Skip to main content

WWW.hacked – a signalling

June 28, 2017 | Expert Insights

Companies and agencies across the world were victims to a number of virulent ransomware attacks on June 27.

The attack seems to have specifically targeted Ukranian businesses and Russia’s biggest oil company. India was also affected by these attacks with one of the country’s largest ports shut down operations for the day.

Danish shipping firm Maersk and British advertising agency WPP (WPPGY) were among the global companies that were hacked.

Background

This is actually the second global cyber attack to take place in the recent months. The WannaCry ransomware attack that took place in May 2017, ended up affecting over 250,000 computers in 150 countries in a span of 24 hours. In fact, a code called as Eternal Blue has been used in the both ransomeware attacks. Many believe that this code was stolen from America’s National Security Agency (NSA). It was a serious attack with the infrastructure of critical organizations being hit including Britain’s National Health Service.

Even individual companies have fallen victim to cyber threats. In May, India’s top tech company, Wipro received an anonymous mail that threatened the safety of its employees. The mail stated that if the company did not pay a ransom of Rs 500 crore in bitcoins, then a fatal biological agent would be released.

However, such attacks or threats aren’t recent. As early as 1988, Robert Tappan Morris created the Morris Worm, one of the first worms to be transmitted through computers. Morris was a student of Cornell University and said that he had only wanted to determine the vastness of the cyber world. As a result about 6,000 computers were damaged.

Analysis

To understand just how expansive these attacks were, it is important to look at the targets:

  • Ukrainian firms, including the state power company and Kiev’s main airport – critical infrastructure.
  • The Chernobyl nuclear plant – critical infrastructure.
  • The Ukrainian central bank, the aircraft manufacturer Antonov, and two postal services – critical infrastructures.
  • Russia’s biggest oil producer, Rosneft – critical infrastructure.
  • Danish shipping company Maersk – transportation.
  • Heritage Valley Health System, a Pennsylvania-based hospital operator – health care.  
  • Spanish food giant Mondelez – food.
  • TNT, a Netherlands based shipping company – logistics.
  • St Gobain, a French construction company – construction.
  • Merck, a US pharmaceuticals maker   - pharmaceuticals.

Assessment

Our assessment is that this is clear signalling from the perpetrators that they can attack across all verticals and paralyze vital systems across the world. The fact the hackers asked for paltry amount as ransom ($300), shows that it wasn’t money that they were after. They wanted to make a statement. And they have signalled the world. It is also important for countries like India to be mindful that this theatre of attack can move from Ukraine to our shores.