Tuesday, June 9, 2020

Which Was Second City Hit by Hackers?


Towns Within One Hour Of Florence


First, we want to thank Spackle99 for alerting us to the ransomware situation in Florence and sending us the very enlightening article we linked yesterday. Was the article correct? One reader felt it placed too much blame on Steve Price, the city's information director:

I don't know the guy, but I serious doubt he clicked on the email. When a computer gets hacked hackers attempt to get admin credentials through a tool called MIMIKATZ. Password are stored on a windows box in memory until the machine is rebooted. Hackers compromise one PC, then move laterally to other PCs based on the credentials they gather, finally finding a super user and their password. Then they posted that password on the dark web. Steve is far from blame, but I don't think its fair to say he was sent the email. 

Yet perhaps the second most interesting takeaway of the article was Mayor Steve Holt's comment:

Holt said the same gang appears to have simultaneously compromised networks belonging to four other victims within an hour of Florence, including another municipality that he declined to name. 

Three institutions and one municipality, all within an hour of Florence? Obviously the institutions would have been large enough to make it worth the hackers' while. Hospitals? Manufacturing plants in Decatur?

The second municipality is the most interesting. We've heard a certain Shoals town mentioned, but have no confirmation. Obviously, smaller towns like Waterloo or Collinwood could be ruled out as not being able to meet an exorbitant ransom demand. Other than that, we have no firm idea.

Sheffield City Hall still closed?



No comments:

Post a Comment