Slashdot Mirror


Ransomware Completely Shuts Down Ohio Town Government (techcrunch.com)

An anonymous reader quotes a report from TechCrunch: In another interesting example of what happens when you don't manage your backups correctly, the Licking County government offices, including the police force, have been shut down by ransomware. Although details are sparse, it's clear that someone in the office caught a bug in a phishing scam or by downloading it and now their servers are locked up. Wrote Kent Mallett of the Newark Advocate: "The virus, accompanied by a financial demand, is labeled ransomware, which has hit several local governments in Ohio and was the subject of a warning from the state auditor last summer. All county offices remain open, but online access and landline telephones are not available for those on the county system. The shutdown is expected to continue at least the rest of the week." The county government offices, including 911 dispatch, currently must work without computers or office phones. "The public can still call 911 for emergency police, fire or medical response," wrote Mallett.

106 comments

  1. Automatically fired by Anonymous Coward · · Score: 1

    Everyone there should be replaced automatically when this happens. It would probably only happen once, and then never again.

    1. Re:Automatically fired by Anonymous Coward · · Score: 0

      And the perpetrators should be tried for treason.

    2. Re:Automatically fired by Anonymous Coward · · Score: 0

      No. Only everyone working in IT should be fired. If IT is outsourced to another country, whoever made that decision should be fired.

    3. Re:Automatically fired by Anonymous Coward · · Score: 0

      Only if IT is allowed to override bonehead decisions made by others, including their supervisors.

    4. Re:Automatically fired by Anonymous Coward · · Score: 0

      And the perpetrators should be tried for treason.

      Tried? You're far too generous. I propose they be beaten with 2x4 clue sticks until dead.

    5. Re:Automatically fired by Anonymous Coward · · Score: 2, Informative

      No. Only everyone working in IT should be fired.

      How about whomever overrode the IT department with regards to security?

      "Nah, that makes it too hard to do our jobs. Just use one shared admin account that is always logged in on all machines, so we can just do whatever we need to..."

    6. Re:Automatically fired by GerryGilmore · · Score: 4, Insightful

      Sadly, a typical reaction today... Fire/LockUp/Execute Everyone Even Remotely Connected to Scandal-De-Jure...FFS, most of these same commenters also want to "shrink government", "cut taxes", etc. NONE of which is going to: improve training and testing; expand, fund and enforce standards across municipalities; enhance LEO capabilities to track and prosecute attackers. But - Hey! - we get to sound awful tough!!

    7. Re:Automatically fired by rubycodez · · Score: 3, Insightful

      Wrong, town would be without protection is all that would happen with your stupid juvenile solution. Most those people can't be expected to be IT experts, and in fact this situation proves that services can exist without a computer in sight.

      Wrong to say backups are a solution, you could the malware nicely backed up too.

    8. Re:Automatically fired by K.+S.+Kyosuke · · Score: 1

      Everyone there should be replaced automatically when this happens.

      In theory, yes. But they probably don't have backups for them. ;)

      --
      Ezekiel 23:20
    9. Re:Automatically fired by TechyImmigrant · · Score: 1

      Wrong to say backups are a solution, you could the malware nicely backed up too.

      Not if you do it in a way that is safe from ransomware.

      1) Make your backup system safe from ransomware by limiting the software run on it and have only skilled IT people operate it.
      2) Give the backup system the privilege to pull the backup data from the machines being backed up and to push the restore data.
      3) Don't give the machines being backed up the privilege to push data to the backup system to ransomware can't corrupt the backups.
      4) Restore every night so you know the restore will work. Have the backup system push a clean image and the applications to each PC and check the consistency of the databases and restore them if they are corrupted.
      5) ????
      6) Profit!

      --
      I should use this sig to advertise my book ISBN-13 : 978-1501515132.
    10. Re:Automatically fired by CaptainDork · · Score: 3, Informative

      Treason is vacuous in this context (and all others right now).

      Article III, Section 3:

      Treason against the United States, shall consist only in levying war against them, or in adhering to their enemies, giving them aid and comfort. No person shall be convicted of treason unless on the testimony of two witnesses to the same overt act, or on confession in open court.

      The Congress shall have power to declare the punishment of treason, but no attainder of treason shall work corruption of blood, or forfeiture except during the life of the person attainted.

      No one in this matter is a United States citizen who has declared war against the United States. The last time that happened was the Civil War.

      The United States does not have any enemies. There is no list of enemies. The last time the United States had an enemies list was World War II.

      This also explains why Snowden could not be charged with treason.

      --
      It little behooves the best of us to comment on the rest of us.
    11. Re:Automatically fired by Anonymous Coward · · Score: 0

      I'm not even sure it's helpful.

      If we fired everyone that ever screwed up with a computer we might as well just raise the unemployment level to 100% now. Computers are getting so ridiculously complex that the chances you're doing everything absolutely correct with respect too all known best practice is flat nil. Best practice is a hotly-debated controversial opinion/debacle spread around virulently and deprecated judiciously, but Google search doesn't know that. Nobody knows what best practice could possibly be.

      But okay, lets assume these guys are complete uber-geniuses and they've figured it all out...they're being lazy, fire em.

    12. Re:Automatically fired by El+Cubano · · Score: 3, Informative

      most of these same commenters also want to "shrink government", "cut taxes", etc. NONE of which is going to: improve training and testing; expand, fund and enforce standards across municipalities; enhance LEO capabilities to track and prosecute attackers. But - Hey! - we get to sound awful tough!!

      Actually, it is not difficult to accomplish both. For example, you could shrink government substantially by implementing a national retail sales tax (lots of conservative lawmakers have proposals, so there plenty of choices) and replacing the entire IRS with something like a 10-20 person office responsible for processing sales tax receipts (this would actually be super easy since sales tax is already collected in something like 99.9% of the US). You could also eliminate entire executive departments that don't actually do anything productive (like education; seriously, the more money the federal government spends on education, the worse it gets, so we should try something different). Those two changes alone would free up considerable funding to apply to the items you list and would result in a net smaller federal government that is also leaner (as defined by doing more of what government should do, like LEO, and less of what it shouldn't, like anything not specifically listed in the constitution). And that is without even touching the sacred cows of social security and medicare.

    13. Re:Automatically fired by PopeRatzo · · Score: 1

      Treason is vacuous in this context

      You're absolutely right. It's not treason. It's an act of war.

      But you know the old saying, In Soviet USA, you ransom government.

      --
      You are welcome on my lawn.
    14. Re:Automatically fired by Anonymous Coward · · Score: 0

      Did you know that federal income tax doesn't go to infrastructure but instead to national debt to IMF banks?

      Reagan's "goldstone" report proves all of this iirc. Look it up get wise to how the IMF globalist bankers are hosing you all in the USA people.

      Did you know that your federal income tax (voluntary one in its founding, not mandatory by law) is stolen prior to you volunteering it??

      IRS agents looking to enforce it and could not by law have even said so, look it up! They themselves refuse to pay federal portions.

      Not 1 cent is used for you but is also being robbed from you for robbing the united states by the 'federal reserve' established shortly before the IRS (how odd right? Not) for these not even really legal taxes NOT ratified by a majority of Congress (during an X-Mas vacation by the fool Wilson) who have also taken Fort Knox's gold and given it to the treasury dept. to "safekeep" (what's wrong w/ Ft. Knox)?

      Knowledge is power.

      When you hear big central government isn't good? This is part of why.

    15. Re:Automatically fired by sjames · · Score: 1

      That's why you need a rolling offline backup. You might lose the day before yesterday's backup, but you'll still have yesterday's.

    16. Re:Automatically fired by CaptainDork · · Score: 1

      Nah.

      It's other stuff like money laundering, extortion, illegally accessing a computer and "other," but not an act of war.

      This is an act of war:

      Act of War Law and Legal Definition

      An act of war is an action by one country against another with an intention to provoke a war or an action that occurs during a declared war or armed conflict between military forces of any origin. The loss or damage caused due to such conflicts are excluded from insurance coverage except for life assurances.

      I'm certain you'll be interested to know that the state of California has just taken steps to make ransomeware illegal.

      --
      It little behooves the best of us to comment on the rest of us.
    17. Re:Automatically fired by UltraZelda64 · · Score: 1

      Wait--so you're saying that being beaten with clue sticks too much could even be hazardous to your health when done in excess? I swear, is *anything* fucking safe these days?!?

    18. Re:Automatically fired by stealth_finger · · Score: 1

      The United States does not have any enemies. There is no list of enemies. The last time the United States had an enemies list was World War II.

      This also explains why Snowden could not be charged with treason.

      Of course they do, now the list just reads muslims in scrawny handwriting and a squiggle that looks like it might say gays. Also did you forget about Russians, Korea, Vietnam, Desert Storm 1 & 2 and all the other jaunts the US military have been on since ww2?

      --
      Wanna buy a shirt?
      https://www.redbubble.com/people/stealthfinger/shop?asc=u
    19. Re: Automatically fired by Anonymous Coward · · Score: 0

      Okay, just shoot them and we'll figure out what to call it later...

    20. Re:Automatically fired by Anonymous Coward · · Score: 0

      "The United States does not have any enemies. There is no list of enemies."

      There is a list of enemies. Only we call it the US census.

    21. Re:Automatically fired by orlanz · · Score: 1

      Ok, looking at the other poster's Wiki link, what I got on that report:
      1/3 of tax revenues are wasted by govt ops
      1/3 aren't collected because people don't pay what they owe
      1/3 are used to pay interest on the national debt

      It predicted that our debt will be 13Trillion by 2000 but that didn't occur till the Housing bubble burst in 2008. For a 15 year forecast, 8 years off ... is kind of bad. Nor does the report take into consideration or provide recommendations to the impact of Congress varying tax rates or the economy's performance.

      1/3 is wasted. This is pretty much true of ALL large organizations. Not just governments. And before people bring up private vs public funds... If your primary customer is the government (Lockheed), you are a country's darling industry (GM, Chrysler, Steel workers), or just too big to fail (Chase, Wells Fargo, Citigroup) the emergency funds are all tax payers'. Even their suppliers are supported by tax payers.

      1/3 is not paid. Right, you are arguing that the government steals our money, wastes it, and provides nothing in return. But the primary reason for nothing in return is that 1/3 don't pay what they owe? This would go up if we switched to only a sales tax like the grand parent says.

      1/3 is used to pay national debt. Its silly how people talk about national debt; like its a singular metric used to define government inefficiencies. Its the flip side of but the same as how people argue about the performance of a company based on revenue increases; never taking into consideration the many other factors in play.

      But paying off debt is easy; we can always just print money. But we don't, because it would hurt the US citizen the most. Because most of the national debt is to ourselves. Far more (2/3s) so than all the foreign nations & entities combined! But really, why are we complaining that others are willing to lend us money to invest in our economy? If they feel we are risky or bad, they will either make it unaffordable or not lend us. The debt stays in a band of efficiency all by itself. Go too high, we print money; go too low, interest rates tank.

      The report is basically bullshit and Congress rightfully ignored it.

      BTW, Tax Withholdings are actually mandatory by law since 1943. The President vetoed it, but Congress passed it. Meaning the State reps overrode the Federal in passing that law. Most states also have Tax Withholdings. So do some cities! Its a fair way for the public (aka government) to collect revenues to pay for the daily services you consume. The alternatives are to pay up front for the year's services, or the federal government takes a loan that is serviced by the year end collection. Without continuous collections to pay continuous services, the public would actually be more in debt. Additionally, most people aren't disciplined enough to actually save their salary to pay their taxes. So the number of people NOT paying their fair share would go up if all collections happened on Jan/April.

      Finally, you can OPT out of most monthly Withholdings! You can elect allowances to reduce the Withholdings. You can even file an Exemption from all Federal Withholdings if you don't own taxes! But of course within a certain margin, you must still pay your total year's worth of taxes on a regular quarterly basis. But the power is entirely within your hands to push your tax payments to the last minute possible. You don't have to pay too much every month and get the extra back a year later.

      Knowledge IS power!

      Also, Ft Knox would be the epitome of "big central government". Federal Reserve is decentralized governance backed by tax payers. Individual banks would be like little governments.

    22. Re:Automatically fired by Anonymous Coward · · Score: 0

      water boating is...

    23. Re:Automatically fired by apoc.famine · · Score: 2

      The problem with a sales tax is that it's inherently regressive. If you live paycheck-to-paycheck, something like 50% of your money gets taxed. (Assuming the other 50% is rent, debt payments, utilities, etc.) If you make upper middle-class or higher income, and you can bank or invest half of that, with the same ratio for the rest of it, you're getting taxed on 25% of your money.

      The more you make, the less you're proportionally taxed. So someone making $20k/year may be taxed on $10k of it, while someone making $200k (10x as much) may only be taxed on $50k of it. (5x the tax for 10x the income.)

      This is why tax codes get so crazy. If you want people to pay a proportional amount of their income in tax, you need the tax code. But that usually means that you need to tax the poor to unreasonable levels to get the money you need. So then more laws are needed to shift collections from the poor to the rich, so that you're extracting a reasonable amount from both groups. And then the rich don't like that, so they bribe (or are) lawmakers and get loopholes put in to shelter money, and, that's where we are today.

      --
      Velociraptor = Distiraptor / Timeraptor
    24. Re:Automatically fired by budgenator · · Score: 1

      Not if you do it in a way that is safe from ransomware.

      If your going to do ransomware, you set it up so it infects the network well before it encrypts the file systems. The ransomware will then be on all of your backups so even if you rebuild from bare metal, as soon as you restore from backups your reinfected.

      --
      Apocalypse Cancelled, Sorry, No Ticket Refunds
    25. Re:Automatically fired by moeinvt · · Score: 1

      Check out the Fair Tax It's a consumption tax, but overcomes the regressive nature of a general sales tax by providing a tax "prebate" up to a certain income threshold.

      Under the fair tax, the government would send everyone a check at the beginning of the year in the amount that a person with $X of income would pay in consumption taxes over the course of the year. If the tax was 8%, and the income threshold was $20k, every household would get a $1,600 check. Thus, a household at that exact income level would pay $0 in tax.

      The fair tax also has the benefit of making domestic goods more competitive because taxes would not be baked in to the prices. Something like the fair tax is really the best way to go. Unfortunately, the voluminous income tax code is the politicians' favorite method of handing out favors to wealthy special interests, so we'll probably never see it happen.

    26. Re:Automatically fired by MachineShedFred · · Score: 1

      Yeah, but those weren't actually declared wars. They were 'police actions' or 'armed conflicts' or some other trite bullshit.

      Calling something what it actually is brings forth a whole new section of laws and regulations that nobody involved wants to deal with. So they skip it.

      --
      Slashdot still doesnâ(TM)t support Unicode after it was added to the HTML standard in 1997.
    27. Re:Automatically fired by MachineShedFred · · Score: 1

      I see what you did there, but this is probably a bit closer to the real list.

      --
      Slashdot still doesnâ(TM)t support Unicode after it was added to the HTML standard in 1997.
    28. Re:Automatically fired by MachineShedFred · · Score: 1

      Yeah, so this is why you put in place policies to restrict the amount of damage that can be done by ignorance, or a bad actor.

      Step 1: Nobody should be logging in interactively as an administrative user. UNIX / Linux / OS X has sudo, Windows has 'run as administrator...'
      Step 2: Everything should be running a firewall that has everything closed by default, and only things that need to receive traffic whitelisted. This firewall and it's rules should be actively monitored and maintained by some kind of automated configuration management.
      Step 3: Any organization that is at all serious about network security should have an authenticated proxy server for outbound traffic, and that proxy should be the only thing allowed to talk to the Internet without a security review. Use this proxy to block known bad actors on the Internet.

      That would drastically reduce the amount of exposure to attack, and it's unlikely that this county office has done any of them, much less all of them.

      --
      Slashdot still doesnâ(TM)t support Unicode after it was added to the HTML standard in 1997.
    29. Re:Automatically fired by TechyImmigrant · · Score: 1

      The clean image should help with that.

      --
      I should use this sig to advertise my book ISBN-13 : 978-1501515132.
    30. Re:Automatically fired by CaptainDork · · Score: 1

      This.

      Again, the last declaration of war was World War II - related. (There have been 11 total declarations of war in US history.)

      There are also diplomatic reasons for a dislike of "declaring war" on a country, as it can often be perceived as holding an entire nation responsible for the actions of a few of its citizens. In the case of the most recent public opposition, those who support such actions have noted that, in the case of the wars in Afghanistan and Iraq, there was no 'target' for a legal declaration of war, rather political groups or individuals. On the other hand many argue that since an invading army seeks to occupy and cause havoc to a target country and its population and not just a political group or individual, the aforementioned justification is tenuous at best.

      --
      It little behooves the best of us to comment on the rest of us.
    31. Re:Automatically fired by stealth_finger · · Score: 1

      That's true but you said the US has no enemies, not hasn't been at war. I would argue you can have lots of enemies without being at war with anyone, especially when conducting "police actions"

      --
      Wanna buy a shirt?
      https://www.redbubble.com/people/stealthfinger/shop?asc=u
    32. Re:Automatically fired by CaptainDork · · Score: 1

      I would argue ...

      Not in court.

      --
      It little behooves the best of us to comment on the rest of us.
    33. Re:Automatically fired by Anonymous Coward · · Score: 0

      There are ways to fix it, like making sales tax apply to every possible purchase. Buy stock? Sales tax. Buy mutual fund? Sales tax. Buy property? Sales tax. Anything you spend money on gets a sales tax applied to it. Keep going until you figure out how to apply a tax the circuitous and complicated system the Walton heirs are using to avoid taxes the system will be complete. Because even the Waltons are paying taxes, the tax rate can drop tremendously.

      The chance of this actually coming about though is virtually nil because the proponents of this system want to use it to avoid taxes, not pay them.

    34. Re:Automatically fired by rubycodez · · Score: 1

      And someday find the malware infected you on day n+y where n is the number of days you have backed up

    35. Re:Automatically fired by rubycodez · · Score: 1

      you are funny, you fail at the step one. That would be the step applied to normal production system but those STILL can get malware

    36. Re:Automatically fired by sjames · · Score: 1

      You can play that game forever, ending with what happens if the quantum vacuum collapses to a lower state, what will you do then, Huh!, HUH!

      Of course, would you rather restore to a state where you had your data but there's a virus about to wipe it again, then try to kill the virus or would you rather just lose it all with no chance?

      Risk will NEVER be zero. The objective is to take a few steps that can reduce the risk by orders of magnitude. With N=2 backups, you greatly reduce your risks. Add in less archiving of your backup and immediate archiving of any data you know will be needed for years (such as video evidence of a crime), and you reduce the risks another few orders.

  2. Found the LUDDITES! by Anonymous Coward · · Score: 0

    If these LUDDITES used appy app apps instead of LUDDITE software, then LUDDITE hackers would get apped, because only apps can app apps!

    Apps!

  3. Imagine all the cowards by Anonymous Coward · · Score: 1

    A government made up entirely of ACs. What a glorious immolation...

    "This smouldering cinder patch was the result of the Great Social Experiment."

    Bless your little souls

    1. Re:Imagine all the cowards by Anonymous Coward · · Score: 0

      "Citizen, you have been randomly selected to vote for or against the following legislation. All votes are anonymous. You have two weeks to familiarize with the subject matter by reading the provided preparatory material or material from any arbitrary source. Voting is mandatory. Voting is duty. Voting is honor."

  4. How much does it take? by Anonymous Coward · · Score: 0

    Ransomware locked states, or the federal government? Maybe the Chinese industry could help to reduce the software and hardware monoculture in the US. ;)

  5. So in Licking.... by surfdaddy · · Score: 2

    ...things are not still Ticking!

    1. Re:So in Licking.... by rtb61 · · Score: 2

      Actually technically speaking they are, this is really a high risk game, across international boundaries, it is extremely problematic. They will find a while bunch of agencies from around the world go after them and the penalties could be quite dramatic. Really, really, not a good idea, there will be a severe price to pay.

      --
      Chaos - everything, everywhere, everywhen
    2. Re:So in Licking.... by Anonymous Coward · · Score: 0

      Fucking nerd! You had the ball sat upon a tee for you and you still didn't manage to hit it. A Timex ad? Really?

  6. Ransomware Insurance by Anonymous Coward · · Score: 1

    The capitalist response is to sell ransomware insurance, because techy solutions are all eggheaded and faggy.

    1. Re:Ransomware Insurance by Anonymous Coward · · Score: 0

      No. The capitalist response is for providers of IT services to make their proposals to this city government, noting that the best choice of IT providers to protect the government's critical infrastructure is usually the one with the most talented IT professionals, not necessarily the one that offers service at the lowest possible price.

  7. I can't wait... by Anonymous Coward · · Score: 0

    ...until ransomware completely shuts down President Bannon's computers. That would be such a YUGE BIGLY problem, even cyber expert Barron couldn't fix it.

  8. Good idea for progressing on secessionist movement by Anonymous Coward · · Score: 2

    If all it takes is a bit of ransomware to shut down government then the secessionist movement of New Hampshire has been doing it all wrong. For those who don't know about the migration of principled libertarians (ie no violence, theft, fraud, or coercion then there is no crime, and government shouldn't be using these things against peaceful people either) to New Hampshire and want more freedom and liberty in our life time then you need to check into this movement. Those who have moved to New Hampshire have a dream of independence for the region. There is a limit to how much government can be shut down once we gain control of the state due to the federal governments existence. For instance copy"right" violates people fundamental rights not to be interfered with given that there is no violence, theft (ie nothing is lost when a copy is made), fraud, or coercion in the case of copy"right" infringement. If you don't like the tyrannical police state and nanny state we live in check out the liberty migration movement (we don't need a majority, just an active minority in order to outnumber the opposing views, and the majority in NH are already not registered democrat or republican)t: http://www.freestateproject.com/ http://forum.shiresociety.com/ http://www.freekeene.com/ http://www.freetalklive.com/

  9. Don't blame all employees by omnichad · · Score: 2

    If it's hitting central servers and shutting everything down, it's probably a weak RDP password with port 3389 wide open. That's what the last ransomware I saw involved.

    1. Re:Don't blame all employees by Tough+Love · · Score: 1

      If it's hitting central servers and shutting everything down, it's probably a weak RDP password with port 3389 wide open.

      And it's probably Windows. Backup strategy is just a contributing problem here. The central problem is using Microsoft products in inappropriate ways, like running servers.

      --
      When all you have is a hammer, every problem starts to look like a thumb.
    2. Re:Don't blame all employees by Anonymous Coward · · Score: 0

      I would not recommend using Samba for Active Directory in a production environment.

    3. Re:Don't blame all employees by Tough+Love · · Score: 1

      Have one Windows server to run AD and provide SMB shares, and move everything critical to Linux. Then get rid of the Windows laptops to improve the perimeter defence.

      --
      When all you have is a hammer, every problem starts to look like a thumb.
    4. Re:Don't blame all employees by Anonymous Coward · · Score: 0

      Have one Windows server to run AD and provide SMB shares

      Why not use Samba, OpenLDAP, and Kerberos on Linux?

    5. Re:Don't blame all employees by Tough+Love · · Score: 1

      You know the red stapler guy in Office Space? That would be the resident Windows sysadmins.

      --
      When all you have is a hammer, every problem starts to look like a thumb.
    6. Re:Don't blame all employees by wbr1 · · Score: 1
      The last one you saw does not equal probably for any others. Your sample size sucks. Mine is not much better, but the last 3 successful crypto attacks I have seen have been through drive by downloads and very well socially engineered emails with attachments.

      Yes RDP open on 3389 is stupid, but believe it or not we have clients with legacy software that requires it. Only solution is to reduce attack surface. Frequently check accounts, change passwords etc. Oh, and the last successful RDP breaches I saw did not result in crypto, mostly ID theft and confidential data exfiltration.

      --
      Silence is a state of mime.
    7. Re:Don't blame all employees by omnichad · · Score: 1

      Your sample size sucks.

      My research included the wider Internet - it's a lot more common than you think. If it's hitting an entire server, and not just network shares, and the computer isn't used for web browsing - you're not going to get it from a drive-by download.

      believe it or not we have clients with legacy software that requires it. Only solution is to reduce attack surface.

      Yeah, like with a VPN. Is there really any software that requires a remote RDP server but couldn't handle it through a VPN connection?

  10. fool me once by Anonymous Coward · · Score: 0

    Fool me once, shame on you.

    Fool me 847194 times over the course of 7 years, shame on me.

    Exactly how man repetitions does it take before people start learning?

    When do employees who fall for these schemes start being fired for gross incompetence?

    When do the staff who failed to create an adequate backup strategy, or the brass who shut down the staff who wanted to do that, be similarly fired for gross incompetence?

    That's what it's gonna take. Until there is something on the line for them personally, people don't seem inclined to use due caution.

    1. Re:fool me once by nobuddy · · Score: 2

      When do the staff who failed to create an adequate backup strategy, or the brass who shut down the staff who wanted to do that, be similarly fired for gross incompetence?

      this hits home. I had a remote site with critical data that had no backups. for 3 years I kept telling the CFO we need this budgeted to add backups. Always put off "till next quarter". Not even a small budget for a CD-R and manual backups. nada.

      Then it happened. Failed system, data lost. No way to recover. Somehow, all my fault. I was fired for it. Presenting my emails and disaster recovery plan requests fell on deaf ears. I was IT, it was my responsibility to prevent.

    2. Re:fool me once by Ol+Olsoc · · Score: 1

      Somehow, all my fault. I was fired for it. Presenting my emails and disaster recovery plan requests fell on deaf ears. I was IT, it was my responsibility to prevent.

      Oh man - you were set up from the beginning. The bright side is that company isn't going to be around too long.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
    3. Re:fool me once by Anonymous Coward · · Score: 0

      Depending on where you were, that's grounds for a wrongful dismissal lawsuit.

    4. Re:fool me once by PopeRatzo · · Score: 0

      The bright side is that company isn't going to be around too long.

      Yeah, but the bad news is that the CEO is now president of the United States.

      --
      You are welcome on my lawn.
    5. Re:fool me once by Ol+Olsoc · · Score: 1

      The bright side is that company isn't going to be around too long.

      Yeah, but the bad news is that the CEO is now president of the United States.

      But he had a good friend putin a good word for him.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
  11. Next week on /. by Anonymous Coward · · Score: 0

    Licking County sheriff announces all crime in county solved. Thanks lack of computers getting in the way.

  12. Oh, for fork's sake by nobuddy · · Score: 0

    We need to start having MASSIVE fines and petty jail time for this. training, phising warnings, attachment warnings- these things happen daily. Someone that still does this needs to be made to suffer. Then, maybe, people will take the warnings seriously.
      Is there a malicious negligence or depraved negligence charge we can level at them?

    1. Re:Oh, for fork's sake by Ol+Olsoc · · Score: 3, Insightful

      We need to start having MASSIVE fines and petty jail time for this. training, phising warnings, attachment warnings- these things happen daily. Someone that still does this needs to be made to suffer. Then, maybe, people will take the warnings seriously. Is there a malicious negligence or depraved negligence charge we can level at them?

      Because getting caught in a phishing scheme is not necessarily depraved indifference. Having to turn off an adblocker so you can get into Forbes.com is plenty enough to get you owned.

      I've seen plenty of competent people get owned. Would you make a vow to commit suicide if you ever in your life got malware on your computer? I sure wouldn't.

      --
      The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
  13. Similar event occurred in Portland, Oregon. by Anonymous Coward · · Score: 0

    Except they had good, tested backups and knew how to use them.

  14. That presumably all-seeing NSA by Applehu+Akbar · · Score: 4, Interesting

    Can a new administration with no concern for political correctness finally turn the NSA loose on finding ransomware perpetrators? Since we in here have decided that their Internet surveillance efforts are omnipotent, they should be able to trace a surveilled Bitcoin payment back to them. Then we hire local talent for "wet work" in killing them off in some eye-catching manner, dissuading others from entering the business.

    1. Re:That presumably all-seeing NSA by Anonymous Coward · · Score: 0

      Can a new administration with no concern for political correctness

      if they have no concern for political correctness then please explain their desire to shut down uc berkeley after their fine show of political incorrectness

    2. Re:That presumably all-seeing NSA by AHuxley · · Score: 2

      Groups have considered that. The staging servers are in safe nations surrounded by layers of real people doing active counter surveillance.
      Say the NSA finds a server in Australia, Canada, NZ or the UK? Lots of support over decades so information is passed and kept very secure.
      A request is created by another US law enforcement agency to hide the NSA origins of the data found.
      Another nation creates a 12 person police team to look at the people using the server. Say 3 person police team on duty, a few shifts per day to watch the area of interest.
      The local inward looking, isolated cult like community soon notices the new vans, tracks, cars, new utility workers doing no real work or small groups of new people who just don't fit in that community. A new camera in a box on a utility pole facing a site.
      Locals will then surround, chat down and confront the undercover police teams. Once photographed teams of undercover police are not much use in that area. Local police then have to help escort the now photographed "undercover" teams out of the area.
      The server is moved only to start up in another safe area once the community works out who is of interest to that police team.
      If an attempt was made to remove the servers by using cyber methods a nations internet provider or gov network would be altered and corrupt staff doing the clean up would find traces of new NSA cyber methods in the wild and report them globally as interesting new malware.
      Most groups set up bait servers just to see what gov, mil, other groups, firms, contractors come looking and what methods they use.
      Groups have layers of counter surveillance options just by selecting a no go part of a city where every police or undercover police action is very easy to spot as it enters that part of a city. The wider local community knows every face, every car, every normal government and city worker expected to be in the area.
      Telco and local gov workers are also loyal to cult like criminal groups over generations of staff and warn of any changes to ISP, telephone networks when normal gov/police logging is requested on local phone numbers or ISP accounts.
      Bribes, infiltration gives days or hours of any local police action. More secure federal police units on the move are spotted in most nations with enough warning to escape. Hardware is lost but teams regroup with funds to set up new servers.
      The only way around such methods is satellite collection, mil grade surveillance aircraft looking at all wireless networks, or unexpected national telco upgrades that totally bypass all local staff. Teams of criminal informants recruited by federal law enforcement to try and renter their old communities hoping their stories and cover holds. Informants are a huge risk as criminal groups know their methods and hire as needed internally, not from people seeking to join.

      Staff members with insights into no go communities are a huge risk too, are they loyal or can they ever be trusted? Law enforcement and the security services in most nations are been filled with many new "translators" and "experts" many of who will report back to their own faiths, cults, criminal groups or other nations.
      Just finding a server is easy. Getting any more details is hard work. Even the new hiring practices of the police and security services now allow for surveillance to be discovered.

      --
      Domestic spying is now "Benign Information Gathering"
    3. Re:That presumably all-seeing NSA by Applehu+Akbar · · Score: 1

      But....but...but doesn't the NSA have infinite powers to surveil the Internet without us even being aware of it?

      In any case, we keep being told that those no-go neighborhoods don't exist. The refugee communities in Paris, Malmö and Calais will gladly throw open their doors to any authority needing to look into what they might be doing on the Internet, won't they?

    4. Re:That presumably all-seeing NSA by Anonymous Coward · · Score: 0

      You twist like a twisty turny thing

    5. Re:That presumably all-seeing NSA by AHuxley · · Score: 1

      The NSA can track any user on most networks. Finding a location is often not the issue for the US.
      The problem for the USA is the methods have to be hidden and requests to local police just alert criminal groups.
      The local police in other nations are corrupt or even members of the same criminal groups, faiths been watched.
      Local police also sell information to the press who then alert criminals.
      Mil, national or federal police in many other nations just cant do undercover work in closed communities or are totally reliant on generations of NSA like collection methods in their own nations.

      Informants tell fictional stories to stay out of the legal system or to get paid. Criminals don't always carry cell phones when planning or doing crime making digital collection less useful. Police in other nations even sell informal lists or witness information in bulk.
      Budget cuts, legal issues, political correctness or a lack of skills over decades often slows national police forces.
      Criminal groups use this to hide in faith based and inward looking communities. Undercover police are easy to spot, police informants are not invited back in.
      The other issue the NSA fears is most nations security forces have been hiring new staff. Security has been replaced by a political demands for diversity.
      The entry level and translation services of many nations elite security forces are now been filled up with new staff who are loyal to other nations or faiths, criminals or cults.
      Even requesting help from a lot of other nations security services is a huge risk thanks to years security leaks back to gangs, faith groups, criminals and other nations.

      The issue then for the US is in finding anyone trust worthy to share the information they gather globally with.
      So the NSA, CIA can find most interesting people on computer networks globally. How to use that information in time is getting more difficult for the US.
      The long term issues for the NSA is the next generation of staff in once trusted 5 eye nations. Even if select staff in other nations can be trusted, new staff standards in other nations are now a security risk.

      --
      Domestic spying is now "Benign Information Gathering"
    6. Re:That presumably all-seeing NSA by Anonymous Coward · · Score: 0

      While not a bad idea, the focus is wrong for a proper solution. The proper solution is to use operating systems more secure than the barely consumer grade crap that Microsoft routinely shits out.

      But meh.

    7. Re:That presumably all-seeing NSA by crtreece · · Score: 1

      I don't think you fully understand how transferring Bitcoins works, especially in a world with VPNs, proxies, and datacenters full of virtual hosts.

      --
      file: .signature not found
    8. Re:That presumably all-seeing NSA by budgenator · · Score: 1

      "Now I can't be sure, but my buddy heard some ransomware dude that hit some town in New Jersey got renditioned to Gitmo as a terrorist by that fascist prick Trump. The week after, his mother's house blew up in a freak gas explosion while she was out grocery shopping and his sister got kidnapped and gang-raped by Muslim Refugees."
      Now we'll just leak that narrative to "Slate" and next week we'll make sure that is trending on Facebook and Twitter.

      --
      Apocalypse Cancelled, Sorry, No Ticket Refunds
    9. Re:That presumably all-seeing NSA by aicrules · · Score: 1

      Committing criminal destruction of property is not political incorrectness...

  15. The worst part about this... by Anonymous Coward · · Score: 0

    ... is that these people still live in Ohio. I feel sorry for them.

    1. Re:The worst part about this... by doesnothingwell · · Score: 2
      I worked for Ohio government offices for 15 years, you'll never find a tighter bunch of inbred boot lickers anywhere. Politic and games abound like the time: (cue the flashbackeffect), I once had the departing elected prosecutor tell me to erase the server files. I did so but commented this must be legal as it is being requested by the ruling interpreter of law for the area.

      Fast forward a week later and the new prosecutor want to know where the files are, so I told him and he was "not happy at all." I explain that ruling authority at that time ordered it so and suggest he take it up with the recently departed prosecutor, there was much posturing and sabre rattling.

      If I had resided in his local area I would probably have spent some time in a cell. I had the files on backup tape in my desk so all was forgiven. Always cover your ass.

      --
      They can have my command prompt when they pry it from my cold dead fingers.
  16. This is what happens by Anonymous Coward · · Score: 0

    This is what happens when backups are not implemented correctly, AND access is not restricted to only the minimum needed for each person to do their job!

  17. Adama's solution. by Anonymous Coward · · Score: 0

    No networked computers on this ship!

  18. Actually, the article states that... by nuckfuts · · Score: 3, Interesting

    County Auditor Mike Smith saw the bright side. “Apparently, our clock still works,” he told the Newark Advocate.

    1. Re:Actually, the article states that... by Anonymous Coward · · Score: 0

      and the sun also rises.

  19. Re: Ransomware's part of why I wrote this by Anonymous Coward · · Score: 0

    Bit of advice, hire someone else to do your marketing, what u wrote is not only unreadable but annoying to even look at

  20. Grace Commission Report by Anonymous Coward · · Score: 0
  21. Backup/Backup/Backup/Backup/Backup by felixrising · · Score: 3, Insightful

    I've had the dubious honour of dealing with and recovering from two attacks in the last two years. On both occasions we had one or more staff open a phishing email and execute the ransomware. On both occasions the ransomware successfully encrypted over 250000 files on file shares. We do have quite a reasonable level of protection in place, including 1) AntiVirus and Anti-Malware (useless in both accounts), 2) moderate level of security groups for users limiting access to only those files they require, with exception of a "temp share" which is a dumping ground for all kinds of stuff, but cleared automatically every 30 days, 3) file name/extension ACLs on windows shares that prevent files like .encrypted .EnCiPhErEd from being created on the file system 4) daily backups. In each case, we still had to do targeted purge/restore to get the files back. We never for a second thought about paying the ransom. I restored all files within 4-6 hours, using a mixture of scripts and manual review of folders and files. The best solution is have great back-ups... those backups should be regularly tested and monitored for success. With good backups, you can recover in a very short time frame....

    1. Re:Backup/Backup/Backup/Backup/Backup by swb · · Score: 1

      I've moved to adding additional backups of servers at greater risk of ransomware encryption, every 2-4 hours depending on what the site's environment can handle in terms of capacity and added disk load, usually retaining these backups for 2-3 days.

      This way if ransomware hits, I've got both an additional backup to the daily backup and a very recent backup in case key files were affected.

         

    2. Re:Backup/Backup/Backup/Backup/Backup by Anonymous Coward · · Score: 0

      Bravo!

    3. Re:Backup/Backup/Backup/Backup/Backup by elistan · · Score: 1

      I've had similar experiences for two ransom ware infections over the past few years - in each case it looked like it got in by the user browsing to a normal website that served up a malicious ad - we've since then switched to a different web filter appliance. Our antivirus didn't stop the encryption, but did detect and alert on the ransom notes. So we were able to shut down the offending PC quickly - it then got its drive pulled and wiped, as no data is stored locally. That lack of local files meant the malware quickly moved on to network shares before being shut down, but good backups meant we could recover in just a couple hours. Our antivirus now looks for 'unauthorized encryption' but we haven't seen it in action yet against actual malware - just false positives for a program we use that does encryption. We do annual DR tests so we know we have recovery capabilities.

    4. Re:Backup/Backup/Backup/Backup/Backup by ebvwfbw · · Score: 1

      Did you follow up with education for the users? Should be done once a year. Set up an external site. I'm often very obvious with the site name. Password checker, health insurance discount site. Social the women too. Women are often really easy to social if you get the right bait.

  22. Re:I see you off-topic unidentifiable ac troll by Anonymous Coward · · Score: 0

    "I see you off-topic unidentifiable ac troll"....

    APK

    P.S.=> APK

  23. It's a shame by Anonymous Coward · · Score: 0

    It's a shame that they shut down the useful parts of government along with the pigs.

    But the pigs' systems down probably made life just a little bit better for everyone else.

  24. Oh how clever (not): Impersonating me! by Anonymous Coward · · Score: 0

    See my subject above, marketing advertising troll & this https://slashdot.org/submission/6715173/adblock-blockers-ineffective-adblocking-up-30-globally-in-two-years/ & don't wonder WHY this excerpt from it is true when "geniuses" like that INFECT, TRACK, & SLOWDOWN us users of websites are blocking you out:

    "rise of adblocking cause nearly three-quarters of users to simply abandon the sites which block adblockers. The report, from pro-ad organisation Playfair, estimates that adblocking has risen by 30% in two years, and by 40% in Asia in 2016 alone. The report predicts that a growing trend towards pre-service agreements by providers and hardware manufacturers will cause adblocking usage to rise further, practically becoming a 'default' position"

    APK

    P.S.=> Lastly: By the way, unlike yourself trolling me earlier giving away WHO & WHAT you are? I do sign off on my posts identifying myself, unlike you (unless you impersonate me as you just have)... apk

  25. sadly by sad_ · · Score: 1

    nothing will be learned from this, and things continue as they were, only matter of time before it happens again. sick & tired of seeing this kind of story almost every day.
    how many ransomware incidents would have happened if these orgs/govs/companies had their things in order?

    --
    On a long enough timeline, the survival rate for everyone drops to zero.
  26. Administrator Rights by Anonymous Coward · · Score: 0

    In the organization that I manage, NO user has administrative rights on their machine. NOT A SINGLE ONE.

    This is why.

    1. Re:Administrator Rights by ebvwfbw · · Score: 1

      Admin is handed out way too easy. Are you sure nobody else has admin rights? I manage a few thousand WIn boxes. Every one had to be audited recently and I found users had admin access that never even knew about the machine nor logged in. Application accounts too. Then if you also use group policies sometimes audit check policies have security changes, that gives someone admin rights. I've said a few times - here's a Windows box, guess how it's configured. I could say guess who has admin access.

      I hope you're right in saying no users have admin access. I wish there were more people like you out there.

  27. Should have used ZFS by Anonymous Coward · · Score: 0

    If you ran all your Windows servers as virtual machines backed by ZFS, you could have fixed this in 2 seconds with a single command. (zfs rollback pool/dataset@yesterday)

  28. Heuristic anti-ransomware? by Anonymous Coward · · Score: 0

    You'd think in a moderately locked down business environment it would be possible to apply anti-ransomware heuristics - encrypting a file (apart from a file already containing random data or already encrypted) is detectable (massive entropy change) so you lock the system down so that only registered/signed executables (PGP, bitlocker, etc.) are allowed to perform encryption. The only issue is how much overhead this would cause. however, you don't necessarily have to check every block as a file is updated - if your aim is to limit damage to a few files rather than prevent it altogether you could just do a before/after entropy check on (say) 1 in 100 blocks.

  29. Re: Ransomware's part of why I wrote this by Anonymous Coward · · Score: 0

    Bah.
    You're just EDUCATED STUPID if you can't immediately see the benefits of the the FOURFOLD SYMMETRIC HOSTS FILE CUBE

  30. Fake news by Anonymous Coward · · Score: 0

    I can't believe that a county in Ohio is actually using computers.

  31. Why was 911 exposed? by Anonymous Coward · · Score: 0

    The 911 Dispatch system should never been exposed to this. No need for it to have Internet or email access. It should have just the resources it needs, access to the CAD and GIS, and little else. Doing anything else is just a time bomb waiting to go off.

  32. Ransomware's part of why I wrote this by Anonymous Coward · · Score: 0

    Prevention = best medicine (& what you can't touch can't hurt you) via NEW version APK Hosts File Engine 9.0++ SR-6 32/64-bit https://www.google.com/search?hl=en&source=hp&biw=&bih=&q=%22APK+Hosts+File+Engine%22+and+%22start64%22&btnG=Google+Search&gbv=1/

    Ads & malware rob speed, security & privacy

    Hosts add speed (via hardcodes/adblocks), security (vs. bad sites/malware/poisoned dns), reliability (vs. dns down), & anonymity (vs. dns requestlogs/trackers).

    Less power/cpu/ram + IO use vs. DNS/routers/addons/antivirus + less security bugs/complexity

    * Using what you already NATIVELY have built into your TCP/IP stack running in FASTER kernelmode!

    APK

    P.S. - Safe https://www.virustotal.com/en/file/e01211ca36aa02e923f20adee0a3c4f5d5187dc65bdf1c997b3da3c2b0745425/analysis/1433430542/

  33. I see u, you off-topic unidentifiable ac troll by Anonymous Coward · · Score: 0

    Your "marketing" bs fails vs. my facts malwaremaker or are you an advertiser losing "$" OR an inferior inefficient "so-called 'competitor'" that uses FAR more yet does FAR less (like NOT doing your job @ all by default in "AlmostALLAdsBlocked")?

    * :)

    QUESTION: Is your FAVORITE COLOR 'transparent'?

    (I see RIGHT thru your b.s. easily & so does anyone else...)

    I'm on topic w/ an EFFECTIVE measure vs. threats like this (& idiots like you listed above) - you're not.

    I'm merely stating facts that have done SO well that my hoster (the highly esteemed malwarebytes via hpHosts) has had to MOVE SERVERS, yet again, due to demand for my program & their data (with that of 10 other hosts file data sources)!

    Yes - YOU are scared, advertiser! Thanks for projecting it, especially on 'marketing' (projecting EXACTLY who you are from my list above, lol!).

    APK

    P.S.=> Desperation & cowardice is your trademark, especially posting from behind an UNIDENTIFIABLE ac post completely off topic too, lol - thanks for helping me by letting me tell the truth of "your kind" here right now! apk