back to article Ransomware crims read our bank balance and demanded the lot, reveals Scotland's Dundee and Angus College

The criminals who took out Scotland's Dundee and Angus College made a ransom demand that precisely added up to the contents of its bank account – and that was no accident, its principal has said. In a postmortem interview with academic IT nonprofit Jisc, Simon Hewitt lifted the lid on the 31 January ransomware attack, which …

  2. Kev99

    Hopefully you'll learn to NOT put sensitive, proprietary or confidential information on the web.

  3. Anonymous Coward
    But the staff are still extremely angry that there was no backup of their professional life's work, in some cases decades of material. No backups!

    1. martinusher Silver badge

      Re: Backup

      Relying on someone else's security and backup strategy only works if the work you're going to lose isn't important.

      I grew up in a world of operating system and driver development where a slightly misplaced piece of code could demolish your development system (back then developmet and test were one and the same and the idea of a network drive to store stuff on was pure fantasy). You very quickly learned the value of backups. Having corporate dictate the use of SourceSafe for version control and source archiving also teaches valuable lessons about not letting your guard down.

    2. Anonymous Coward
      Anonymous Coward

      Re: Backup

      Not that unusual.

      I've been called out to clients where they had backup drives and tapes etc but nobody was changing them. Surprisingly frequently tbh.

      Even better is when they backup to the cloud but someone changed the password a couple of years ago and didn't think to do so on the server that actually backed up data to it. So for 2 years+ it's been failing to access.

  4. Missing Semicolon Silver badge

    So instead of un-backed-up local storage

    .. they are going to use un-backed-up cloud storage! Profit!

      Re: So instead of un-backed-up local storage

      And it's in Microsoft's contract that your data is ultimately your responsibility, and they are not liable if it gets nuked in a way unrelated to them (i.e. not storage or server failure).

      Frequently, Exchange Online just doesn't fucking work. What do you do when your cloud rains?

    We were hit by a ransomware attack at the start of the year.. my heart skipped a few beats when I discovered it. They destroyed our accounts software, company documents, years worth of client files etc. All from a compromised user password via remote web workplace.

    Luckily my backup strategy was sound and we were able to restore everything with no losses. It took a few days as we have terabytes worth of data.. Remote access is now only possible via OpenVPN with unique usernames, passwords and certificates for each user.

    1. Phil O'Sophical Silver badge

      Re: Backups

      Luckily my backup strategy was sound

      That wasn't luck, it sounds more like professionalism to me.

    2. yoganmahew

      Re: Backups

      And what Rabbit shows is that every business that uses IT is in the IT business; it's not a cost centre, it's a central part of the business. It's depressing how few businesses realise this.

    3. c1ue

      Re: Backups

      Sounds like a law firm.

      Just out of curiosity: what is the ratio of demanded ransom vs. losses suffered from the BCI of the restoration?

  6. man_iii

    STOP using MicroShaft for critical infra?

    If you depend on Microsoft then you probably deserve to get hacked. I remember when colleges used to run Sun Solaris servers and dos mounted Unix samba volumes per Dept software or used NFS all located on UNIX servers I dunno how long those things were running for. .. until when I left they tore it out and instead installed Microsoft AD and outlook. ... cue infinite crashes and instability and networks going wonky students mail lost. ..


    1. Anonymous Coward
      Anonymous Coward

      Re: The Need For Speed

      Ah yes.. the old 'security by obscurity'. Nobody uses UNIX for anything important, which is why nobody bothers to go after it... all the really vital stuff all runs on Windows, UNIX and Linux are for script kiddies....

      (If only we could troll icon as A/C eh...)

        Paris Hilton

        Re: The Need For Speed

        I don't think he was talking about security. Which is strange given the context of the article, but still.

        In closing, as a Windows sysadmin: fsck Windows.

  7. Sparkus Bronze badge

    be it a 'cloud' or a central-services model, the only 'backup' you can depend on is the one you can touch, feel, and restore yourself.

    All else is subject to so-called SLA negotiation, competence / incompetence of IT staff, and the vagaries of the Black Hats in the world.

  8. Santa from Exeter

    Cyber Essentials

    To Quote "At the end of 2019 we were proud of the fact we had got Cyber Essentials in place, but it didn't 'save' us"

    Of course it sodding well didn't! CE is self-adjudicated, what did you say that you were doing but fudged the truth a bit?

    1. EnviableOne Silver badge

      Re: Cyber Essentials

      Even CE+ which is externallly assessed wont protect you against someone targeting you speificially.

      It will however put you in a good place to resist untargeted or random attacks, in the sense, that yyou will be harder to hit than some others.

      CE is just that, its the basics, and if you are doing them right, you need to start working towards something more substantial, like 10 steps, CIS top 20, and on to ISO27000 and others....

  9. c1ue

    Attackers sound like amateurs.

    Doesn't seem like backups were compromised - plus the ransom demanded was clearly too high.

  10. Alan Brown Silver badge

    at some point....

    these people are going to find that the response consists of a .22 doubletap

