{"id":18885,"date":"2022-04-28T09:10:07","date_gmt":"2022-04-28T17:10:07","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2022\/04\/28\/news-12618\/"},"modified":"2022-04-28T09:10:07","modified_gmt":"2022-04-28T17:10:07","slug":"news-12618","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/04\/28\/news-12618\/","title":{"rendered":"FBI warns food and agriculture to brace for seasonal ransomware attacks"},"content":{"rendered":"<p><strong>Credit to Author: Jovi Umawing| Date: Thu, 28 Apr 2022 16:48:18 +0000<\/strong><\/p>\n<p>The Federal Bureau of Investigation (FBI) recently released a Private Industry Notification warning agriculture cooperatives (also known as &#8220;farmers&#8217; co-ops&#8221;) of the <a href=\"https:\/\/www.ic3.gov\/Media\/News\/2022\/220420-2.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">looming danger of well-timed ransomware attacks<\/a>. The agency warns that during the critical planting and harvesting seasons, attacks could result in the theft of proprietary information, and operational disruption leading to financial losses and even food shortages.<\/p>\n<p>This is the second time the FBI has warned the food and agriculture sector. <a href=\"https:\/\/s3.documentcloud.org\/documents\/21053966\/fbi-bc-cyber-criminal-actors-targeting-the-food-and-agriculture-sector-with-ransomware-attacks.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">In September 2021<\/a>, the agency revealed that ransomware threat actors were ramping up attacks as the sector adopted more smart technologies.<\/p>\n<p>&#8220;Since 2021, multiple agricultural cooperatives have been impacted by a variety of ransomware variants,&#8221; the agency said, &#8220;Initial intrusion vectors included known but unpatched common vulnerabilities and exploits and secondary infections from the exploitation of shared network resources or compromise of managed services.&#8221;<\/p>\n<p>The FBI is concerened that threat actors might think agricultural cooperatives have an extra incentive to pay ransoms because some phases of their work are so time-sensitive. <\/p>\n<h2>After-effects of ransomware attacks against the FA sector<\/h2>\n<p>Attacks against organizations at the root of the food supply chain can cause significant downstream disruption.<\/p>\n<p>During the same month as the FBI&#8217;s initial warning, in September 2021, BlackMatter ransomware hit Iowa&#8217;s NEW Cooperative, demanding a ransom of <a href=\"https:\/\/www.zdnet.com\/article\/iowa-farm-services-provider-hit-with-blackmatter-ransomware-and-5-9-million-ransom\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">$5.9 million<\/a>. The company was forced to take affected devices offline to stop the threat from spreading, and the ransomware gang was reportedly able to steal 1,000GB of data, including financial documents, employee data, and source code for a farming technology platform.<\/p>\n<p>Two days after the NEW Cooperative attack, Crystal Valley Cooperative, a major farmer&#8217;s co-op in Minnesota, was <a href=\"https:\/\/www.zdnet.com\/article\/crystal-valley-cooperative-becomes-latest-agriculture-business-hit-with-ransomware\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">hit by a still-unnamed ransomware strain<\/a>. This stopped the group from processing major payment cards and caused its phone system some downtime.<\/p>\n<p>In the last decade, the agriculture sector has been through a rapid technological transformation as traditional farm machinery\u2014such as tractors\u2014have joined the Internet of Things (IoT).<\/p>\n<p>In a recent Lock and Code podcast about <a href=\"https:\/\/blog.malwarebytes.com\/podcast\/2021\/08\/hackers-tractors-and-a-few-delayed-actors-how-hacker-sick-codes-learned-too-much-about-john-deere-lock-and-code-s02e16\/\">the vulnerability of agricultural technology<\/a>, podcast host Davd Ruiz interviewed Sick Codes, a hacker who has taken a deep dive into the security of John Deere and other agricultural equipment manufacturers. <\/p>\n<p>He told us that while the industry is beginning to think about the cybersecurity of its devices and systems, many vendors still struggle with the basics like where they store data and how to make it safe, leaving it open to easy exploitation. In one example of what might be possible, Sick explained that threat actors might be able to &#8220;game&#8221; the market for corn prices by intercepting unencrypted data about the crop as it moves from tractor fleets into the cloud:<\/p>\n<blockquote class=\"wp-block-quote\">\n<p>If somebody is to catch that data on the way out, they will be able to predict the price of corn. And corn is a commodity. It fluctuates daily.\u00a0So actually if you have all that data, you\u2019d be out to make serious money.<\/p>\n<\/blockquote>\n<p>The FBI has taken stock of ransomware gangs that have hit organizations within the food and agriculture sector: <a href=\"https:\/\/blog.malwarebytes.com\/detections\/ransom-blackbyte\/\">BlackByte<\/a>, <a href=\"https:\/\/blog.malwarebytes.com\/ransomware\/2021\/07\/blackmatter-a-new-ransomware-group-claims-link-to-darkside-revil\/\">BlackMatter<\/a>, <a href=\"https:\/\/blog.malwarebytes.com\/threat-spotlight\/2021\/05\/threat-spotlight-conti-the-ransomware-used-in-the-hse-healthcare-attack\/\">Conti<\/a>, <a href=\"https:\/\/blog.malwarebytes.com\/threat-spotlight\/2021\/03\/hellokitty-when-cyberpunk-met-cy-purr-crime\/\">HelloKitty<\/a> (aka Five Hands), <a href=\"https:\/\/blog.malwarebytes.com\/detections\/ransom-lockbit\/\">LockBit<\/a>, <a href=\"https:\/\/blog.malwarebytes.com\/threat-spotlight\/2019\/07\/threat-spotlight-sodinokibi-ransomware-attempts-to-fill-gandcrab-void\/\">Sodinokibi<\/a> (aka REvil), and <a href=\"https:\/\/blog.malwarebytes.com\/detections\/ransom-suncrypt\/\">SunCrypt<\/a>.<\/p>\n<h2>FBI recommendations<\/h2>\n<p>The agency advises the sector to focus on protecting its networks, systems, and applications as threat actors can and will exploit vulnerabilities in them. It also offered some guidance on how to protect against ransomware attacks, including:<\/p>\n<ul>\n<li><strong>Regularly back up data<\/strong> to an offline, air-gapped location where it can&#8217;t be reached by attackers.<\/li>\n<li><strong>Patch software<\/strong> and firmware as soon as security updates become available.<\/li>\n<li><strong>Segment networks<\/strong> to slow down attackers, make finding them easier, and limit their damage.<\/li>\n<li><strong>Use <a href=\"https:\/\/blog.malwarebytes.com\/glossary\/multi-factor-authentication-mfa\/\">multi-factor authentication (MFA)<\/a><\/strong> whenever possible.<\/li>\n<li><strong>Use strong passwords<\/strong> and avoid reusing them.<\/li>\n<\/ul>\n<p>More guidelines can be found in the agency&#8217;s <a href=\"https:\/\/www.ic3.gov\/Media\/News\/2022\/220420-2.pdf\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Private Industry Notification<\/a> on the subject.<\/p>\n<p>For a glimpse of the current state of cybersecurity in an Internet-connected agriculture sector, listen to our Lock and Code podcast below:<\/p>\n<figure class=\"wp-block-embed is-type-rich is-provider-spotify wp-block-embed-spotify wp-embed-aspect-21-9 wp-has-aspect-ratio\">\n<div class=\"wp-block-embed__wrapper\"> <iframe title=\"Spotify Embed: Hackers, tractors, and a few delayed actors. How hacker Sick Codes learned too much about John Deere\" style=\"\" width=\"100%\" height=\"420\" frameborder=\"0\" allowfullscreen allow=\"autoplay; clipboard-write; encrypted-media; fullscreen; picture-in-picture\"><\/iframe>         <\/p>\n<div class=\"col-md-8 embedded-video-alt\">\n<div class=\"embedded-video-alt-inner\">\n<div class=\"embedded-video-alt-text\">                   This video cannot be displayed because your <i>Functional Cookies<\/i> are currently disabled.<\/p>\n<p>                        To enable them, please visit our <i><a href=\"https:\/\/www.malwarebytes.com\/privacy\/#how-we-collect-information\">privacy policy<\/a><\/i> and search for the Cookies section. Select <i>&#8220;Click Here&#8221;<\/i> to open the Privacy Preference Center and select <i>&#8220;Functional Cookies&#8221;<\/i> in the menu. You can switch the tab back to <i>&#8220;Active&#8221;<\/i> or disable by moving the tab to <i>&#8220;Inactive.&#8221;<\/i> Click <i>&#8220;Save Settings.&#8221;<\/i>             <\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/figure>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/vital-infrastructure\/2022\/04\/fbi-warns-food-and-agriculture-to-brace-for-seasonal-ransomware-attacks\/\">FBI warns food and agriculture to brace for seasonal ransomware attacks<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/vital-infrastructure\/2022\/04\/fbi-warns-food-and-agriculture-to-brace-for-seasonal-ransomware-attacks\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Jovi Umawing| Date: Thu, 28 Apr 2022 16:48:18 +0000<\/strong><\/p>\n<p>For the second time, the FBI has warned the food and agriculture sector about the risk of ransomware attacks.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/vital-infrastructure\/2022\/04\/fbi-warns-food-and-agriculture-to-brace-for-seasonal-ransomware-attacks\/\">FBI warns food and agriculture to brace for seasonal ransomware attacks<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[25302,24646,25141,25872,25873,25874,6627,25474,25875,25876,25877,24306,24761,24616,25878,10600,11738,25879,5820,3765,22297,25560,22299,25880,21437],"class_list":["post-18885","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-blackbyte","tag-blackmatter","tag-conti","tag-crystal-valley-cooperative","tag-fa-sector","tag-farmers-co-op","tag-fbi","tag-federal-bureau-of-investigations","tag-five-hands","tag-food-and-agriculture","tag-hellokitty","tag-lock-and-code","tag-lock-and-code-podcast","tag-lockbit","tag-maze-cartel","tag-mfa","tag-multi-factor-authentication","tag-new-cooperative","tag-podcast","tag-ransomware","tag-revil","tag-sick-codes","tag-sodinokibi","tag-suncrypt","tag-vital-infrastructure"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18885","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=18885"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/18885\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=18885"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=18885"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=18885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}