Scale, details of massive Kaseya ransomware attack emerge - CTV News | Canada News Media
Connect with us

Business

Scale, details of massive Kaseya ransomware attack emerge – CTV News

Published

 on


BOSTON —
Cybersecurity teams worked feverishly Sunday to stem the impact of the single biggest global ransomware attack on record, with some details emerging about how the Russia-linked gang responsible breached the company whose software was the conduit.

An affiliate of the notorious REvil gang, best known for extorting $11 million from the meat-processor JBS after a Memorial Day attack, infected thousands of victims in at least 17 countries on Friday, largely through firms that remotely manage IT infrastructure for multiple customers, cybersecurity researchers said. They reported ransom demands of up to $5 million.

The FBI said in a statement Sunday that it was investigating the attack along with the federal Cybersecurity and Infrastructure Security Agency, though “the scale of this incident may make it so that we are unable to respond to each victim individually.”

President Joe Biden suggested Saturday the U.S. would respond if it was determined that the Kremlin is at all involved. He said he had asked the intelligence community for a “deep dive” on what happened.

The attack comes less than a month after Biden pressed Russian President Vladimir Putin to stop providing safe haven to REvil and other ransomware gangs whose unrelenting extortionary attacks the U.S. deems a national security threat.

A broad array of businesses and public agencies were hit by the latest attack, apparently on all continents, including in financial services, travel and leisure and the public sector — though few large companies, the cybersecurity firm Sophos reported. Ransomware criminals break into networks and sow malware that cripples networks on activation by scrambling all their data. Victims get a decoder key when they pay up.

The Swedish grocery chain Coop said most of its 800 stores would be closed for a second day Sunday because their cash register software supplier was crippled. A Swedish pharmacy chain, gas station chain, the state railway and public broadcaster SVT were also hit.

In Germany, an unnamed IT services company told authorities several thousand of its customers were compromised, the news agency dpa reported. Also among reported victims were two big Dutch IT services companies — VelzArt and Hoppenbrouwer Techniek. Most ransomware victims don’t publicly report attacks or disclose if they’ve paid ransoms.

CEO Fred Voccola of the breached software company, Kaseya, estimated the victim number in the low thousands, mostly small businesses like “dental practices, architecture firms, plastic surgery centers, libraries, things like that.”

Voccola said in an interview that only between 50-60 of the company’s 37,000 customers were compromised. But 70% were managed service providers who use the company’s hacked VSA software to manage multiple customers. It automates the installation of software and security updates and manages backups and other vital tasks.

Experts say it was no coincidence that REvil launched the attack at the start of the Fourth of July holiday weekend, knowing U.S. offices would be lightly staffed. Many victims may not learn of it until they are back at work on Monday. The vast majority of end customers of managed service providers “have no idea” what kind of software is used to keep their networks humming, said Voccola,

Kaseya said it sent a detection tool to nearly 900 customers on Saturday night.

John Hammond of Huntress Labs, one of the first cybersecurity firms to sound the alarm on the attack, said he’d seen $5 million and $500,000 demands by REVil for the decryptor key needed to unlock scrambled networks. The smallest amount demanded appears to have been $45,000.

Sophisticated ransomware gangs on REvil’s level usually examine a victim’s financial records — and insurance policies if they can find them — from files they steal before activating the data-scrambling malware. The criminals then threaten to dump the stolen data online unless paid. It was not immediately clear if this attack involved data theft, however. The infection mechanism suggests it did not.

“Stealing data typically takes time and effort from the attacker, which likely isn’t feasible in an attack scenario like this where there are so many small and mid-sized victim organizations,” said Ross McKerchar, chief information security officer at Sophos. “We haven’t seen evidence of data theft, but it’s still early on and only time will tell if the attackers resort to playing this card in an effort to get victims to pay.”

Dutch researchers said they alerted Miami-based Kaseya to the breach and said the criminals used a “zero day,” the industry term for a previous unknown security hole in software. Voccola would not confirm that or offer details of the breach — except to say that it was not phishing.

“The level of sophistication here was extraordinary,” he said.

When the cybersecurity firm Mandiant finishes its investigation, Voccola said he is confident it will show that the criminals didn’t just violate Kaseya code in breaking into his network but also exploited vulnerabilities in third-party software.

It was not the first ransomware attack to leverage managed services providers. In 2019, criminals hobbled the networks of 22 Texas municipalities through one. That same year, 400 U.S. dental practices were crippled in a separate attack.

One of the Dutch vulnerability researchers, Victor Gevers, said his team is worried about products like Kaseya’s VSA because of the total control of vast computing resources they can offer. “More and more of the products that are used to keep networks safe and secure are showing structural weaknesses,” he wrote in a blog Sunday.

The cybersecurity firm ESET identified victims in least 17 countries, including the United Kingdom, South Africa, Canada, Argentina, Mexico, Indonesia, New Zealand and Kenya.

Kaseya says the attack only affected “on-premise” customers, organizations running their own data centers, as opposed to its cloud-based services that run software for customers. It also shut down those servers as a precaution, however.

Kaseya, which called on customers Friday to shut down their VSA servers immediately, said Sunday it hoped to have a patch in the next few days.

Active since April 2019, REvil provides ransomware-as-a-service, meaning it develops the network-paralyzing software and leases it to so-called affiliates who infect targets and earn the lion’s share of ransoms. U.S. officials say the most potent ransomware gangs are based in Russia and allied states and operate with Kremlin tolerance and sometimes collude with Russian security services.

Cybersecurity expert Dmitri Alperovitch of the Silverado Policy Accelerator think tank said that while he does not believe the Kaseya attack is Kremlin-directed, it shows that Putin “has not yet moved” on shutting down cybercriminals.

——

AP reporters Eric Tucker in Washington, Kirsten Grieshaber in Berlin, Jari Tanner in Helsinki and Sylvie Corbet in Paris contributed to this report.

Adblock test (Why?)



Source link

Continue Reading

Business

Telus prioritizing ‘most important customers,’ avoiding ‘unprofitable’ offers: CFO

Published

 on

 

Telus Corp. says it is avoiding offering “unprofitable” discounts as fierce competition in the Canadian telecommunications sector shows no sign of slowing down.

The company said Friday it had fewer net new customers during its third quarter compared with the same time last year, as it copes with increasingly “aggressive marketing and promotional pricing” that is prompting more customers to switch providers.

Telus said it added 347,000 net new customers, down around 14.5 per cent compared with last year. The figure includes 130,000 mobile phone subscribers and 34,000 internet customers, down 30,000 and 3,000, respectively, year-over-year.

The company reported its mobile phone churn rate — a metric measuring subscribers who cancelled their services — was 1.09 per cent in the third quarter, up from 1.03 per cent in the third quarter of 2023. That included a postpaid mobile phone churn rate of 0.90 per cent in its latest quarter.

Telus said its focus is on customer retention through its “industry-leading service and network quality, along with successful promotions and bundled offerings.”

“The customers we have are the most important customers we can get,” said chief financial officer Doug French in an interview.

“We’ve, again, just continued to focus on what matters most to our customers, from a product and customer service perspective, while not loading unprofitable customers.”

Meanwhile, Telus reported its net income attributable to common shares more than doubled during its third quarter.

The telecommunications company said it earned $280 million, up 105.9 per cent from the same three-month period in 2023. Earnings per diluted share for the quarter ended Sept. 30 was 19 cents compared with nine cents a year earlier.

It reported adjusted net income was $413 million, up 10.7 per cent year-over-year from $373 million in the same quarter last year. Operating revenue and other income for the quarter was $5.1 billion, up 1.8 per cent from the previous year.

Mobile phone average revenue per user was $58.85 in the third quarter, a decrease of $2.09 or 3.4 per cent from a year ago. Telus said the drop was attributable to customers signing up for base rate plans with lower prices, along with a decline in overage and roaming revenues.

It said customers are increasingly adopting unlimited data and Canada-U.S. plans which provide higher and more stable ARPU on a monthly basis.

“In a tough operating environment and relative to peers, we view Q3 results that were in line to slightly better than forecast as the best of the bunch,” said RBC analyst Drew McReynolds in a note.

Scotiabank analyst Maher Yaghi added that “the telecom industry in Canada remains very challenging for all players, however, Telus has been able to face these pressures” and still deliver growth.

The Big 3 telecom providers — which also include Rogers Communications Inc. and BCE Inc. — have frequently stressed that the market has grown more competitive in recent years, especially after the closing of Quebecor Inc.’s purchase of Freedom Mobile in April 2023.

Hailed as a fourth national carrier, Quebecor has invested in enhancements to Freedom’s network while offering more affordable plans as part of a set of commitments it was mandated by Ottawa to agree to.

The cost of telephone services in September was down eight per cent compared with a year earlier, according to Statistics Canada’s most recent inflation report last month.

“I think competition has been and continues to be, I’d say, quite intense in Canada, and we’ve obviously had to just manage our business the way we see fit,” said French.

Asked how long that environment could last, he said that’s out of Telus’ hands.

“What I can control, though, is how we go to market and how we lead with our products,” he said.

“I think the conditions within the market will have to adjust accordingly over time. We’ve continued to focus on digitization, continued to bring our cost structure down to compete, irrespective of the price and the current market conditions.”

Still, Canada’s telecom regulator continues to warn providers about customers facing more charges on their cellphone and internet bills.

On Tuesday, CRTC vice-president of consumer, analytics and strategy Scott Hutton called on providers to ensure they clearly inform their customers of charges such as early cancellation fees.

That followed statements from the regulator in recent weeks cautioning against rising international roaming fees and “surprise” price increases being found on their bills.

Hutton said the CRTC plans to launch public consultations in the coming weeks that will focus “on ensuring that information is clear and consistent, making it easier to compare offers and switch services or providers.”

“The CRTC is concerned with recent trends, which suggest that Canadians may not be benefiting from the full protections of our codes,” he said.

“We will continue to monitor developments and will take further action if our codes are not being followed.”

French said any initiative to boost transparency is a step in the right direction.

“I can’t say we are perfect across the board, but what I can say is we are absolutely taking it under consideration and trying to be the best at communicating with our customers,” he said.

“I think everyone looking in the mirror would say there’s room for improvement.”

This report by The Canadian Press was first published Nov. 8, 2024.

Companies in this story: (TSX:T)

Source link

Continue Reading

Business

TC Energy cuts cost estimate for Southeast Gateway pipeline project in Mexico

Published

 on

 

CALGARY – TC Energy Corp. has lowered the estimated cost of its Southeast Gateway pipeline project in Mexico.

It says it now expects the project to cost between US$3.9 billion and US$4.1 billion compared with its original estimate of US$4.5 billion.

The change came as the company reported a third-quarter profit attributable to common shareholders of C$1.46 billion or $1.40 per share compared with a loss of C$197 million or 19 cents per share in the same quarter last year.

Revenue for the quarter ended Sept. 30 totalled C$4.08 billion, up from C$3.94 billion in the third quarter of 2023.

TC Energy says its comparable earnings for its latest quarter amounted to C$1.03 per share compared with C$1.00 per share a year earlier.

The average analyst estimate had been for a profit of 95 cents per share, according to LSEG Data & Analytics.

This report by The Canadian Press was first published Nov. 7, 2024.

Companies in this story: (TSX:TRP)

The Canadian Press. All rights reserved.

Source link

Continue Reading

Business

BCE reports Q3 loss on asset impairment charge, cuts revenue guidance

Published

 on

 

BCE Inc. reported a loss in its latest quarter as it recorded $2.11 billion in asset impairment charges, mainly related to Bell Media’s TV and radio properties.

The company says its net loss attributable to common shareholders amounted to $1.24 billion or $1.36 per share for the quarter ended Sept. 30 compared with a profit of $640 million or 70 cents per share a year earlier.

On an adjusted basis, BCE says it earned 75 cents per share in its latest quarter compared with an adjusted profit of 81 cents per share in the same quarter last year.

“Bell’s results for the third quarter demonstrate that we are disciplined in our pursuit of profitable growth in an intensely competitive environment,” BCE chief executive Mirko Bibic said in a statement.

“Our focus this quarter, and throughout 2024, has been to attract higher-margin subscribers and reduce costs to help offset short-term revenue impacts from sustained competitive pricing pressures, slow economic growth and a media advertising market that is in transition.”

Operating revenue for the quarter totalled $5.97 billion, down from $6.08 billion in its third quarter of 2023.

BCE also said it now expects its revenue for 2024 to fall about 1.5 per cent compared with earlier guidance for an increase of zero to four per cent.

The company says the change comes as it faces lower-than-anticipated wireless product revenue and sustained pressure on wireless prices.

BCE added 33,111 net postpaid mobile phone subscribers, down 76.8 per cent from the same period last year, which was the company’s second-best performance on the metric since 2010.

It says the drop was driven by higher customer churn — a measure of subscribers who cancelled their service — amid greater competitive activity and promotional offer intensity. BCE’s monthly churn rate for the category was 1.28 per cent, up from 1.1 per cent during its previous third quarter.

The company also saw 11.6 per cent fewer gross subscriber activations “due to more targeted promotional offers and mobile device discounting compared to last year.”

Bell’s wireless mobile phone average revenue per user was $58.26, down 3.4 per cent from $60.28 in the third quarter of the prior year.

This report by The Canadian Press was first published Nov. 7, 2024.

Companies in this story: (TSX:BCE)

The Canadian Press. All rights reserved.

Source link

Continue Reading

Trending

Exit mobile version