NATIONAL NEWS

Biden: US Damage Appears Minimal In Big Ransomware Attack

Jul 6, 2021, 8:26 PM | Updated: Jul 5, 2023, 11:28 am

FILE (Photo by Morris MacMatzen/Getty Images)...

FILE (Photo by Morris MacMatzen/Getty Images)

(Photo by Morris MacMatzen/Getty Images)

WASHINGTON (AP) — President Joe Biden said Tuesday that damage to U.S. businesses in the biggest ransomware attack on record appears minimal, though information remained incomplete. The company whose software was exploited said fewer than 1,500 businesses worldwide appeared compromised but cybersecurity experts caution that the incident isn’t over.

Also Tuesday, a security researcher who chatted online with representatives of the Russia-linked REvil gang behind the attack said they claimed to have stolen data from hundreds of companies, but offered no evidence.

Answering a reporter’s question at a vaccine-related White House event, Biden said his national security team had updated him Tuesday morning on the attack, which exploited a powerful remote-management tool run by Miami-based software company Kaseya in what is known as a supply-chain attack.

“It appears to have caused minimal damage to U.S. businesses but we’re still gathering information,” Biden said. “And I’m going to have more to say about this in the next several days.” An official at the Cybersecurity and Infrastructure Security Agency, speaking on condition they not be further identified, said no federal agencies or critical infrastructure appear to have been impacted.

On Wednesday, Biden and Vice President Kamala Harris will lead an interagency meeting to discuss the administration’s efforts to counter ransomware.

White House spokeswoman Jen Psaki held out the prospect of retaliatory action. What Biden told President Vladimir Putin in Geneva last month still holds, she said: “If the Russian government cannot or will not take action against criminal actors residing in Russia, we will take action or reserve the right to take action on our own.”

What sort of action that would be is unclear.

Biden has said repeatedly that the Kremlin bears responsibility for giving ransomware criminals safe harbor, even if it is not directly involved. There is no indication that Putin has moved against the gangs. Psaki said Russian and U.S. representatives were meeting next week and would discuss the matter.

Further underscoring the geopolitical stakes in cyberspace, the Republican National Committee said Tuesday that it had been informed over the weekend that one of its contractors had been breached, though it was not immediately clear by whom. The RNC said no data was accessed.

The contractor, Synnex, initially said that the action “could potentially be in connection with the recent cybersecurity attacks of Managed Service Providers,” a likely reference to the breaches last week. But it backed away from that claim in a second statement late Tuesday.

Friday’s attack hobbled businesses in at least 17 countries. It shuttered most of the 800 supermarkets in the Swedish Coop chain over the weekend because cash registers stopped working, and reportedly knocked more than 100 New Zealand kindergartens offline.

Kaseya said it believes only about 800 to 1,500 of the estimated 800,000 to 1,000,000 mostly small business end-users of its software were affected. They are customers of companies that use Kaseya’s virtual system administrator, or VSA, product to fully manage their IT infrastructure.

Cybersecurity experts said, however, it is too early for Kaseya to know the true impact given its launch on the eve of the Fourth of July holiday weekend in the U.S. They said many targets might only discover it upon returning to work Tuesday.

Ransomware criminals infiltrate networks and sow malware that cripples them by scrambling all their data. Victims get a decoder key when they pay up. Most ransomware victims don’t publicly report attacks or disclose if they’ve paid ransoms. In the U.S, disclosure of a breach is required by state laws when personal data that can be used in identity theft is stolen. Federal law mandates it when healthcare records are exposed.

Security researchers said that in this attack, the criminals did not appear to have had time to steal data before locking up networks. That raised the question whether the motivation behind the attack was profit alone, because extortion through threatening to expose sensitive pilfered data betters the odds of big payoffs.

But Ryan Sherstobitoff, threat intelligence chief of the cybersecurity firm Security Scorecard, said REvil representatives claimed Saturday to have stolen data from hundreds of companies and were threatening to sell it if ransom demands of up to $5 million for bigger victims — they were seeking $45,000 per infected computer — were not met.

“The operators are claiming that, though there is not necessarily direct evidence,” added Sherstobitoff, who said he masqueraded as a victim to engage the criminals. He said the criminals claimed banks were among victims.

REvil offered a universal software decoder to free all victims in exchange for a lump sum payment of $50 million, he added. On Sunday, that sum rose to $70 million in a post on the criminals’ dark web site.

Analysts say the chaos ransomware criminals have wrought in the past year — hitting hospitals, schools, local governments and other targets at the rate of about one every eight minutes — serves Putin’s strategic agenda of destabilizing the West.

Most of the more than 60 Kaseya customers that company spokeswoman Dana Liedholm said were affected are managed service providers (MSPs), with multiple customers downstream.

“Given the relationship between Kaseya and MSPs, it’s not clear how Kaseya would know the number of victims impacted. There is no way the numbers are as low as Kaseya is claiming though,” said Jake Williams, chief technical officer of the cybersecurity firm BreachQuest. Others researchers also questioned Kaseya’s visibility into crippled managed service providers.

The hacked VSA tool remotely maintains customer networks, automating security and other software updates. Essentially, a product designed to protect networks from malware was cleverly used to distribute it.

In an interview on Sunday, Kaseya CEO Fred Voccola estimated the number of victims in “the low thousands.” The German news agency dpa had reported that an unnamed German IT services company told authorities that several thousand of its customers were compromised. Also among reported victims were two Dutch IT services companies.

A broad array of businesses and public agencies were hit, apparently on all continents, including in financial services, travel and leisure and the public sector — though few large companies, the cybersecurity firm Sophos said.

Liedholm, the Kaseya spokeswoman, said the vast majority of the company’s 37,000 customers were unaffected and said the company expected to release a patch Wednesday.

REvil, previously best known for extorting $11 million from the meat-processing giant JBS after hobbling it on Memorial Day, broke into at least one Kaseya server after identifying a “zero day” vulnerability, cybersecurity researchers said.

Dutch researchers said they alerted Kaseya to the zero day and a number of “severe vulnerabilities” ahead of the attack. Neither they nor Kaseya would say how far in advance.

____

Associated Press reporters Darlene Superville and Eric Tucker in Washington and Alan Suderman in Richmond, Virginia, contributed to this report.

KSL 5 TV Live

National News

NEW YORK, NEW YORK - MAY 6: Former U.S. President Donald Trump speaks to the media as he attends hi...

Michael R. Sisak, Jennifer Peltz, Eric Tucker and Jake Offenhartz

Trump fined $1,000 for gag order violation in hush money case as judge warns of possible jail time

The judge presiding over Donald Trump's hush money trial has fined him $1,000 for violating his gag order and sternly warned the former president that additional violation could result in jail time.

2 hours ago

In this photo provided by Mammoth Mountain Ski Area, snow falls in Mammoth Lakes, Calif., Saturday,...

Associated Press

Sierra Nevada records snowiest day of the season from brief but potent California storm

A weekend spring storm that drenched the San Francisco Bay area and closed Northern California mountain highways also set a single-day snowfall record for the season on Sunday in the Sierra Nevada.

13 hours ago

The bridge over Lake Houston, along West Lake Houston Parkway from Kingwood to Atascocita, was clos...

Sara Tonks, Joe Sutton and Paradise Afshar, CNN

Young boy dies in Texas floodwaters as authorities make more than 200 rescues across state

The body of a young boy was recovered from floodwaters near Fort Worth, Texas, on Sunday, as search and rescue teams statewide continue to patrol streets and neighborhoods inundated by rainfall.

14 hours ago

This image released by Universal Pictures shows Ryan Gosling in a scene from "The Fall Guy." (Unive...

Jake Croyle, The Associated Press

‘The Fall Guy’ gives Hollywood a muted summer kickoff with a $28.5M opening

“The Fall Guy,” the Ryan Gosling-led, action-comedy ode to stunt performers, opened below expectations with $28.5 million, according to studio estimates Sunday, providing a lukewarm start to a summer movie season that’s very much to be determined for Hollywood.

17 hours ago

PORTO ALEGRE, BRAZIL - MAY 5:  In this aerial view, flood waters surround the Gremio Arena after he...

Eleonore Hughes, Associated Press

Floods in southern Brazil kill at least 75 people over 7 days, with 103 people missing

Authorities say massive floods in Brazil's southern Rio Grande do Sul state have killed at least 75 people over the last seven days and another 103 are reported missing.

21 hours ago

Man in tuxedo with a white beard and hair...

Brian Melley, Associated Press

Actor Bernard Hill, of ‘Lord of the Rings and ‘Titanic’ has died at 79

Actor Bernard Hill who starred in "The Lord of the Rings" trilogy and "Titanic," has died.

22 hours ago

Sponsored Articles

Side view at diverse group of children sitting in row at school classroom and using laptops...

PC Laptops

5 Internet Safety Tips for Kids

Read these tips about internet safety for kids so that your children can use this tool for learning and discovery in positive ways.

Women hold card for scanning key card to access Photocopier Security system concept...

Les Olson

Why Printer Security Should Be Top of Mind for Your Business

Connected printers have vulnerable endpoints that are an easy target for cyber thieves. Protect your business with these tips.

Modern chandelier hanging from a white slanted ceiling with windows in the backgruond...

Lighting Design

Light Up Your Home With These Top Lighting Trends for 2024

Check out the latest lighting design trends for 2024 and tips on how you can incorporate them into your home.

Technician woman fixing hardware of desktop computer. Close up....

PC Laptops

Tips for Hassle-Free Computer Repairs

Experiencing a glitch in your computer can be frustrating, but with these tips you can have your computer repaired without the stress.

Close up of finger on keyboard button with number 11 logo...

PC Laptops

7 Reasons Why You Should Upgrade Your Laptop to Windows 11

Explore the benefits of upgrading to Windows 11 for a smoother, more secure, and feature-packed computing experience.

Stylish room interior with beautiful Christmas tree and decorative fireplace...

Lighting Design

Create a Festive Home with Our Easy-to-Follow Holiday Prep Guide

Get ready for festive celebrations! Discover expert tips to prepare your home for the holidays, creating a warm and welcoming atmosphere for unforgettable moments.

Biden: US Damage Appears Minimal In Big Ransomware Attack