LeightonJames Posted February 1, 2016 Posted February 1, 2016 Someone is in some MAJOR trouble for this one. Talking about the attack, she said: "It happened very quickly. Once we identified it we shut the network down, but some damage is always done before you get to that point - and some files have been locked by the software. "A lot of the files will be available for us to restore from the back-up." Lincolnshire County Council hit by £1m malware demand - BBC News
srochford Posted February 1, 2016 Posted February 1, 2016 There's an update here - Lincolnshire County Council 'will not pay cyber ransom' - BBC News - it says that they were hit by a zero-day atttack. No idea if that's true but it's certainly plausible.
CAM Posted February 1, 2016 Posted February 1, 2016 Cryptolocker and ransomware is hardly new, it's just newspaper scaremongering. They've been hit by a zero day vulnerability, council has backups and they've worked over the weekend to restore them. Sounds like decent disaster recovery to me (if they stop it coming back).
Joanne Posted February 1, 2016 Posted February 1, 2016 I read this this morning... they mentioned that someone had opened an attachment on an e-mail.... looks like they need to train staff to spot spoofs! Wonder if it was off a personal e-mail too..... hmmm.
jcookhgs Posted February 25, 2016 Posted February 25, 2016 Anyone hear of any schools hit? Just an email fom business manager stating that he has just learned 2 schools have been in ict shutdown for past week due to ransomware...
snagrat Posted February 25, 2016 Posted February 25, 2016 Anyone hear of any schools hit? Just an email fom business manager stating that he has just learned 2 schools have been in ict shutdown for past week due to ransomware... I know of several schools hit, but most are back up in a day
timbo343 Posted February 25, 2016 Posted February 25, 2016 (edited) We had our bursar say that ransomware was doing the rounds and ive been checking out our GFI logs and sure enough last week we got bombarded with loads of the LOCKY ransomware which our system detected and deleted. Here is what i posted on another forum last week: On the back of this, the otherhalf got an email from her work's IT Support (NHS) and they also warned of potential viruses running round the system. This prompted me to jump on twitter to see what all the hype was about and looking on there, LOCKY is doing it's rounds, so i thought i would let people know about it. Obviously we all know that we shouldn't open emails that come from senders we dont know but there are some users out there who think invoice emails are genuine emails so they open it up and bam! the virus has done it's job. 9 times out of 10, AV will kick in but because this LOCKY virus seems like the next big thing since conficker, i'm posting up some links that might help you in gpo https://medium.com/@networksecurity/locky-ransomware-virus-spreading-via-word-documents-51fcb75618d2#.dmtstged6 https://medium.com/@networksecurity/it-s-time-to-secure-microsoft-office-be50ec2797e3#.krtux6x0a I guess this LOCKY ransomware was the one that killed the Lincolnshire Council network. Edited February 25, 2016 by timbo343
Arthur Posted February 25, 2016 Posted February 25, 2016 (edited) @timbo343. Your Locky links do not work. I'm guessing it's one of these articles on Kevin Beaumont's blog... https://medium.com/@networksecurity Locky experiments with Windows Script Host delivery You, your endpoints and the Locky virus Locky ransomware virus spreading via Word documents Endpoint security is broken — the trojan reality of enterprise IT Edited February 25, 2016 by Arthur
timbo343 Posted February 25, 2016 Posted February 25, 2016 @timbo343. Your Locky links do not work. I'm guessing it's one of these... https://medium.com/@networksecurity Locky experiments with Windows Script Host delivery You, your endpoints and the Locky virus Locky ransomware virus spreading via Word documents Endpoint security is broken — the trojan reality of enterprise IT Thank you, should be working now.
jcookhgs Posted February 26, 2016 Posted February 26, 2016 Thanks. Don't suppose your bursar mentioned which schools? The usual panicking/flapping is occurring as per usual!
timbo343 Posted February 26, 2016 Posted February 26, 2016 Thanks. Don't suppose your bursar mentioned which schools? The usual panicking/flapping is occurring as per usual! It came from Veritau but we already have systems in place. Luckily they hit over half term when no one was in.
LiamH Posted February 26, 2016 Posted February 26, 2016 We had a machine in the heating plant get hit by a zero-day, lucky it was just the machine the workers use for taking logs and browsing the web, the logs got encrypted but are backed up. Judging by the time it was hit it was during the night shift so not sure if it was a booby trapped website or a email attachment. There are a couple of antivirus programs out there now that detect when files are being encrypted and block it, most are still optional programs run alongside the main antivirus, I noticed they block network writes as well unless folders are added to an exception list which totally defeats the point for servers.
dsquared2 Posted March 1, 2016 Posted March 1, 2016 (edited) We are a school in Lincolnshire and we were hit on the same day as Lincolnshire County Council with a form of ransom ware. We have a feeling it may have been the same email as the Council were hit with as the sender was a parent that works for a group of Lincolnshire newspapers. It was sent to his whole address book so I wouldn't be surprised if he has contact with LCC. Anyway we were down for a day while we recovered the infected drive from the back up the night before. Edited March 1, 2016 by dsquared2
sonofsanta Posted March 2, 2016 Posted March 2, 2016 In which event, I believe you're the second school to have been caught up in that attack. So one man's poor online hygiene brought down (at least) two schools and a county council. Can you get court injunctions against people owning computers?
kearton Posted May 10, 2016 Posted May 10, 2016 Has anyone with a Sophos UTM on v9.4 had a play with the new attachment sandboxing feature yet?
Arthur Posted October 31, 2016 Posted October 31, 2016 More ransomware in Lincolnshire? All Lincolnshire hospital operations cancelled after IT system hit by virus Operation appointments across Lincolnshire hospitals for tomorrow, including Lincoln County Hospital, have been cancelled after a virus struck the IT system of a neighbouring trust. As stated earlier on Lincolnshire Reporter, a virus infected electronic systems for Scunthorpe and Grimsby hospitals in North Lincolnshire on Sunday, October 30. As a result, major systems at the hospitals were shut down. United Lincolnshire Hospitals Trust has now confirmed that shared IT systems must be shut down across the county to minimise risks. As a result, operations at Lincoln, Grantham and Boston have now also been cancelled. A&E departments are also expected to face delays. The trust has said any patients with a planned operation on November 1 should presume it is cancelled unless contacted and told otherwise.
MatthewL Posted November 1, 2016 Posted November 1, 2016 The source is at NLAG which is Grimsby, Scunthorpe & Goole. ULH have links due to pathology systems amongst others been shared. Very surprised at the amount of cancellations due to this but the IT department are very stressed and I would be if I was still in the NHS at this time. Would hate to have been carrying the on call bleep on Sunday! The Northern Lincolnshire NHS trusts were very far forward in IT terms in the NHS world hence the joined up way of working and sharing systems. I think my former colleagues all aged by 20 years when they walked in this morning and wished they had booked A/L!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now