Cyberattack Hits Ukraine Then Spreads Internationally – The …
Like the WannaCry attacks in May, the latest global hacking took control of computers and demanded digital ransom from their owners to regain access. The new attack used the same National Security Agency hacking tool, Eternal Blue, that was used in the WannaCry episode, as well as two other methods to promote its spread, according to researchers at the computer security company Symantec.
The National Security Agency has not acknowledged its tools were used in WannaCry or other attacks. But computer security specialists are demanding that the agency help the rest of the world defend against the weapons it created.
The N.S.A. needs to take a leadership role in working closely with security and operating system platform vendors such as Apple and Microsoft to address the plague that theyve unleashed, said Golan Ben-Oni, the global chief information officer at IDT, a Newark-based conglomerate hit by a separate attack in April that used the agencys hacking tools. Mr. Ben-Oni warned federal officials that more serious attacks were probably on the horizon.
The vulnerability in Windows software used by Eternal Blue was patched by Microsoft in March, but as the WannaCry attacks demonstrated, hundreds of thousands of groups around the world failed to properly install the fix.
Just because you roll out a patch doesnt mean itll be put in place quickly, said Carl Herberger, vice president for security at Radware. The more bureaucratic an organization is, the higher chance it wont have updated its software.
Because the ransomware used at least two other ways to spread on Tuesday including stealing victims credentials even those who used the Microsoft patch could be vulnerable and potential targets for later attacks, according to researchers at F-Secure, a Finnish cybersecurity firm, and others.
A Microsoft spokesman said the companys latest antivirus software should protect against the attack.
Governments and companies in Europe and the United States have been impacted. Here are several:
The Ukrainian government said several of its ministries, local banks and metro systems had been affected. A number of other European companies, including Rosneft, the Russian energy giant; Saint-Gobain, the French construction materials company; and WPP, the British advertising agency, also said they had been targeted.
Ukrainian officials pointed a finger at Russia on Tuesday, although Russian companies were also affected. Home Credit bank, one of Russias top 50 lenders, was paralyzed, with all of its offices closed, according to the RBC news website. The attack also affected Evraz, a steel manufacturing and mining company that employs about 80,000 people, the RBC website reported.
In the United States, the multinational law firm DLA Piper also reported being hit. Hospitals in Pennsylvania were being forced to cancel operations after the attack hit computers at Heritage Valley Health Systems, a Pennsylvania health care provider, and its hospitals in Beaver and Sewickley, Penn., and satellite locations across the state.
The ransomware also hurt Australian branches of international companies. DLA Pipers Australian offices warned clients that they were dealing with a serious global cyber incident and had disabled email as a precautionary measure. Local news reports said that in Hobart, Tasmania, on Tuesday evening, computers in a Cadbury chocolate factory, owned by Mondelez International, had displayed ransomware messages that demanded $300 in bitcoins.
Qantas Airways booking system failed for a time on Tuesday, but the company said the breakdown was due to an unrelated hardware issue.
The Australian government has urged companies to install security updates and isolate any infected computers from their networks.
This ransomware attack is a wake-up call to all Australian businesses to regularly back up their data and install the latest security patches, said Dan Tehan, the cybersecurity minister. We are aware of the situation and monitoring it closely.
A National Security Agency spokesman referred questions about the attack to the Department of Homeland Security. The Department of Homeland Security is monitoring reports of cyberattacks affecting multiple global entities and is coordinating with our international and domestic cyber partners, Scott McConnell, a department spokesman, said in a statement.
Computer specialists said the ransomware was very similar to a virus that emerged last year called Petya. Petya means Little Peter, in Russian, leading some to speculate the name referred to Sergei Prokofievs 1936 symphony Peter and the Wolf, about a boy who captures a wolf.
Reports that the computer virus was a variant of Petya suggest the attackers will be hard to trace. Petya was for sale on the so-called dark web, where its creators made the ransomware available as ransomware as a service a play on Silicon Valley terminology for delivering software over the internet, according to the security firm Avast Threat Labs.
That means anyone could launch the ransomware with the click of a button, encrypt someones systems and demand a ransom to unlock it. If the victim pays, the authors of the Petya ransomware, who call themselves Janus Cybercrime Solutions, get a cut of the payment.
That distribution method means that pinning down the people responsible for Tuesdays attack could be difficult.
The attack is an improved and more lethal version of WannaCry, said Matthieu Suiche, a security researcher who helped contain the spread of the WannaCry ransomware when he created a kill switch that stopped the attacks.
In just the last seven days, Mr. Suiche noted, WannaCry had tried to hit an additional 80,000 organizations but was prevented from executing attack code because of the kill switch. Petya does not have a kill switch.
Petya also encrypts and locks entire hard drives, whereas the earlier ransomware attacks locked only individual files, said Chris Hinkley, a researcher at the security firm Armor.
The hackers behind Petya demanded $300 worth of the cybercurrency Bitcoin to unlock victims machines. By Tuesday afternoon, online records showed that 30 victims had paid the ransom, although it was not clear whether they had regained access to their files. Other victims may be out of luck, after Posteo, the German email service provider, shut down the hackers email account.
In Ukraine, people turned up at post offices, A.T.M.s and airports to find blank computer screens, or signs about closures. At Kievs central post office, a few bewildered customers milled about, holding parcels and letters, looking at a sign that said, Closed for technical reasons.
The hackers compromised Ukrainian accounting software mandated to be used in various industries in the country, including government agencies and banks, according to researchers at Cisco Talos, the security division of the computer networking company. That allowed them to unleash their ransomware when the software, which is also used in other countries, was updated.
The ransomware spread for five days across Ukraine, and around the world, before activating Tuesday evening.
If I had to guess, I would think this was done to send a political message, said Craig Williams, the senior technical researcher at Talos.
One Kiev resident, Tetiana Vasylieva, was forced to borrow money from a relative after failing to withdraw money at four automated teller machines. At one A.T.M. in Kiev belonging to the Ukrainian branch of the Austrian bank Raiffeisen, a message on the screen said the machine was not functioning.
Ukraines Infrastructure Ministry, the postal service, the national railway company, and one of the countrys largest communications companies, Ukrtelecom, had been affected, Volodymyr Omelyan, the countrys infrastructure minister, said in a Facebook post.
Officials for the metro system in Kiev said card payments could not be accepted. The national power grid company Kievenergo had to switch off all of its computers, but the situation was under control, according to the Interfax-Ukraine news agency. Metro Group, a German company that runs wholesale food stores, said its operations in Ukraine had been affected.
At the Chernobyl plant, the computers affected by the attack collected data on radiation levels and were not connected to industrial systems at the site, where, although all reactors have been decommissioned, huge volumes of radioactive waste remain. Operators said radiation monitoring was being done manually.
Cybersecurity researchers questioned whether collecting ransom was the true objective of the attack.
Its entirely possible that this attack could have been a smoke screen, said Justin Harvey, the managing director of global incident response at Accenture Security. If you are an evildoer and you wanted to cause mayhem, why wouldnt you try to first mask it as something else?
An earlier version of this article referred incorrectly to the occupation of Justin Harvey. He is the managing director of global incident response at Accenture Security, not the chief security officer for the Fidelis cybersecurity company.
Reporting was contributed by Liz Alderman, Andrew E. Kramer, Iuliia Mendel, Ivan Nechepurenko and Isabella Kwai.
A version of this article appears in print on June 28, 2017, on Page A1 of the New York edition with the headline: A Cyberattack Hits Ukraine, Then Spreads.
Go here to see the original:
Cyberattack Hits Ukraine Then Spreads Internationally - The ...
- Ukraine war briefing: Zelenskyy says US has linked security guarantees to ceding of Donbas - The Guardian - March 26th, 2026 [March 26th, 2026]
- Welcome to 'New Russia': How the Kremlin is remaking occupied Ukraine - The Detroit News - March 26th, 2026 [March 26th, 2026]
- Iran war deflects attention from Ukraine as an emboldened Russia starts spring offensive - abcnews.com - March 26th, 2026 [March 26th, 2026]
- In Rural Ukraine, Basic Health Care Is a Casualty of War - The New York Times - March 26th, 2026 [March 26th, 2026]
- Trump pressuring Ukraine to cede territory to Russia, Zelenskyy says - politico.eu - March 26th, 2026 [March 26th, 2026]
- Welcome to New Russia: How the Kremlin is remaking occupied Ukraine - Reuters - March 26th, 2026 [March 26th, 2026]
- G7 allies meet against backdrop of wars in Ukraine and Iran, with unpredictable US - Reuters - March 26th, 2026 [March 26th, 2026]
- Russia says it hopes for new round of Ukraine talks with US as soon as conditions allow - The Detroit News - March 26th, 2026 [March 26th, 2026]
- Ukraine Spent Big to Shield Energy Industry From Drones. Is the Mideast Next? - The New York Times - March 26th, 2026 [March 26th, 2026]
- The Coming Drone-War Inflection in Ukraine - IEEE Spectrum - March 26th, 2026 [March 26th, 2026]
- Russia fires more than 1,000 drones against Ukraine as spring offensive ramps up on battlefield - CNN - March 26th, 2026 [March 26th, 2026]
- Estonia and Latvia say drones hit their NATO territory as Ukraine and Russia traded attacks - CBS News - March 26th, 2026 [March 26th, 2026]
- US security guarantees tied to Ukraine's withdrawal from Donbas, Zelensky says - The Kyiv Independent - March 26th, 2026 [March 26th, 2026]
- Ukraine faces new Russian offensive as peace talks stall - Reuters - March 26th, 2026 [March 26th, 2026]
- Ukraine's unique role in the Iran war: From the Politics Desk - NBC News - March 26th, 2026 [March 26th, 2026]
- Ukraine: four years of heartache - Anabaptist World - March 26th, 2026 [March 26th, 2026]
- Russian forces begin offensive in Ukraine as Zelensky worries about impact of Iran conflict - CNN - March 26th, 2026 [March 26th, 2026]
- Ukraine Crushes Russias Spring Offensive, Wiping Out a Week of Recruits in 3 Days - UNITED24 Media - March 26th, 2026 [March 26th, 2026]
- Iran war deflects attention from Ukraine as an emboldened Russia starts spring offensive - AP News - March 26th, 2026 [March 26th, 2026]
- Kenyans fighting illegally for Russia in Ukraine to be granted amnesty - BBC - March 26th, 2026 [March 26th, 2026]
- The USA offers Ukraine a way to end the war - Defence24.com - March 26th, 2026 [March 26th, 2026]
- Ukraine terminates 116 agreements with Russia, Belarus, and CIS - Ukrinform - March 26th, 2026 [March 26th, 2026]
- Putins spring offensive in Ukraine has begun. Experts warn Trump has given Russia window of opportunity - The Independent - March 26th, 2026 [March 26th, 2026]
- Watch Iran, Ukraine Conflicts Top of the Agenda as G-7 Foreign Ministers Meet in in Vaux-de-Cernay, France - Bloomberg.com - March 26th, 2026 [March 26th, 2026]
- Latvia and the defense of Ukraine: the evolution of military support - - March 26th, 2026 [March 26th, 2026]
- Sweden to Join Special Tribunal for Investigating Russias War Crimes in Ukraine - UNITED24 Media - March 26th, 2026 [March 26th, 2026]
- The National Guard of Ukraine Is a Force That Has Become One of the Key Pillars of Our Defense and Our Active Operations Along the Entire Front Line ... - March 26th, 2026 [March 26th, 2026]
- Ukraine v Sweden: where to watch and what you need to know about the most important match for the Ukrainian national team - Visit Ukraine - March 26th, 2026 [March 26th, 2026]
- Ukraine: Why is Ecocide So Hard to Prove? - Institute for War & Peace Reporting - IWPR - March 26th, 2026 [March 26th, 2026]
- Ukraine says it has terminated 116 agreements concluded with Russia, Belarus, CIS - Anadolu Ajans - March 26th, 2026 [March 26th, 2026]
- US Army general who oversaw Ukraine left classified maps on train, overindulged in alcohol: IG report - Fox News - March 17th, 2026 [March 17th, 2026]
- Zelenskyy: Ukraine has thwarted Russian offensive operation planned for March - - March 17th, 2026 [March 17th, 2026]
- IMF Raises Alarm Over Aid to Ukraine With Parliament in Gridlock - Bloomberg.com - March 17th, 2026 [March 17th, 2026]
- Opinion | I traveled to Ukraine to teach sociology. It left me amazed. - The Washington Post - March 17th, 2026 [March 17th, 2026]
- Sean Penn skipped the Oscars to meet with Zelenskyy in Ukraine - San Francisco Chronicle - March 17th, 2026 [March 17th, 2026]
- Ukraine's anti-drone tech is in high demand as Iran attacks its neighbors - NBC News - March 17th, 2026 [March 17th, 2026]
- Ukraine worries about losing the Americans as global attention shifts to the war in the Middle East - CNN - March 17th, 2026 [March 17th, 2026]
- Ukraine had a brutal plan to bankrupt Putin with his own war dead until Trumps oil U-turn wrecked it - The Independent - March 17th, 2026 [March 17th, 2026]
- Russia and Ukraine both claim front-line progress with US-brokered talks on hold - AP News - March 17th, 2026 [March 17th, 2026]
- Lessons from Ukraine for Defending Gulf Airspace from Shaheds - War on the Rocks - March 17th, 2026 [March 17th, 2026]
- Exclusive: Ukraine's Naftogaz in talks with Romania's OMV Petrom to develop Black Sea gas find, sources say - Reuters - March 17th, 2026 [March 17th, 2026]
- US Army general who oversaw Ukraine left classified maps on train, overindulged in alcohol: IG report - Yahoo - March 17th, 2026 [March 17th, 2026]
- Kenya and Russia agree no Kenyans will be recruited for Ukraine war - Al Jazeera - March 17th, 2026 [March 17th, 2026]
- Ukraine war briefing: War in the Middle East is bad news for Ukraine, says Zelenskyy - The Guardian - March 17th, 2026 [March 17th, 2026]
- Sean Penn Seen in Ukraine After Skipping His Third Oscar Win - People.com - March 17th, 2026 [March 17th, 2026]
- Kremlin dismisses FT report that Ukraine peace process is fizzling out - Reuters - March 17th, 2026 [March 17th, 2026]
- Exclusive | Ukraine ready to jump in to help US as other American allies drag feet, Zelensky tells Post - New York Post - March 17th, 2026 [March 17th, 2026]
- Working group set up in Ukraine to focus on reopening airports - - March 17th, 2026 [March 17th, 2026]
- President Zelenskyy thanks Oscars no-show Sean Penn for visit: 'We know what a true friend of Ukraine is' - Entertainment Weekly - March 17th, 2026 [March 17th, 2026]
- After bashing allies, Trump now wants their help except from Ukraine - The Kyiv Independent - March 17th, 2026 [March 17th, 2026]
- Best Supporting Actor Winner Sean Penn Skipped the Oscars Because Hes in Ukraine - Consequence of Sound - March 17th, 2026 [March 17th, 2026]
- Russia scoffs at US-Israeli 'miscalculation' in Iran, years after failing to take Ukraine in days - The Kyiv Independent - March 17th, 2026 [March 17th, 2026]
- Russian military loses another 760 soldiers in war against Ukraine - Ukrinform - March 17th, 2026 [March 17th, 2026]
- Reznikov: "Ukraine and Israel must confront the axis of evil together" - Ukrainian Jewish Encounter - March 17th, 2026 [March 17th, 2026]
- Trump v Nato: from tariffs to Ukraine, how will the US respond? - The Times - March 17th, 2026 [March 17th, 2026]
- Elon Musk Moves Against the Russians in Ukraine - The Atlantic - February 27th, 2026 [February 27th, 2026]
- Ukraine war has claimed lives of 55 Ghanaians, foreign minister says - Reuters - February 27th, 2026 [February 27th, 2026]
- Ghana says at least 55 of its people killed after Russia lured them to fight Ukraine - The Guardian - February 27th, 2026 [February 27th, 2026]
- Hungarys Viktor Orbn seeking to drum up votes by doing down Ukraine - The Guardian - February 27th, 2026 [February 27th, 2026]
- 4 years into Russias full-scale invasion of Ukraine, a look at the war by the numbers - AP News - February 27th, 2026 [February 27th, 2026]
- Russia's war on Ukraine puts women off having children and that could spell economic disaster - CNBC - February 27th, 2026 [February 27th, 2026]
- Ukraine Eliminates Shahed Drone Relay Stations Operating From Belarus - UNITED24 Media - February 27th, 2026 [February 27th, 2026]
- As Ukraine war enters fifth year, Zelenskyy says Russia failing at its goals and Kremlin agrees - CBS News - February 27th, 2026 [February 27th, 2026]
- Ukraine: Use every diplomatic tool to end this war, top UN official tells Security Council - UN News - February 27th, 2026 [February 27th, 2026]
- Germany supplies Ukraine with natural gas for the first time - Euronews.com - February 27th, 2026 [February 27th, 2026]
- Ukraine: 'The war could still last for years and paradoxically, time is not on the Kremlin's side' - Le Monde.fr - February 27th, 2026 [February 27th, 2026]
- Were experts on the Ukraine war. Heres what we think will happen next - The Independent - February 27th, 2026 [February 27th, 2026]
- Ukraine ups target to 50,000 Russian casualties a month with The Post seeing the killer drones of war - New York Post - February 27th, 2026 [February 27th, 2026]
- How Ukraine Hunted Down and Crippled a Russian Surveillance Ship - The National Interest - February 27th, 2026 [February 27th, 2026]
- Ukraine war latest: Putin may escalate if he doesn't get 'the only thing that can save him' - expert - Sky News - February 27th, 2026 [February 27th, 2026]
- Ukraine war today: Tens of thousands without power in Russia after missile attack - The Independent - February 27th, 2026 [February 27th, 2026]
- Death, glory and a soldiers stipend lures Colombians to Ukraine - The Times - February 27th, 2026 [February 27th, 2026]
- Russia-Ukraine War in 10 Charts - CSIS | Center for Strategic and International Studies - February 27th, 2026 [February 27th, 2026]
- Ukraine and Russia to meet for second round of talks as fourth anniversary of war looms - The Guardian - February 16th, 2026 [February 16th, 2026]
- Kremlin says main Ukraine issues will be discussed in Geneva talks, including territory - Reuters - February 16th, 2026 [February 16th, 2026]
- Peace talks round three: Ukraine-US-Russia Geneva meeting's key topics - Euronews.com - February 16th, 2026 [February 16th, 2026]
- Ukraine war briefing: Drone attack on Russian port sparks fires ahead of fresh peace talks - The Guardian - February 16th, 2026 [February 16th, 2026]
- North Korea opens a housing district for families of its soldiers killed in Russia-Ukraine war - NPR - February 16th, 2026 [February 16th, 2026]
- Kim Jong-un unveils housing for families of North Koreans killed in Ukraine war - The Guardian - February 16th, 2026 [February 16th, 2026]
- Zelenskyy says Ukraine, not Russia, is facing pressure to make concessions to end war - NBC News - February 16th, 2026 [February 16th, 2026]