NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Juha Saarinen: Don't keep quiet about ransomware attacks

Juha Saarinen
By Juha Saarinen
Tech blogger for nzherald.co.nz.·NZ Herald·
4 Feb, 2020 04:00 PM5 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Logistics multinational Toll Group isn't saying much about why it closed down an unspecified amount of systems and customer apps. Photo / Supplied

Logistics multinational Toll Group isn't saying much about why it closed down an unspecified amount of systems and customer apps. Photo / Supplied

COMMENT:

Ransomware is back in the news, and not in a good way. We're waiting to hear what the "IT cyber security incident" is that led logistics multinational Toll Group to close down an unspecified amount of systems and customer apps [UPDATE: Toll has finally admitted a ransomware attack is behind its ongoing problems.]

The company isn't saying much apart from saying it is "making progress with our recovery activities to restore our systems and Toll customer-facing applications" but this could be yet another large ransomware attack.

READ MORE:
• Toll - finally - admits to ransomware attack
• Juha Saarinen: The ransomware money trail
• Juha Saarinen: Travelex attack could have been much worse

An anonymous source contacted Australian enterprise IT publication ITnews and said over a 1,000 servers had been hit by ransomware. Staff have been told not to switch on desktop and laptop computers, and leave them disconnected from Toll's corporate network.

Advertisement
Advertise with NZME.

The ransomware activates on user logins, and has forced Toll to take down its IT systems.

Toll was asked if the security incident is in fact a ransomware attack, and didn't deny it.

The logistics company's IT is managed by Infosys which too declined to provide further details.

If the Travelex ransomware experience is anything to go by, staying quiet on what has happened isn't a great idea for Toll Group and Infosys. If it's not ransomware, they should say so. If it is, sharing information on the attack could help prevent future "cyber security incidents".

Advertisement
Advertise with NZME.

Travelex eventually owned up to what everyone suspected was the case, namely that they were hit by REvil/Sodikinobi ransomware from which the forex giant still hasn't fully recovered. We don't know if Travelex paid the ransom or not.

It's fair to say the ransomware situation is getting worse every week, causing massive damage.

Discover more

Business

Juha Saarinen: Microsoft needs to go Marie Kondo on Windows

12 Jan 06:00 AM
Business

Juha Saarinen: Travelex attack could have been much worse

13 Jan 04:00 PM
Business

Juha Saarinen: 'Good' hackers and selfies must die

21 Jan 04:00 PM
Business

Juha Saarinen: Deadly diesels done dirt cheap

29 Jan 04:37 AM

REvil for example is being rented out to affiliate ransomware raiders on a colossal scale: Dutch internet provider KPN tracked the REvil attacks it could find over the last half of 2019, and counted a staggering 150,000 unique infections.

Working off the ransom notes it found in REvil samples, KPN estimated the criminals were hoping to extort US$38 million ($58.8m) from victims.

Again, that's just the number KPN could see. It's likely the number of attacks is far higher, but not in Russia or the post-Soviet Commonwealth of Independent States which are off limits for the ransomware.

Ransomware attacks are not just becoming more frequent, they are getting nastier too. As observed last year, ransomware criminals have started stealing data as well as encrypting computers.

Local security vendor Emsisoft has been tracking the Maze ransomware gang, which has attacked a local authority in the United States, medical practices and an accounting firm.

Travelex eventually owned up to what everyone suspected was the case. Photo / Getty Images
Travelex eventually owned up to what everyone suspected was the case. Photo / Getty Images

To force companies to pay the ransom, the Maze gang name them on their website. To further "incentivise" the companies to pay, the Maze criminals publish small samples of the data taken from compromised computers.

Advertisement
Advertise with NZME.

"It is the equivalent of kidnappers sending a pinky finger," Emsisoft threat analyst Brett Callow said.

No payment means more sensitive data is published, and Emsisoft now says at least five law firms have been hit by Maze in the recent week.

It doesn't take much imagination to realise how serious an escalation publishing sensitive information about people's legal matters on the web is.

Callow said some data has been published in Russian hacker forums with a note to "use this information in any nefarious way that you want".

The Maze gang has started to charge a million for decrypting data and another million to delete it. As Emsisoft suggests, it's highly unlikely criminals would delete data that they can make money out of at a later stage.

Again, it seems ransomware victims are trying to hide that they were attacked, with Emsisoft estimating that only a fifth of companies making a public disclosure.

That seems true, None of the companies hit by Maze that I contacted last month responded, even though the messages went through.

In one case Maze published sensitive data on a company's employees. This included home addresses, banking and insurance data, and drug test results.

The employer didn't tell its staffers who only found out after Callow said he phoned them to make them aware that their personal information was published online.

Keeping quiet like that, whether or not a ransom is paid, is guaranteed to encourage criminals. Ransomware attacks need to be reported.

That, and making sure that you have current backups of all data. The backups need to be stored offsite and offline so that they can't be deleted.

If you feel that the flood of ransomware attacks isn't being taken seriously, you're not alone. Security experts say the situation is totally out of control and ransomware attacks are done pretty much in the open. That has to change, or we'll never see an end to this devastating problem.

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Airlines

Pilot group to honour Erebus legacy with safety award

17 Jun 07:00 AM
Premium
Business

The NZ boardrooms where women buck gender pay gap trend

17 Jun 06:00 AM
Premium
Shares

Market close: NZX 50 down 0.4% as Israel-Iran conflict intensifies

17 Jun 05:48 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Pilot group to honour Erebus legacy with safety award

Pilot group to honour Erebus legacy with safety award

17 Jun 07:00 AM

The industry faces challenges but hopes to bring newcomers and veterans together.

Premium
The NZ boardrooms where women buck gender pay gap trend

The NZ boardrooms where women buck gender pay gap trend

17 Jun 06:00 AM
Premium
Market close: NZX 50 down 0.4% as Israel-Iran conflict intensifies

Market close: NZX 50 down 0.4% as Israel-Iran conflict intensifies

17 Jun 05:48 AM
Median house prices down again, sales taking longer: monthly report

Median house prices down again, sales taking longer: monthly report

17 Jun 05:32 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP