Hacker News new | ask | show | jobs
by jruohonen 887 days ago
"One of Tietoevry’s several datacenters in Sweden has become partially subject to a ransomware attack."

Sounds bad.

2 comments

Yeah. From what I know at least Filmstaden (Swedens biggest cinema chain, owned by AMC) can’t sell a thing right now. No tickets can be sold at all, and no snacks can be sold at the cinema either :(

Rusta is another affected store chain. I guess there is a lot more affected customers unknown to the public right now

In a meeting right now, team lead just recounted how she'd had to pay in cash at Rusta (ESpoo, I assume) yesterday or the other day because card payment wasn't working. "I was lucky to happen to have cash on me, others turned around and left."
Granngården is another.
Yeah, and parts of Vellinge Kommun as well. Apparently a lot of their day-to-day-systems are affected [0].

Also, a HR system called primula is affected. It is mostly used by universities from what I can gather.

[0] = https://www.dn.se/sverige/it-attacken-paverkar-myndigheter-o... (Swedish, one of the biggest newspaper in Sweden)

lol yeah. Primula is affected. So no one can apply for vacation, business travel, reimbursement, or even parental leave.

Time to work work work work..

It only affecting one datacenter is good news, IMO:

It makes it likely that the attackers didn't breach Tietoevry itself, or that they had only very limited access (unless Tietoevry has incredibly good separation between business units, so that only a small subset is affected).

That increases the chance that the customers have to deal with an outage, not an outage followed by ransom demands and their customer data being leaked.

They obviously had no separation at all between customers within the DC though. Which is worrying.
At the moment word is that attackers encrypted Tietoevrys hypervisor platform (Hyper-V, vSphere or KVM not known) which was hosting multiple customers VMs. So attackers breached Tietoevrys management network, not customer networks.
TietoEvry do the same in Norway, where accounts are prefixed with customer name.