<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Shuttering a business the hard way. in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Shuttering-a-business-the-hard-way/m-p/19018#M2231</link>
    <description>&lt;P&gt;Clearly, who ever did it has inside information.&amp;nbsp; Could have been operating inside.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Motive is unclear.&amp;nbsp; Maybe a disgruntled employee, or someone else wanting to hurt the company.&amp;nbsp; Strange they didn't want to extort money from them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 13 Feb 2019 18:29:49 GMT</pubDate>
    <dc:creator>emb021</dc:creator>
    <dc:date>2019-02-13T18:29:49Z</dc:date>
    <item>
      <title>Shuttering a business the hard way.</title>
      <link>https://community.isc2.org/t5/Industry-News/Shuttering-a-business-the-hard-way/m-p/19017#M2230</link>
      <description>&lt;P&gt;Only the best business plans have an exit strategy when the business has exceeded it's design and needs to be closed. This &lt;A href="https://www.itpro.co.uk/security/32972/us-email-provider-wiped-out-by-hacker" target="_blank" rel="noopener"&gt;company&lt;/A&gt;&amp;nbsp;probably didn't have in mind what happened to them.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For those of you who read the article I'm curious what you think of the incident. I think it had to be a disgruntled employee.&amp;nbsp; What do you think?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 17:37:25 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shuttering-a-business-the-hard-way/m-p/19017#M2230</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2019-02-13T17:37:25Z</dc:date>
    </item>
    <item>
      <title>Re: Shuttering a business the hard way.</title>
      <link>https://community.isc2.org/t5/Industry-News/Shuttering-a-business-the-hard-way/m-p/19018#M2231</link>
      <description>&lt;P&gt;Clearly, who ever did it has inside information.&amp;nbsp; Could have been operating inside.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Motive is unclear.&amp;nbsp; Maybe a disgruntled employee, or someone else wanting to hurt the company.&amp;nbsp; Strange they didn't want to extort money from them.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 18:29:49 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shuttering-a-business-the-hard-way/m-p/19018#M2231</guid>
      <dc:creator>emb021</dc:creator>
      <dc:date>2019-02-13T18:29:49Z</dc:date>
    </item>
    <item>
      <title>Re: Shuttering a business the hard way.</title>
      <link>https://community.isc2.org/t5/Industry-News/Shuttering-a-business-the-hard-way/m-p/19020#M2233</link>
      <description>&lt;P&gt;My little brother didn't trust GMail, so almost all of his various email addresses/accounts were on &lt;A href="https://thehackernews.com/2019/02/vfemail-cyber-attack.html" target="_blank" rel="noopener"&gt;VFEmail.net&lt;/A&gt;.&amp;nbsp; I guess I'll have to wait until he sends me a message from some new platform&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(Possibly one of the reasons I have multiple accounts on at least six different platforms ...)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;(On at least two continents&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Disgruntled employee" sounds likely, particularly since the different servers had different authentications.&amp;nbsp; (Finding someone who had all those authentications shouldn't be hard.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On the forum, someone said that the story set off all his conspiracy theory alarms.&amp;nbsp; He also posited that, if you had broken into a system and were using it for other attacks, you might just flatten the thing on your way out, to destroy any evidence.&amp;nbsp; Hacked systems are just so cheap, these days.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The fact that no ransom was demanded is also another possible indicator of "disgruntled employee."&amp;nbsp; Which brings me to my recommendation for ransomware and many, many other forms of attack: backup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Backup, backup, backup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The oldest protection in the book, possibly the most effective, and the one that everyone has (mostly invalid) reasons that they don't use.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I know the backup servers were formatted as well.&amp;nbsp; That just means you use other forms of backup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've got an external drive that's semi-permanently attached and running a Windows backup program. It's supposed to backup any changes every fifteen minutes. I don't really trust it, but I've recovered stuff off it occasionally. I don't really trust it because it's attached. Like in the VFEmail case, I figure if I can get at it without plugging in cables, so can the bad guys. I figure the same goes for other machines on the LAN or online or cloud drives or storage systems. I do keep my "current" presentations on Google Drive, just in case.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The one I really rely on is an old Passport drive. I have to plug it in to make a backup. I do it sporadically, and probably not as frequently as I should, but it's been surprisingly effective. That drive is, itself, backed up on to external and non-connected laptops. (Well, at this point, laptop. It's on the Windows laptop. It used to be on the Mac as well, but the Mac had a corruption breakdown recently, and I replaced the drive. Since I keep all my old drives [hey, I'm an old malware researcher, and I've got samples and zoos all over the place, so just sending them to recycling would be a bit irresponsible] then I guess it is still backed up on a very external drive.)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I got a "credit card" USB drive at a show, recently, and I keep it in my wallet. It's pig slow, so I don't do backups on it as much, but I do keep my current presentations on it, and, at the moment as I writing this, I'm backing up all my email onto it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;OK, this is all just to back up my own stuff, and I couldn't keep masses of corporate data in my wallet.&amp;nbsp; (Although it's surprising how much of the most important stuff you &lt;STRONG&gt;can&lt;/STRONG&gt; put on there.)&amp;nbsp; But the point is the same: backups can save your backside, and a little thought and imagination is more important than million dollar contracts on remote hot sites.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 19:03:26 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shuttering-a-business-the-hard-way/m-p/19020#M2233</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-13T19:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Shuttering a business the hard way.</title>
      <link>https://community.isc2.org/t5/Industry-News/Shuttering-a-business-the-hard-way/m-p/19030#M2238</link>
      <description>&lt;P&gt;It could have been a cover up for something else going on internally to protect the integrity of the organisations business or associates?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Caute_cautim&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 21:28:40 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shuttering-a-business-the-hard-way/m-p/19030#M2238</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2019-02-13T21:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: Shuttering a business the hard way.</title>
      <link>https://community.isc2.org/t5/Industry-News/Shuttering-a-business-the-hard-way/m-p/19043#M2239</link>
      <description>&lt;P&gt;OK, this story still needs some work.&amp;nbsp; My brother, who I mentioned has lots of VFEmail accounts, says that, while he lost email sent/received during a certain period, can access his (new) email, although only via Web access ...&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 23:36:21 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shuttering-a-business-the-hard-way/m-p/19043#M2239</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-13T23:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: Shuttering a business the hard way.</title>
      <link>https://community.isc2.org/t5/Industry-News/Shuttering-a-business-the-hard-way/m-p/19146#M2249</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Securing backups often involves keeping them offline --- that way, you have to access them physically to do any damage. If all this has been the result of an attacker 'formatting everything' --- as was described --- then it's clear that the company's security was lax. We could have a disgruntled employee working by himself, an outsider having an accomplice on the inside, or else an outsider taking advantage of bad security.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Motivations can vary: if there's no ransom demand, it's not necessarily a disgruntled employee --- it might be an external party who's been well compensated by a competing organisation, or perhaps even someone who doesn't treasure financial benefits...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, an organization might be more likely to claim it's been the victim of cyber-attacks, rather than admit that its&lt;FONT face="inherit"&gt;&amp;nbsp;infrastructure was so &lt;/FONT&gt;poorly&lt;FONT face="inherit"&gt;&amp;nbsp;secured that internal factors were to blame.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 16 Feb 2019 14:25:34 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Shuttering-a-business-the-hard-way/m-p/19146#M2249</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2019-02-16T14:25:34Z</dc:date>
    </item>
  </channel>
</rss>

