{"id":3223,"date":"2016-11-28T17:04:52","date_gmt":"2016-11-28T22:04:52","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=3223"},"modified":"2017-06-01T18:58:35","modified_gmt":"2017-06-01T22:58:35","slug":"san-francisco-ransomware","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/san-francisco-ransomware\/","title":{"rendered":"Ransomware Hits San Francisco&#8217;s Public Transportation"},"content":{"rendered":"<h2>A quarter of the SFMTA\u2019s network was infected over the holiday weekend.<\/h2>\n<p>Riders of San Francisco&#8217;s metro system (SFMTA) were treated to free rides this weekend. But what appeared to be a pleasant holiday surprise, was actually the result of a nasty ransomware infection affecting the train\u2019s ticketing computers, which left no option but to allow free rides while the computer systems were down.<\/p>\n<p>Ransomware has been making headlines for the last few years. It is a type of malware that encrypts files on the infected computer, blocking access to them unless the user pays a ransom in bitcoin (or other untraceable methods). Ransomware has been so effective because it employs social engineering &#8211; the term given to attacks which rely on manipulating people &#8211; often spreading through phishing emails and documents claiming to be official invoices or bills.<\/p>\n<p>The full extent of the damage to the SFMTA is unclear, but reporting from <a href=\"http:\/\/www.sfexaminer.com\/alleged-muni-hacker-demands-73000-ransom-computers-stations-restored\/\" rel=\"nofollow\">SF Examiner<\/a> indicates that the ransomware is throughout its systems. <a href=\"https:\/\/twitter.com\/FitzTheReporter\/status\/802659189260550144\" rel=\"nofollow\">Photographs <\/a>of station agent computers show they were infected, and on Sunday, drivers were being assigned routes \u201cvia handwritten notes posted to bulletin boards, as opposed to the usual computer printouts.\u201d Sources <a href=\"http:\/\/sanfrancisco.cbslocal.com\/2016\/11\/26\/you-hacked-cyber-attackers-crash-muni-computer-system-across-sf\/\" rel=\"nofollow\">told KPIX 5<\/a> that computers handling payroll may also be affected, which could delay employees\u2019 paychecks.<\/p>\n<p>Affected computers displayed the message:<\/p>\n<blockquote><p>\u201cYou Hacked, ALL Data Encrypted. Contact For Key(<a href=\"mailto:cryptom27@yandex.com\">cryptom27@yandex.com<\/a>)ID:681 , Enter Key: \u00a0\u00a0Missing operating system.\u201d<\/p><\/blockquote>\n<p>The San Francisco ransomware, <a href=\"https:\/\/twitter.com\/redteamwrangler\/status\/802669514466869248\" rel=\"nofollow\">believed to be a strain of HDDCryptor<\/a>, encrypts the MBR (Master Boot Record) of the computer, a system-critical function, without which, a computer is unable to start properly.<\/p>\n<p><a href=\"http:\/\/hoodline.com\/2016\/11\/hackers-hold-sfmta-s-computer-network-hostage-for-73k-ransom\" rel=\"nofollow\">Hoodline.com<\/a> and <a href=\"http:\/\/www.theverge.com\/2016\/11\/27\/13758412\/hackers-san-francisco-light-rail-system-ransomware-cyber security-muni\" rel=\"nofollow\">The Verge<\/a> contacted the email address listed in the message. The attacker, going by the name \u2018Andy Saolis,\u2019\u00a0said:<\/p>\n<blockquote><p>\u201cWe do this for money, nothing else ! i hope it\u2019s help [sic] to company to make secure IT before we coming !\u201d<\/p><\/blockquote>\n<p>The exact method of infection is not known, but it looks like it was one of the usual vectors of ransomware, which is usually delivered via phishing sites or emails. A list of infected computers <a href=\"http:\/\/www.csoonline.com\/article\/3144991\/security\/ransomware-forces-sfmta-to-give-free-rides-73-000-demanded-by-attackers.html\" rel=\"nofollow\">obtained by CSO Online<\/a> suggests that a staff member\u2019s computer may have been the original entry point.<\/p>\n<p>We do know that the SFMTA was not specifically targeted. Saolis wrote:<\/p>\n<blockquote><p>\u201cOur software working completely automatically and we don&#8217;t have targeted attack to anywhere! SFMTA network was Very Open and 2000 Server\/PC infected by software!\u201d<\/p><\/blockquote>\n<p>To remove the ransomware and restore functionality, Saolis is demanding a ransom of 100 bitcoin, which is <a href=\"http:\/\/www.coindesk.com\/price\/\" rel=\"nofollow\">currently worth<\/a> approximately $73,000 USD. In exchange for that ransom, decryption keys are provided that can automatically un-encrypt the computers and return them back to normal.<\/p>\n<p>According to Saolis, 2,112 of the 8,656 computers in the Municipal Transportation Agencies\u2019 network are infected. Though as of Sunday night, the ticketing machines were functioning again, which suggests that SFMTA may be solving the problem on its own.<\/p>\n<p>If an organization has proper measures in place (most importantly, backups), it can avoid paying the ransom and restore the computers on their own with little to no data loss. Ransomware distributors often impose a deadline to force victims into action.<\/p>\n<p>If SFMTA is going to pay the ransom, <a href=\"https:\/\/www.nomoreransom.org\/\">which security companies discourage<\/a>, it may not have much time left. Saolis wrote: \u201cwe are waiting one more day for \u201cwe are waiting one more day for deal and after it this email closing for security reason!\u201d (which would be Monday). In another email, Saolis wrote \u201cmany ppl and news agency send email and question, it&#8217;s boring, i want to close this email!\u201d<\/p>\n<p>Apparently, he is not appreciating the coverage.<\/p>\n<p>SFMTA is a government agency, which raises questions about whether it could even use funds to pay the ransom if it wanted to. <a href=\"https:\/\/www.sfmta.com\/sites\/default\/files\/SFMTA%20Adopted%20Operating%20Budget%20Book%20FY2015%20AND%20FY2016.Full%20details.pdf\" rel=\"nofollow\">According to SFMTA\u2019s budget<\/a>, it brings in an average of $559,000 per day in ticket fares, so whatever it does, it will want to get this sorted out quickly.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>A quarter of the SFMTA\u2019s network was infected over the holiday weekend. Riders of San Francisco&#8217;s metro system (SFMTA) were treated to free rides this weekend. But what appeared to&#8230;<\/p>\n","protected":false},"author":2,"featured_media":3227,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16],"tags":[271,263,269,270],"class_list":["post-3223","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","tag-hddcryptor","tag-ransomware","tag-san-francisco","tag-sfmta","post-with-tags"],"views":8014,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2016\/11\/iStock-502064892.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3223","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=3223"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/3223\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/3227"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=3223"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=3223"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=3223"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}