{"id":15270,"date":"2019-05-07T13:17:02","date_gmt":"2019-05-07T21:17:02","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2019\/05\/07\/news-9019\/"},"modified":"2019-05-07T13:17:02","modified_gmt":"2019-05-07T21:17:02","slug":"news-9019","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2019\/05\/07\/news-9019\/","title":{"rendered":"What&#8217;s Behind the Wolters Kluwer Tax Outage?"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Tue, 07 May 2019 19:56:44 +0000<\/strong><\/p>\n<p>Early in the afternoon on Friday, May, 3, I asked a friend to relay a message to his security contact at <strong>CCH<\/strong>, the cloud-based tax division of the global information services firm <a href=\"https:\/\/en.wikipedia.org\/wiki\/Wolters_Kluwer\" target=\"_blank\" rel=\"noopener\">Wolters Kluwer\u00a0<\/a>in the Netherlands. The message was that the same file directories containing new versions of CCH&#8217;s software were open and writable by any anonymous user, and that there were suspicious files in those directories indicating some user(s) abused that access.<\/p>\n<p>Shortly after that report, the CCH file directory for tax software downloads was taken offline. As of this publication, several readers have reported outages affecting multiple CCH Web sites. These same readers reported being unable to access their clients&#8217; tax data in CCH&#8217;s cloud because of the ongoing outages. A <a href=\"https:\/\/np.reddit.com\/r\/sysadmin\/comments\/blcswm\/wolters_kluwer_cch_axcess_outage\/\" target=\"_blank\" rel=\"noopener\">Reddit thread<\/a> is full of theories.<\/p>\n<div id=\"attachment_47636\" style=\"width: 604px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-47636\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/05\/wkia.jpg\" alt=\"\" width=\"594\" height=\"600\" \/><\/p>\n<p class=\"wp-caption-text\">One of the many open and writable directories on CCH&#8217;s site before my report on Friday.<\/p>\n<\/div>\n<p>I do not have any information on whether my report about the world-writable file server had anything to do with the outages going on now at CCH. Nor did I see any evidence that any client data was exposed on the site.<\/p>\n<p>What I did see in those CCH directories were a few odd PHP and text files, including one that seemed to be promoting two different and unrelated Russian language discussion forums.<\/p>\n<p>I sent Wolters Kluwer an email asking how long the file server had been so promiscuous (allowing anyone to upload files to the server), and what the company was doing to validate the integrity of the software made available for download by CCH tax customers.<\/p>\n<p><strong>Marisa Westcott<\/strong>, vice president of marketing and communications at Wolters Kluwer, told KrebsOnSecurity on Friday that she would &#8220;check with the team to see if we can get some answers to your questions.&#8221;<\/p>\n<p>But subsequent emails and phone calls have gone unreturned. Calls to the company&#8217;s main support number (800-739-9998)\u00a0generate the voice message, &#8220;We are currently experiencing technical difficulties. Please try your call again later.&#8221;<\/p>\n<p>This morning, Wolters Kluwer released an update on the extensive outage this morning <a href=\"https:\/\/twitter.com\/Wolters_Kluwer\/status\/1125773345281196032\" target=\"_blank\" rel=\"noopener\">on Twitter, saying:<\/a><\/p>\n<blockquote>\n<p>&#8220;Since yesterday, May 6, we are experiencing network and service interruptions after certain Wolters Kluwer platforms and applications. Out of an abundance of caution, we proactively took offline a number of other applications and we immediately began our investigation and remediation efforts. The secure use of our products and services is our top priority. we have ben able to restore network and services for a number &#8211; but not all &#8212; of our systems.&#8221;<\/p>\n<\/blockquote>\n<p><em>Accounting Today<\/em> <a href=\"https:\/\/www.accountingtoday.com\/news\/the-wolters-kluwer-cch-outage-what-happened\" target=\"_blank\" rel=\"noopener\">reports today<\/a> that a PR representative from\u00a0Wolters Kluwer Tax &amp; Accounting, which makes the CCH products, confirmed the outage was the result of a malware attack:<span id=\"more-47631\"><\/span><\/p>\n<blockquote>\n<p>\u201cOn Monday May 6, we started seeing technical anomalies in a number of our platforms and applications,\u201d the statement given to<i>\u00a0Accounting Today\u00a0<\/i>reads. \u201cWe immediately started investigating and discovered the installation of malware. As a precaution, in parallel, we decided to take a broader range of platforms and applications offline. With this action, we aimed to quickly limit the impact this malware could have had, giving us the opportunity to investigate the issue with assistance from third-party forensics consultants and work on a solution. Unfortunately, this impacted our communication channels and limited our ability to share updates. On May 7, we were able to restore service to a number of applications and platforms.\u201d<\/p>\n<\/blockquote>\n<p><em>Accounting Today<\/em> says the limited ability to share updates angered CCH users, many of whom took to social media to air their grievances against a cloud partner they perceive to be ill-prepared for maintaining ongoing service and proper security online.<\/p>\n<p>&#8220;Despite CCH stating that a number of applications and platforms were up and running today, May 7, several users on a\u00a0<u><a href=\"https:\/\/www.reddit.com\/r\/sysadmin\/comments\/blcswm\/wolters_kluwer_cch_axcess_outage\/\" target=\"_blank\" rel=\"noopener\">Reddit thread<\/a><\/u>\u00a0on the topic have stated that as of this morning in Florida, Maine, Texas, Pittsburgh and South Carolina, their CCH systems are still down,&#8221; Accounting Today wrote.<\/p>\n<p>Special thanks to <strong>Alex Holden<\/strong> of <a href=\"https:\/\/www.holdsecurity.com\" target=\"_blank\" rel=\"noopener\">Hold Security<\/a> for help in notifying CCH.<\/p>\n<p>Update, 4:26 p.m. ET: Ms. Westcott from Wolters Kluwer followed up with this added statement just now:<\/p>\n<blockquote>\n<p>&#8220;We regret any inconvenience and that we were unable to share more information initially, as our focus was on investigation and restoring services as quickly as possible for our customers.&#8221;<\/p>\n<p>&#8220;We have seen no evidence that customer data was taken or that there was a breach of confidentiality of that data. Also, there is no reason to believe that our customers have been infected through our platforms and applications. Our investigation is ongoing. We want to apologize for any inconvenience this may have caused.&#8221;<\/p>\n<\/blockquote>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2019\/05\/whats-behind-the-wolters-kluwer-tax-outage\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2019\/05\/wkia.jpg\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Tue, 07 May 2019 19:56:44 +0000<\/strong><\/p>\n<p>Early in the afternoon on Friday, May, 3, I asked a friend to relay a message to his security contact at CCH, the cloud-based tax division of the global information services firm Wolters Kluwer\u00a0in the Netherlands. The message was that the same file directories containing new versions of CCH&#8217;s software were open and writable by any anonymous user, and that there were suspicious files in those directories indicating some user(s) abused that access.    Shortly after that report, the CCH file directory for tax software downloads was taken offline. As of this publication, several readers have reported outages affecting multiple CCH Web sites. These same readers reported being unable to access their clients&#8217; tax data in CCH&#8217;s cloud because of the ongoing outages.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[10644],"class_list":["post-15270","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-other"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15270","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=15270"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/15270\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=15270"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=15270"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=15270"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}