Halloween cyber scares: two short ransomware horror stories that really happened

1) The UK schools group that took on a ransomware gang

Being the victim of a ransomware attack is no fun. When a Russian cybercriminals hit the Harris Federation, a multi-academy trust with 48 schools in and around London, with ransomware in March this year, it shut down the schools’ systems and made threats to release sensitive information online.

Important financial files like bank statements, credit card details and information relating to staff were encrypted, and unusable. All the schools were compromised, and the Trust had to shut down its entire computer network to limit further damage. This meant electronic whiteboards and doors didn’t work, CCTV stopped operating and staff couldn’t even access registers.

The Harris Federation turned to the National Cyber Security Centre. But when they contacted the recommended firms who should have been able to help them recover from the attack, none of them would take the schools group on – they were all at capacity dealing with other cyber attacks.

Instead, the Harris Federation employed an Incident Response Company with a team whose experience included Israeli military intelligence for help. Meanwhile, an expert negotiator posed as a hapless school manager and sent the hackers a message. They began discussing the ransom demands and how much the Harris Federation could afford.

The hackers responded by doubling the price, but after some back and forth, they reduced it to $3m. By this time, it had been ten days since negotiations began. But the Harris Federation had already decided they weren’t going to pay – they’d just been buying time.

Unfortunately, their data was still leaked on the dark web. But the schools group managed to recover their data without paying the ransom and within three months, they were pretty much back up and running, with the odd glitch here and there. They even managed to get their students’ coursework back.

But they had paid over half a million pounds making sure further vulnerabilities were plugged and devices were clean from the virus, so they certainly didn’t escape unscathed.

2) A local business that nearly lost everything through a ransomware attack

The day began in an ordinary way. We had been approached by a new client that wanted to achieve Cyber Essentials Plus, a government-backed accreditation that helps businesses ensure – and prove – that their cyber security is in good shape.

The accreditation requires a qualified third party (in this case Securious) to conduct an audit to verify the client’s answers to questions about their compliance. This is the major difference between Cyber Essentials Plus and the entry level Cyber Essentials certification.

But on this occasion, the client’s answers weren’t all accurate.

They had answered ‘yes’ when asked whether all their devices were running supported operating systems. But when we ran a vulnerability scan, we realised that wasn’t the case – which immediately constituted an automatic failure of the entire audit. In fact, the scan identified some major areas of weakness that left them wide open to attack…

And that’s when we saw it.

They weren’t just wide open to attack – they were mid-attack. Petya Ransomware had been installed across all the devices – including the servers.

All it would take for the ransomware to trigger would be for one device to reboot. This was a terrifying position to be in because it would encrypt all their files, unless a ransom was paid.

We immediately halted the audit, removed our scanners, and informed the business of their critically precarious position.

They called in an incident response team, who ran ransomware removal software. They are now busy updating their operating systems, hoping to be on track for their Cyber Essentials audit again soon.

It was a close call. Fortunately, the organisation didn’t suffer huge losses because we managed to catch it in time. But they’re one of the lucky ones.

If you want to learn more and ensure your business is protected from and prepared for a ransomware attack, get in touch with our team using the contact form below