Looking beyond the great Blue Yonder ransomware attack

According to a Sophos report into the state of ransomware in the retail sector this year, compromised credentials were the biggest root cause of attacks in the UK. And 33% of incidents were pinned on poor passwords.

Globally, Sophos found that it took 28% of ransomware-impacted retailers more than a month to recover from such an incident. And that 39% of those organisations now require their suppliers to have some form of cyber insurance policy in place.

Why am I throwing these statistics at you? Because retailers are firmly in the crosshairs once again, with the fallout from the Blue Yonder ransomware attack.

“While the full impact of this particular attack remains unclear,โ€ the Sophos Director of Incident Response, Peter Mackenzie, said, โ€œaffected customers often have limited options while awaiting remediation.โ€

And remediation appears to be taking some time. Blue Yonder, which provides an AI-powered platform providing everything from fulfillment to logistics help, fell victim to ransomware on 21 November. The last time it updated the company cybersecurity incident page was four days ago, 24 November, when it stated: โ€œThere are no additional updates to share at this time with regard to our restoration timeline.โ€

Well, Iโ€™m sure its customers will be pleased to hear that. Customers such as Starbucks in the US, which told me that while serving coffee from the counter has not been impacted, the same canโ€™t be said of the back office systems.

Jaci Anderson, Starbucks’ Director of Corporate Communications, didnโ€™t want to be quoted directly but confirmed that the incident had disrupted a back-end Starbucks process that enables the employee hours platform. This allows employees to view and manage their schedules and track hours worked. Starbucks also said that all employees had been fully paid and anticipated that Thanksgiving holiday weekend pay wouldnโ€™t be impacted.

Blue Yonder: a supply chain ransomware attack?

“We’ve reached a point where a lot of companies outsource functions like payroll, HR forms, etc to service providers,โ€ said Michael Smith, CTO at Vercara.

โ€œWhile we should have service level agreements, they are applied after the service interruption and are not a preventative measure.โ€

And thatโ€™s partly the problem here, a reliance upon reactive rather than proactive security along the supply chain. A couple of years ago, maybe more, ransomware gangs realised that primary targets were reasonably well defended, so they switched to the supply chain, to service providers.

That’s โ€œbecause service providers have multiple customers,โ€ Smith explained, โ€œand a ransomware incident penalises them with SLAs, they are more likely to pay a ransom.”

Paul Caron, Head of Cyber Security, Americas, at global intelligence firm S-RM, takes issue with calling this a supply chain attack, however.

โ€œThe Blue Yonder incident attack should not be confused with the type of cyberattack called a ‘supply chain attack’, which is a means to access vendorsโ€™ networks of their clients,โ€ he said.

And heโ€™s right, in the sense that the attackers donโ€™t appear to have been after lateral movement towards customer data breaches. But he’s also wrong, in that it is definitely an attack against a provider in the supply chain. The details are semantics in the end.

I wonโ€™t argue with Caron when he says that companies should โ€œroutinely test the organisational operating procedures for when third-party services become unavailable,โ€ as that, dear reader, is just common security sense. What a shame so many companies donโ€™t seem to possess it.

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.