Campus Life

USU Employees Advised to be on the Lookout for Ransomware

The success of ransomware attacks recently has created a “gold-rush mentality” among hackers, but, so far, Utah State University has not proven a good destination for “black hat” prospectors.

Bob Bayn, who works in security for the Office of Information Technology, is not expecting the “black hats,” as they are often called in the cyber-security world, to ignore USU as a potential ransomware victim anytime soon. The black hats just need one person to open an attachment or click on a link to get started.

Ransomware attacks use a variety of approaches, such as email warning you that your password is about the expire, that you have a package waiting, or even notifying you that you have been caught on a traffic cam speeding through a light. If the hackers can convince you to open their attachment or click on their link, your system can be infected with malware that could encrypt all your data, Bayn said. Then comes the demand for a bitcoin payment to get a key to unencrypt the data.

“Just like Butch Cassidy held up trains, these are people who make their living perfecting and deploying certain kinds of scams,” Bayn said of the hackers.

Bayn has read of attacks that have tripped up other institutions only to discover, with relief, that USU’s filters prevented those same ransomware emails from getting to USU employees. He knows they’ll keep trying, however, so he is doing all he can to educate employees so that ransomware emails that make it through the filters will be recognized and reported by employees before anyone is fooled into clicking on them. Bayn encourages people to become “internet skeptics” and hundreds of employees each year report suspicious emails they receive to phish@usu.edu.

“When we get an email from someone who hasn’t been identified as a spammer or in a form that isn’t recognized by our filters, it will get through,” he said. “And then it’s going to be up to the recipient to recognize the possibility of mischief or it will be up to the victim’s technical support people to clean up after the damage has been done.”

The College of Humanities and Social Services is taking steps to minimize the impact of a successful attack. It is automatically backing up faculty and staff computers to dedicated servers, according to Chris Okelberry, a senior systems administrator.

“Everyone knows the value of backups, but the threat of ransomware has focused our efforts on being prepared,” he said.

Bayn said that departmental IT people may want to consider doing such backups as an additional level of protection for critical documents. He also emphasized the importance of using Box for work files as a safeguard that provides backup copies in the cloud, instead of on a laptop hard drive. While some more sophisticated ransomware can infect files on a laptop that are then synched to the cloud, Box keeps previous versions of a file and could help minimize the impact of ransomware.

“We’ve always had to deal with hard-drive failures and backing up data has always been a wise practice,” Bayn said. “Ransomware has the same impact as a hard-drive failure, in that it suddenly makes all your data inaccessible unless you have a backup somewhere.”

A report issued by Symantec, a global company that specializes in cybersecurity, says that ransomware attacks were at an all-time high in 2015 and the FBI has reported it looks like they are on the increase this year. The Washington Post recently ran a story that cited a Kaspersky Lab study that says the number of users dealing with malware attacks rose from 313,000 in 2014 to 718,000 in 2015.

“The perfection of the ransomware business model has created a gold-rush mentality among attackers, as growing numbers seek to cash in,” the Symantec report says.

Several news sources reported in June that the University of Calgary paid out nearly $16,000 in bitcoins to recover data it lost after a ransomware attack.

The FBI does not support paying ransoms after such attacks. In a press release, issued earlier this year, it quoted FBI Cyber Division Assistant Director James Trainor.

“Paying a ransom doesn’t guarantee an organization that it will get its data back — we’ve seen cases where organizations never got a decryption key after having paid the ransom,” he said. “Paying a ransom not only emboldens current cyber criminals to target more organizations, it also offers an incentive for other criminals to get involved in this type of illegal activity. And finally, by paying a ransom, an organization might inadvertently be funding other illicit activity associated with criminals.”

Ransomware attacks are not only proliferating, they’re becoming more sophisticated, the FBI said.

“Several years ago, ransomware was normally delivered through spam e-mails, but because e-mail systems got better at filtering out spam, cyber criminals turned to spear phishing e-mails targeting specific individuals,” the FBI press release says.

Trainer says that some cyber criminals aren’t even using emails to do their damage.

“These criminals have evolved over time and now bypass the need for an individual to click on a link,” he said. “They do this by seeding legitimate websites with malicious code, taking advantage of unpatched software on end-user computers.”

Bayn warns that ransomware isn’t just sent to people at big companies and organizations. Hackers have learned people will pay to recover personal data like the pictures and documents they have on their computers.

Reports of companies being hit up for thousands or millions of dollars have been in the news but Symantec says that the average ransomware demand this year is $679, up from $294 in 2015.

A Washington Post story, “A new way to fight back when hackers take your data hostage,” reported on a new initiative called “No More Ransom” that launched a website that features a “tool that can help some victims decrypt their data without paying off criminals.”

Writer and contact person: Steve Eaton 435-760-4884


SHARE


TRANSLATE

Comments and questions regarding this article may be directed to the contact person listed on this page.

Next Story in Campus Life

See Also