San Francisco Chronicle

Countries race to halt ransomware

- By Sylvia Hui, Allen G. Breed and Jim Heintz Sylvia Hui, Allen G. Breed and Jim Heintz are Associated Press writers.

LONDON — A global ransomware cyberattac­k, unpreceden­ted in scale, had technician­s scrambling to restore Britain’s crippled hospital network Saturday and secure the computers that run factories, banks, government agencies and transport systems in many other nations.

The worldwide effort to extort cash from computer users is so unpreceden­ted that Microsoft quickly changed its policy, making security fixes available for free for the older Windows systems still used by millions of individual­s and smaller businesses.

A malware tracking map showed “WannaCry” infections popping up around the world. Britain canceled or delayed treatments for thousands of patients, even people with cancer. Train systems were hit in Germany and Russia, and phone companies in Madrid and Moscow. Renault’s futuristic assembly line in Slovenia, where rows of robots weld car bodies together, was stopped cold.

In Brazil, the social security system had to disconnect its computers and cancel public access. The state-owned oil company Petrobras and Brazil’s Foreign Ministry also disconnect­ed computers as a precaution­ary measure, and court systems went down, too.

Britain’s home secretary said one in five of 248 National Health Service groups had been hit. Home Secretary Amber Rudd said all but six of the NHS trusts were back to normal Saturday.

The U.K.’s National Cyber Security Center was “working round the clock” to restore vital health services, while urging people to update security software fixes, run anti-virus software and back up their data elsewhere.

Who perpetrate­d the wave of attacks remains unknown. Two security firms — Kaspersky Lab and Avast — said they identified the malicious software in more than 70 countries. Both said Russia was hit hardest.

These hackers “have caused enormous amounts of disruption— probably the biggest ransomware cyberattac­k in history,” said Graham Cluley, a veteran of the anti-virus industry in Oxford, England.

And all this may be just a taste of what’s coming, another cyber security expert warned.

Computer users worldwide — and everyone else who depends on them — should assume that the next big ransomware attack has already been launched, and just hasn’t manifested itself yet, said Ori Eisen, who founded the Trusona cybersecur­ity firm in Scottsdale, Ariz.

The attack held hospitals and other entities hostage by freezing computers, encrypting data and demanding money through online bitcoin payments. But it appears to be “low-level” stuff, Eisen said Saturday, given the amount of ransom demanded — $300 at first, rising to $600 before it destroys files hours later.

This is already believed to be the biggest online extortion attack ever recorded, disrupting services in nations as diverse as the U.S., Ukraine, Brazil, Spain and India. Europol, the European Union’s police agency, said the onslaught was at “will require a complex internatio­nal investigat­ion to identify the culprits.”

In Russia, government agencies insisted that all attacks had been resolved. Russian Interior Ministry, which runs the national police, said the problem had been “localized.”

 ?? P. Goetzelt / Deutsche Presse-Agentur ?? An error message appears on a display Friday at the train station in Chemnitz, Germany. The nation’s national railway was among entities hit by the attack.
P. Goetzelt / Deutsche Presse-Agentur An error message appears on a display Friday at the train station in Chemnitz, Germany. The nation’s national railway was among entities hit by the attack.

Newspapers in English

Newspapers from United States