9 ms·
Merck’s NotPetya attack: Was it an act of war?
- hdhgzwhegh 7y agoIf the attacker doesn't declare war and the defender doesn't respond by going to war then the blunt answer seems like it'd have to be a no.
- Iv 7y agoThe claim in the article is that the target was Ukraine, the attacker Russia, and Merck a collateral casualty at an attempt to disguise a state-sponsored cyber-attack as a criminal extortion attempt. One would need to dig deeper to get a really informed opinion. I do believe Russia to be able and willing to do that, I do believe the so-called "Western intelligence agencies" to blame any malware on Russia or China on the flimsiest evidences. There is also the possibility that the same tools were used both by the GRU and Russian criminals, leading to a misleading identification. Black hats would totally take someone else's malware and modify it for their purpose while still hiding their tracks. Zero days are expensive to get but once they are exploits in the wild, they are anyone's to use.
- dvfjsdhgfv 7y agoIf you analyze the NotPetya attack, it differs from other ransomware attempts in two respects. First, it was specifically targetting Ukraine. Second, the attackers didn't actually take any money but rendered all systems defunct. If you are a criminal, you aim to make money, right? Why give up on that possibility? It makes no sense. So, even if in the infosec world you can never say never, but just as Stuxnet is generally attributed to Israel/USA, in the same way NotPetya is attributed to Russia, even though none of these countries will ever admit they actually did it.
- pbhjpbhj 7y ago>If you are a criminal, you aim to make money, right? // I don't think that is right. You don't decide to be a criminal, you decide to perform an action, you get labelled then by others. Some people want to destroy big businesses, they can possibly make as much money as they need already. Of course you can make money through a side-channel that's less traceable too.
- Iv 7y agoOh I did not know that. The attack was behaving differently on Ukrainian targets? That's a pretty damning thing indeed and makes the question of the act of war very relevant. Note that it could make sense to a pro-Russia Ukranian group to extort money abroad and to hurt economically on the target. That seems to be the Russian MO to not be directly implicated in the Ukrainian operations: help with tools, weapons and money the groups that are already in place. They give up direct control over the actions in exchange of deniability.
- MattPalmer1086 7y agoAs far as I know, it didn't behave differently on Ukraine targets. The attack was on Ukrainian tax software M.E.Doc that businesses in the Ukraine are legally mandated to use. So it was targeted at the Ukraine, but plenty of multinational companies also operate there, so they were collateral damage
- qaq 7y agoThis is a bit simplistic my educated guess is in Russia, Ukraine and prob some other countries given pay structure in 3 letter agencies they simply can not afford hiring proper skills for the cyber sec especially for the offensive side. So they have a hybrid private/gov system where certain groups get some level of immunity for their "commercial" activities in exchange for deploying their skills for 3 letter agency use when needed. Alternatively people who are caught for some criminal activity get their sentence suspended in exchange for services.
- Buge 7y ago> One would need to dig deeper to get a really informed opinion. There are a ton of security experts who have indeed dug deeper, and came to the conclusion that it was Russia.
- Iv 7y agoThere just need to be one, with a good write up of the evidence and the evidence be better than "they used the same tools" or "their IP is in Russia". The linked article does not detail them. I have seen US TLAs blame China on really laughable evidences (and fail to do it properly on the one undeniable attack they did on GitHub)
- gamedori5 7y agoSo what does this mean for company cybersecurity? Will companies be motivated to secure their networks by higher insurance rates? Will insurers hire infosec auditors? Will insurers stop offering coverage, and leave companies to consider hacks as Black Swan events?
- deleted 7y ago[deleted]
- throwaway28488 7y agoDon't know but news like this makes me happy I switched from a senior in embedded firmware to a junior in cybersecurity. The future looks good.
- RandomTisk 7y agoThey would be very wise to hire their own auditors, not necessarily to go into their client's businesses but to review the assessments most of them are already getting periodically, to make sure that evidence presented actually made sense and earned them a pass. It's been my experience that IT auditors are often book smart, but IT-experience poor. Some are simply not savvy or experienced enough to interpret their own framework the same way a week or a month later.
- EddieCPU 7y agoI don't believe it, NotPetya was generic ransomware that spread to a lot of organizations including the NHS in England. This fiction, yet another example of the neocons attempting to demonize the Russian Federation, no doubt to distract from problems at home.
- dvfjsdhgfv 7y agoYou must be kidding, right? NotPetya was designed for Ukrainian targets and brought the country to their knees (again) - what some Western companies like Merck or Maersk experienced was just a tiny fraction of what the institutions in Kiev went through. Whether insurers like AIG can run away from their contractual obligations playing the "cyber war" card is a different issue. Technically, it was a cyberattack similar to many others, no matter if the authors were Kremlin-employed or not.
- RachelF 7y agoThe ransomware wanted $300 in Bitcoin per computer encrypted. This is a commercial extortion attempt, not an act of war. The insurers, as is their wont don't want to pay out.
- dvfjsdhgfv 7y agoThis article is talking about NotPetya. It was NOT ransomware. There was no way to recover the files.
- draugadrotten 7y agoJust as a thought experiment, if country X would shut down power in country Y, asking for 100 billion in ransom to start power again. Would that be an act of war, or just commercial extortion? It matters from a legal perspective, and perhaps the laws of war have to be updated for cyber warfare.
- brutt 7y agoLaws of war require to wear uniform, even for cyber soldiers. If they are not wearing uniform when doing their informational attacks, masquerading as civilians, then it's just act of war crime. There is no need to update the law.
- mlb_hn 7y agoEspionage/sabotage is not a war crime https://ihl-databases.icrc.org/customary-ihl/eng/docs/v2_rul_rule107_sectionb https://ihl-databases.icrc.org/customary-ihl/eng/docs/v2_rul...
- brutt 7y agoInformational war is not a espionage, nor sabotage. It similar to sabotage, but, unlike sabotage, it's done from withing territory of attacker. If someone will destroy a factory behind enemy line, then it's sabotage. If someone will launch a rocket from their country to factory in another country, then it's not. If it done by state military agency, then it's act of war. If it done by civilians without support of and not directed by state, then it's terrorism. If it done by civilians, with support of or directed by state, then it's state sponsored terrorism, a war crime. There is no excuse for not wearing of uniform for warriors at their own country.
- throwGuardian 7y agoAct of war against .... Merck, a company? I've heard of some circuitous logic to deny insurance claims, but this was not an act of war against Merck, which BTW isn't a country, so by definition, one can't go to war with it? Well, maybe hyperbolically a competitor might, but unlike real war, they're bound by the rules and laws of civil society This is the very definition of an accident, if the article is to be believed, with Merck not even being the target. Pay up insurers, this is why you exist. Further, what is the point of insurance, especially for sensitive IP laden companies like pharma research, if there's no protection against nationa-state attacks, which isn't outside the realm of possibility for such companies.
- marvin 7y agoWhile I’m opposed to using legal terms to weasel out of an insurance claim, it’s an interesting question. If Russia deliberately dropped a bomb on Merck’s factory, it would unquestionably be an act of war. Likewise if they dropped a bomb on a neighboring plant and also accidentally destroyed Merck’s plant. But dropping a bomb on a facility in Ukraine, with equally destructive shrapnel destroying facilities all over the world? Knowing that using this weapon can easily cause such collateral damage? We barely have the terminology for discussing this type of warfare. The initial attack was an act of war, certainly. Beyond that, we have to come up with definitions and reactions. At the very least, it’s a subject for diplomatic channels, maybe even sanctions.
- gchamonlive 7y agoDropping a bomb is not an act of war because of the target itself. It is because to do it you have to violate the country's whole security system and cause damage to the country's real state, which is an act of war, whereas to invade a company's cluster of computers you don't have to compromise the country's whole cybernetwork. It is interesting though to think about aftermath. If it is not an act of war, one can compromise a country's economy without going directly against the country itself.
- dsfyu404ed 7y ago
- arminiusreturns 7y agoThe main problem with allowing cyberattacks into the "declaration of war" category against all known diplomatic norms, is that attribution is extremely questionable. History is full of false flags done in the physical realm. Cyberattacks will be no different, other than easier to perform.
- hurrdurr2 7y agoNo.
- anon9001 7y agoIt's really an act of not being prepared. $1.7B? They should be able to destroy and rebuild their entire infrastructure in less than a day. Have tested backup and restore processes. Ideally have all users in VMs. I don't see how this isn't entirely Merck's fault.
- _Wintermute 7y agoI work at a pharmaceutical company and this does not suprise me at all. Our IT infrastructure and support is atrocious.
- marvin 7y agoNot entirely Merck's fault. It wouldn't have happened (at this time) if Russia hadn't used their weaponized exploit. There's also something to be said for being the first large-scale victim of a category of catastrophe that is known to be a real threat, but hasn't happened on this scale before. But you do have a point. There were probably security or IT ops people who warned about this, and if Merck's shareholders take the full hit, organizations will properly feel the risk and adjust their backup & restore processes accordingly. Not so if insurance pays the full damages.
- MattPalmer1086 7y agoIf you cannot trust any of your existing infrastructure anymore, including servers, desktops, storage systems, directory services, and the backup systems themselves, you will not be rebuilding it all in a day...
- UweSchmidt 7y agoOur entire software and hardware ecosystem is extremely vulnerable and any single layer or part you can name has been proven insecure. Processors, programming languages, frameworks and packages, undersea cables, routers...it's swiss cheese all the way down. All of us who are working in software and hardware are in a way to blame for this disaster and until everything is rebuilt from the ground up computing will depend on the worldwide cooperation of benevolent actors.
- anon73044 7y ago
- Teknoman117 7y ago> One researcher told a colleague she’d lost 15 years of work. You're telling me that you had never backed up anything in the span of 15 years?
- pjc50 7y agoThis happens far more often than it should. Non-experts simply don't realise the importance of backups.
- SmellyGeekBoy 7y agoIt could be that the backups were "online" and therefore also wiped out by the malware.
- dragonelite 7y agoYeah sure, just like sanctions and tariffs are a economic way of doing war. But how do you response with counter cyber attacks or sanctions and tariffs.
- filleokus 7y agoSomething like a missile attack on a Samsung factory is so easy to investigate and get conclusive evidence about what happened. Within hours or days we would know with almost certainty if it was an act of war or something else (accidental firing by the South Korea military or something...). Consider something like Stuxnet, it took years before it was truly discovered and attribution could be made, at least in way which would hold up in a lawsuit about insurance claims.
- drhagen 7y agoI worked at Merck for three years as a scientist and only left a week before this went down. My former colleagues said they stood around and did absolutely nothing for days and then struggled to get the tiniest amount of work done for weeks. The article chooses not to get into stunning mistakes by Merck's IT that allowed this to happen in the first place. The patches for the EternalBlue exploit were released by Microsoft on March 14, but Merck's IT chose to sit on it for over three months. (Like many large companies, they disable Windows update, choosing to release patches on their own schedule.) Even after the WannaCry attack crippled computers around the world on May 12, they still had a month before NotPetya brought them to their knees on June 27.
- mc32 7y agoI'm not familiar with their environment but depending on the software and vendors who support aspects of software, those patches may be held at their request. That is people like Rockwell, Emmerson, whatever, may not “release” a patch because it can have implications for GxP environments. So not saying this is the case, but there are times when that is the case and companies have to sit on fixes. However in these situations those systems are siloed and segregated do that things don’t propagate. I have no idea how Merck is setup.
- drhagen 7y agoAs far I understood, particular machines were under GxP requirements, but the vast majority were not. We scientists had local admin access to our laptops. To access some GxP software, we connected via a client that was like a remote desktop.
- moftz 7y agoUnless you do development where a Windows patch could break a complex environment, most people in the workplace are always using all Microsoft products anyway so they should just be on auto-update. All it takes is for some IT manager to sit on a critical patch for too long. If auto-updates break your setup, then you could opt-out and be moved to a sandboxed environment where you still get patches but only after they are verified. I remember when some vcredist patch broke a very expensive development suite. Despite all the engineers affected complaining to IT, it took them weeks to roll it back for us. In the mean time, we had figured out ways to debug the tool with Visual Studio, catch the error, and continue past it without crashing everything. The patch must have broke quite a lot of things because there was another one that came shortly after that seemed to avoid the problems.
- ga-vu 7y agoYes it was. I think everyone from Five Eyes to private cyber-security experts have said this already for the past two years.
- piffey 7y agoNo, it wasn't. And this over-militarized diction of cybersecurity is dangerous. You want nation states to be bombing developers sitting in offices due to a perceived threat because this garbage rhetoric is how that happens. Oh wait, here we are. Hope your bunker is ready! https://www.zdnet.com/article/in-a-first-israel-responds-to-hamas-hackers-with-an-air-strike/ https://www.zdnet.com/article/in-a-first-israel-responds-to-...
- upofadown 7y agoIf a country funds a bunch of script kiddies to attack something somewhere does that make the attack a state action? If the state takes measures to conceal the source of that funding then is it still a state action? If a group of script kiddies takes action due to a general suggestion from a state actor? If a group of script kiddies with political aims congruent with one or more state actors takes action all on their own? This stuff is fundamentally different than the case where a group of people end up with guns and engage in politically motivated violence. It is really a form of advanced trolling. The fact that absolutely anyone can do with with no fear for their life or freedom makes it politically meaningless. There is no such thing as cyberwar... So insurance is really just about insuring against security lapses. It should be priced appropriately and should come with requirements.
- nabla9 7y agoIt's up for the attacked (the US) to decide when the line is crossed and how to respond. Russian strategy is to confuse as mush as possible possible. They do cyber attacks, assassinations and political operations in the western countries. Obama used covert action against Russia in response to election meddling. "Obama used covert retaliation in response to Russian election meddling." https://www.washingtonpost.com/news/monkey-cage/wp/2017/06/29/obama-used-covert-retaliation-in-response-to-russian-election-meddling-heres-why/ https://www.washingtonpost.com/news/monkey-cage/wp/2017/06/2... Trump is not responding. Is hybrid warfare a warfare until it includes conventional warfare in the mix? https://en.wikipedia.org/wiki/Hybrid_warfare https://en.wikipedia.org/wiki/Hybrid_warfare > Hybrid warfare is a military strategy which employs political warfare and blends conventional warfare, irregular warfare and cyberwarfare[1] with other influencing methods, such as fake news,[2] diplomacy, lawfare and foreign electoral intervention. > The U.S. Army Chief of Staff defined a hybrid threat in 2008 as an adversary that incorporates "diverse and dynamic combinations of conventional, irregular, terrorist and criminal capabilities".[9] The United States Joint Forces Command defines a hybrid threat as, “any adversary that simultaneously and adaptively employs a tailored mix of conventional, irregular, terrorism and criminal means or activities in the operational battle space. Rather than a single entity, a hybrid threat or challenger may be a combination of state and nonstate actors".[9] The U.S. Army defined a hybrid threat in 2011 as "the diverse and dynamic combination of regular forces, irregular forces, criminal elements, or a combination of these forces and elements all unified to achieve mutually benefiting effects".[9] NATO uses the term to describe "adversaries with the ability to simultaneously employ conventional and non-conventional means adaptively in pursuit of their objectives"
- exabrial 7y agoNo. Not an act of war: an act of embarrassment. Merck should be shamed. Can we stop calling these things "cyber attacks" or "hacks"? I think "gross negligence on applying even basic information security" and "a focus on security theatrics" fit much better.
- LatteLazy 7y agoI really enjoyed this despite insurance usually being billed as dull. A few points I don't see anyone else making: * Act of war is poorly defined (and gets more poorly defined by the year). Since insurers use this term and (I assume) wrote the contracts, any reasonable question over its definition should be interpreted in the insured favour. That's how most contract law works since otherwise the contract writer has a perverse incentive to make their contract language unclear and then argue definitions and technicalities. That's not just dishonest, it creates unnecessary uncertainty and excess court cases and those cost everyone. * I was sort of amazed by mention of the presidents pronouncements as if they mattered. Do they matter legally? They shouldn't: presidents are in no way a reliable source of information on geopolitical matters. Quite the opposite, they have the most motive to lie and its literally often illegal to expose that (if an NSA employee leaked classified proof it was NOT the Russians, they'd be imprisoned under the espionage act). Leaving aside the current presidents reliability, Obama pronounced on the Sony hack, blaming North Korea. Almost 5 years later and no evidence has been produced and plenty of people doubt that. Its also worth noting that no president should be empowered to effectively decide billion (trillion?) dollar lawsuits without oversight or scrutiny, they're not kings after all. * Finally I thought how adult and reasonable Lloyds' response was. Both in settling the claim (assuming they did so for a reasonable fraction of what was owed) and requiring explicit cyber policies going forwards. That's the act of a group that is reasonable and wishes to take a long term, useful, role in the economy. Any bozo can sell "insurance" policies and then quibble over ever claim, the result is people stop buying. But honouring your commitments and correcting yourself going forwards is exactly what we need in insurers. I wonder what can be done to get US Corporate structures to follow a similar model?
- FpUser 7y agoSpeaking of war. Just to show how effed is the definition, here is the article where they try to decipher between war, armed conflict, whatever else they've come up with: https://www.washingtonpost.com/world/national-security/is-it-a-war-an-armed-conflict-why-words-matter-in-the-us-fight-vs-the-islamic-state/2014/10/06/f4528a6c-49a1-11e4-891d-713f052086a0_story.html https://www.washingtonpost.com/world/national-security/is-it...
- dmix 7y agoConsidering it hit the company by accident via a server in Ukraine the whole act of war thing is really questionable. It’s completely reckless use of malware and there should be consequences for Russia not taking care of their offensive weapons and causing serious damage. But phrases like “act of war” shouldn’t be thrown around like that. I highly doubt that was Russia’s intention, which I think should matter, even if we still find them at fault.
- tqi 7y agoI don't think the accidental nature is the crux here. As I understand it, if a Russian bomb had inadvertently damaged / destroyed a physical office in Ukraine, the insurance would not have covered that either. The question is whether or not this virus was an act of war (against Ukraine) or if this was an act of vandalism/crime by an individual actor.