Ransomware Hits Capitol Hill Contractor (therecord.media) 41
A company that provides a user engagement platform for US politicians has suffered a ransomware attack, leaving many lawmakers unable to email their constituents for days. From a report: The attack, which hit DC-based iConstituent, has affected the offices of nearly 60 House lawmakers across both parties, Punchbowl News reported earlier today, citing House officials, lawmakers, and office aides. Catherine Szpindor, the Chief Administrative Officer of the House, said she was informed of the attack, which appears to have been limited to iConstituent's e-newsletter service and did not impact the company's GovText text messaging system. Szpindor, which is in charge of House cybersecurity, was also quick to distance the US government's network from the attack. "At this time, the CAO is not aware of any impact to House data," Szpindor told Punchbowl News. "The CAO is coordinating with the impacted offices supported by iConstituent and has taken measures to ensure that the attack does not affect the House network and offices' data."
Silver blessing. (Score:5, Funny)
A company that provides a user engagement platform for US politicians has suffered a ransomware attack, leaving many lawmakers unable to email their constituents for days.
THANK YOU! THANK YOU! THANK YOU!
Re: (Score:1)
Re: (Score:1, Informative)
They weren't gonna be emailing you. Their constituents are Amazon, Apple, Alphabet, Exxon Mobil, and so on.
The point (Score:5, Insightful)
They weren't gonna be emailing you. Their constituents are Amazon, Apple, Alphabet, Exxon Mobil, and so on.
You're missing the point. If ransomware affects politicians, they might do something about it.
Re: (Score:1)
I really don't want politicians deciding what happens with ransomware. All that will happen is that they will ask their patrons to create a committee slanted for their use to come up with ways to decide on it, which benefit them.
I wouldn't be surprised to see more DMCA or CFAA like laws, which wouldn't stop ransomware, but add a lot to the Federal private prison population. Or, we will see mandates that all Internet connected devices be locked down, similar to how the MPAA demands all Blu-Ray devices be r
Re: The point (Score:5, Interesting)
Or we could see new NIST standards developed for incremental backups. The federal government and all federal government contractors are required to follow NIST.
We could also possibly see an outright criminalization of individuals involved in paying data ransoms, drying up all possible revenue sources.
Re: (Score:2)
That would be great, but the average business wouldn't know a STIG from an inode, and generally, FISMA/FedRamp tends to bring with it provisions for backups.
Criminalization is also a good idea, and technically paying ransoms is a criminal act to hostile entities. However, companies can easily dance around that by paying a consultant to "fix" their problem, and the consultant (likely offshore) takes the cash and pays the ransom. The company has plausible deniability and their data back, the consultant has
Re: (Score:2)
Re: The point (Score:4, Informative)
That would be great, but the average business wouldn't know a STIG from an inode...
We don't need "average" businesses right now in charge of Federal contracts. For this very reason.
Either they can learn to be secure, or they can stick to making bowling balls or some shit.
Re: The point (Score:5, Interesting)
I think we will see either a ban or much tougher AML controls on Bitcoin exchanges, and a ban on US banks having anything to do with exchanges that don't meet the required standards.
Re: (Score:2)
These are politicians.
Re: (Score:3)
Or we could see new NIST standards developed for incremental backups. The federal government and all federal government contractors are required to follow NIST.
Yeah. And that actual adoption rate was going so well that they were forced to create the CMMC standard, and put the threat of 3rd party compliance validation behind it.
Maybe 5% of the DIB has fully complied with NIST 800-171 after years of it being pushed as a "mandate".
CMMC requires backups to be encrypted and offline. Because of the very threat of ransomware. We'll see how many It'll-never-happen-to-ME orgs take that seriously. Good backups are always too expensive, until the day they're worth their
Re: (Score:2)
I really don't want politicians deciding what happens with ransomware. All that will happen is that they will ask their patrons to create a committee slanted for their use to come up with ways to decide on it, which benefit them.
Yes, they could in fact do that.
And in response, they attack the committee with ransomware.
Re:Silver blessing. (Score:4, Insightful)
They'll email you unsolicited photo-op fluff after you get added to their mailing list. You won't get an individual reply to any email you send unless you're a major donor or someone individually know to their staff.
Re: (Score:3)
No, they direct mail those constituents directory, or even have them on speed-dial. The engagement platform is for sending out spam to voters. Generally email of the sort saying "our opponents are destroying this country so please send me money and subscribe to my newsletter!"
Re: (Score:2)
Re: (Score:2)
I was going to say, "And how is this a bad thing?"
Re: (Score:2)
THANK YOU! THANK YOU! THANK YOU!
Here's $20. Leave the ransomware in place.
hurrying up (Score:1)
I guess the Ransomware people are hurrying up to get as much as they can from the US. Why ? We all know the new cyber push by the US Gov will fix everything forever.
Re: (Score:3)
You really think anything will ever really change? Politicians lie and society doesn't really want to be equitable. We want our tribe to be #1. It's a human condition.
Re: (Score:2)
Well past sick and tired of the excuses (Score:2)
Re: Well past sick and tired of the excuses (Score:2)
The patchwork of vendors and solutions fortunately gives us a level of systemic defense. We'll probably see more and more companies getting hacked over time, but projecting that trend infinitely into the future isn't realistic. At some point we'll hit a critical mass of problems and they'll be addressed.
The tricky part is addressing it. A good start would be:
- criminal liability for anyone who knows of a hack but doesn't report it
- financial penalty of around $25k for each incident paid to t
Re: (Score:2)
The patchwork of vendors and solutions fortunately gives us a level of systemic defense.
Except it is the patchwork of vendors and solutions that are part of the problem. Just look at Solarwinds.
Re: Well past sick and tired of the excuses (Score:2)
Certainly. But it also means a wider attack on all the critical infrastructure at the same time is quite hard to pull off. It would be better if the security was better, but I'm not worried about some sort of social collapse due to the power going out across the country for days.
Re: (Score:2)
At some point we'll hit a critical mass of problems and they'll be addressed.
NEWS FLASH: We're there already.
We need to fix all this shit NOW, not years from now.
From their website...it's "secure" (Score:4, Informative)
...We built the iConstituent Engagement Platform with the belief that secure, efficient, impactful communications can bring people and government closer together....
Yup, more bullshit from magic cloud land...
Re: (Score:2)
It says "secure" so it must be secure!
Reminds me of my first monitor (15" CRT - free) that had "low radiation" on it. No brand name but at least it was low radiation!
My Take (Score:1)
.... And Nothing Of Value Was Lost!
Congress now has a reason... (Score:1)
Congress now has a reason to do nothing. I used to watch CSPAN and seeing lawmakers giving speeches to an empty chamber. Or how often Congress goes into recess without any meaningful legislation passed.
So now Congress can blame ransomware and do what it always does...nothing. Progress indeed.
Billy Preston in 1974 was prescient on this...
https://www.youtube.com/watch?... [youtube.com]
JoshK.
Simple Fix (Score:3)
Simply outlaw Cryptocurrency worldwide and this problem virtually disappears overnight.
Yes, it really is just that simple. Ransomware absolutely depends on Cryptocurrency. No Cryptocurrency, little to no Ransomware.
Try it and prove me wrong. Iâ(TM)ll wait...
Re: (Score:2)
I like my Cryptocurrency. It buys me stuff to live.
Too Fucking Bad.
So do other, legal, forms of currency.
Microsoft Windows hits Capitol Hill contractor (Score:2)
Not On Patch Tuesday! (Score:1)
"Another vulnerability, a privilege escalation flaw in the DWM Core Library, has already been exploited in the wild, according to Microsoft. An attacker could trigger CVE-2021-33739 by running an executable or script on the local machine. Although this vulnerability has a CVSS score of 8.4 out of 10, Microsoft still considers it to be “important.” Talos would also like to spec
Re: (Score:1)