Technology
Cheapskates wouldn't pay for security help, got hit by ransomware, and went bust months later
Key Points
Welcome back to PWNED, the weekly column where we highlight some of the lowlights in corporate security. This week, we’ll talk about two scenarios, one that ended in tragedy and another that shows the power of a good defense over dedicated phishing attacks. Have a story about someone leaving a gaping hole in their network?
Welcome back to PWNED, the weekly column where we highlight some of the lowlights in corporate security. This week, we’ll talk about two scenarios, one that ended in tragedy and another that shows the power of a good defense over dedicated phishing attacks. Have a story about someone leaving a gaping hole in their network? Share it with us at [email protected]. Anonymity is available upon request. Both stories come courtesy of Dave Hatter, a cybersecurity and compliance consultant with Intrust IT. In his many years of experience with the company, Hatter has had to work for a variety of small companies that needed help with their security, whether they knew it or not. One time several years ago, the new CFO at a small construction company phoned Intrust and expressed interest in hiring them. However, the proposal was vetoed by the owner of the company, an older gentleman who thought his business was too small to interest hackers and that his existing, one-person IT staff was all he could afford. “We got a guy, my brother’s uncle’s cousin does my IT, don’t need you guys,” Hatter quotes the owner as saying. “We hear this all the time. Thanks for shopping. You’re too expensive.” Three weeks later, Hatter got a call from a local accountant friend who begged him to help a client who'd been hit with a ransomware attack. Hatter said he couldn’t really give more than general guidance, but would talk to the victim anyway. As soon as he called the number, Hatter realized that the ransomware victim was actually the same construction company that had turned down his services a few weeks earlier. The business had an old unpatched Windows server that contained all its most important data. There was a backup drive, but it was connected to the same server, so both devices were encrypted by the ransomware. “Their entire backup is this external drive, which, of course, is now encrypted,” Hatter said. “So, literally, they can't pay their employees. They don't know who owes them money.” Hatter could not help the company, and he never found out whether it paid the ransom. However, the org, which had been around for years, went out of business within months. This sad story shows the importance of having real backups that are off-site or in the cloud and patching whatever servers you have. You can never assume that your company is too small to be attacked because ransomware gangs want your money and they are just as happy to take on small businesses as large ones, which are likely to be harder targets. The other incident involved two companies in the landscaping and construction business. Somebody broke into an executive’s email account at company one and started sending phishing emails to company number two. The miscreants had also set up email filtering rules in the first company’s account so that the messages from the phishing campaign were routed to buried folders where the real-life account holder would never see them. The phishing mails took the form of RFPs (requests for proposal) – a perfect lure, because who wouldn't want new business? They were perfectly crafted, with no grammar errors or obvious tells, and the return address matched company one's. However, instead of attaching the RFP as a PDF or PowerPoint file, it had a button for the user to click to download it. “If I can get in your email and send out emails as you, the recipients, especially if they've interacted with me before, aren't going to have any guard up,” Hatter said. “Especially if there's no crazy language or crazy requests in there because they've got an email from me before.” Upon clicking the download button, the user was transported to a Microsoft 365 login screen that looked identical to the real one but was not on the microsoft.com domain. The user was then invited to put in their email address and password to gain access to the desired file. Because the user had 2FA, this fake page also asked them for their limited-time 2FA code. Behind the scenes, the threat actors were transmitting the login to Microsoft so that Microsoft itself would send an SMS message to the victim at company number two. Then the victim would pass along the one-time passcode via the fake login site. A classic man-in-the-middle attack. It worked, and the threat actors now had access to the Microsoft 365 account and email for the victim at company number two. This could've allowed them to do almost anything using that person’s email. If the victim had access to bank accounts or customer data, the attackers could have initiated password resets from the account, then conducted fraudulent money transfers, or stolen personal information. At the very least, they could've used the victim's account to phish other contacts. Fortunately, Hatter's client had installed a piece of software his company made called TarBot, which runs in the Microsoft 365 environment and uses Entra ID P2 to help customers identify suspicious logins. “It throws off a bunch of telemetry, statistics, metrics, whatever you want to call it, that allows our software to say, this is an anomalous login, revoke the token, and make the user log in again,” Hatter said. He said his company is not the only one to make apps like TarBot that detect suspicious logins. So the bad guys were kicked out after just a few minutes. But Hatter says the better way to stop these attacks is to use phishing-resistant MFA, such as hardware keys (like the YubiKey line) or passkeys. With today’s AI-assisted phishing, telltale signs such as bad grammar or obviously fake login pages are becoming few and far between. ®