Skip to main content

Govt issues critical alert over ransomware threat


No major incident yet in the country, but central bank, stock exchanges, other vital institutions told to bolster defences; companies rush to protect computer systems.The government’s cybersecurity arm has asked the central bank, stock exchanges, the National Payments Corp. of India (NPCI) and other vital institutions to safeguard their systems against the latest cyberattack that has infected thousands of systems globally and may escalate further.

The Indian Computer Emergency Response Team (CERT-In), the central agency coordinating efforts on cyber security issues, has issued a “critical alert” and has advised the installation of relevant “patches” to protect against any data breaches.

The virus dubbed Wanna Cry, a so-called ransomware, has locked up more than 100,000 computers and sent cybersecurity experts scrambling on Sunday to patch computers and restore infected ones. Experts fear that the ransomware worm that stopped car factories, hospitals, shops and schools in more than 100 countries could wreak fresh havoc on Monday when employees log back on.

Indian officials, who declined to be named, said no major incident of cyberattack has been brought to the notice of CERT-In yet.

Even so, information security officers and senior executives in charge of running the information technology operations in Indian enterprises have been rushing to protect their computer systems against the attack.

Security experts in the country said that the full extent of damage to systems in India would become known when employees log into their systems on Monday morning.

“The number of systems being patched (which means a security plug-in is applied to prevent a loophole in software being exploited) in the past 48 to 72 hours in India is unprecedented,” said Burgess Cooper, partner, cybersecurity, at advisory and consulting firm EY India. He said some manufacturing and consumer goods companies in India may be impacted, though there were no confirmed reports at the time of going to press.

A ransomware typically logs users out of their own systems through forced encryption of data and asks them to pay a ransom (in the case of WannaCry, the ransom was demanded in bitcoin, a crypto-currency) if they want to access the encrypted data.

The country most affected by WannaCry is said to be the UK, where 48 of the 248 National Health Service trusts were impacted, causing widespread disruption to health services in the country.

Renault on Saturday said it had halted manufacturing at plants in Sandouville, France and Romania to prevent the spread of ransomware in its systems.Among the other victims is a Nissan car plant in Sunderland, northeast England.

The WannaCry malware, according to CERT-In, spreads “by using a vulnerability in implementations of Server Message Block” in systems running Microsoft’s Windows  operating system.

Microsoft released patches last month and on Friday to fix the vulnerability that allowed the worm to spread across networks, a rare and powerful feature that caused infections to surge on Friday.

Code for exploiting that bug, which is known as “Eternal Blue”, was released on the internet in March by a hacking group known as the Shadow Brokers.The group claimed it was stolen from a repository of the US National Security Agency (NSA)’s hacking tools. The agency has not responded to requests for comment.

Though the spread of the virus has slowed, cybersecurity experts warned that the respite may be brief as new versions of the worm were expected.The control of the situation has been attributed to a 22-year-old UK researcher who went by the name of MalwareTech.

According to a report on Forbes.com, the researcher is said to have noted that one of the web domains used by the attackers hadn’t been registered. So he registered  the site, took control of the domain for $10.69 and started seeing connections from infected victims, which enabled him to track the ransomware’s spread. This accidentally stopped the malware—at least in the UK.

Mint New Delhi, 15th May 2017

Comments

Popular posts from this blog

RBI deputy governor cautions fintech platform lenders on privacy concerns during loan recovery

  India's digital lending infrastructure has made the loan sanctioning system online. Yet, loan recovery still needs a “feet on the street” approach, Swaminathan J, deputy governor of the Reserve Bank of India, said at a media event on Tuesday, September 2, according to news agency ANI.According to the ANI report, the deputy governor flagged that fintech operators in the digital lending segment are giving out loans to customers with poor credit profiles and later using aggressive recovery tactics.“While loan sanctioning and disbursement have become increasingly digital, effective collection and recovery still require a 'feet on the street' and empathetic approach. Many fintech platforms operate on a business model that involves extending small-value loans to customers often with poor credit profiles,” Swaminathan J said.   Fintech platforms' business models The central bank deputy governor highlighted that many fintech platforms' business models involve providing sm

Credit card spending growth declines on RBI gaze, stress build-up

  Credit card spends have further slowed down to 16.6 per cent in the current financial year (FY25), following the Reserve Bank of India’s tightening of unsecured lending norms and rising delinquencies, and increased stress in the portfolio.Typically, during the festival season (September–December), credit card spends peak as several credit card-issuing banks offer discounts and cashbacks on e-commerce and other platforms. This is a reversal of trend in the past three financial years stretching to FY21 due to RBI’s restrictions.In the previous financial year (FY24), credit card spends rose by 27.8 per cent, but were low compared to FY23 which surged by 47.5 per cent. In FY22, the spending increased 54.1 per cent, according to data compiled by Macquarie Research.ICICI Bank recorded 4.4 per cent gross credit losses in its FY24 credit card portfolio as against 3.2 per cent year-on-year. SBI Cards’ credit losses in the segment stood at 7.4 per cent in FY24 and 6.2 per cent in FY23, the rep

India can't rely on wealthy to drive growth: Ex-RBI Dy Guv Viral Acharya

  India can’t rely on wealthy individuals to drive growth and expect the overall economy to improve, Viral Acharya, former deputy governor of the Reserve Bank of India (RBI) said on Monday.Acharya, who is the C V Starr Professor of Economics in the Department of Finance at New York University’s Stern School of Business (NYU-Stern), said after the Covid-19 pandemic, rural consumption and investments have weakened.We can’t be pumping our growth through the rich and expect that the economy as a whole will do better,” he said while speaking at an event organised by Elara Capital here.f there has to be a trickle-down, it should have actually happened by now,” Acharya said, adding that when the rich keep getting wealthier and wealthier, they have a savings problem.   “The bank account keeps getting bigger, hence they look for financial assets to invest in. India is closed, so our money can't go outside India that easily. So, it has to chase the limited financial assets in the country and