Outgoing Little Rock School Board President provides update on cybersecurity breach - "cybercriminals were paid a $250,000 ransom"

kark.com
archive.ph

Outgoing Little Rock School Board President provides update on cybersecurity breach​

by: Andrew Epperson
Posted: Dec 16, 2022 / 09:51 PM CST
Updated: Dec 16, 2022 / 10:04 PM CST

LITTLE ROCK, Ark. — The outgoing Little Rock School Board President provided updates regarding a cybersecurity breach he said left thousands of people impacted.

Greg Adams is no longer the president as of Thursday, but he said he wants to see this through since it happened under his tenure. He said cybercriminals were paid a $250,000 ransom, and data was returned.

“I’m sure that people are very curious about more of the details,” Adams said.

In a publicly posted letter, Adams detailed some of the newly available information. He said Friday he still cannot get into some details.

Adams said cybersecurity experts are not parsing through the information to return it to people who were impacted.

“We had individual information [taken], so just probably use your imagination and picture any information a school district might have about an individual student or employee,” Adams said.

Adams said making the deal was a risk, but even in the cybercriminal world reputation is everything. Had the criminals taken the money and refused their end of the deal, it could have impacted future deals, Adams said.

“It could actually hurt their financial interest in the future because then people will not want to work with them,” Adams said. “Then, they could not trust them.”

Adams said he understands why people were frustrated about the secrecy associated with deciding what to do, but he said the board was in a difficult position.

“We hope that over time, the public understands that we tried to do the best we can to get the best outcomes for the most people,” Adams said.
 
Reminder that stuff like this is why you and others should care about privacy. Even if you trust the organization (lol), it is increasingly likely they will be hacked and then bad actors will spread your personal data as they see fit.

Adams said making the deal was a risk, but even in the cybercriminal world reputation is everything. Had the criminals taken the money and refused their end of the deal, it could have impacted future deals, Adams said.
So suddenly you're an expert? They have the data and can double dip or just attack you again, retard. If it hurts their "financial interest" they just make up a new name and pretend to be another group. They still have your data and can still sell it to whoever is interested.
It's like he took what the hackers told him to heart.

“We hope that over time, the public understands that we tried to do the best we can to get the best outcomes for the most people,” Adams said.
What was done to prevent this from happening in the first place? Most of the time very little.
What has been done to prevent this from happening again?

These "updates" suck but good reminder to not trust anyone with your data.
 
If only you invested that $250k into a working backup solution, retard.
Adams said making the deal was a risk, but even in the cybercriminal world reputation is everything. Had the criminals taken the money and refused their end of the deal, it could have impacted future deals, Adams said.
Good job encouraging these attacks and ensuring that future attackers know that you have lousy security and will pay the ransom.
“We had individual information [taken], so just probably use your imagination and picture any information a school district might have about an individual student or employee,” Adams said.
Soooo... basically everything? For staff and students it'll be a total dox and for students it'll be particularly bad as there may be mental health, CPS, etc. info in there.
Adams said making the deal was a risk, but even in the cybercriminal world reputation is everything.
Literally the thing that every ransomware group puts in their demand letter and this tard believed it.
“We hope that over time, the public understands that we tried to do the best we can to get the best outcomes for the most people,” Adams said.
Negligence this bad should earn a prison sentence.
 
For those more IT privy, specifically networking, these ransomware attacks penetrate business networks through emails right? Either to download or visit a contaminated site right? Would it be beyond the realm of possibility to just have company emails be screened first on a VM or other virtual environment unassociated with the main network? I might be over thinking this. A lot of my friends in IT always complain that they'd like to add more infosec or even upgrade hardware but often get shafted by the budget department. Would a two step process help prevent ransomware or is it just a better idea to backup the entire network every day or so? Because it is very obvious to me that humans are retarded when it comes to this sort of thing.
 
For those more IT privy, specifically networking, these ransomware attacks penetrate business networks through emails right? Either to download or visit a contaminated site right? Would it be beyond the realm of possibility to just have company emails be screened first on a VM or other virtual environment unassociated with the main network? I might be over thinking this. A lot of my friends in IT always complain that they'd like to add more infosec or even upgrade hardware but often get shafted by the budget department. Would a two step process help prevent ransomware or is it just a better idea to backup the entire network every day or so? Because it is very obvious to me that humans are retarded when it comes to this sort of thing.
Scanned for what, are you going to ban hyperlinks?
 
Scanned for what, are you going to ban hyperlinks?
My bad, I should have explained it better. I meant more like an incubation tank. The employees look at their emails and if they verify nothing is exploding when doing whatever, forward it to a different internal email that is on the main network itself. Also, maybe ban hyperlinks to external sites that aren't previously placed in a policy. IDK, just spit balling. It happens too much and I'm curious.
 
For those more IT privy, specifically networking, these ransomware attacks penetrate business networks through emails right?
Easiest answer: "It's complicated". These come in via any angle you can imagine, guessed passwords (spraying, for instance), phishing, malware (sometimes e-mailed, sometimes from malicious webpages, whatever), exploited web applications or external services (like the Travelex one was due to an unpatched VPN appliance). The list of potential avenues is basically endless.
Would it be beyond the realm of possibility to just have company emails be screened first on a VM or other virtual environment unassociated with the main network?
A lot of companies sell products that do this kinda stuff. Microsoft has a Defender-based sandboxing service in 365, Trend Micro claims to do something similar with TMCAS and I'm sure there's a dozen others (like Proofpoint, Mimecast, whatever) that'll do sandboxing, malware scanning, heuristics and whatever else. The reality is that given enough time, some asshole will slip a 0-day in and that's where you'll have a nicely segmented network, EDRs picking up weird shit happening, competent IT people patching your internal infrastructure so attackers can't easily exploit internal resources, etc.
A lot of my friends in IT always complain that they'd like to add more infosec or even upgrade hardware but often get shafted by the budget department.
Yeah this is a constant issue. I get there's a balance between IT's desire for gold plated server hardware and the business's desire to not go bankrupt tomorrow, but it's hard not to get angry when everyone is using 5 year old laptops with dead batteries meanwhile senior management is giving 6 figure positions to troons and jerking each other off over Agile and Cloud Transformations.
 
For those more IT privy, specifically networking, these ransomware attacks penetrate business networks through emails right? Either to download or visit a contaminated site right? Would it be beyond the realm of possibility to just have company emails be screened first on a VM or other virtual environment unassociated with the main network? I might be over thinking this. A lot of my friends in IT always complain that they'd like to add more infosec or even upgrade hardware but often get shafted by the budget department. Would a two step process help prevent ransomware or is it just a better idea to backup the entire network every day or so? Because it is very obvious to me that humans are retarded when it comes to this sort of thing.
There's not much they can do besides filtering. I've seen a few software developers fall for phishing links, so I doubt any amount of training would ever work.
 
A lot of companies sell products that do this kinda stuff. Microsoft has a Defender-based sandboxing service in 365, Trend Micro claims to do something similar with TMCAS and I'm sure there's a dozen others (like Proofpoint, Mimecast, whatever) that'll do sandboxing, malware scanning, heuristics and whatever else. The reality is that given enough time, some asshole will slip a 0-day in and that's where you'll have a nicely segmented network, EDRs picking up weird shit happening, competent IT people patching your internal infrastructure so attackers can't easily exploit internal resources, etc.
Blegh, I guess that is why I always hear about incident response being almost more important that the actual security policies ahaha. I don't know how true that is as my knowledge is hobbyist and my friends group is small. How do you mitigate this sort of attack? Say the network is completely locked up, bad guys succeeded, and are demanding money. Would a full recovery need to happen?

Yeah this is a constant issue. I get there's a balance between IT's desire for gold plated server hardware and the business's desire to not go bankrupt tomorrow, but it's hard not to get angry when everyone is using 5 year old laptops with dead batteries meanwhile senior management is giving 6 figure positions to troons and jerking each other off over Agile and Cloud Transformations.
It's a little annoying ain't it ahaha! Don't look at the Government computer systems, I think they are the prime example of exactly this but without the fear of going bankrupt...ha.

There's not much they can do besides filtering. I've seen a few software developers fall for phishing links, so I doubt any amount of training would ever work.
Yeah, when I was able to take a couple classes at a local community college I learned that most Cybersecurity attacks hinge on human error. Thanks for offering your answer!
 
How do you mitigate this sort of attack? Say the network is completely locked up, bad guys succeeded, and are demanding money. Would a full recovery need to happen?
Getting a little OT but yeah, if it's bad enough you basically need to rebuild. A big issue when recovering from incidents where you are completely owned is trying to keep the attackers from just coming back 2 seconds later and blasting your shit again. If they got seriously embedded then they'll probably have malware lurking in servers and hidden credentials (Look up KRBTGT for inspiration). It's a total nightmare and honestly something that keeps me awake at night sometimes. I've never had it happen personally but I've got a buddy who leads an IR team at a big shot security company and it's crazy how often this happens.
It's a little annoying ain't it ahaha! Don't look at the Government computer systems, I think they are the prime example of exactly this but without the fear of going bankrupt...ha.
Been in public and private, it's just a shitfest everywhere. Surprisingly the government places had way less rainbow flag waving bullshit going on but were packed with boomers who are too lazy and incompetent to succeed anywhere else.
Yeah, when I was able to take a couple classes at a local community college I learned that most Cybersecurity attacks hinge on human error. Thanks for offering your answer!
Are you looking at getting into cybersecurity? I got subbed into an analyst role for 6 months and decided I'd rather neck myself than continue so good luck if you decide to go with it. I'd rather reboot servers for a living and profess total ignorance of cybersecurity shit. Cybersecurity pays very good money and has a massive shortage of competent people so you'll have no issues succeeding if you've got a brain and at least vaguely enjoy it.
 
Dealing with trickery and scams is sadly part of cybersecurity and many simply assume that alot of these malware is the result of some trenchcoat hacker in the 90s that is typing madly on their keyboard. When the reality is, someone in the company clicked the wrong link, connected a contaminated device on there or have been browsing sketchy sites at work.

Or simply a sketchy guy who got into their office and uploaded said ransomware onto the network. Physical security is always a factor.
 
For those more IT privy, specifically networking, these ransomware attacks penetrate business networks through emails right? Either to download or visit a contaminated site right? Would it be beyond the realm of possibility to just have company emails be screened first on a VM or other virtual environment unassociated with the main network? I might be over thinking this. A lot of my friends in IT always complain that they'd like to add more infosec or even upgrade hardware but often get shafted by the budget department. Would a two step process help prevent ransomware or is it just a better idea to backup the entire network every day or so? Because it is very obvious to me that humans are retarded when it comes to this sort of thing.
They could have just found an obvious hole in the school's network or done phishing as you say. A lot of them find targets that are more likely to pay and then go after them.
What you're talking about sort of exists but getting a school district to shell out for it is a big ask and there's still the chance something gets through. As was already posted just paying for proper backups would have been a sound investment here but they didn't even do that and it's fundamental at this point.
 
Adams said making the deal was a risk, but even in the cybercriminal world reputation is everything. Had the criminals taken the money and refused their end of the deal, it could have impacted future deals, Adams said.
So suddenly you're an expert? They have the data and can double dip or just attack you again, retard. If it hurts their "financial interest" they just make up a new name and pretend to be another group.
Basically an admission that it was an inside job IMHO.
 
I don't know, the "We have a reputation to uphold..." bullshit is exactly what an attacker would say to make someone feel better about paying the criminals. Often it takes the experts to show up and explain how retarded it is.
Like six years ago the FBI just gave up and gave people the okay to pay ransoms. Shit's fucked.
 
For those more IT privy, specifically networking, these ransomware attacks penetrate business networks through emails right?
Thats one vector.

Could be unpatched vulnerabilities.
Could be some sort of social engineering.
Could be someone running a malicious macro/script
Could be someone visiting a compromised website
Could be someone installing malicious software
Could be someone bringing in a malicious usb drive

80% of the vectors can be dealt with by making sure your shit is patched and basic security protocols are implemented. Other 20% is on your users not being fucktards.

How do you mitigate this sort of attack? Say the network is completely locked up, bad guys succeeded, and are demanding money. Would a full recovery need to happen?
Ideally by having backups. But that only goes so far since...

Not everyone has backups.
Backups arent always up to date
Backups can take a while to get up and running again

Generally a competent org is gonna have a disaster recovery plan for such a situation. Basically a already made checklist of what to do in such a situation like this. The fact they got to "Pay the $250,000 ransom" is evident retards run that district. Its 2022 and with how much money is thrown at school districts nowadays zero reason for this kind of thing to happen.
 
Última edición:
In my experience, the majority of attacks succeed because the end user is an idiot. The amount of times I've had to wipe and reset some salesperson's email, active directory account and PC or laptop because they got a phsihing email in Engrish from some gibberish address, is alarmingly high.

Edit: spelling
 
Última edición:
Email is probably the most common vector as its easiest to spray. The threat actors really come out and play during the holiday seasons in the US because people like Linda in HR, who reminds everyone to take their cybersecurity readiness assessments, is the first one the click on the bad ”FedEx” link.

You can invest hundreds of thousands of dollars on solutions like FireEye, etc. that sit on endpoints. If an indicator of compromise is detected, you can remotely isolate that machine from the network so that the payload doesn’t spread - then capture a triage file for forensic investigation. Even then, this scarcely prevents anything. You really rely on your users to not be stupid enough to interact with threat vectors.

There’s also shit like Proofpoint for email, but this only reduces the risk, doesn’t eliminate it.

State agencies, like schools, etc. are easy targets because bumpkins with pensions stick around forever and refuse to get with the times. Many school systems in rural towns still have machines running Windows 7, or very early instances of OSX. Business continuity and disaster recovery plans are one of those things you write off until disaster strikes, then, you find yourself spending way more money on solutions because of ignorance. It’s an endless cycle.
 
Atrás
Top Abajo