Skip to main content

Texas cops lose evidence going back eight years in ransomware attack

  • January 27, 2017
  • 0 replies
  • 0 views

Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54
It must be remembered that although the rule is Backup, Backup, Backup, the backups must be good, valid and not from AFTER the infection has taken place.
 

We have to get very, very tough on cyber and cyber warfare… and backups?

 
                                


 
27 Jan 2017 at 16:57, Alexander J Martin
 
Cockrell Hill, Texas has a population of just over 4,000 souls and a police force that managed to lose eight years of evidence when a departmental server was compromised by ransomware.
 
In a public statement, the department said the malware had been introduced to the department's systems through email. Specifically, it arrived "from a cloned email address imitating a department issued email address" and after taking root, requested 4 Bitcoin in ransom, worth about $3,600 today, or "nearly $4,000" as the department put it.
 
It was at this point that the cops' backup procedures were tested and found to have failed to account for the mischief. When recovery was attempted, they realised they had only managed to back up the encrypted files.
 
Full Article