back to article Nothing to scoff at: Crisps and nuts biz KP Snacks smacked in ransomware hack attack

Some of Britain's favourite pub munch could end up in short supply after KP Snacks, makers of nuts and crisps, suffered a ransomware attack. KP dry roasted peanuts A family pack perfectly normal single serving of KP dry roasted peanuts Kenyon Produce, to give the company its formal name, wrote to small shops around the UK …

  1. KarMann Silver badge
    Facepalm

    Neither confirm nor deny, if you can't

    Representatives of KP had not answered phonecalls seeking comment.
    To be fair, they may well be using IP phones, and so….

    1. TRT Silver badge

      Re: Neither confirm nor deny, if you can't

      I'm surprised the headline didn't refer to either "NikNaks Shack in Hack Attack" or "This time it's the Real McCoy."

  2. Spaceharrier

    Inside job?

    Apparently this attack has been attributed to a threat actor known as POM-BEAR.

    1. Dave559 Silver badge

      Re: Inside job?

      Reports that a football pundit was seen trying to plug in a USB stick at the reception desk PC are completely untrue…

      (Not that his own snack-making friends haven't had IT problems of their own fairly recently. The spice, and other savoury and salty tasty snack product supplies, must flow!)

      1. Korev Silver badge
        Coat

        Re: Inside job?

        He did it and then just Walkers out...

        1. TRT Silver badge

          Re: Inside job?

          Pwn cocktail?

  3. Inventor of the Marmite Laser Silver badge

    Crumbs!

    1. Ayemooth

      Surely any ransom request would be peanuts to a company the size of KP?

      1. The Oncoming Scorn Silver badge
        Pint

        Cash Please!

        To be paid in crisp £50 notes

        1. mif

          Re: Cash Please!

          Cryspocurrency, surely?

          1. TRT Silver badge

            Re: Cash Please!

            Bitscoins?

  4. Anon

    To the German Commander:

    N U T S !

    -- The American Commander

  5. Howard Sway Silver badge

    ransomware gangs have concentrated on the soft underbelly of the West

    But by hitting the supplier of these products, our bellies are likely to become much less soft.

  6. Robert E A Harvey

    "fuck clinics in the USA this week" said one criminal

    I'd quite like to go to a fuck clinic. It sounds a lot more fun than the ones I normally have to attend.

    1. Neil Barnes Silver badge
      Paris Hilton

      Re: "fuck clinics in the USA this week" said one criminal

      Depends whether you have to go 'to' or 'because'...

    2. Jedit Silver badge
      Coat

      Re: "fuck clinics in the USA this week" said one criminal

      Fuck clinics in the USA

      Fuck clinics in the USA

      Whoooooa-ohhh (Fuck clinics!)

      Mine's the one with the heart of glass...

      1. TRT Silver badge

        Re: "fuck clinics in the USA this week" said one criminal

        A fun loving criminal?

  7. This post has been deleted by its author

  8. Piro Silver badge

    Kenyon Produce?

    I didn't know that, thanks for the trivia.

  9. Pascal Monett Silver badge

    They are cooperating with the authorities

    And have responsibly disclosed the situation.

    One can only hope that this will aid authorities to home in on the source and get Putin to do something about them.

    With all the hacker groups he has, Putin can afford to sacrifice another one.

    1. TRT Silver badge

      Re: They are cooperating with the authorities

      Did he also attack Mondelez savoury products division? That'd be Putin on the Ritz.

  10. Ken Moorhouse Silver badge

    They should have...

    ...used more salt.

    1. TRT Silver badge

      Re: They should have...

      They should have engaged an ethical hacking organisation to determine their Penn State.

  11. Anonymous Coward
    Anonymous Coward

    In other NEWS

    Doctors predict a small downswing in coronary patient admissions in coming weeks.

    1. Ken Moorhouse Silver badge

      Re: Doctors predict a small downswing in coronary patient admissions

      Not forgetting people with a nut allergy.

      1. Anonymous Coward
        Anonymous Coward

        Re: Doctors predict a small downswing in coronary patient admissions

        Peanuts are a pea not a nut.

        People either have a specific Peanut allergy, or a non-specific nut allergy (cannot contain Peanuts by definition), or both!

        It makes a lot of difference to be accurate and the media don't help in this matter, always conflating the two problems.

        EpiPen at the ready!

  12. Anonymous Coward
    Anonymous Coward

    Windoze security as service

    Lemme take a guess that the ransomware infected vector was a Winduze platform ?

    STOP using Windooze for mission critical tasks!!!

    1. Little Mouse
      Meh

      Re: Windoze security as service

      </yawn...>

    2. Anonymous Coward
      Anonymous Coward

      Re: Windoze security as service

      STOP using Windooze for mission critical tasks!!!

      I've been saying that for the last twenty years. Anything in a medical environment, factory, military where you want your system functional when you use it, should NOT be running Windows.

      I've seen first hand medical equipment put out of action at critical times because a windows update killed the system. All updates on critical systems should only be done under the control of an engineer ( in the case of a medical device) and in a scheduled and controlled manner.

      Preferably use Linux. Brownie points to GE who got that right.

      1. Stuart Castle Silver badge

        Re: Windoze security as service

        Merely switching the OS isn't going to stop ransomware.

        Linux may be harder to attack that Windows, but it is not invulnerable.

        When setting up a corporate network, you need to build in security from the start.

        You need to ask yourself which stations on the network need access to the internet, and why. Any stations that don't need internet access should not have it. By "stations", I mean any device that may be attached to the network, whether it's a computer, printer, a medical device or some sort of manufacturing machine. Things like printers should not be accessible on the Internet.

        If something needs remote activation, or updating, you need to see if the manufacturers can offer a local Update or Licencing/Activation server.

        You also need a decent security system, including firewall/antivirus/intrusion detection, and to ensure any systems are locked down as tightly as they can be without impacting corporate needs.

        The downside for all this is that if you do have a specialist machine connected to the network, and it goes wrong, the manufacturer will need to actually send an engineer to diagnose the problem. They will not be able to do it remotely, unless you give that machine Internet access.

        Any new software/hardware that goes on the network should be thoroughly tested before use, and any updates should also be thoroughly tested, but should be deployed when they pass the test. It *is* important to keep software up to date.

        Finally, there is the User. Users need to be told how to spot scams, and need to know not to just click random links in emails, or open attachments from those they don't know.

        The trouble is, all that costs money to do properly, and if done properly, all it achieves is the system working as it should. That is a difficult sell to the beancounters because they'd point out that the system is just doing what it was bought to do, and they'd question why they need to spend more on it..

        There is a lot more I could say about this (people have written books on this stuff), but this post is already too long. The TLDR is that no software/hardware is invulnerable. You need a well designed network, with security built in and good security practices being carried out by staff as well..

        1. John Brown (no body) Silver badge

          Re: Windoze security as service

          "Finally, there is the User. Users need to be told how to spot scams, and need to know not to just click random links in emails, or open attachments from those they don't know."

          Unfortunately, badly thought out "security" just trains uses to click "OK" to everything. We recently were forced onto O365. My laptop, now on the corporate domain, won't allow me to install my preferred LibreOffice. (preferred, because of my limited use of spreadsheets and documents so the cleaner interface is far better IMO). This means every time I open a local spreadsheet, I'm warned that "documents from the internet could be harmful" and have to click it into edit more from read-only mode. Every time. And can't change it. Ditto, when I'm finished with a particular spreadsheet and move it to the archive folder, I get warned again, and have to click OK to say, yes, I really want to copy this "dangerous file" from one local directory to another. Interestingly, if I get a spreadsheet by email and open it from outlook in edit mode from Onedrive, I don't see those warnings. If I was more cynical, I might suspect that MS are trying to discourage users from creating and storing local documents in favour of storing them where they can take a peek.

          1. J.G.Harston Silver badge

            Re: Windoze security as service

            Reporting from the coal face, another issue is too much software is badly written and requires the user to have Admin permissions to run, or requires Admin to allow another user to run it, or to see the test equipment plugged into it.

            Doing the recent Win10 rollout, way too much required hours on the phone to the supplier for them to remote in and flick some switch somewhere. For Every Single Bloody Machine.

        2. Dante Alighieri
          Big Brother

          remote access medical devices

          No access, no support I'm afraid.

          Some even use NTP from Japan.

          The big 6+ figure toys I play with in medical imaging are connected, they have to be.

          In theory you could switch access on and off as required. In reality not so much.

          I know there are NHS IT commentards and am happy to be corrected but would be surprised if I was.

      2. FatSuperman

        Re: Windoze security as service

        I'm sure all of us would be happy to migrate to Linux, once we get over the major hurdles of there not being the software, skills or support to run it for everything in the world.

        Once that lifetime's endeavor is complete, we'll need to move to some other OS, because the baddies will simply follow where the users are.

        If we magically switch Windows for Linux, we'd barely improve the security landscape.

    3. andy gibson

      Re: Windoze security as service

      "Windooze" and "Windoze"

      How original. At least you didn't use Micro$$$oft and Micro$$haft I suppose.

    4. J.G.Harston Silver badge

      STOP using Windooze for mission critical tasks!!!

      CardioView doesn't work on Linux.

      INRStar doesn't work on Linux.

      Sullivan Cuff doesn't work on Linux.

      UroDiary doesn't work on Linux.

      accuRx doesn't work on Linux.

      CardioLink doesn't work on Linux.

      Crescendo doesn't work on Linux.

      DigiScript doesn't work on Linux.

      EasyLog doesn't work on Linux.

      EMIS doesn't work on Linux.

      SystemOne doesn't work on Linux.

      JayEx doesn't work on Linux.

      MicroLife doesn't work on Linux.

      ECGViewer doesn't work on Linux.

      ScriptSwitch doesn't work on Linux.

      SpaceLab doesn't work on Linux.

      Spirometry doesn't work on Linux.

      1. cawfee
        Pint

        Re: STOP using Windooze for mission critical tasks!!!

        don't you know that all you need is wine and an obscure foss shim and you'll be just fine, everything runs perfectly on linux and you don't worry about spending loads of time to set anything up ever

        /s in case it wasn't clear.

        make mine a pinot >

      2. TRT Silver badge

        Re: STOP using Windooze for mission critical tasks!!!

        More w(h)ining.

      3. Dante Alighieri
        Black Helicopters

        Medical software

        I'm sure you are right!

        How many work on a Mac? (real question)

        But it is a self fulfilling prophecy - won't run, so no demand on other platforms.

        There are some very smart GPs doing all sorts of IT development and platform agnostic or FOSS.

        I've seen their work on another restricted forum.

        There IS an appetite for this. Getting the medical megacorps to respond is harder.

        WINE is constantly improving and can help but the real solution is multiplatform support.

        Open standards can and do work in helping this - check out what happens with DICOM and the IHE connectathons. It pulled a whole industry into line.

    5. Anonymous Coward
      Anonymous Coward

      Re: Windoze security as service

      I’m more concerned about piss poor applications as the attack vector than the underlying O/S.

      1. Ken Moorhouse Silver badge

        Re: piss poor applications as the attack vector than the underlying O/S.

        I would argue that when the underlying O/S is so ephemeral in nature, writing robust applications for it is a challenge. MS fall foul of this as much as others, but for smaller developers it can be uneconomic to write software for it.

  13. Mr. V. Meldrew
    Coat

    Your going to get a kick in the .....

    Dear Ransomware Cretin,

    I have a small family gathering at my home tomorrow (Saturday).

    My cousins who are the last of my family will be attending.

    If I cannot obtain their favourite snack, KP Dry Roasted Peanuts (250g pack) then I will hunt you down and give your nuts the big kicking they deserve.

    Yours, without malice aforethought

    Mark T.

    (Snacks at 3.00 PM - Carriages at Midnight - All welcome, BYOB.)

  14. TRT Silver badge

    Oh no!

    That's Tyrreble news!

  15. Anonymous Coward
    Anonymous Coward

    This even made the BBC R4 news this morning. As one presenter commented, never mind all the other problems in the world, now we'll have a shortage of Hula Hoops as well.

  16. Will Godfrey Silver badge

    <sigh>

    This has now become positively endemic, yet is is pretty much a solvable problem - for industry at least.

    A few years back, before I retired I was seriously impressed when I went to fit a new drive to a timber merchants CnC sawmill. Physically fitting the drive was pretty much standard, but it then had to be configured.

    With the drive itself was a telephone number which I had to ring. This got me to one of the manufactures tech bods, who asked for model and serial numbers of both the machine and the drive. He then asked me to enter the configuration page on the machine's control system and confirm that it had a specific ID. At this point I had to enter a password he gave me. Apparently, although the machine was on the network, it was completely deaf and dumb until these steps were taken.

    To my surprise, on doing so a small window insert opened with a view of the guy. From then on he handled the setup asking me to confirm various actions were taking place. Finally, he sent a software update, and told me to shutdown the machine, and on restart it would be ready.

    P.S. Heidelberg has a variation for their modern printing presses. These are continually sending telemetry to them, and they will then call the print shop to warn them that a part is worn and needs replacing, or if the machine has faulted, they give instructions on the probable cause and where the engineer should look! This again, is pretty hard to defeat, as it's 'send only'.

    1. Ken Moorhouse Silver badge

      Re: continually sending telemetry

      This can be very useful for all concerned. However, I have encountered questionable antics by printer suppliers to bolster their monthly revenue. The most obvious is the install team configuring the printer to always print in colour rather than using black, resulting in unnecessarily high charges for companies who predominantly require black copies.

      Easy to change, sure, but many companies rely on third-parties to do the honourable thing and give them properly configured tools for their job.

      1. Anonymous Coward
        Anonymous Coward

        Re: continually sending telemetry

        Heidelberg presses are a bit different (and a LOT bigger) from a home printer - think newspaper presses instead of the printer/photocopier in the corner of the office. They are also more likely to be sold with a service contract, which takes the sting out of paying for maintenance work.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like