According to a Sophos report into the state of ransomware in the retail sector this year, compromised credentials were the biggest root cause of attacks in the UK. And 33% of incidents were pinned on poor passwords.
Globally, Sophos found that it took 28% of ransomware-impacted retailers more than a month to recover from such an incident. And that 39% of those organisations now require their suppliers to have some form of cyber insurance policy in place.
Why am I throwing these statistics at you? Because retailers are firmly in the crosshairs once again, with the fallout from the Blue Yonder ransomware attack.
“While the full impact of this particular attack remains unclear,โ the Sophos Director of Incident Response, Peter Mackenzie, said, โaffected customers often have limited options while awaiting remediation.โ
And remediation appears to be taking some time. Blue Yonder, which provides an AI-powered platform providing everything from fulfillment to logistics help, fell victim to ransomware on 21 November. The last time it updated the company cybersecurity incident page was four days ago, 24 November, when it stated: โThere are no additional updates to share at this time with regard to our restoration timeline.โ
Well, Iโm sure its customers will be pleased to hear that. Customers such as Starbucks in the US, which told me that while serving coffee from the counter has not been impacted, the same canโt be said of the back office systems.
Jaci Anderson, Starbucks’ Director of Corporate Communications, didnโt want to be quoted directly but confirmed that the incident had disrupted a back-end Starbucks process that enables the employee hours platform. This allows employees to view and manage their schedules and track hours worked. Starbucks also said that all employees had been fully paid and anticipated that Thanksgiving holiday weekend pay wouldnโt be impacted.
Blue Yonder: a supply chain ransomware attack?
“We’ve reached a point where a lot of companies outsource functions like payroll, HR forms, etc to service providers,โ said Michael Smith, CTO at Vercara.
โWhile we should have service level agreements, they are applied after the service interruption and are not a preventative measure.โ
And thatโs partly the problem here, a reliance upon reactive rather than proactive security along the supply chain. A couple of years ago, maybe more, ransomware gangs realised that primary targets were reasonably well defended, so they switched to the supply chain, to service providers.
That’s โbecause service providers have multiple customers,โ Smith explained, โand a ransomware incident penalises them with SLAs, they are more likely to pay a ransom.”
Paul Caron, Head of Cyber Security, Americas, at global intelligence firm S-RM, takes issue with calling this a supply chain attack, however.
โThe Blue Yonder incident attack should not be confused with the type of cyberattack called a ‘supply chain attack’, which is a means to access vendorsโ networks of their clients,โ he said.
And heโs right, in the sense that the attackers donโt appear to have been after lateral movement towards customer data breaches. But he’s also wrong, in that it is definitely an attack against a provider in the supply chain. The details are semantics in the end.
I wonโt argue with Caron when he says that companies should โroutinely test the organisational operating procedures for when third-party services become unavailable,โ as that, dear reader, is just common security sense. What a shame so many companies donโt seem to possess it.
Related supply chain articles