Cyber Mayday and the Day After. Daniel Lohrmann
Чтение книги онлайн.

Читать онлайн книгу Cyber Mayday and the Day After - Daniel Lohrmann страница 12

СКАЧАТЬ Services, Intelligence Center, and Division of Homeland and Emergency Security Services – enabled better defenses against cyber threats, protected citizens and government assets, and assured a coordinated, whole-of-state response to cyber incidents.

      From 2018 through 2019, ransomware attacks continued to accelerate in number and sophistication across the United States, targeting hospitals, state and local governments, and schools, causing major operational disruptions and financial impact. New York was not exempt.

      On Saturday, March 30, 2019, the government cyber response team received a call from the City of Albany, which had experienced a major ransomware attack. Servers and workstations had been encrypted, resulting in significant operational impact across multiple systems and services. The attackers were demanding payment in Bitcoin to unlock systems. The City had engaged law enforcement, and FBI investigators were onsite. Within 30 minutes, the Cyber Command Center CIRT team members were onsite, helping City IT staff and the FBI with critical response actions and forensics.

      City officials coordinated response and communications as the investigation and recovery efforts unfolded. The complex interdependencies between systems, data, critical functions, and services that incidents reveal never fail to amaze. Fully understanding these connections and program touchpoints in advance is critical, including linkages to county and state agencies' systems, potential collateral impact on program services, and related third-party dependencies.

      New York's CIRT team responded to a call from the IT director of Lansing High School in Ithaca, reporting the presence of Ryuk ransomware on the school's IT infrastructure. The next call came from the school district in Watertown. They too had suffered a ransomware attack. A similar attack crippled the Syracuse city school district's computer system. Over the next days and weeks, calls were fielded from multiple school districts across New York State.

      The New York State Education Department notified all districts about the cyberattacks and coordinated the response to the incidents in affected educational agencies with the assistance of the State Office of Information Technology Services, CYCOM, and other state cybersecurity teams, including the State Intelligence Center, Division of Homeland and Emergency Security Services, and the Multi-State Information and Analysis Center (MS-ISAC). Briefings with the New York State Department of Education and 11 Regional Information Centers (RICs) ensured that everyone had current information and focused support. The attacks were investigated, and the affected agencies recovered and implemented processes to mitigate recurrence.

      On Christmas Day, 2020, the Albany (NY) International Airport was subject to a ransomware attack, and later paid a ransom to restore access to their data. The ransomware, attributed to a Russian threat actor, had spread to the airport's servers and backup servers from a managed service provider's systems. While the incident reportedly did not impact airport operations, TSA or airline computers, or expose sensitive data, it illustrated the need for organizations to exercise vigilance in protecting against such attacks and manage third-party/supply chain cyber risk exposure.