Quantcast
Jump to content


Recommended Posts

Last week our business network was hit with a ransomware attack. One of our company officers was looking at resumes for prospective employees and opened an attachment on an email response from a Craigslist ad. The attachment was in.zip format and as soon as it opened she knew something was wrong. Within minutes, critical files on the computer were encrypted and unusable. In addition, files on other computers that were shared on the network were also encrypted. The computer screen was filled with instructions on how to pay a $1000 ransom to buy the decryption software that would return everything to normal. The payment method is in bitcoin through untraceable networks so the jerks at the other end are completely anonymous and untraceable as well.



The ransom attack targets specific file types that such as .doc, .pdf, Excel files and graphics files. Why graphics files? People don’t want to lose family pictures and will pay to get them back.


What do you do? You and your “IT guy” can’t crack the encryption, so you are faced with either paying the ransom or finding a way to live without them… UNLESS you have a backup. Do you? We use Carbonite on our critical data and it may turn out to be a blessing. Immediately after the attack, we found out that the machine in question had not been backing up for the past 45 days! Why? We’re still not sure, but it’s not a total disaster because we want to get back a lot of the old files. We also learned that as soon as you find out you’ve been hit, you need to freeze your backup, otherwise Carbonite starts backing up the encrypted files. Also, immediately power down the infected machine and disconnect it from your local network before powering it back up again.


My biggest fear was losing our Quickbooks files, but to my surprise the attack didn’t include them. But it did get our Excel day reports for the gas station and C-store and it destroyed the data in our car lot’s dealer management system, mostly PDF files. Fortunately that machine had a current backup in Carbonite. Thanks to our backups, I was able to make the decision not to pay the ransom, but I have now spent four days cleaning machines, attempting to take the machine that was attacked back to ground zero, updating files with old backups. I’m not done yet and will spend at least part of tomorrow working with the dealer management system people to get the car lot up and running again.


Monday night and everything is working again if your are willing to accept the loss of some data, and, believe me, I am. I sit here thinking that it could happen again tomorrow and I haven’t really prepared my defense, but I willl be working on that, believe me.

  • Like 1
Link to comment
Share on other sites



Pretty scary story. I know we've probably all heard it, but try to avoid opening anything that looks suspicious. avoid .zip and .exe files that get emailed. One suggestion might be to use gmail to open these resumes going forward. If it's truly a document type file, gmail should be able to handle that in the browser itself. Also, you might try opening them first on your phone if possible. Yea, you could brick your phone, but a new cell phone is cheaper and less of a headache than a new shop computer.

 

*EDIT: I just re-read your post and saw that it was a .zip file. I would immediately hold a meeting or at least send out an email blast to everyone in the company saying to never, ever, under any circumstance, open a .zip or .exe file that you receive in an email from someone you do not absolutely 100% trust. A .zip or .exe from and unknown source is almost guaranteed to be a virus of some sort.

Edited by mmotley
Link to comment
Share on other sites

I always suggest to use an up-to-date internet security suite like Nortons and have browser protection enabled. It should warn you and sniff these things out. :D

 

http://www.cbc.ca/news/technology/antivirus-software-1.3668746

Unfortunately, this is pretty much false in this day and age.

There are a vast number of articles everywhere about security software giving you a false sense of security.

Technology, specifically malware linked to organized crime, changes way too fast for security software to keep up.

While I'm not saying security software is 100% useless, it's definitely outlived most of it's usefulness. (not to mention it's a drain on your wallet for something that doesn't work well)

 

Your best bet is to keep regular backups, keep your operating system, browser and software patched and up-to-date, and USE COMMON SENSE!

Don't EVER open a .zip or .exe file in an email! Don't open any email attachment unless you are expecting them!

Don't get lulled into a false sense of security!

  • Like 1
Link to comment
Share on other sites

I have used this training, there are 3 basic classes totally about 1.5 hours. it's inexpensive and very informing. It also allows you to test your people if your emails are all the same domain. They are very helpful and easy to work with. I signed all my staff up as well as techs and family members.

 

https://www.knowbe4.com/

  • Like 1
Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Have you checked out Joe's Latest Blog?

         4 comments
      A recent study, done by Harvard Business School, concluded that the real problem with attracting and retaining employees has more to do with the workplace environment, not pay or benefits. While the study did find that an adequate pay plan and offering an attractive benefits package did help with recruiting and retention, it’s not enough to satisfy the needs of employees, especially those of front-line workers.
      The study also stated that in 2021, many companies were convinced that giving raises, sign-on bonuses, and other perks would solve the worker shortage problem and prevent people from quitting. However, this strategy did not work. So, what does work regarding attracting quality people and keeping them employed?
      Essentially, it all comes down to the culture of your company.  Management: do all it can to consider the individual needs of your employees. Your employees want to feel that they have a voice, that their opinion counts, and that their role in your company is both respected and recognized. Yes, pay and a great benefits package will go a long way toward making your employees feel secure, but that’s only financial security. People want more than money.
      To attract and keep top talent requires creating a company that people feel proud to work for. You need to reach the hearts and minds of your employees. Become a leader that people are enthusiastic about working for. You want your employees bragging to their friends and family that your shop is a great place to work!
      Step one to attracting and retaining quality employees: Create an amazing workplace environment for your employees!  Trust me, happy employees make happy shop owners too!
  • Similar Topics

    • By Joe Marconi

      Premium Member Content 

      This content is hidden to guests, one of the benefits of a paid membership. Please login or register to view this content.

    • By Joe Marconi

      Premium Member Content 

      This content is hidden to guests, one of the benefits of a paid membership. Please login or register to view this content.

    • By carmcapriotto
      This week Hunt discusses the actual cost of that aging loaner fleet. Are they really as cheap as you think?
      • What is an opportunity cost? How does that impact the actual cost of my loaner fleet?
      • Does opportunity cost apply to me and my team equally?
      • So, you spend a couple hundred dollars in parts to keep that beater on the road, but is it really "cheaper than a car payment?"
      • How does opportunity cost apply to a tow truck that I also have off the road and not making me money?
      Thanks to our sponsor partner NAPA TRACS
      NAPATRACS.com
      Paar Melis and Associates – Accountants Specializing in Automotive Repair
      Visit us Online : www.paarmelis.com
      Email Hunt: [email protected]
      Get a copy of my Book : Download Here
      Click to go to the Podcast on Remarkable Results Radio
    • By Joe Marconi

      Premium Member Content 

      This content is hidden to guests, one of the benefits of a paid membership. Please login or register to view this content.

    • By carmcapriotto
      This episode is sponsored by AutoLeap. AutoLeap is a cloud-based all-in-one automotive invoice software that helps you supercharge your mechanic shop. Their customers have experienced:
      30% increase in revenue by improving transparency and trust
      50% reduction in time spent researching and ordering parts
      10% increase in profit margins through robust reporting
      Click here to learn more about AutoLeap and schedule a demo:
       
      AutoLeap Link: http://bit.ly/3GRgO88
       
      In this podcast episode, Coach Chris Cotton discusses the importance of having a business coach for independent auto repair shop owners. He lists 16 reasons why having a coach is beneficial, including providing accountability, fresh perspectives, and unbiased insight. A coach can also help with setting attainable goals, improving organization, and celebrating wins. Additionally, they can assist with growth strategies, financial management, employee management and training, and industry expertise. Coach Chris emphasizes that having a coach is essential for shop owners to achieve their dreams and take their businesses to the next level.
      Should You Have a Business Coach? [00:01:44] Coach Chris Cotton explains why everyone should have a business coach, the challenges of running a business, and how a coach can help you achieve your goals.
      Unbiased Insight [00:06:40] A business coach provides unbiased constructive criticism and insights that friends, family, and coworkers may not be able to offer.
      Fresh Perspective [00:08:02] A business coach can help you identify problems and solutions that you may have overlooked due to being too involved in your business.
      Growth [00:07:29] A coach can help you create a strategic business plan to boost growth, qualify your database, and generate leads.
      Balance [00:08:21] A coach can teach you how to balance your professional and personal life, encouraging you to take breaks and prioritize work-life balance.
      Employee Management [00:11:50] A coach can assist in building a strong team, providing guidance on hiring, training, and retaining skilled employees, and implementing performance management systems.
      Don't forget to rate and review us!
      Connect with Chris:
      [email protected]
      940.400.1008
      www.autoshopcoaching.com
      Facebook: https://www.facebook.com/AutoFixAutoShopCoaching
      Youtube: https://bit.ly/3ClX0ae
       
      #autofixautoshopcoaching #autofixbeautofixing #autoshopprofits #autoshopprofit #autoshopprofitsfirst #autoshopleadership #autoshopmanagement #autorepairshopcoaching #autorepairshopconsulting #autorepairshoptraining #autorepairshop #autorepair
      Click to go to the Podcast on Remarkable Results Radio


  • Our Sponsors



×
×
  • Create New...