0% found this document useful (0 votes)
12 views2 pages

Case Study Yuba County Forward Ransomware

Yuba County successfully survived a ransomware attack in February 2021, recovering 100% of their data backups without paying any ransom, thanks to their partnership with Rubrik. The county's IT team, led by former CIO Paul LaValley, implemented a robust disaster recovery strategy that allowed them to restore operations quickly and efficiently. The incident highlighted the importance of having secure, immutable backups and a responsive support team to mitigate the impact of cyber threats.

Uploaded by

apingbas
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
12 views2 pages

Case Study Yuba County Forward Ransomware

Yuba County successfully survived a ransomware attack in February 2021, recovering 100% of their data backups without paying any ransom, thanks to their partnership with Rubrik. The county's IT team, led by former CIO Paul LaValley, implemented a robust disaster recovery strategy that allowed them to restore operations quickly and efficiently. The incident highlighted the importance of having secure, immutable backups and a responsive support team to mitigate the impact of cyber threats.

Uploaded by

apingbas
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

How Yuba County Survived a Ransomware

Attack and Lived to Tell the Tale

Yuba County is a rural county in Northern California. Within it are various departments
concerned with health and public safety including the Sheriff’s office consisting of 911
dispatch for fire and ambulance. Another critical area is the health department which
manages testing, contact tracing and vaccinations for COVID-19. All are vital services
for the citizens of Yuba County.

Paul LaValley, former CIO for Yuba County, oversees a team of 16 people who are
INDUSTRY
responsible for providing a dependable, always-on infrastructure for the community’s
Local Government
safety and livelihood. Due in large part to the pandemic and an increased prevalence
in remote work, ransomware attacks are on the rise and have become a lucrative
RESULTS
business for cybercriminals.
• $0 paid in ransom
“When we were hit by ransomware in February 2021, it could have been a debilitating
• 100% of backups recovered
disaster for the county; however, one of the few moments of satisfaction during weeks
within 7 days
of discomfort was knowing that Rubrik was backing up our data and that we wouldn’t
• 90%+ management time savings
have to pay the ransom for data recovery,” LaValley remarked.
• Near-zero RTOs

CHALLENGES DoppelPaymer, Dridex, IceID, Oh My!

• Attack initiated through Yuba County confirmed they were hit with ransomware when a DoppelPaymer
infected PC ransomware note showed up on several servers and PCs. “By the time we got to it, it
had encrypted roughly 50 PCs and 100 servers,” LaValley described. Prior to this, there
• Kerberos issues behind
were several indications that they were compromised.
AD servers
• ~50 PCs and 100 “First, we noticed there were Kerberos issues behind our active directory (AD) servers,
servers encrypted which prevented them from communicating. Later that evening, a GPO push occurred
and an enterprise AD admin account was created. We knew through forensic analysis
BUSINESS that Dridex, Cobalt Strike, IcedID, as well as PowerShell scripts were all used for
TRANSFORMATION portions of the attack. Based on that, we realized our compromise was a Kerberos
Yuba County not only strengthened attack, traditionally called a Golden Ticket attack, which was used to compromise
their DR strategy with Rubrik, they AD and enable and deploy ransomware encryption on multiple machines,”
survived a ransomware attack and added LaValley.
lived to tell the tale. With Rubrik,
Yuba County had peace of mind
Ransomware Survival Kit Fit for the County
knowing that 100% of their backups
were able to be recovered and they How did Yuba County respond? In multiple phases: “In the initial 24 hours, we
did not have to pay the ransom for disconnected all servers, backed up files, disabled admin accounts, and reset
their data. passwords,” LaValley explained. “The next step was restarting the department and
user notifications. We communicated to department heads, county management,
PARTNER and users what was going on. This included the FBI, various CA State Agencies,
ePlus

CASE STUDY | YUBA COUNTY


in particular the California Office of Emergency Services. • 100% of backups recovered within 7 days: “We were able to
Additionally, we blocked all inbound and outbound network recover 100% of what we had on Rubrik thanks to its native
traffic outside of the US.” immutability and avoided paying any ransom.”

With Rubrik, Yuba County was able to accelerate its • 90%+ management time savings (26 days of productivity
ransomware recovery with just a few clicks and restore to the back): “Previously, we were spending between four to five
most recent clean slate. “Backups are one of the most, if not hours per week managing our backups. This has now been
the most, important defenses against ransomware. Rubrik’s file reduced to 30 minutes per week with Rubrik. As a result, our
system was built to be immutable, meaning backups cannot be team has gained 26 days of productivity. As a small shop, we
encrypted or deleted by ransomware. I am very fortunate to say don’t have a dedicated backup administrator, so any time
that 100% of what we had on Rubrik we were able to recover savings that we can devote to other projects is critical.”
with LiveMount since 90% of our servers are virtualized,”
• World-class support: “As soon as we were notified of the
LaValley stated.
attack, Rubrik’s support team engaged us and prioritized
What initially drove Yuba County to adopt Rubrik was the need our recovery efforts. They worked around the clock to help
for a different type of DR. The DR strategy they had in place maintain continuity and were always available to help. I
was for the typical flood or earthquake, unfit for modern-day couldn’t be more thankful to the Rubrik team.”
threats, especially ransomware. “Rubrik saved our data during
• Recoverable isolated backups: “Having recoverable
this sensitive time thanks to its immutability, MFA, and retention
isolated backups that attackers cannot get to is the key
lock. Understanding the hackers were in control of AD, Rubrik
component in protecting against ransomware. You cannot
ensured we cleared AD of anything tied to Rubrik, building an
prevent someone from attacking you but at least you have
immutable protected vault,” explained LaValley.
recoverable data with Rubrik. The peace of mind we have is
“Needless to say, I learned a lot through this process. I can sleep priceless.”
better at night knowing we have systems in place to impede
• Near-zero RTOs: “With our legacy solution, we were
either a recurrence or another ransomware attack.” LaValley
unable to perform granular restores. We were tasked
remarked. Additional benefits:
with recovering an on-prem file server for legal discovery
• $0 paid in ransom: “One of the few moments of satisfaction purposes but ended up having to recover a complete
in weeks of discomfort was knowing Rubrik was backing up backup to restore a single file server image. This entire
our data and that we wouldn’t have to pay the ransom for process took one week and even worse, our backups came
data recovery. This saved the county potentially hundreds, if to a halt. With Rubrik, the difference is night and day—it
not millions, of dollars.” takes minutes to recover our data from on-prem and the
cloud. We also have the granularity to recover exactly what
we need.”

Rubrik, the Multi-Cloud Data Control™ Company, enables enterprises to maximize value from data
Global HQ that is increasingly fragmented across data centers and clouds. Rubrik delivers a single, policy-driven
1001 Page Mill Rd., Building 2 1-844-4RUBRIK platform for data recovery, governance, compliance, and cloud mobility. For more information, visit
Palo Alto, CA 94304 inquiries@[Link] [Link] and follow @rubrikInc on Twitter. © 2021 Rubrik. Rubrik is a registered trademark of
United States [Link] Rubrik, Inc. Other marks may be trademarks of their respective owners.

20210707_v1

CASE STUDY | YUBA COUNTY

Common questions

Powered by AI

Other counties can learn from Yuba County the importance of integrating advanced cybersecurity measures into their IT frameworks. Key lessons include adopting technology that supports immutable backups to negate ransomware's effectiveness and ensuring rapid recovery capabilities to maintain service continuity. Furthermore, Yuba County's emphasis on inter-agency communication and collaboration with external IT partners like Rubrik highlights a strategic approach to collective crisis management, where leveraging partnerships and informing stakeholders leads to more resilient IT and public service ecosystems .

Yuba County's successful recovery from the ransomware attack without paying a ransom was largely due to their adoption of Rubrik's technology, which provided an immutable backup system resistant to encryption and deletion by ransomware. Key components included 100% recoverability of their backups within seven days using Rubrik’s LiveMount feature, use of multi-factor authentication (MFA), and maintaining retention locks. Additionally, Rubrik's system allowed for recoverable isolated backups that attackers couldn't access, enabling the county to quickly restore services without paying a ransom .

For public entities like Yuba County, a modern disaster recovery strategy is critical due to the increasingly complex nature of cyber threats like ransomware. Yuba County faced challenges such as compromised Active Directory systems and widespread server encryption. Their existing DR plan, which addressed physical disasters, was inadequate for these threats. They leveraged Rubrik's technology to implement a DR strategy that was responsive to ransomware, incorporating immutable backups and swift recovery processes. Such a strategy ensures continuous public safety services even amidst cyber incidents, reflecting an essential evolution in response to contemporary security challenges .

Rubrik's system was designed with immutability at its core, ensuring backups cannot be encrypted or deleted by ransomware. In Yuba County's case, this design allowed for full data recovery post-attack without paying ransom. Rubrik's multi-tiered approach included MFA and retention locks which protected backups even when attackers controlled Active Directory. These features ensured recovery of 100% of backups within seven days, illustrating Rubrik's effectiveness in maintaining data integrity and operational continuity amidst a ransomware attack .

The partnership with Rubrik enhanced Yuba County's IT operations beyond cybersecurity by reducing the management time required for backups by over 90%, equating to 26 days of additional productivity. The reliability and speed of Rubrik's recovery protocol also improved operational efficiency, enabling swift, granular data recoveries. The overall effectiveness in resource allocation and task completion allowed the IT team to focus on other critical projects, further optimizing their operational capacity and service delivery .

Yuba County's experience underscored the role of effective communication and collaboration during a cybersecurity crisis. Upon detecting the ransomware attack, they promptly communicated with FBI and California State Agencies, ensuring transparent information flow about the breach. This coordination was crucial for effective incident response and resource mobilization. Internally, regular updates were provided to department heads, management, and users, fostering understanding and cooperation across the organization. Additionally, their collaboration with Rubrik facilitated direct, synchronized recovery efforts, exemplifying the crucial interplay between internal and external stakeholders during a crisis .

Yuba County transitioned to using Rubrik for their disaster recovery needs due to the inadequacy of their existing strategy, which was suited for natural disasters like floods or earthquakes, not modern threats like ransomware. They achieved significant gains, including 100% data recovery without ransom payment and a 90% reduction in management time related to backups, saving 26 days of productivity. The immutable nature of Rubrik's backups and the ability to make granular recoveries efficiently contributed to their operational resilience and enhanced security posture .

Yuba County detected the ransomware attack beginning with Kerberos issues in their Active Directory servers. A GPO push created an enterprise AD admin account, indicating advanced persistent threat tactics. Subsequently, using forensic analysis, they identified malicious activities linked to Dridex and Cobalt Strike, confirming a Kerberos or Golden Ticket attack. In response, Yuba County disconnected all servers, backed up critical files, disabled admin accounts, and reset passwords within the first 24 hours. They also communicated the breach to necessary authorities and blocked all non-US network traffic .

The ransomware attack on Yuba County involved a sophisticated sequence beginning with Kerberos issues in the Active Directory, suggesting a Golden Ticket attack, allowing attackers to impersonate authentication tokens. The use of Dridex and Cobalt Strike as part of the attack vector reflects a broader cybersecurity threat where well-known malware and penetration testing tools are utilized to gain access and deploy ransomware efficiently across networks. Such attacks are complex, often multi-stage, and curated to exploit specific vulnerabilities in IT infrastructures .

Successfully recovering without paying the ransom had significant economic implications for Yuba County. It avoided costs potentially reaching hundreds of thousands to millions of dollars, preserving financial resources for other essential public services. The implemented Rubrik solution not only ensured data recovery but also contributed to long-term financial savings through reduced administrative costs and improved productivity, evidenced by a 90% decrease in backup management time. These factors cumulatively bolster the county's economic resilience and resource allocation efficiency, underscoring the financial benefits of robust cybersecurity measures .

You might also like