Businesses around the world scrambled on Saturday to prepare for a renewed cyber attack, convinced that a lull in a computer offensive that has stopped car factories, hospitals, schools and other organizations in around 100 countries was only temporary.
The pace of the attack by a destructive virus dubbed WannaCry slowed late on Friday, after the so-called "ransomware" locked up more than 100,000 computers, demanding owners pay to $300 to $600 get their data back.
"It's paused but it's going to happen again. We absolutely anticipate that this will come back," said Patrick McBride, an executive with cyber-security firm Claroty.
Symantec predicted infections so far would cost tens of millions of dollars, mostly from cleaning corporate networks. Ransoms paid so far amount to only tens of thousands of dollars, one analyst said, but he predicted they would rise.
Companies rushed to protect Windows systems with patches that Microsoft released last month and on Friday. WannaCry exploited a vulnerability to spread itself across networks, a rare and powerful feature that caused infections to surge on Friday.
Code for exploiting that bug, which is known as "Eternal Blue," was released on the internet in March by a hacking group known as the Shadow Brokers. The group claimed it was stolen from a repository of National Security Agency hacking tools. The agency has not responded to requests for comment.
The identity of the Shadow Brokers is not known, though many security researchers say they believe they are in Russia, which is a major source of ransomware and was one of the countries hit first and hardest by WannaCry.
Cyber security experts, who have been on watch for months for an "Eternal Blue"-based attack, said on Saturday that they expect the computer code to be used in types of cyber attacks beyond extortion campaigns, including efforts to seize control of networks and steal data.
Governments and private security firms on Saturday that they expect hackers to tweak the malicious code used in Friday's attack, restoring the ability to self-replicate. Those expectations prompted businesses to call in technicians to work over the weekend to make sure networks were protected with security updates needed to thwart Eternal Blue.
"It's all hands on deck," said Shane Shook, an independent security consultant whose customers include large corporations and governments.
Guillaume Poupard, head of France’s national cyber security agency, told Reuters he is concerned infections could surge again on Monday, when workers return to the office and turn on computers.
The U.S. government on Saturday issued a technical alert with advice on how to protect against the attacks, asking victims to report attacks to the Federal Bureau of Investigation or Department of Homeland Security.
RENAULT HALTS PRODUCTION
Security software maker Avast said it had observed 126,534 ransomware infections in 99 countries, with Russia, Ukraine and Taiwan the top targets.
Security experts said that they were not sure how many victims would pay the ransoms, or if access to computers was being restored after such payments.
Elliptic, a private security firm that investigates ransomware attacks, said that only about $32,000 had been sent to bitcoin addresses listed by the extortionists in ransom demands that flashed on screens of infected computers.
"We expect this number to increase significantly over the course of the weekend," said Tom Robinson, lead investigator at Elliptic.
That is far below what it is likely to cost companies to recover from such attacks.
Symantec researcher Vikram Thakur said that total repair costs are likely to be in the tens of millions of dollars.
"The expensive part is the clean up of the machine and restoring the encrypted data," he said.
Still, such figures do not account for lost production at firms like Renault, which on Saturday said it had halted stopped manufacturing at plants in Sandouville, France and Romania to prevent the spread of ransomware in its systems.
Among the other victims is a Nissan manufacturing plant in Sunderland, northeast England, though a spokesman said "there has been no major impact on our business."
Hundreds of hospitals and clinics in the British National Health Service were infected on Friday, forcing them to send patients to other facilities. On Saturday, Interior Minister Amber Rudd said that 97 percent of the nation's health service trusts were "working as normal."
German rail operator Deutsche Bahn said some electronic signs at stations announcing arrivals and departures were infected.
In Asia, some hospitals, schools, universities and other institutions were affected, though the full extent of the damage is not yet known due to the weekend.
International shipper FedEx Corp said some of its Windows computers were also breached. "We are implementing remediation steps as quickly as possible," a FedEx statement said.
Telecommunications company Telefonica was among many targets in Spain. Portugal Telecom and Telefonica Argentina both said they were also targeted.
Europol's European Cybercrime Centre said it was working closely with national law enforcement agencies and private security firms to combat the threat and help victims.
"The recent attack is at an unprecedented level and will require a complex international investigation to identify the culprits," it said in a statement.
Some experts said the threat had receded in part because a British-based researcher, who declined to give his name, registered a domain that he noticed the malware was trying to connect to, and so limited the worm's spread.
Finance chiefs from the Group of Seven rich countries were to commit on Saturday to joining forces to fight the growing threat of international cyber attacks, according to a draft statement of a meeting they are holding in Italy.
"Appropriate economy-wide policy responses are needed," the ministers said in their draft statement, seen by Reuters.
Reuters
Sun May 14 2017
Ambulances are parked at The Royal London Hospital in London, Britain May 13, 2017. REUTERS/Neil Hall
Pro-Palestinian NGOs seek court order to stop Dutch arms exports to Israel
The Dutch state, as a signatory to the 1948 Genocide Convention, has a duty to take all reasonable measures at its disposal to prevent genocide.
How quickly can Trump's Musk-led efficiency panel slash US regulations?
Moves by Trump and his appointees to eliminate existing rules will be met with legal challenges, as many progressive groups and Democratic officials have made clear.
2TM: Consultations on PTPTN loans, admission to IPTA at MOHE booth
Consultations on PTPTN loans and admission to IPTA are among services provided at the Higher Education Ministry booth.
Kampung Tanjung Kala residents affected by flooded bridge every time it rains heavily
Almost 200 residents from 60 homes in Kampung Tanjung Kala have ended up stuck when their 200-metre (m) long concrete bridge flooded.
COP29 climate summit draft proposes rich countries pay $250 billion per year
The draft finance deal criticised by both developed and developing nations.
Bomb squad sent to London's Gatwick Airport after terminal evacuation
This was following the discovery of a suspected prohibited item in luggage.
Kelantan urges caution amidst northeast monsoon rains
Kelantan has reminded the public in the state to refrain from outdoor activities with the arrival of the Northeast Monsoon season.
Former New Zealand PM Jacinda Ardern receives UN leadership award
Former New Zealand prime minister Jacinda Ardern was given a global leadership award by the United Nations Foundation.
ICC'S arrest warrants for Netanyahu, Gallant an apt decision - PM
The decision of the ICC to issue arrest warrants against Benjamin Netanyahu and Yoav Gallant is apt, said Datuk Seri Anwar Ibrahim.
KTMB provides two additional ETS trains for Christmas, school holidays
KTMB will provide two additional ETS trains for the KL Sentral-Padang Besar route and return trips in conjunction with the holidays.
BNM'S international reserves rise to USD118 bil as at Nov 15, 2024
Malaysia's international reserves rose to US$118.0 billion as at Nov 15, 2024, up from US$117.6 billion on Oct 30, 2024.
Findings by dark energy researchers back Einstein's conception of gravity
The findings announced are part of a years-long study of the history of the cosmos focusing upon dark energy.
NRES responds to Rimbawatch press release on COP29
The Ministry of Natural Resources and Environmental Sustainability (NRES) wishes to offer the following clarifications to the issues raised.
Online Safety Bill and Anti-Cyberbullying Laws must carefully balance rights and protections
The Online Safety Advocacy Group (OSAG) stands united with people in Malaysia in the fight against serious online harms.
Malaysia's inflation at 1.9 pct in Oct 2024 - DOSM
Malaysia's inflation rate for October 2024 has increased to 1.9 per cent, up from 1.8 per cent in September this year.
Saudi Arabia showcases Vision 2030 goals at Airshow China 2024
For the first time, Saudi Arabia is participating in the China International Aviation & Aerospace Exhibition held recently in Zhuhai.
King Charles' coronation cost GBP 71mil, govt accounts show
The coronation of Britain's King Charles cost taxpayers GBP72 million (US$90 million), official accounts have revealed.
Couple and associate charged with trafficking 51.9 kg of meth
A married couple and a man were charged in the Magistrate's Court here today with trafficking 51.974 kilogrammes of Methamphetamine.
PDRM to consult AGC in completing Teoh Beng Hock investigation
The police may seek new testimony from existing witnesses for additional insights into the investigation of Teoh Beng Hock's death.
Thai court rejects petition over ex-PM Thaksin's political influence
Thailand's Constitutional Court rejects a petition seeking to stop Thaksin Shinawatra from interfering in the running the Pheu Thai party.