Cyberattack Hits Ukraine Then Spreads Internationally – The …
Like the WannaCry attacks in May, the latest global hacking took control of computers and demanded digital ransom from their owners to regain access. The new attack used the same National Security Agency hacking tool, Eternal Blue, that was used in the WannaCry episode, as well as two other methods to promote its spread, according to researchers at the computer security company Symantec.
The National Security Agency has not acknowledged its tools were used in WannaCry or other attacks. But computer security specialists are demanding that the agency help the rest of the world defend against the weapons it created.
The N.S.A. needs to take a leadership role in working closely with security and operating system platform vendors such as Apple and Microsoft to address the plague that theyve unleashed, said Golan Ben-Oni, the global chief information officer at IDT, a Newark-based conglomerate hit by a separate attack in April that used the agencys hacking tools. Mr. Ben-Oni warned federal officials that more serious attacks were probably on the horizon.
The vulnerability in Windows software used by Eternal Blue was patched by Microsoft in March, but as the WannaCry attacks demonstrated, hundreds of thousands of groups around the world failed to properly install the fix.
Just because you roll out a patch doesnt mean itll be put in place quickly, said Carl Herberger, vice president for security at Radware. The more bureaucratic an organization is, the higher chance it wont have updated its software.
Because the ransomware used at least two other ways to spread on Tuesday including stealing victims credentials even those who used the Microsoft patch could be vulnerable and potential targets for later attacks, according to researchers at F-Secure, a Finnish cybersecurity firm, and others.
A Microsoft spokesman said the companys latest antivirus software should protect against the attack.
Governments and companies in Europe and the United States have been impacted. Here are several:
The Ukrainian government said several of its ministries, local banks and metro systems had been affected. A number of other European companies, including Rosneft, the Russian energy giant; Saint-Gobain, the French construction materials company; and WPP, the British advertising agency, also said they had been targeted.
Ukrainian officials pointed a finger at Russia on Tuesday, although Russian companies were also affected. Home Credit bank, one of Russias top 50 lenders, was paralyzed, with all of its offices closed, according to the RBC news website. The attack also affected Evraz, a steel manufacturing and mining company that employs about 80,000 people, the RBC website reported.
In the United States, the multinational law firm DLA Piper also reported being hit. Hospitals in Pennsylvania were being forced to cancel operations after the attack hit computers at Heritage Valley Health Systems, a Pennsylvania health care provider, and its hospitals in Beaver and Sewickley, Penn., and satellite locations across the state.
The ransomware also hurt Australian branches of international companies. DLA Pipers Australian offices warned clients that they were dealing with a serious global cyber incident and had disabled email as a precautionary measure. Local news reports said that in Hobart, Tasmania, on Tuesday evening, computers in a Cadbury chocolate factory, owned by Mondelez International, had displayed ransomware messages that demanded $300 in bitcoins.
Qantas Airways booking system failed for a time on Tuesday, but the company said the breakdown was due to an unrelated hardware issue.
The Australian government has urged companies to install security updates and isolate any infected computers from their networks.
This ransomware attack is a wake-up call to all Australian businesses to regularly back up their data and install the latest security patches, said Dan Tehan, the cybersecurity minister. We are aware of the situation and monitoring it closely.
A National Security Agency spokesman referred questions about the attack to the Department of Homeland Security. The Department of Homeland Security is monitoring reports of cyberattacks affecting multiple global entities and is coordinating with our international and domestic cyber partners, Scott McConnell, a department spokesman, said in a statement.
Computer specialists said the ransomware was very similar to a virus that emerged last year called Petya. Petya means Little Peter, in Russian, leading some to speculate the name referred to Sergei Prokofievs 1936 symphony Peter and the Wolf, about a boy who captures a wolf.
Reports that the computer virus was a variant of Petya suggest the attackers will be hard to trace. Petya was for sale on the so-called dark web, where its creators made the ransomware available as ransomware as a service a play on Silicon Valley terminology for delivering software over the internet, according to the security firm Avast Threat Labs.
That means anyone could launch the ransomware with the click of a button, encrypt someones systems and demand a ransom to unlock it. If the victim pays, the authors of the Petya ransomware, who call themselves Janus Cybercrime Solutions, get a cut of the payment.
That distribution method means that pinning down the people responsible for Tuesdays attack could be difficult.
The attack is an improved and more lethal version of WannaCry, said Matthieu Suiche, a security researcher who helped contain the spread of the WannaCry ransomware when he created a kill switch that stopped the attacks.
In just the last seven days, Mr. Suiche noted, WannaCry had tried to hit an additional 80,000 organizations but was prevented from executing attack code because of the kill switch. Petya does not have a kill switch.
Petya also encrypts and locks entire hard drives, whereas the earlier ransomware attacks locked only individual files, said Chris Hinkley, a researcher at the security firm Armor.
The hackers behind Petya demanded $300 worth of the cybercurrency Bitcoin to unlock victims machines. By Tuesday afternoon, online records showed that 30 victims had paid the ransom, although it was not clear whether they had regained access to their files. Other victims may be out of luck, after Posteo, the German email service provider, shut down the hackers email account.
In Ukraine, people turned up at post offices, A.T.M.s and airports to find blank computer screens, or signs about closures. At Kievs central post office, a few bewildered customers milled about, holding parcels and letters, looking at a sign that said, Closed for technical reasons.
The hackers compromised Ukrainian accounting software mandated to be used in various industries in the country, including government agencies and banks, according to researchers at Cisco Talos, the security division of the computer networking company. That allowed them to unleash their ransomware when the software, which is also used in other countries, was updated.
The ransomware spread for five days across Ukraine, and around the world, before activating Tuesday evening.
If I had to guess, I would think this was done to send a political message, said Craig Williams, the senior technical researcher at Talos.
One Kiev resident, Tetiana Vasylieva, was forced to borrow money from a relative after failing to withdraw money at four automated teller machines. At one A.T.M. in Kiev belonging to the Ukrainian branch of the Austrian bank Raiffeisen, a message on the screen said the machine was not functioning.
Ukraines Infrastructure Ministry, the postal service, the national railway company, and one of the countrys largest communications companies, Ukrtelecom, had been affected, Volodymyr Omelyan, the countrys infrastructure minister, said in a Facebook post.
Officials for the metro system in Kiev said card payments could not be accepted. The national power grid company Kievenergo had to switch off all of its computers, but the situation was under control, according to the Interfax-Ukraine news agency. Metro Group, a German company that runs wholesale food stores, said its operations in Ukraine had been affected.
At the Chernobyl plant, the computers affected by the attack collected data on radiation levels and were not connected to industrial systems at the site, where, although all reactors have been decommissioned, huge volumes of radioactive waste remain. Operators said radiation monitoring was being done manually.
Cybersecurity researchers questioned whether collecting ransom was the true objective of the attack.
Its entirely possible that this attack could have been a smoke screen, said Justin Harvey, the managing director of global incident response at Accenture Security. If you are an evildoer and you wanted to cause mayhem, why wouldnt you try to first mask it as something else?
An earlier version of this article referred incorrectly to the occupation of Justin Harvey. He is the managing director of global incident response at Accenture Security, not the chief security officer for the Fidelis cybersecurity company.
Reporting was contributed by Liz Alderman, Andrew E. Kramer, Iuliia Mendel, Ivan Nechepurenko and Isabella Kwai.
A version of this article appears in print on June 28, 2017, on Page A1 of the New York edition with the headline: A Cyberattack Hits Ukraine, Then Spreads.
Go here to see the original:
Cyberattack Hits Ukraine Then Spreads Internationally - The ...
- A crisis over using frozen Russian assets to help Ukraine - The Economist - December 7th, 2025 [December 7th, 2025]
- 2 killed as Russian overnight attack hits infrastructure in Ukraine, officials say - ABC News - December 7th, 2025 [December 7th, 2025]
- Zelenskys Government Sabotaged Oversight, Allowing Corruption in Ukraine to Fester - The New York Times - December 7th, 2025 [December 7th, 2025]
- Ukraine war live: Kremlin welcomes US security vision ahead of London peace talks - The Independent - December 7th, 2025 [December 7th, 2025]
- Nicola Jennings on Putins dealings with Trump over Ukraine cartoon - The Guardian - December 7th, 2025 [December 7th, 2025]
- Russia bombards Ukraine as US says progress made in talks with Kyiv - BBC - December 7th, 2025 [December 7th, 2025]
- Russia rapidly gaining territory in Ukraine ahead of Downing Street summit - The Telegraph - December 7th, 2025 [December 7th, 2025]
- Putin says Russia will take Donbas by force or Ukraine's troops will withdraw - BBC - December 7th, 2025 [December 7th, 2025]
- Russia unleashes massive drone and missile attack on Ukraine as talks to end war continue - PBS - December 7th, 2025 [December 7th, 2025]
- Alarm grows in Europe over what is seen as Trumps betrayal of Ukraine - Los Angeles Times - December 7th, 2025 [December 7th, 2025]
- Only Europe can save Ukraine from Putin and Trump but will it? - The Guardian - December 7th, 2025 [December 7th, 2025]
- Ukraine's peace talks with US constructive but not easy: Zelenskyy - TRT World - December 7th, 2025 [December 7th, 2025]
- Ukraine, Europe and the new economics of war - Financial Times - December 7th, 2025 [December 7th, 2025]
- Ukraine showed the UK its classic 'tactically safe' trench-clearing methods don't work in chaotic, booby-trapped trenches - Business Insider - December 7th, 2025 [December 7th, 2025]
- Looking for the 10 best Ukraine-related books of 2025? Weve got you - The Kyiv Independent - December 7th, 2025 [December 7th, 2025]
- U.S. and Ukraine hold marathon talks in Miami on Trump's peace plan - Axios - December 5th, 2025 [December 5th, 2025]
- Ukraine-Russia war latest: Putin risks fresh row with Trump after pledging to supply uninterrupted fuel to India - The Independent - December 5th, 2025 [December 5th, 2025]
- No mistrust between Europe and US over Ukraine, Macron says - The Guardian - December 5th, 2025 [December 5th, 2025]
- Putin says there are points he can't agree to in the U.S. proposal to end Ukraine war - NPR - December 5th, 2025 [December 5th, 2025]
- France's Macron: unity between Europe and U.S on Ukraine is "essential" - Reuters - December 5th, 2025 [December 5th, 2025]
- This Week in the Russia-Ukraine War (December 5) - Defense Security Monitor - December 5th, 2025 [December 5th, 2025]
- Putin says Russia will take all of Ukraine's Donbas region militarily or otherwise - Reuters - December 5th, 2025 [December 5th, 2025]
- Enough dithering. Europe must pay to save Ukraine - The Economist - December 5th, 2025 [December 5th, 2025]
- What are the Results of U.S. talks in Russia to end the war in Ukraine? - NPR - December 5th, 2025 [December 5th, 2025]
- Putin says there are points he can't agree to in the US proposal to end Russia's war in Ukraine - AP News - December 5th, 2025 [December 5th, 2025]
- Stakes High, Europe Races to Save Its Financing Plan for Ukraine - The New York Times - December 5th, 2025 [December 5th, 2025]
- Ukraine war briefing: Stop wasting the worlds time, Putin told - The Guardian - December 5th, 2025 [December 5th, 2025]
- Ukraine war latest: HUR says it destroyed Russian Su-24 tactical bomber, other targets in occupied Crimea - The Kyiv Independent - December 5th, 2025 [December 5th, 2025]
- Giving up territory would be 'unjust peace', says Ukraine's armed forces chief - Sky News - December 5th, 2025 [December 5th, 2025]
- Putin tells Ukraine to withdraw from Donbas or face being forced out - upi.com - December 5th, 2025 [December 5th, 2025]
- US and Ukrainian officials holding further talks on Trump's proposal to end Russia-Ukraine war - AP News - December 5th, 2025 [December 5th, 2025]
- Ukraine peace talks reveal a world slipping back into an acceptance of war - The Conversation - December 5th, 2025 [December 5th, 2025]
- Why is Belgium opposed to using Russian assets to support Ukraine? - Al Jazeera - December 5th, 2025 [December 5th, 2025]
- With reparations loan for Ukraine, the EU defies both Putin and Trump - Euronews.com - December 5th, 2025 [December 5th, 2025]
- Putin visits India amid Ukraine peace push: Whats on the agenda? - Al Jazeera - December 5th, 2025 [December 5th, 2025]
- Which areas is Russia demanding as its price for peace in Ukraine? visual explainer - The Guardian - December 5th, 2025 [December 5th, 2025]
- US, Ukraine officials say they'll meet for 3rd day after progress on creating a security framework - WRAL - December 5th, 2025 [December 5th, 2025]
- Macron reportedly warned Zelenskyy US may betray Ukraine on territory - The Guardian - December 5th, 2025 [December 5th, 2025]
- Rubio says US-Ukraine talks on Russia war were productive but much work remains in search of a deal - NPR - December 5th, 2025 [December 5th, 2025]
- Commission unveils two solutions to support Ukraine's financing needs in 2026-2027 - European Commission - December 5th, 2025 [December 5th, 2025]
- Oil prices hold steady due to stalled Ukraine peace talks and supply outlook - CNBC - December 5th, 2025 [December 5th, 2025]
- Key negotiators in the talks to end the war in Ukraine - WRAL - December 2nd, 2025 [December 2nd, 2025]
- Live updates: Trump presidency, Witkoff and Kushner meet with Putin in Moscow for Ukraine talks - CNN - December 2nd, 2025 [December 2nd, 2025]
- Ukraine war latest: Putin warns Europe that Russia is 'ready' for war - as Trump team at Kremlin for talks - Sky News - December 2nd, 2025 [December 2nd, 2025]
- Putin meets with U.S. officials on Ukraine after accusing Europe of 'blocking the entire peace process' - CBC - December 2nd, 2025 [December 2nd, 2025]
- Russia says before talks with US it has fully captured city of Pokrovsk, Ukraine denies it - Reuters - December 2nd, 2025 [December 2nd, 2025]
- Putin warns Europe against war ahead of meeting with Trump envoys on Ukraine - Reuters - December 2nd, 2025 [December 2nd, 2025]
- Ireland to give 125m to Ukraine as Zelensky visits Dublin - BBC - December 2nd, 2025 [December 2nd, 2025]
- Trump's push to end Ukraine war raises fears of 'ugly deal' for Europe - Reuters - December 2nd, 2025 [December 2nd, 2025]
- Putin threatens to 'cut Ukraine off from the sea' after attacks on tankers - Reuters - December 2nd, 2025 [December 2nd, 2025]
- Putin and Trump envoy Steve Witkoff set for key Ukraine talks in Moscow - BBC - December 2nd, 2025 [December 2nd, 2025]
- Putin: Russia ready for war with Europe, will target tankers of countries helping Ukraine - NewsNation - December 2nd, 2025 [December 2nd, 2025]
- Putin accuses Europe of blocking US efforts to end war in Ukraine - The Guardian - December 2nd, 2025 [December 2nd, 2025]
- U.S. delegation in Moscow for talks on Ukraine war as Russia says it seized more land - CBS News - December 2nd, 2025 [December 2nd, 2025]
- Putin accuses Europeans of sabotaging peace efforts in Ukraine - AP News - December 2nd, 2025 [December 2nd, 2025]
- Russia claims to have captured key city of Pokrovsk, as Ukraine dismisses Moscows loud statements ahead of Witkoff talks - CNN - December 2nd, 2025 [December 2nd, 2025]
- US envoy Witkoff to meet Putin in Moscow amid peace efforts to end Ukraine war - France 24 - December 2nd, 2025 [December 2nd, 2025]
- Trump turns to unconventional negotiating team heading to Russia in push for Ukraine peace deal - CNN - December 2nd, 2025 [December 2nd, 2025]
- Why Russias Claimed Capture of Pokrovsk Matters in the Ukraine War - Modern Diplomacy - December 2nd, 2025 [December 2nd, 2025]
- Ukraine Working With Warrant Holders to Resolve Bond-Deal Snag - Bloomberg.com - December 2nd, 2025 [December 2nd, 2025]
- Trump says theres a good chance a deal can be reached to end the war after US-Ukraine talks in Florida - CNN - December 2nd, 2025 [December 2nd, 2025]
- Five South Africans in court over alleged recruitment for Russias war in Ukraine - The Guardian - December 2nd, 2025 [December 2nd, 2025]
- Putin Says Russia Ready Right Now for War with Europe, Accuses EU Leaders of Sabotaging Ukraine Talks - National Review - December 2nd, 2025 [December 2nd, 2025]
- Live: Putin accuses Europeans of sabotaging peace efforts ahead of US talks on Ukraine - France 24 - December 2nd, 2025 [December 2nd, 2025]
- Man allegedly sets fire to historic Sadigura synagogue in Ukraine - The Times of Israel - November 28th, 2025 [November 28th, 2025]
- Ukraine Says It Wont Give Up Land to Russia - The Atlantic - November 28th, 2025 [November 28th, 2025]
- If the fighting ends in Ukraine, the infighting in Europe will begin - The Economist - November 28th, 2025 [November 28th, 2025]
- Ukraine war latest: Ukraine's land not for sale, ex-president says - and only 'unity' can save nation amid scandal - Sky News - November 28th, 2025 [November 28th, 2025]
- Ukraine war live: Kyivs top negotiator says no territory will be given up to Putin - The Independent - November 28th, 2025 [November 28th, 2025]
- Friday briefing: How will Ukraine fare this winter as Trump pushes for a controversial peace deal? - The Guardian - November 28th, 2025 [November 28th, 2025]
- The 28-point peace plan for Ukraine may be dead but Trump still wont stop Putin | Dmytro Kuleba - The Guardian - November 28th, 2025 [November 28th, 2025]
- Putin hosts Hungary's Orban for talks on energy and Ukraine - Reuters - November 28th, 2025 [November 28th, 2025]
- Putin says US plan could be basis of a Ukraine deal but threatens to take land by force if Kyiv doesnt withdraw - CNN - November 28th, 2025 [November 28th, 2025]
- Could the latest Ukraine talks actually end the war? Heres what to know - CNN - November 28th, 2025 [November 28th, 2025]
- JD Vance is right about the bonkers political obsession over Ukraine - The Hill - November 28th, 2025 [November 28th, 2025]
- Putin says US peace plan could form basis for end to Ukraine war as it happened - The Guardian - November 28th, 2025 [November 28th, 2025]
- Ukraine War Live UpdatesRussia Praises Trump 'Realism', Putin Promises Allies New Weapons - Newsweek - November 28th, 2025 [November 28th, 2025]
- War rages in Ukraine as push for peace complicated by leaked call from U.S. negotiator - PBS - November 28th, 2025 [November 28th, 2025]
- Letters to the editor | Bad alternate to Obamacare, Trump and Ukraine - Ventura County Star - November 28th, 2025 [November 28th, 2025]
- Russia Strikes Ukraine and Signals Resistance to Amended Peace Plan - The New York Times - November 28th, 2025 [November 28th, 2025]