RSAC Resources
WannaCry Ransomware Attack (2017)
WannaCry is a ransomware attack that took place in May 2017 and became one of the most notorious cyberattacks in history. The attack impacted a wide range of organizations worldwide, causing significant disruptions and financial losses.
Sources:
https://youtu.be/etPizFNPupk
https://www.justice.gov/opa/pr/north-korean-regime-backed-programmer-charged-conspiracy-conduct-multiple-cyber-attacks-and
https://usa.kaspersky.com/resource-center/threats/ransomware-wannacry
https://www.cloudflare.com/learning/security/ransomware/wannacry-ransomware/
https://en.wikipedia.org/wiki/WannaCry_ransomware_attack
Crowdstrike Outages
The CrowdStrike outages in July 2024 were caused by a faulty software update to their security software. This update led to widespread crashes of Microsoft Windows systems, affecting approximately 8.5 million devices globally. The incident disrupted critical services across industries like airlines, banks, hospitals, and government operations. Financial damages were estimated at over $10 billion.
CrowdStrike quickly identified the issue and released a fix, but many systems required manual intervention, prolonging the recovery process.
Sources:
https://en.wikipedia.org/wiki/2024_CrowdStrike-related_IT_outages
https://www.cisa.gov/news-events/alerts/2024/07/19/widespread-it-outage-due-crowdstrike-update
https://www.crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf
https://www.cnn.com/2024/07/24/tech/crowdstrike-outage-cost-cause/index.html
SOLAR WINDS
The SolarWinds supply chain attack impacted numerous sectors, including energy and government agencies. Hackers were able to insert malware into software updates for SolarWinds’ Orion platform, affecting multiple organizations, including those in critical infrastructure sectors.
Sources:
https://www.techtarget.com/whatis/feature/SolarWinds-hack-explained-Everything-you-need-to-know
https://en.wikipedia.org/wiki/2020_United_States_federal_government_data_breach
https://www.gao.gov/blog/solarwinds-cyberattack-demands-significant-federal-and-private-sector-response-infographic
https://www.gao.gov/products/gao-22-104746
SALT TYPHOON
The Salt Typhoon hack was one of the largest and most extensive hacks in US history, with a high level of sophistication.
Deployed a kernel-level rootkit to gain remote access to targeted servers. Attackers targets US telecommunications companies. Hackers accessed the metadata of millions of users, and were able to access audio recordings of calls by high-profile individuals.
Sources:
https://en.wikipedia.org/wiki/Salt_Typhoon
https://www.nytimes.com/2024/10/25/us/politics/trump-vance-hack.html
https://en.wikipedia.org/wiki/Salt_Typhoon
Notpetya
The NotPetya cyberattack in 2017 was a devastating ransomware incident, initially targeting Ukraine but rapidly spreading worldwide. It caused significant disruptions and billions in losses. Unlike traditional ransomware, NotPetya aimed primarily to inflict damage rather than collect ransom, highlighting the dangers of state-sponsored cyber warfare.
Sources:
https://www.hypr.com/security-encyclopedia/notpetya
https://www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/
https://en.wikipedia.org/wiki/2017_Ukraine_ransomware_attacks
https://en.wikipedia.org/wiki/Petya_(malware_family)