Strong cybersecurity policy (for businesses and other organizations)

strong cybersecurity policy

A strong cybersecurity policy is essential for protecting an organization’s assets, data, and reputation from cyber threats. A comprehensive policy should address all aspects of cybersecurity, including risk assessment and management, access control and authentication, data protection, network and system security, incident response, training and awareness, and compliance.

One key aspect of a strong cybersecurity policy is risk assessment and management. This involves identifying potential cybersecurity threats and prioritizing them based on their likelihood and potential impact. Appropriate controls and measures should then be implemented to mitigate these risks.

Access control and authentication are also critical components of a strong cybersecurity policy. Employees should use unique login credentials and regularly update their passwords to prevent unauthorized access. Two-factor authentication can also provide an additional layer of security.

Data protection is another important consideration. Sensitive data should be classified based on its sensitivity and appropriate safeguards (e.g. encryption) should be put in place to protect it. Regular backups of critical data should also be performed to ensure it can be recovered in the event of a disaster.

Network and system security are essential for protecting against cyber threats. This includes the use of firewalls and other security measures to protect networks and systems, as well as regular updates and patches for all software and systems.

An incident response plan is critical for handling cyber threats when they occur. This should include a process for identifying and containing threats, as well as notification of relevant parties (e.g. law enforcement, affected individuals). Regular testing and drills of the incident response plan can help ensure it is effective when needed.

Training and awareness are crucial for ensuring that all employees understand their role in protecting the organization from cyber threats. This can include regular training on cybersecurity best practices and current threats, as well as the provision of resources (e.g. newsletters, posters) to remind employees of their responsibilities.

Finally, it is important for an organization to ensure compliance with relevant laws and regulations related to cybersecurity. This may include regular review and updates to the cybersecurity policy to ensure compliance, as well as investigation of any reported policy violations.

Overall, a strong cybersecurity policy is essential for protecting an organization from cyber threats. By addressing all aspects of cybersecurity and regularly reviewing and updating the policy, organizations can ensure they are prepared to handle any potential threats that may arise.

Sample outline topics to consider for your organization's cybersecurity policy

  1. Introduction:
  • Purpose of the policy
  • Scope of the policy (e.g. applies to all employees, contractors, etc.)
  • Consequences of non-compliance
  1. Risk assessment and management:
  • Regular risk assessments to identify and prioritize potential cybersecurity threats
  • Implementation of appropriate controls and measures to mitigate identified risks
  1. Access control and authentication:
  • Use of unique login credentials for each employee
  • Regular password updates and use of strong passwords
  • Use of two-factor authentication when appropriate
  1. Data protection:
  • Classification of data based on sensitivity and implementation of appropriate safeguards (e.g. encryption)
  • Regular backups of critical data
  • Restriction of access to sensitive data to authorized personnel only
  1. Network and system security:
  • Use of firewalls and other security measures to protect networks and systems
  • Regular updates and patches for all software and systems
  • Monitoring of networks and systems for suspicious activity
  1. Incident response:
  • Creation of an incident response plan to be followed in the event of a cybersecurity breach
  • Regular testing and drills of the incident response plan
  • Notification of relevant parties (e.g. law enforcement, affected individuals) in the event of a breach
  1. Training and awareness:
  • Regular training for employees on cybersecurity best practices and current threats
  • Provision of resources (e.g. newsletters, posters) to remind employees of their responsibilities related to cybersecurity
  1. Compliance:
  • Regular review and updates to the cybersecurity policy to ensure compliance with relevant laws and regulations
  • Investigation of any reported violations of the policy.
  1. Mobile device security:
  • Implementation of appropriate controls and measures to secure company-owned and personally-owned mobile devices that access company data
  • Use of mobile device management software to monitor and secure devices
  1. Email security:
  • Use of spam filters and email encryption to protect against phishing attacks and other email-based threats
  • Prohibiting the use of personal email accounts for company business
  1. Physical security:
  • Implementation of physical safeguards (e.g. locked cabinets) to protect against unauthorized access to devices and data
  • Use of security cameras and other monitoring measures to protect against physical threats
  1. Vendor security:
  • Evaluation of the cybersecurity practices of vendors and service providers before entering into a relationship
  • Requiring vendors and service providers to adhere to certain cybersecurity standards in order to do business with the company
  1. Cloud security:
  • Careful evaluation of the security measures in place when storing data in the cloud
  • Use of contracts and other legal measures to ensure the security of company data in the cloud
  1. Internet of Things (IoT) security:
  • Evaluation of the security of IoT devices before deployment
  • Implementation of appropriate controls and measures (e.g. changing default passwords) to secure IoT devices
  1. Cybersecurity insurance:
  • Consideration of the purchase of cybersecurity insurance to protect against financial losses resulting from a cyberattack.
  1. Network segmentation:
  • Segmentation of networks to limit the spread of potential threats and reduce the attack surface
  • Use of network access control lists to restrict access to certain network resources to authorized users
  1. Secure development practices:
  • Adoption of secure coding practices to reduce the likelihood of vulnerabilities in custom software
  • Use of code review and testing processes to identify and address potential vulnerabilities
  1. Security monitoring and reporting:
  • Implementation of security monitoring tools to identify and alert on potential threats
  • Regular reporting to management on the state of cybersecurity within the organization
  1. Third-party security assessments:
  • Regular third-party security assessments to identify and address potential vulnerabilities
  • Implementation of recommendations from security assessments
  1. Employee offboarding:
  • Implementation of processes to secure company data and systems when an employee leaves the organization
  • Deactivation of accounts and revocation of access to company resources
  1. Business continuity and disaster recovery:
  • Implementation of a business continuity plan to ensure the continued operation of critical business functions in the event of a cyberattack or other disaster
  • Regular testing of the business continuity plan
  • Implementation of a disaster recovery plan to recover from a disaster and restore systems and data.
  1. Security-related policies and procedures:
  • Development of policies and procedures related to specific security measures (e.g. password management, data classification)
  • Communication of these policies and procedures to all employees
  1. Security-related contracts and agreements:
  • Use of contracts and agreements (e.g. service level agreements, data processing agreements) to ensure the security of company data and systems when working with third parties
  • Regular review of contracts and agreements to ensure compliance with current security standards
  1. Communication of security incidents:
  • Development of a process for communication of security incidents to relevant parties (e.g. employees, customers, law enforcement)
  • Regular testing of the incident communication process
  1. Compliance with relevant laws and regulations:
  • Regular review of the cybersecurity policy to ensure compliance with relevant laws and regulations (e.g. GDPR, HIPAA)
  • Implementation of measures to ensure compliance with relevant laws and regulations
  1. Review and update of the cybersecurity policy:
  • Regular review and update of the cybersecurity policy to ensure it remains effective and relevant
  • Communication of updates to the policy to all employees.
  1. Security governance:
  • Development of a framework for security governance to ensure the effective management of cybersecurity within the organization
  • Definition of roles and responsibilities for security governance
  1. Risk appetite:
  • Definition of the organization’s risk appetite with regard to cybersecurity
  • Use of the risk appetite to guide decision-making related to cybersecurity measures
  1. Security metrics:
  • Development of security metrics to measure the effectiveness of cybersecurity measures
  • Regular review of security metrics and use of the results to inform improvements to the cybersecurity policy
  1. Security-aware culture:
  • Promotion of a security-aware culture within the organization through regular training and awareness campaigns
  • Encouragement of employees to report potential security concerns
  1. Collaboration with industry peers:
  • Collaboration with industry peers to share information and best practices related to cybersecurity
  • Participation in industry groups and forums focused on cybersecurity.
  1. Security assessments:
  • Regular security assessments to identify and prioritize potential vulnerabilities and threats
  • Implementation of appropriate controls and measures to address identified vulnerabilities and threats
  1. Security testing:
  • Regular security testing (e.g. penetration testing, vulnerability assessments) to identify and address potential vulnerabilities
  • Use of results from security testing to inform improvements to the cybersecurity policy
  1. Security monitoring:
  • Implementation of security monitoring tools to identify and alert on potential threats in real-time
  • Regular review of security monitoring logs and use of the results to inform improvements to the cybersecurity policy
  1. Security incident management:
  • Development of a process for managing security incidents, including incident response, notification, and reporting
  • Regular testing of the incident management process
  1. Security awareness training:
  • Regular security awareness training for all employees to educate them on cybersecurity best practices and current threats
  • Use of a variety of training methods (e.g. in-person training, online modules) to ensure the effectiveness of the training
  1. Policies and procedures for third-party access:
  • Development of policies and procedures for granting third parties access to company systems and data
  • Regular review of access granted to third parties to ensure it is still necessary and appropriate.
  1. Supply chain security:
  • Evaluation of the cybersecurity practices of suppliers and other partners in the supply chain
  • Implementation of measures to ensure the security of the supply chain
  1. Security in the development lifecycle:
  • Integration of security considerations into the development lifecycle (e.g. secure coding practices, security testing)
  • Regular review of the development process to ensure the inclusion of security measures
  1. Security of connected devices:
  • Evaluation of the security of connected devices (e.g. IoT devices) before deployment
  • Implementation of appropriate controls and measures to secure connected devices
  1. Security of cloud-based services:
  • Evaluation of the security measures in place when using cloud-based services
  • Use of contracts and other legal measures to ensure the security of company data in the cloud
  1. Security of mobile devices:
  • Implementation of controls and measures to secure company-owned and personally-owned mobile devices that access company data
  • Use of mobile device management software to monitor and secure devices
  1. Security of remote access:
  • Implementation of controls and measures to secure remote access to company systems and data
  • Use of virtual private networks (VPNs) and other secure remote access technologies.

 

This list is by no means definitive and cybersecurity policy needs vary drastically based on each organization’s needs, but this should give you some ideas to consider when developing cybersecurity policy for your own organization.

Top cyber security threats for 2023

Top cyber security threats for 2023

As we enter 2023, it is important to be aware of the top cyber security threats that are likely to emerge in the coming year. Here are some of the top cyber security threats to be aware of in 2023:

  1. Ransomware: Ransomware is a type of malware that encrypts a victim’s files until a ransom is paid to the attacker. Ransomware attacks are likely to continue to be a major threat in 2023, with attackers targeting both individuals and businesses.

  2. Phishing scams: Phishing scams involve attackers sending fake emails or text messages that appear to be from a legitimate source, in an attempt to trick victims into revealing sensitive information or installing malware. Phishing scams are likely to continue to be a major threat in 2023.

  3. Internet of Things (IoT) attacks: The Internet of Things (IoT) refers to the growing number of connected devices, such as smart home devices, that are connected to the internet. As the number of IoT devices increases, so too do the risks of IoT attacks, in which attackers exploit vulnerabilities in these devices to gain access to networks and steal data.

  4. Cloud attacks: As more businesses move their data and applications to the cloud, the risks of cloud attacks are likely to increase in 2023. Cloud attacks involve attackers gaining access to cloud-based systems and stealing or manipulating data.

  5. Artificial intelligence (AI) and machine learning attacks: As artificial intelligence (AI) and machine learning become more prevalent, so too do the risks of AI and machine learning attacks. These attacks involve attackers using AI and machine learning to evade detection and launch sophisticated cyber attacks.

By being aware of these top cyber security threats and taking steps to protect against them, individuals and businesses can help reduce the risks of falling victim to a cyber attack in 2023.

Top 25 cyber attacks of all time

Top 25 cyber attacks of all time

Here’s the list of top 25 cyber attacks of all time:

 

  1. SolarWinds: The SolarWinds attack, which was revealed in December 2020, impacted government agencies and businesses around the world. The attack involved attackers infiltrating the software supply chain of SolarWinds, a provider of network management software, and distributing malware to customers through updates.

  2. Marriott data breach: In November 2020, Marriott revealed that hackers had gained access to the reservation system of its subsidiary, Starwood Hotels & Resorts, and had accessed the personal data of up to 500 million guests.

  3. Colonial Pipeline ransomware attack: In May 2021, the Colonial Pipeline, which transports fuel along the East Coast of the United States, was hit by a ransomware attack that forced the company to shut down operations. The attack had a significant impact on fuel supplies in the region.

  4. Capitol One data breach: In July 2019, the personal data of over 100 million individuals was exposed in a data breach at Capital One. The attack was carried out by a former Amazon Web Services employee.

  5. Equifax data breach: In September 2017, the personal data of 147 million individuals was exposed in a data breach at credit reporting company Equifax. The attack was the result of a vulnerability in the company’s web application software.

  6. Yahoo data breaches: In December 2016, Yahoo disclosed that it had suffered two data breaches, one in 2013 and one in 2014, which exposed the personal data of all 3 billion of its users.

  7. Target data breach: In December 2013, the personal data of 40 million credit and debit card users was exposed in a data breach at retail giant Target. The attack was the result of malware that was installed on the company’s point-of-sale systems.

  8. Sony Pictures hack: In November 2014, Sony Pictures was the victim of a cyber attack that exposed sensitive emails and personal data of employees. The attack was later attributed to North Korea.

  9. Anthem data breach: In February 2015, the personal data of 78.8 million individuals was exposed in a data breach at health insurance company Anthem. The attack was the result of a spearphishing campaign.

  10. JPMorgan Chase data breach: In July 2014, the personal data of 76 million households and 7 million small businesses was exposed in a data breach at JPMorgan Chase. The attack was attributed to Russian hackers.

  11. Uber data breach: In November 2017, Uber disclosed that it had suffered a data breach in October 2016 that exposed the personal data of 57 million riders and drivers.

  12. OPM data breach: In June 2015, the personal data of 22 million individuals was exposed in a data breach at the Office of Personnel Management (OPM). The attack was attributed to Chinese hackers.

  13. Deloitte data breach: In October 2017, Deloitte disclosed that it had suffered a data breach in March 2016 that exposed the personal data of clients and the confidential emails of Deloitte employees.

  14. eBay data breach: In May 2014, the personal data of 145 million eBay users was exposed in a data breach. The attack was the result of the attackers gaining access to the company’s corporate network through the use of compromised employee credentials.

  15. Home Depot data breach: In September 2014, the personal data of 56 million payment cards was exposed in a data breach at Home Depot. The attack was the result of malware being installed on the company’s point-of-sale systems.

  16. Adobe data breach: In October 2013, the personal data of 153 million Adobe users was exposed in a data breach. The attack was the result of the attackers gaining access to Adobe’s network through the use of compromised employee credentials.

  17. Dyn DDoS attack: In October 2016, internet performance company Dyn was the victim of a distributed denial of service (DDoS) attack that caused widespread internet disruption. The attack was launched using the Mirai botnet, which was made up of compromised IoT devices.

  18. Snapchat data breach: In December 2013, the personal data of 4.6 million Snapchat users was exposed in a data breach. The attack was the result of a third-party app that was able to access Snapchat’s user database.

  19. LinkedIn data breach: In May 2016, the personal data of 117 million LinkedIn users was exposed in a data breach. The data had been stolen in a 2012 data breach and was later sold on the dark web.

  20. Airbnb data breach: In November 2014, Airbnb disclosed that it had suffered a data breach in October 2014 that exposed the personal data of its users. The attack was the result of an employee’s account being compromised.

  21. Dropbox data breach: In August 2016, it was revealed that the personal data of 68 million Dropbox users had been exposed in a data breach that occurred in 2012. The data had been stolen and was later sold on the dark web.

  22. Twitter data breach: In November 2017, Twitter disclosed that it had suffered a data breach in October 2017 that exposed the personal data of 330 million users.

  23. TalkTalk data breach: In October 2015, the personal data of 157,000 TalkTalk customers was exposed in a data breach. The attack was the result of a SQL injection attack.

  24. Ashley Madison data breach: In July 2015, the personal data of 37 million users of the Ashley Madison dating website was exposed in a data breach. The attack was carried out by a group calling itself the “Impact Team.”

  25. VTech data breach: In November 2015, the personal data of 4.2 million children and 200,000 adults was exposed in a data breach at VTech, a manufacturer of children’s electronic toys. The attack was the result of a SQL injection attack.

These 25 cyber attacks demonstrate the importance of good digital hygiene and the need for individuals and businesses to take steps to protect themselves and their data against cyber threats. By being aware of the risks and taking steps to protect against them, individuals and businesses can help reduce the chances of falling victim to a cyber attack.

Keep the fraudsters at bay this Black Friday

Keep the fraudsters at bay this Black Friday

As Black Friday approaches, you may be starting to think about all the amazing gadgets you can pick up at bargain prices. But be wary.

As we enter the busiest period of the year for shopping, criminals will be keeping busy too.

At this time, we’re here to remind you about one of the most common forms of cybercrime, and how you can stay protected.

Purchase scams

Purchase scams are when fake or non-existent items are advertised for sale.

These goods often appear on auction sites or social media, with images (and even reviews) taken from genuine sellers to convince you that they’re the real deal.

Criminals also use cloned websites, with small changes to the URL, to trick you into thinking that you’re buying from a genuine retailer.

How to spot them?

🚩 If you see products and services heavily discounted from their retail price, then be on guard!

🚩 If you’re asked to pay by bank transfer instead of an online payment or card transaction, that’s also a red flag.

🚩 Scammers will often counterfeit receipts and invoices. Always read these carefully and look for tell-tale signs of forgery. These include spelling errors, poor grammar, and unusual contact details — such as the seller’s address and email.

How to act?

If something sounds too good to be true, then that may well be the case.

We recommend using a secure payment method, and to avoid paying via bank transfer. Also, make sure you read online reviews to check that websites and sellers are genuine.

Disposable Cards

Using Revolut’s Disposable Virtual Cards is one way to make safer and more secure payments online.

Each time you make an online payment with a Virtual Card, they will automatically destroy the existing card details and generate new ones. These will then appear directly in the app, as a new disposable card.

These cards are designed to protect your card details from being cloned when paying online.

You can check out revolut.com for disposable virtual cards.

Online shopping fraud – a winter tale that always ends with fraudsters behind bars

Europol building

A coordinated crackdown on e-commerce fraud has seen 59 scammers arrested and new investigative leads triggered all across Europe as part of the 2022 e-Commerce Action (eComm 2022). 

The month-long (1-31 October 2022) operation saw 19 countries take part in this clampdown on the criminal networks using stolen credit card information to order high-value goods from online shops.  

The action was coordinated by Europol’s European Cybercrime Centre (EC3) and the Merchant Risk Council. It received the direct assistance from merchants, logistic companies, banks and payment card schemes. 

After several months of preparation, law enforcement authorities in participating countries raided the locations where illegally purchased goods had been delivered, arresting the suspects and confiscating the fraudulently purchased goods. Evidence was built to support the cases all the way to prosecuting the suspects. Investigations are still ongoing in various countries, with more arrests expected in the coming weeks.

Participating countries

Albania, Austria, Bosnia-Herzegovina, Colombia, Czech Republic, Finland, France, Georgia, Germany, Greece, Hungary, Latvia, Poland, Portugal, Romania, Slovak Republic, Spain, Sweden and United Kingdom.

Changing attack vectors

Even if payments online are generally very secure, mostly thanks to Secure Customer Authentication (SCA) methods widely implemented in Europe, criminals are continuously altering their techniques to unlock new ways of stealing money. 
The findings of eComm 2022 have identified the following key threats to the e-commerce sector: 

  • Phishing, vishing and smishing fraud: Stolen credit card numbers are often obtained through phishing/vishing/smishing attacks whereby criminals contact people by phone, text messages, messaging apps or email and attempt to convince them to hand over their credit card information. Sometimes these attacks promise a reward, other times they impersonate a trusted business or a government agency.
  • Account takeover fraud: This fraud occurs when a criminal gains access to a user’s account on an ecommerce store. This can be achieved through a variety of methods, including purchasing stolen passwords, security codes, or personal information on the dark web or successfully implementing a phishing scheme against a particular customer. Once they have gained access to a user’s account, criminals can engage in fraudulent activity. For instance, they can change the details of a user’s account, make purchases on ecommerce stores, can withdraw funds, and can even gain access to other accounts for this user.
  • Triangulation fraud: This type of fraud happens when online criminals set up a fake or replica website and entice buyers with cheap goods. Sometimes these fake websites may appear in ads, or be sent to a user’s email directing to the website through a phishing attempt. The catch is that these goods don’t actually exist, or of course are never shipped.

How to fight back against e-commerce fraud

Through an awareness campaign launching today, law enforcement across Europe are teaming up with Europol and the Merchant Risk Council to share practical advice on how to outwit criminals trying to abuse the online shopping experience. 

The aim of the campaign is to make e-commerce more secure by promoting safe online purchasing methods and by helping new merchants to open their online shop without the risk of cyberattacks.

Participating countries and partners will promote the campaign through their social media channels using the #SellSafe hashtag to help merchants understand the risks of e-commerce fraud.

Tips to protect your e-business:

  • Ensure all your employees are aware of the fraud issues affecting online stores.
  • Stay up to date on the types of payment fraud affecting businesses and have the tools in place to prevent them. Your national payments organisation will have details on payment fraud types.
  • Get to know your customers in order to be able to verify their payments.

Tips for online shoppers:

  • Never send your card number, PIN or any other card information to anyone by e-mail.
  • Never send money to anyone you don’t know.
  • Always save all documents related to your online purchases.
  • If you are not buying anything, don’t submit your card details.
  • Check your online banking service regularly. Notify your bank immediately if you see payments or withdrawals that you have not made yourself.

World’s most dangerous malware EMOTET disrupted through global action

Europol building

Law enforcement and judicial authorities worldwide have this week disrupted one of most significant botnets of the past decade: EMOTET. Investigators have now taken control of its infrastructure in an international coordinated action.

This operation is the result of a collaborative effort between authorities in the Netherlands, Germany, the United States, the United Kingdom, France, Lithuania, Canada and Ukraine, with international activity coordinated by Europol and Eurojust. This operation was carried out in the framework of the European Multidisciplinary Platform Against Criminal Threats (EMPACT).

EMOTET has been one of the most professional and long lasting cybercrime services out there. First discovered as a banking Trojan in 2014, the malware evolved into the go-to solution for cybercriminals over the years. The EMOTET infrastructure essentially acted as a primary door opener for computer systems on a global scale. Once this unauthorised access was established, these were sold to other top-level criminal groups to deploy further illicit activities such data theft and extortion through ransomware.

Spread via Word documents

The EMOTET group managed to take email as an attack vector to a next level. Through a fully automated process, EMOTET malware was delivered to the victims’ computers via infected e-mail attachments.  A variety of different lures were used to trick unsuspecting users into opening these malicious attachments. In the past, EMOTET email campaigns have also been presented as invoices, shipping notices and information about COVID-19.

All these emails contained malicious Word documents, either attached to the email itself or downloadable by clicking on a link within the email itself. Once a user opened one of these documents, they could be prompted to “enable macros” so that the malicious code hidden in the Word file could run and install EMOTET malware on a victim’s computer.

Attacks for hire

EMOTET was much more than just a malware. What made EMOTET so dangerous is that the malware was offered for hire to other cybercriminals to install other types of malware, such as banking Trojans or ransomwares, onto a victim’s computer.

This type of attack is called a ‘loader’ operation, and EMOTET is said to be one of the biggest players in the cybercrime world as other malware operators like TrickBot and Ryuk have benefited from it.

Its unique way of infecting networks by spreading the threat laterally after gaining access to just a few devices in the network made it one of the most resilient malware in the wild.

Disruption of EMOTET’s infrastructure

The infrastructure that was used by EMOTET involved several hundreds of servers located across the world, all of these having different functionalities in order to manage the computers of the infected victims, to spread to new ones, to serve other criminal groups, and to ultimately make the network more resilient against takedown attempts.

To severely disrupt the EMOTET infrastructure, law enforcement teamed up together to create an effective operational strategy. It resulted in this week’s action whereby law enforcement and judicial authorities gained control of the infrastructure and took it down from the inside. The infected machines of victims have been redirected towards this law enforcement-controlled infrastructure.  This is a unique and new approach to effectively disrupt the activities of the facilitators of cybercrime.

How to protect oneself against loaders

Many botnets like EMOTET are polymorphic in nature. This means that the malware changes its code each time it is called up. Since many antivirus programmes scan the computer for known malware codes, a code change may cause difficulties for its detection, allowing the infection to go initially undetected.

A combination of both updated cybersecurity tools (antivirus and operating systems) and cybersecurity awareness is essential to avoid falling victim to sophisticated botnets like EMOTET. Users should carefully check their email and avoid opening messages and especially attachments from unknown senders. If a message seems too good to be true, it likely is and emails that implore a sense of urgency should be avoided at all costs.

As part of the criminal investigation conducted by the Dutch National Police into EMOTET, a database containing e-mail addresses, usernames and passwords stolen by EMOTET was discovered. You can check if your e-mail address has been compromised.  As part of the global remediation strategy, in order to initiate the notification of those affected and the cleaning up of the systems, information was distributed worldwide via the network of so-called Computer Emergency Response Teams (CERTs).

EMOTET

The following authorities took part in this operation:

  • Netherlands: National Police (Politie), National Public Prosecution Office (Landelijk Parket)
  • Germany: Federal Criminal Police (Bundeskriminalamt), General Public Prosecutor’s Office Frankfurt/Main (Generalstaatsanwaltschaft)
  • France: National Police (Police Nationale), Judicial Court of Paris (Tribunal Judiciaire de Paris)
  • Lithuania: Lithuanian Criminal Police Bureau (Lietuvos kriminalinės policijos biuras), Prosecutor’s General’s Office of Lithuania
  • Canada: Royal Canadian Mounted Police
  • United States: Federal Bureau of Investigation, U.S. Department of Justice, US Attorney’s Office for the Middle District of North Carolina
  • United Kingdom: National Crime Agency, Crown Prosecution Service 
  • Ukraine: National Police of Ukraine (Національна поліція України), of the Prosecutor General’s Office (Офіс Генерального прокурора).

Hit by ransomware? No More Ransom now offers 136 free tools to rescue your files

No more ransom

As the initiative turns six, over 10 million people have downloaded the decryption tools

Ransomware attacks have been growing in number and severity for years, with headlines focused on ransom demands that have climbed to amounts once unthinkable. While the data is alarming, it does not mean that you are helpless against the high-tech extortionists orchestrating these attacks. The No More Ransom initiative offers over a hundred free decryption tools to rescue your hostage files. 

Six years of public-private partnership

Celebrating its sixth anniversary today, No More Ransom provides keys to unlocking encrypted files as well as information on how to avoid getting infected in the first place.

Launched by Europol, the Dutch National Police (Politie) and IT security companies, the No More Ransom portal initially offered four tools for unlocking different types of ransomware and was available only in English.

Six years later, No More Ransom offers 136 free tools for 165 ransomware variants, including Gandcrab, REvil/Sodinokibi, Maze/Egregor/Sekhmet and more. Over 188 partners from the public and private sector have joined the scheme, regularly providing new decryption tools for the latest strains of malicious software.  

To date, the scheme has so far helped over 1.5 million people successfully decrypt their devices without needing to pay the criminals. The portal is available in 37 languages in order to better assist victims of ransomware across the globe.

No better cure than prevention

The best cure against ransomware remains diligent prevention. You are strongly advised to:

  • Regularly back up data stored on your electronic devices.
  • Watch your clicks – do you know where a link will take you?
  • Do not open attachments in e-mails from unknown senders, even if they look important and credible.
  • Ensure that your security software and operating system are up to date.
  • Use two-factor authentication (2FA) to protect your user accounts.
  • Limit the possibility to export large amounts of corporate data to external file exchange portals.
  • If you become a victim, do not pay! Report the crime and check No More Ransom for decryption tools.

Join the fight against ransomware

Are you a cybersecurity company willing to join forces with law enforcement and industry leaders in the fight to disrupt ransomware?

Do you have an innovative solution for ransomware families not covered yet in the portal to help victims recover their files without giving into the demands of the criminals?

Then we want to hear from you!

Find more information and prevention tips on www.nomoreransom.org 

US, UK: Russia responsible for cyberattack against Ukrainian banks

US, UK: Russia responsible for cyberattack against Ukrainian banks

WASHINGTON, Feb 18 (Reuters) – Russian military hackers were behind a spate of distributed denial of service (DDoS) attacks that briefly knocked Ukrainian banking and government websites offline, the United States and the United Kingdom said on Friday.

U.S. deputy national security adviser Anne Neuberger told journalists at the White House that Washington was seeking to hold Russia to account for its aggressive moves in cyberspace.

“Russia likes to move in the shadows and counts on a long process of attribution,” Neuberger said. “In light of that, we’re moving quickly to attribute the DDoS attacks. We believe the Russian government is responsible for widespread attacks on Ukrainian banks this week.”

Neuberger said that Americans have data showing that infrastructure connected with Russia’s military agency, generally known as the GRU, “was seen transmitting high volumes of communication to Ukraine-based IP addresses and domains.”

In a simultaneous announcement, British officials said the GRU was “almost certainly involved” in the DDoS, which works by flooding targeted websites with a firehose of data.

“The attack showed a continued disregard for Ukrainian sovereignty,” Britain’s Foreign Commonwealth and Development Office (FCDO) said in a statement. “This activity is yet another example of Russia’s aggressive acts against Ukraine.”

“This disruptive behavior is unacceptable,” the FCDO said.

Russia has denied any role in the DDoS, which inflicted relatively limited disruption on Tuesday.

Kyiv had already blamed Moscow for the DDoS amid heightened tensions since Russia began massing troops near the border, raising fears Russia was planning to attack. The Kremlin has denied it plans to push deeper into the country.

Neuberger said that while the denial of service had “limited impact,” the recent spate of malicious digital activity could be a prelude to “more disruptive cyberattacks accompanying a potential further invasion of Ukraine’s sovereign territory.”

Queensland hospitals and nursing centers afflicted by cyber attack

Several Queenland hospitals and nursing centers have been affected by a cyberattack, which has caused several disruptions in internal systems.
According to news sources the entire UnitingCare Queensland IT system was attacked by ransomware software, with all UCQ hospitals and nursing homes working without IT systems until further notice.

Among a number of nursing centers that have been affected in Queenland, Wesley and St.Andrews war hospitals in Brisbane have also had inoperable systems.

The cyber attack has impacted all operational IT systems including staff emails and patient’s booking systems for treatments, forcing onsite staff to revert to paper-based operations for the foreseeable future. Doctors have been told not to expect to be able to access vital patient information and details like x-rays. UnitingCare Queensland confirmed the attack but wasn’t able to provide an estimation when the systems could be brought back up.

“On Sunday, 25th of April, UnitingCare Queensland was impacted by a cyber incident. As a result of this incident, some of the organisation’s digital and technology systems are currently inaccessible,” a UnitingCare spokesperson said. “It is not possible to provide a resolution timeframe at this stage, however, our Digital and Technology Team are working to resolve this issue,”

It is currently unclear if any of the patients’ personal data was breached during the attack.