Malicious actors trying to exploit global tech outage for their own gain

Advertisement

Advertise with us

As the world continues to recover from massive business and travel disruptions caused by a faulty software update from cybersecurity firm CrowdStrike, malicious actors are trying to exploit the situation for their own gain.

Read this article for free:


or

Already have an account? Log in here »

To continue reading, please subscribe:

Subscribe and receive a limited-edition Free Press branded hat or tote.

Digital Subscription

One year of digital access for only $205*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles

*First annual payment billed as $205.00 + GST for one year. This annual subscription will automatically renew at $233.00 + GST every 52 weeks (10% off the regular annual price of $259.35). Offer available to new and qualified returning subscribers only. Cancel any time.

To continue reading, please subscribe:

Add Free Press access to your Brandon Sun subscription for only an additional

$1 for the first 4 weeks*

  • Enjoy unlimited reading on winnipegfreepress.com
  • Read the E-Edition, our digital replica newspaper
  • Access News Break, our award-winning app
  • Play interactive puzzles
Start now

*Your next Brandon Sun subscription payment will increase by $1.00 and you will be charged $17.95 plus GST for four weeks. After four weeks, your payment will increase to $24.95 plus GST every four weeks.

Hey there, time traveller!
This article was published 20/07/2024 (785 days ago), so information in it may no longer be current.

As the world continues to recover from massive business and travel disruptions caused by a faulty software update from cybersecurity firm CrowdStrike, malicious actors are trying to exploit the situation for their own gain.

Government cybersecurity agencies across the globe and CrowdStrike CEO George Kurtz are warning businesses and individuals about new phishing schemes that involve malicious actors posing as CrowdStrike employees or other tech specialists offering to assist those recovering from the outage.

“We know that adversaries and bad actors will try to exploit events like this,” Kurtz said in a statement. “I encourage everyone to remain vigilant and ensure that you’re engaging with official CrowdStrike representatives.”

Retired IT Technician William Taylor lines up to purchase a four-day train ride ticket to Jackson, Mississippi, at Union Station in Los Angeles, Friday, July 19, 2024, as a widespread Microsoft outage disrupted flights, banks, media outlets, and companies worldwide. (AP Photo/Damian Dovarganes)
Retired IT Technician William Taylor lines up to purchase a four-day train ride ticket to Jackson, Mississippi, at Union Station in Los Angeles, Friday, July 19, 2024, as a widespread Microsoft outage disrupted flights, banks, media outlets, and companies worldwide. (AP Photo/Damian Dovarganes)

The UK Cyber Security Center said they have noticed an increase in phishing attempts around this event.

Microsoft said 8.5 million devices running its Windows operating system were affected by the faulty cybersecurity update Friday that led to worldwide disruptions. That’s less than 1% of all Windows-based machines, Microsoft cybersecurity executive David Weston said in a blog post on Saturday.

He also said such a significant disturbance is rare but “demonstrates the interconnected nature of our broad ecosystem.”

What’s happening with air travel?

With their tightly timed, interwoven schedules and complex technology systems, many big airlines struggle to stay on time when everything goes well. It perhaps was not surprising that the industry was among the hardest hit by the outage, with crews and planes caught out of position.

By mid-afternoon Saturday on the U.S. East Coast, airlines around the world had canceled more than 2,000 flights, according to tracking service FlightAware. That was down from 5,100-plus cancellations on Friday.

About 1,600 of Saturday’s canceled flights occurred in the United States, where carriers scrambled to get planes and crews back into position after massive disruptions the day before. According to travel data provider Cirium, U.S. carriers canceled about 3.5% of their scheduled flights for Saturday. Only Australia was hit harder.

Canceled flights were running at about 1% in the United Kingdom, France and Brazil and about 2% in Canada, Italy and India among major air-travel markets.

Robert Mann, a former airline executive and now a consultant in the New York area, said it was unclear exactly why U.S. airlines were suffering disproportionate cancellations, but possible causes include a greater degree of outsourcing of technology and more exposure to Microsoft operating systems that received the faulty upgrade from CrowdStrike.

Which airlines are getting hit the hardest?

Delta Air Lines canceled more than 800 flights, or one-fourth of its schedule for Saturday, and that number did not include Delta Connection regional flights. It was followed by United Airlines, which dropped nearly 400 flights.

The worst airport to be, for a second straight day, was Hartsfield–Jackson Atlanta International Airport, where Delta is the dominant carrier. The Atlanta Journal-Constitution reported that thousands of people spent the night at the airport, many sleeping on the floors.

European airlines and airports appeared to be recovering slowly, although Lufthansa and its affiliates canceled dozens of flights. Its Eurowings budget subsidiary said check-in, boarding, booking and rebooking flights were all available again, although “isolated disruptions” were possible.

London’s Heathrow Airport said it was busy but operating normally on Saturday and that “all systems are back up and running.” Flights at Berlin’s main airport were departing on or close to schedule, German Press Agency dpa reported, citing an airport spokesman.

How are healthcare systems holding up?

Health care systems affected by the outage faced clinic closures, canceled surgeries and appointments and restricted access to patient records.

Cedars-Sinai Medical Center in Los Angeles, Calif., said “steady progress has been made” to bring its servers back online and thanked its patients for being flexible during the crisis.

“Our teams will be working actively through the weekend as we continue to resolve remaining issues in preparation for the start of the work week,” the hospital wrote in a statement.

In Austria, a leading organization of doctors said the outage exposed the vulnerability of relying on digital systems. Harald Mayer, vice president of the Austrian Chamber of Doctors, said the outage showed that hospitals need analog backups to protect patient care.

Planes line up at gates at Chicago O'Hare International Airport, in Chicago, Friday, July 19, 2024. Transport providers, businesses and governments are rushing to get all their systems back online after long disruptions following a widespread technology outage. (AP Photo/Carolyn Kaster)
Planes line up at gates at Chicago O'Hare International Airport, in Chicago, Friday, July 19, 2024. Transport providers, businesses and governments are rushing to get all their systems back online after long disruptions following a widespread technology outage. (AP Photo/Carolyn Kaster)

The organization also called on governments to impose high standards in patient data protection and security, and on health providers to train staff and put systems in place to manage crises.

“Happily, where there were problems, these were kept small and short-lived and many areas of care were unaffected” in Austria, Mayer said.

The Schleswig-Holstein University Hospital in northern Germany, which canceled all elective procedures Friday, said Saturday that systems were gradually being restored and that elective surgery could resume by Monday.

Will the tech industry face a reckoning?

“I wasn’t that surprised that an accident caused severe global digital disruption. I was a little surprised that the cause of it was a software update from a very well-respected cybersecurity company,” said Oxford University management professor Ciaran Martin, a former chief executive of the U.K.’s National Cyber Security Center.

“There are some very hard questions for CrowdStrike. How on earth did this update get through quality control?” he said. “Clearly the testing regime, whatever it is, failed.”

Martin said governments in the U.K. and the European Union will be powerless to take steps to prevent such breakdowns “because we have become dependent on a very American version of technology, and the power to do anything about that doesn’t rest in this continent.”

Other analysts doubted that the outage would lead Washington or any other government to propose new mandates on tech companies.

“I don’t know what the mandate would be. Do better QA?” said Gartner analyst Eric Grenier, using an acronym for quality assurance.

What did scam artists learn from the outage?

Grenier expects that a majority of affected machines will be fixed in about a week, with more time needed to reach laptops used by far-flung workers because the work can’t be done remotely – it’s a hands-on operation.

In the meantime, there will be scammers trying to take advantage of businesses that have indicated they were affected by the outage.

“The threat is very real,” Grenier said. “Bad actors have the information to send targeted phishing emails and calls. They know what endpoint-protection tools you use. They know you use CrowdStrike.”

Grenier said affected businesses need to make sure they use a fix supplied by CrowdStrike. “Don’t accept the help of somebody coming out of the blue and saying, ‘I’ll fix that for you,’” he said.

___

Isabella O’Malley in Philadelphia, Stephen Graham in Berlin and Technology writer Matt O’Brien contributed to this report.

Report Error Submit a Tip

More Stories

A life's story: ‘Ivor the Driver’ found his calling in the ranching life

Aaron Epp 7 minute read Preview

A life's story: ‘Ivor the Driver’ found his calling in the ranching life

Aaron Epp 7 minute read Updated: 9:59 AM CDT

Ivor Asham’s family couldn’t have picked a better image to accompany his obituary. There he is, riding Flash, his beloved brown and white quarter horse, a black cowboy hat on his head and a drink in his hand.

Asham owned and operated Birds Hill Park Ranch for nearly 35 years, where he shared his lifelong passion for horses with thousands of visitors. He moved hay, harnessed horses and drove the wagons, introducing himself as “Ivor the Driver.”

Over the years, Asham built a reputation as the quintessential cowboy.

There’s a restaurant at the ranch filled with memorabilia that he collected over the years. Calgary Stampede posters, cowboy boot-shaped shot glasses, a child’s rocking horse, a wagon wheel and numerous photos of legendary actor John Wayne are just some of the items that line the walls.

Read
Updated: 9:59 AM CDT

Police are investigating after a child was struck by a vehicle in a Walmart parking lot on Kenaston Boulevard Friday evening.

At 9 p.m. officers from the Winnipeg Police Service traffic division attended to a motor vehicle-pedestrian collision in the 1600 block of Kenaston, police said Saturday.

A school-aged child was taken to hospital in unstable condition, police said, but the child was later upgraded to stable condition.

Police said the child sustained minor injuries and an investigation is ongoing.

Closure of Nomads field massive upset for North End

Joshua Frey-Sam 5 minute read Preview

Closure of Nomads field massive upset for North End

Joshua Frey-Sam 5 minute read Updated: Yesterday at 8:49 AM CDT

The North Winnipeg Nomads have a flag on the field.

The long-standing minor football club was recently informed that its field is unfit to host games and that it would need to find a new home for its five youth and adult teams until repairs are made to the playing surface.

“Our board has made every effort to address the condition of our home field,” the club wrote in a statement. “Unfortunately, following a professional assessment, the field has been determined to be unsafe and unstable for our athletes.”

All five of the club’s teams will play their 2026 season at Frank Whyte Field, part of the Northwood Community Centre, with no confirmed date for when they can play on their home field again.

Read
Updated: Yesterday at 8:49 AM CDT

Highway-safety upgrades in progress after tragic Interlake crash

Chris Kitching 5 minute read Preview

Highway-safety upgrades in progress after tragic Interlake crash

Chris Kitching 5 minute read Updated: Yesterday at 6:25 PM CDT

Provincial workers have started to update or install safety measures at a rural Interlake intersection where four teenage friends died in a crash on Labour Day weekend.

Pavement markings were repainted at Highway 8 and Provincial Road 229, just west of Winnipeg Beach, ahead of work to refresh worn-down rumble strips, starting Monday, and install flashing lights atop two stop signs, following an assessment earlier this week.

“They will also need to incorporate any information from the RCMP report that might be helpful if we were to consider any additional safety measures at this intersection,” Transportation and Infrastructure Minister Lisa Naylor said of department staff.

“The most important thing is safety, and any kinds of changes we make at any intersection actually have to make it safer.”

Read
Updated: Yesterday at 6:25 PM CDT

Artist’s inspired work brings Red River Métis story back to Portage and Main

Conrad Sweatman 8 minute read Preview

Artist’s inspired work brings Red River Métis story back to Portage and Main

Conrad Sweatman 8 minute read Updated: Yesterday at 2:47 PM CDT

Jennine Krauchi calls them the “grandmothers.” “They speak to you very silently. You never hear a word, but they speak,” Krauchi says, referring to the antique pieces of Métis needlework she’s carefully studied for years. But there are few precedents for her latest art project: a 85-foot-wide by 32-foot-high chain curtain of Métis needlework that drapes over the historic Bank of Montreal’s neoclassical facade.

Read
Updated: Yesterday at 2:47 PM CDT

Is Trump about to poke Quebec’s political beehive?

Peter McKenna 6 minute read Preview

Is Trump about to poke Quebec’s political beehive?

Peter McKenna 6 minute read 2:00 AM CDT

When was the last time that a U.S. president seriously stirred the hornet’s nest of Quebec politics?

My best recollection is former U.S. president Bill Clinton. During the 1994 Quebec referendum campaign, Clinton made clear that the U.S. wholly endorsed a united and strong federal Canada — as opposed to a dismembered one. He went on to add that an independent Quebec would have no guarantee of joining the North American Free Trade Agreement as a full-fledged member.

Today, we see U.S. President Donald Trump inserting himself — unwittingly or wittingly — into the electoral and sovereignty politics of Quebec. It’s pretty clear that the resurgent Coalition Avenir Québec government is trying to make the Oct. 5 provincial election about anything other than its own governmental record and more about Trump’s economic coercion against Canada. Of course, the Parti Québécois, the odds-on-favourite, wants to make the electoral contest a referendum on the CAQ and its party leader, Christine Fréchette.

But what if Trump really wanted to make his presence felt in Quebec’s political life? How much influence could he have on shaping political outcomes in Quebec? How much of an “X factor” could he be?

Read
2:00 AM CDT