lemmy.mlaga97.space
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Zerush@lemmy.ml to Security@lemmy.ml · 1 month ago

‘If you are reading…’: This password ‘mistake’ shuts down a 158-year-old company

www.hindustantimes.com

external-link
message-square
5
link
fedilink
0
external-link

‘If you are reading…’: This password ‘mistake’ shuts down a 158-year-old company

www.hindustantimes.com

Zerush@lemmy.ml to Security@lemmy.ml · 1 month ago
message-square
5
link
fedilink
Access Denied
www.hindustantimes.com
external-link
alert-triangle
You must log in or # to comment.
  • Petter1@discuss.tchncs.de
    link
    fedilink
    arrow-up
    0
    ·
    1 month ago

    This article is so long and and has so few information 🙉

    • Zerush@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      1 month ago

      Andi’s writeup

      A weak employee password led to the collapse of KNP, a 158-year-old British transport company, after hackers from the Akira ransomware group gained access to their systems in 2023[1]. The attackers encrypted the company’s data and left a ransom note stating “If you’re reading this, it means the internal infrastructure of your company is fully or partially dead”[2].

      Unable to pay the estimated £5 million ransom demand, KNP lost all its financial records and operational data[1:1]. Despite having cybersecurity insurance and industry-standard IT protections, the company went into administration three months after the attack, resulting in 730 job losses[3].

      “We need organisations to take steps to secure their systems, to secure their businesses,” said Richard Horne, CEO of the National Cyber Security Centre[1:2]. The hackers gained entry through a “brute force” attack by guessing one employee’s password - a person who was never told they were the weak link that led to the company’s demise[4].


      1. Weak password allowed hackers to sink a 158-year-old company - BBC ↩︎ ↩︎ ↩︎

      2. The Times - My company thrived for 150 years ↩︎

      3. The Straits Times - How a ransomware attack caused a British company to go bust ↩︎

      4. The Times - My company thrived for 150 years ↩︎

  • That Weird Vegan@lemmy.blahaj.zone
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    dang. I use a password manager, and all my important passwords are 30-40 chars long. Lesson learnt?

    • Zerush@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      1 month ago

      Passphrase and 2FA , better an physical token access, is the minimum in a company, apart a backup of all important data. These hackers are in need to be send a Guantanamo, but also the IT employees of this company, a weak password without 2FA and backups are also a crime in a company.

  • flatbield@beehaw.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    1 month ago

    If one password can take down the company, you do not have sane security. That is just stupid.

Security@lemmy.ml

security@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !security@lemmy.ml

Confidentiality Integrity Availability

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 1 user / day
  • 2 users / week
  • 7 users / month
  • 33 users / 6 months
  • 0 local subscribers
  • 6.05K subscribers
  • 292 Posts
  • 324 Comments
  • Modlog
  • mods:
  • ghost_laptop@lemmy.ml
  • BE: 0.19.12
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org