NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • Deloitte Fast 50
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In

Advertisement
Advertise with NZME.
Premium
Home / Business

Juha Saarinen: Don't keep quiet about ransomware attacks

Juha Saarinen
By Juha Saarinen
Tech blogger for nzherald.co.nz.·NZ Herald·
4 Feb, 2020 04:00 PM5 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save
    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Logistics multinational Toll Group isn't saying much about why it closed down an unspecified amount of systems and customer apps. Photo / Supplied

Logistics multinational Toll Group isn't saying much about why it closed down an unspecified amount of systems and customer apps. Photo / Supplied

COMMENT:

Ransomware is back in the news, and not in a good way. We're waiting to hear what the "IT cyber security incident" is that led logistics multinational Toll Group to close down an unspecified amount of systems and customer apps [UPDATE: Toll has finally admitted a ransomware attack is behind its ongoing problems.]

The company isn't saying much apart from saying it is "making progress with our recovery activities to restore our systems and Toll customer-facing applications" but this could be yet another large ransomware attack.

READ MORE:
• Toll - finally - admits to ransomware attack
• Juha Saarinen: The ransomware money trail
• Juha Saarinen: Travelex attack could have been much worse

An anonymous source contacted Australian enterprise IT publication ITnews and said over a 1,000 servers had been hit by ransomware. Staff have been told not to switch on desktop and laptop computers, and leave them disconnected from Toll's corporate network.

Advertisement
Advertise with NZME.

The ransomware activates on user logins, and has forced Toll to take down its IT systems.

Toll was asked if the security incident is in fact a ransomware attack, and didn't deny it.

The logistics company's IT is managed by Infosys which too declined to provide further details.

If the Travelex ransomware experience is anything to go by, staying quiet on what has happened isn't a great idea for Toll Group and Infosys. If it's not ransomware, they should say so. If it is, sharing information on the attack could help prevent future "cyber security incidents".

Advertisement
Advertise with NZME.

Travelex eventually owned up to what everyone suspected was the case, namely that they were hit by REvil/Sodikinobi ransomware from which the forex giant still hasn't fully recovered. We don't know if Travelex paid the ransom or not.

It's fair to say the ransomware situation is getting worse every week, causing massive damage.

Discover more

Business

Juha Saarinen: Microsoft needs to go Marie Kondo on Windows

12 Jan 06:00 AM
Business

Juha Saarinen: Travelex attack could have been much worse

13 Jan 04:00 PM
Business

Juha Saarinen: 'Good' hackers and selfies must die

21 Jan 04:00 PM
Business

Juha Saarinen: Deadly diesels done dirt cheap

29 Jan 04:37 AM

REvil for example is being rented out to affiliate ransomware raiders on a colossal scale: Dutch internet provider KPN tracked the REvil attacks it could find over the last half of 2019, and counted a staggering 150,000 unique infections.

Working off the ransom notes it found in REvil samples, KPN estimated the criminals were hoping to extort US$38 million ($58.8m) from victims.

Again, that's just the number KPN could see. It's likely the number of attacks is far higher, but not in Russia or the post-Soviet Commonwealth of Independent States which are off limits for the ransomware.

Ransomware attacks are not just becoming more frequent, they are getting nastier too. As observed last year, ransomware criminals have started stealing data as well as encrypting computers.

Local security vendor Emsisoft has been tracking the Maze ransomware gang, which has attacked a local authority in the United States, medical practices and an accounting firm.

Travelex eventually owned up to what everyone suspected was the case. Photo / Getty Images
Travelex eventually owned up to what everyone suspected was the case. Photo / Getty Images

To force companies to pay the ransom, the Maze gang name them on their website. To further "incentivise" the companies to pay, the Maze criminals publish small samples of the data taken from compromised computers.

Advertisement
Advertise with NZME.

"It is the equivalent of kidnappers sending a pinky finger," Emsisoft threat analyst Brett Callow said.

No payment means more sensitive data is published, and Emsisoft now says at least five law firms have been hit by Maze in the recent week.

It doesn't take much imagination to realise how serious an escalation publishing sensitive information about people's legal matters on the web is.

Callow said some data has been published in Russian hacker forums with a note to "use this information in any nefarious way that you want".

The Maze gang has started to charge a million for decrypting data and another million to delete it. As Emsisoft suggests, it's highly unlikely criminals would delete data that they can make money out of at a later stage.

Again, it seems ransomware victims are trying to hide that they were attacked, with Emsisoft estimating that only a fifth of companies making a public disclosure.

That seems true, None of the companies hit by Maze that I contacted last month responded, even though the messages went through.

In one case Maze published sensitive data on a company's employees. This included home addresses, banking and insurance data, and drug test results.

The employer didn't tell its staffers who only found out after Callow said he phoned them to make them aware that their personal information was published online.

Keeping quiet like that, whether or not a ransom is paid, is guaranteed to encourage criminals. Ransomware attacks need to be reported.

That, and making sure that you have current backups of all data. The backups need to be stored offsite and offline so that they can't be deleted.

If you feel that the flood of ransomware attacks isn't being taken seriously, you're not alone. Security experts say the situation is totally out of control and ransomware attacks are done pretty much in the open. That has to change, or we'll never see an end to this devastating problem.

Save
    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Opinion

Simon Devoy: Exporter tips to overcome US tariff challenges

Premium
OpinionSasha Borissenko

Sasha Borissenko: The bright young legal minds rewriting the rules

Premium
Shares

English label set to boost a2 Milk profit


Sponsored

Why NZ businesses lag on solar and the adoption of clean on-site renewable energy

Advertisement
Advertise with NZME.

Latest from Business

Premium
Premium
Simon Devoy: Exporter tips to overcome US tariff challenges
Opinion

Simon Devoy: Exporter tips to overcome US tariff challenges

Wai Mānuka needs $5-7 million to crack the US market.

17 Aug 03:00 AM
Premium
Premium
Sasha Borissenko: The bright young legal minds rewriting the rules
Sasha Borissenko
OpinionSasha Borissenko

Sasha Borissenko: The bright young legal minds rewriting the rules

17 Aug 03:00 AM
Premium
Premium
English label set to boost a2 Milk profit
Shares

English label set to boost a2 Milk profit

17 Aug 01:00 AM


Why NZ businesses lag on solar and the adoption of clean on-site renewable energy
Sponsored

Why NZ businesses lag on solar and the adoption of clean on-site renewable energy

14 Aug 09:40 PM
NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP