{"id":6510,"date":"2020-09-09T08:58:00","date_gmt":"2020-09-09T08:58:00","guid":{"rendered":"https:\/\/outofsite.biz\/cynance\/?p=6510"},"modified":"2020-10-27T15:44:25","modified_gmt":"2020-10-27T15:44:25","slug":"newcastle-university-learns-a-new-lesson-the-hard-way","status":"publish","type":"post","link":"https:\/\/outofsite.biz\/cynance\/newcastle-university-learns-a-new-lesson-the-hard-way\/","title":{"rendered":"Newcastle University learns a new lesson the hard way"},"content":{"rendered":"\n
The cyber attacks keep coming this year, and Newcastle University is the latest victim.<\/a> At the end of August, their IT systems failed to block a ransomware attack, causing chaos in the leadup to the new academic year. Let\u2019s take a look at the cyber attack they experienced, and whether it could have been avoided.<\/p>\n\n\n\n On 30th August, the hacker group DoppelPaymer used ransomware to attack the university\u2019s IT systems and stole files, shut them out of systems, and disrupted the university\u2019s IT and services. DoppelPaymer then uploaded some of the stolen files to the \u201cDoppel Leaks\u201d site, and threatened to release more if they are not paid a ransom.<\/p>\n\n\n\n This attack was perfectly timed to cause maximum chaos. The staff at Newcastle University should be in the middle of one of their busiest times, the lead up to the start of the next academic year. Instead, they are now in the middle of a literal nightmare with some systems down, others at risk of shutting down, and computers, servers and other hardware liable to be taken away at any moment. Whatever work was already done for the new year may well need to be redone. The university still doesn’t know the full extent of the damage, and it will take weeks to return to normal. <\/p>\n\n\n\n Ransomware is a piece of malicious software that enters a company\u2019s IT systems, and locks them out unless they pay a sum of money (basically holding their own property ransom). Some ransomware will steal data, and demand payment to stop them leaking it and exposing private information.<\/p>\n\n\n\n DoppelPaymer claimed responsibility for the cyber attack in a Tweet on 7th September 2020: \u201cDear students of the New Castle University Congratulations with an upcoming release of your personal data. What a great start of a new educational year #doppelpaymer #ransomware #malware #doppleleaks\u201d<\/p>\n\n\n\n DoppelPaymer is a hacker group with great experience of getting ransom payments from their victims. In the last few years, they have attacked high profile companies including SpaceX, Tesla<\/a> and Mexico\u2019s state-owned oil company PEMEX. They have been so successful, Group-IB calls them one of \u201cthe greediest ransomware families with highest payoff\u201d.<\/p>\n\n\n\n DoppelPaymer also has friends and alliances with other hacker groups, potentially including Evil Corp. The US Treasury has placed sanctions on Evil Corp because they suspect they work for Russian intelligence services. If they are indeed connected, Newcastle University will breach US sanctions simply by paying the ransom.<\/p>\n\n\n\nUnder (cyber) attack<\/h2>\n\n\n\n
What is a ransomware attack?<\/h2>\n\n\n\n
Who is DoppelPaymer?<\/h2>\n\n\n\n
Why was Newcastle University the victim of a cyber attack?<\/h2>\n\n\n\n