Picture

    RSS Feed

    Archives

    December 2022
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    June 2022
    May 2022
    April 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    July 2021
    June 2021
    May 2021
    April 2021
    March 2021
    February 2021
    January 2021
    December 2020
    November 2020
    October 2020
    September 2020
    August 2020
    July 2020
    June 2020
    May 2020
    April 2020
    March 2020
    February 2020
    January 2020
    December 2019
    November 2019
    October 2019
    September 2019
    August 2019
    July 2019
    June 2019
    May 2019
    April 2019
    March 2019
    February 2019
    January 2019
    December 2018
    November 2018
    October 2018
    September 2018
    August 2018
    July 2018
    June 2018
    May 2018
    April 2018
    March 2018
    February 2018
    January 2018
    December 2017
    November 2017
    October 2017
    September 2017
    August 2017
    July 2017
    June 2017
    May 2017
    April 2017
    March 2017
    February 2017
    January 2017
    December 2016
    November 2016
    October 2016
    September 2016
    August 2016
    July 2016
    June 2016
    May 2016
    April 2016
    March 2016
    February 2016
    January 2016
    December 2015
    November 2015
    October 2015
    September 2015
    August 2015
    July 2015
    June 2015
    May 2015
    April 2015
    March 2015
    February 2015
    January 2015
    December 2014
    November 2014
    October 2014
    September 2014
    August 2014
    July 2014
    June 2014
    May 2014
    April 2014
    March 2014
    February 2014
    January 2014
    December 2013
    November 2013
    October 2013
    September 2013
    August 2013
    July 2013
    June 2013
    May 2013
    April 2013
    March 2013
    February 2013
    January 2013
    December 2012
    November 2012
    October 2012
    September 2012
    August 2012
    July 2012
    June 2012
    May 2012
    April 2012
    March 2012
    February 2012
    January 2012
    December 2011
    November 2011
    October 2011
    September 2011
    August 2011
    July 2011
    June 2011
    May 2011
    March 2011
    January 2011
    December 2010
    November 2010
    October 2010
    September 2010
    August 2010
    June 2010
    May 2010
    April 2010
    March 2010
    November 2009

    RSS Feed

Powered by Create your own unique website with customizable templates.