Cyberattack wave ebbs, but experts see risk of more

<p>Global cyber chaos is spreading as companies boot up computers at work following the weekend's worldwide &quot;ransomware&quot; cyberattack.</p>

News 12 Staff

May 15, 2017, 8:48 PM

Updated 2,538 days ago

Share:

Cyberattack wave ebbs, but experts see risk of more
By JILL LAWLESS and DANICA KIRKA
Associated Press
LONDON (AP) - The "ransomware" cyberattack that has hit companies and governments around the world ebbed in intensity on Monday, though experts warned that new versions of the virus could emerge.
Thousands more infections were reported Monday, largely in Asia, which had been closed for business when the malware first struck Friday. The cases were more contained, however, than the systemic outbreak that last week paralyzed computers running factories, banks, government agencies and transport systems around the world.
Many of the 200,000 victims in more than 150 countries were still struggling to recover from the first attack of the so-called "WannaCry" virus.
Carmaker Renault said one of its French plants, which employs 3,500 people, wasn't reopening Monday as a "preventative step."
Britain's National Health Service said about a fifth of NHS trusts - the regional bodies that run hospitals and clinics - were hit by the attack on Friday, leading to thousands of canceled appointments and operations. Seven of the 47 affected trusts in England were still having IT problems that disrupted services Monday. Thirteen health bodies in Scotland that were hit were up and running Monday, Scottish First Minister Nicola Sturgeon said.
As cybersecurity firms worked around the clock to monitor the situation and install a software patch, new variants of the rapidly replicating malware were discovered Sunday. One did not include the so-called kill switch that allowed researchers to interrupt the malware's spread Friday by diverting it to a dead end on the internet.
Ryan Kalember, senior vice president at Proofpoint Inc., which helped stop its spread, said the version without a kill switch could spread. It was benign because it contained a flaw that prevented it from taking over computers and demanding ransom to unlock files but other more malicious ones will likely pop up.
"We haven't fully dodged this bullet at all until we're patched against the vulnerability itself," Kalember said.
Lynne Owens, director-general of Britain's National Crime Agency, said there was no indication of a second surge of the cyberattack, "But that doesn't mean there won't be one."
Tim Stevens, a lecturer in global security at King's College London, said the incident should be a wakeup call to both the public and private sectors to incorporate security into computer systems from the ground up, rather than as an afterthought.
"This thing cannot be brushed under the carpet," he said. "It is so visible and so global. There is going to have to be change at levels where change can be made."
On Monday, Chinese state media said 29,372 institutions there had been infected along with hundreds of thousands of devices.
Universities and other educational institutions in the country were among the hardest hit, possibly because schools tend to have old computers and be slow to update operating systems and security.
On social media, students complained about not being able to access their work, and people in various cities said they hadn't been able to take their driving tests because some local traffic police systems were down.
Railway stations, mail delivery, gas stations, hospitals, office buildings, shopping malls and government services also were reportedly affected.
In Japan, 2,000 computers at 600 locations were reported to have been affected. Companies including Hitachi and Nissan Motor Co. reported problems but said they had not seriously affected their operations. In Indonesia, the malware locked patient files on computers in two hospitals in the capital, Jakarta, causing delays.
In Britain, the government denied allegations that lax cybersecurity in the financially stretched, state-funded health service had helped the attack spread.
Prime Minister Theresa May said "warnings were given to hospital trusts" about the Microsoft vulnerability exploited by the attackers.
NHS Digital, which oversees U.K. hospital cybersecurity, said it sent alerts about the problem - and a patch to fix it - to health service staff and IT professionals last month.
Experts urged organizations and companies to immediately update older Microsoft operating systems, such as Windows XP, with a patch released by Microsoft Corp. to limit vulnerability to a more powerful version of the malware - or to future versions that can't be stopped.
The attack held users hostage by freezing their computers, popping up a red screen with the words, "Oops, your files have been encrypted!" and demanding money through online bitcoin payment - $300 at first, rising to $600 before it destroys files hours later.
Microsoft distributed a patch two months ago that protected computers from such an attack, but in many organizations it was likely lost among the blizzard of updates and patches that large corporations and governments strain to manage.
The president of Microsoft laid some of the blame at the feet of the U.S. government. Brad Smith criticized U.S. intelligence agencies, including the CIA and National Security Agency, for "stockpiling" software code that can be used by hackers. Cybersecurity experts say the unknown hackers who launched the attacks used a vulnerability that was exposed in NSA documents leaked online.
Tom Bossert, a homeland security adviser to President Donald Trump, said "criminals" were responsible, not the U.S. government. Bossert said the U.S. hasn't ruled out involvement by a foreign government, but that the recent ransom demands suggest a criminal network.
Bossert told ABC's "Good Morning America" that the attack is something that "for right now, we've got under control" in the United States.
So far, not many people have paid the ransom demanded by the malware, Europol spokesman Jan Op Gen Oorth told The Associated Press.
Eiichi Moriya, a cybersecurity expert and professor at Meiji University, warned that paying the ransom would not guarantee a fix.
"You are dealing with a criminal," he said. "It's like after a robber enters your home. You can change the locks but what has happened cannot be undone."
___
Yuri Kageyama in Tokyo, Louise Watt, Yu Bing and Liu Zheng in Beijing, John Leicester in Paris, Youkyung Lee in Seoul and Kelvin Chan in Hong Kong contributed to this report.
Copyright 2017 The Associated Press. All rights reserved. This material may not be published, broadcast, rewritten or redistributed.


More from News 12
1:42
Westchester commuters, residents weigh in on official congestion pricing rollout date

Westchester commuters, residents weigh in on official congestion pricing rollout date

2:10
Late-day showers for Saturday in the Hudson Valley; chance of thunderstorm for Sunday

Late-day showers for Saturday in the Hudson Valley; chance of thunderstorm for Sunday

0:52
Mother and daughter from Mount Vernon sentenced in pandemic-relief fraud scheme

Mother and daughter from Mount Vernon sentenced in pandemic-relief fraud scheme

1:53
Shop Mother’s Day Gifts – Exclusive Offers Up to 75% OFF!

Shop Mother’s Day Gifts – Exclusive Offers Up to 75% OFF!

0:32
Carmel police: Yorktown shoplifting suspects arrested

Carmel police: Yorktown shoplifting suspects arrested

0:52
'Kindness in a cup.' Sleepy Coffee, Too celebrates grand opening in Sleepy Hollow

'Kindness in a cup.' Sleepy Coffee, Too celebrates grand opening in Sleepy Hollow

1:53
Officials call for no-show Orange County legislator to step down after missing meetings for two years

Officials call for no-show Orange County legislator to step down after missing meetings for two years

0:34
Yonkers police: Man wanted for failing to appear in court for car break-in charges

Yonkers police: Man wanted for failing to appear in court for car break-in charges

1:57
White Plains dispensary pays it forward, spends green on legal help

White Plains dispensary pays it forward, spends green on legal help

0:49
Gov. Hochul signs $10 million literacy plan into law

Gov. Hochul signs $10 million literacy plan into law

0:28
Yonkers hip-hop legend Mary J. Blige, Pepsi team up to help women in the city

Yonkers hip-hop legend Mary J. Blige, Pepsi team up to help women in the city

0:32
Kingston man charged in barbershop stabbing

Kingston man charged in barbershop stabbing

2:13
MTA outlines new details on congestion pricing, including start date

MTA outlines new details on congestion pricing, including start date

2:04
Movie theater experience: A close look at the Jacob Burns Film Center in Pleasantville

Movie theater experience: A close look at the Jacob Burns Film Center in Pleasantville

1:35
 White Plains community memorializes impactful couple as part of 41st Arbor Day celebration

White Plains community memorializes impactful couple as part of 41st Arbor Day celebration

0:21
Funeral held for Westchester correction officer killed in Scarsdale motorcycle crash

Funeral held for Westchester correction officer killed in Scarsdale motorcycle crash

0:31
Police: 18-year-old Washingtonville man with autism has gone missing

Police: 18-year-old Washingtonville man with autism has gone missing

0:23
New Korean-style fried chicken restaurant opens in Mahopac

New Korean-style fried chicken restaurant opens in Mahopac

2:16
New Rochelle teacher receives birthday surprise from students, colleagues

New Rochelle teacher receives birthday surprise from students, colleagues

1:23
Pro-Palestinian demonstrators rally in Irvington during President Biden's visits to Westchester

Pro-Palestinian demonstrators rally in Irvington during President Biden's visits to Westchester