Paying for not upgrading

June 2017 News & Events

Tuesday 27th June saw a new cyber attack hitting the world. Not long after the WannaCry ransomware attacks that affected more than 150 countries, most famously the British NHS health service, there’s a new attack based on the same ‘EternalBlue’ exploit, thought to have been developed by the NSA and leaked by Shadow Brokers.

The new attack is known as Petya and seems to be even worse than WannaCry in that it won’t be as easy to stop. Petya takes advantage of the Server Message Block (SMB) vulnerability in Windows – which has been patched.

GNLcyber.com reports that a string of large companies have already been hit, from UK advertising company WPP, through to Russian oil producer Rosneft, and the Danish shipping giant Maersk. Multinationals in Spain are also in the firing line.

Worst hit, up to the time of writing, is the Ukraine where it is said that government departments, the central bank, an aircraft manufacturer and the Kiev airport (among other large targets) have all been paralysed by Petya.

For those who have not been affected by Petya, GNLcyber.com recommends:

Ensure all versions of Windows on all your computers are patched up to the latest updates available. (Microsoft’s auto-update is a pain, but very useful.)

• The company also recommends disabling the outdated protocol SMBv1.

• Isolate all unpatched systems from the network.

If you feel unhappy about paying the $300 in Bitcoin that the criminals want to restore computers, update your systems and applications, and don’t open suspicious email attachments or even suspicious emails.

Of course, when paying the $300 you are relying on the word of a criminal. GNLcyber.com informed Hi-Tech Security Solutions that as of about 21:00 on Tuesday night, about 27 Petya victims had paid a total of just over $6800 in ransom, and did not get their files back. The company says this indicates the attack may be more cyber terrorism than simply for financial gain.

Nigel Tozer, solutions marketing director, Commvault, said: “The only reliable defence against the recent Petya ransomware attacks, is backup. Clearly the malicious forces behind this and other recent attacks continue to be one step ahead of threat detection software, so if your systems and data is held to ransom the only true means of recovery is to be able to revert back to data from the last backup before the infection.

“When files are encrypted and corrupted by a ransomware attack, cloud sync and share tools aren’t something you can rely on either, because the sync facility means cloud files are as infected as their originals. The other issue is that these cloud services, especially free or those targeted at consumers, typically don’t cover all of your data and may not always have retention policies that pre-date the attack.

“The best option, to insure against data-mincing malware, is an in-house centrally managed backup solution. Whilst reverting to the backup prior to the infection might mean losing a limited amount of data, it is nominal compared to the impact of losing all your data permanently.”





Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Woolworths attack raises bomb preparedness questions
News & Events
Two explosions have been reported at Woolworths stores in South Africa over the past week. SMART Security Solutions asked Jimmy Roodt, an experienced and accredited explosive ordnance disposal specialist from Gauntlet Security Solutions, for his insight into the events.

Read more...
Growing adoption of AI at work
News & Events AI & Data Analytics
AI adoption accelerates worldwide, with South Africa making gains amid uneven diffusion. Locally, South Africa ranks 46th of 147 economies measured, and its AI usage increased to 23,1% in Q1 2026.

Read more...
Enterprise AI hits the wall
News & Events AI & Data Analytics
Demands for AI privacy and sovereignty expose the limits of architectures built for centralised and borderless data flows. Organisations that redesign early are gaining a measurable edge in AI readiness and scale.

Read more...
71% of organisations suffered an identity breach
News & Events Information Security
The State of Identity Security 2026 report from Sophos finds human error and poor non-human identity management are the root causes of most attacks, as agentic AI accelerates the risk.

Read more...
From the Editor's desk: Security goes mainstream
Technews Publishing News & Events
      Welcome to SMART Security’s SMART Mining & Industrial Security Handbook 2026. While the world is focused on cybersecurity and AI, physical security has become a board-level concern across South Africa’s ...

Read more...
Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Industry perspective on industrial cybersecurity
Technews Publishing News & Events Infrastructure Industrial (Industry)
The Industrial Security Harmonization Group has released a joint industry perspective highlighting a critical truth in industrial cybersecurity: secure communication is not determined by protocols alone, but by how they are deployed and managed in real-world environments.

Read more...
Aerial firefighter training revolution
Fire & Safety News & Events
Sophisticated new flight simulation software capable of accurately modelling the performance of firefighting helicopters could help train pilots to tackle wildfires more effectively and safely in the future.

Read more...
PoPIA turns its attention to gated access
News & Events Security Services & Risk Management
The Information Regulator has gazetted its proposed Code of Conduct for the processing of personal information at gated access points. At 65 pages long, the code signals a significant shift in how personal information is collected and managed at entry points.

Read more...
Surge in AI-enabled cybercrime and a 389% increase in ransomware
News & Events Information Security
Cybercrime no longer functions as a series of isolated campaigns; it operates as a system, with malicious hackers operating across an end-to-end life cycle and compressing the attack life cycle with shadow agents.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.