Tony Dick
Dropbox02
7/10/2021
Information Systems Security
CCIS 391 ADE
It seems like the most popular attacks these days are ransomware attacks. This would
fall under the category of “Information Extortion”. The article I have chosen is an overview
of a Tesla employee who was approached and offered $500,000.00 to install ransomware
software on to Tesla’s information systems. If the employee would have taken the hacker up
on the offer it would have been even bigger news than it already is. One thing I noticed when
looking for an article was there are so many attacks and potential attacks every single month.
The ones that show up are the big ones, I’m sure there are plenty of attacks that don’t even
show up in news articles. The pure size and scope of ransomware attacks these days is
astounding.
My article falls under the Information Extortion category as well. Ransomware is
something where the hacker holds the victim’s information hostage until a ransom is paid.
This is extortion by definition. You could also consider the ransomware to be a “Software
Attack” too, but in the end the goal was to hold the information hostage.
The title of the article is “Incident Of The Week: Thwarted Ransomware Attack
Against Tesla Serves as A Warning” It is by Seth Adler and it was published in September of
2020. The article overviews the thwarted ransomware attack in early August of 2020. The
employee followed company protocol and notified Tesla immediately. This is a great sign
that Tesla treats its employees well and makes the security policies known to the employees.
The attack is a type of “Social Engineering”. Social Engineering is a very popular thing to do
for hackers because as we learned this week, one of the most vulnerable parts of a company is
the employees. And they are most vulnerable to social engineering attacks.
The article details how the attack would have taken place. The employee would have
installed the software through USB or email, and it would have been fully encrypted. They
even detailed how they would DDOS attack Tesla during the install to thwart Tesla’s security
team. This seems like an intense battle of wits if it would have gone down between the
Russian hackers and Tesla’s security team.
Some of the tips given by the article is to adopt a zero-trust strategy, monitor employee
accounts for unusual activities, enact approval policies, provide additional employee training,
and create a culture to be proud of so your employees will fight on your side. And the very
last point was to always report these attacks to the FBI.
It was a great article and overviews the potential attack in detail. We can learn a lot
from it.
[Link]
against-tesla-serves-as-a-warning?preview=1882a995f678930583a8722943f42babe42f1e92
Tony Dick
Dropbox02
7/10/2021
Information Systems Security
CCIS 391 ADE
Sources:
Incident Of The Week: Thwarted Ransomware Attack Against Tesla Serves As A
Warning". Cyber Security Hub, 2020, [Link]
of-the-week-thwarted-ransomware-attack-against-tesla-serves-as-a-warning?
preview=1882a995f678930583a8722943f42babe42f1e92. Accessed 11 July 2021.
Whitman M. E., & Mattord H. J. (2017). Principles of Information Security. [Columbia College].
Retrieved from [Link]