SA companies, including banks, have fallen prey to a global cyber attack on Microsoft’s e-mail exchange server system, which has allegedly been orchestrated by Chinese hackers.
The attacks have sent governments across the world into a crisis mode, with the US government announcing last week that it had established an emergency task force, involving the FBI, to investigate the attack.
Three weeks ago the US’s Cyber Security and Infrastructure Security Agency issued a global alert for all companies using the Microsoft exchange e-mail server to investigate whether they had been hacked.
The attacks, which began in January but which were only detected in March, have seen hackers exploiting system design vulnerabilities in Microsoft’s e-mail exchange server which thousands of businesses around the world use.

According to a study by Comparitech, which was released on Wednesday and which looked at various cyber security factors including malware infection rates, phishing attacks, spam e-mails, cyber attack preparedness and cyber security legislation, SA ranked 24 out 75 countries.
The most cyber secure country is Denmark and the least cyber security conscious country is Tajikistan.
SA, according to the report, has experienced a dramatic increase in malware attacks on computers within the country.
SA cyber security experts say that though Microsoft has created a patch to repair the vulnerabilities, the time frame in which it took to detect and then fix the security issues has allowed the hackers to plant “backdoors” on hundreds of thousands of businesses computer servers.
The hackers later use these backdoors to access sensitive company information.

SA cyber forensic expert Jacques van Heerden said a client, who worked within the banking industry, had been compromised.
Declining to name the client because of confidentiality clauses, he said a backdoor had been found on the businesses computer server.
“From the speed at which the attacks are happening, it’s estimated that at least 30,000 businesses are being attacked by these hackers every hour. In the US at least 600,000 businesses have been attacked.
“This is a global crisis.”
He said the vulnerabilities allowed hackers access to plant codes on companies’ IT servers, which they could use to steal sensitive information
“Even if a company patches the vulnerability, it is no guarantee that the problem is solved as hackers could have created backdoors on the their target’s IT server. These backdoors will not be known about unless they investigate as to whether their server has actually been compromised.”
Van Heerden said the attack had been incredibly focused, with the hackers mainly targeting governments, banks and electrical, defence and pharmaceutical companies.
“What is known through investigations is that the attack originated from China.”

Danny Myburgh, Cyanre, the Digital Forensics Lab’s MD, said the hack was serious.
“The potential for thousands of SA businesses to be affected is huge. Two of our clients have been affected, one of them badly,” he said, declining to identify them.
He said there were four vulnerabilities within the Microsoft e-mail exchange server system, which individually and collectively are exploitable by hackers.
“If hackers exploit them collectively they can wreak major havoc on a business, including being able to steal sensitive data and change businesses banking details.”
He said despite patches being created to fix the vulnerabilities within the system, if businesses did not take certain remedial steps before installing the patches the vulnerabilities would still exist.
Myburgh said despite Microsoft making patches, the threat to businesses was still very real, especially in SA where few people and businesses seem to be aware of the danger.
He said figures from the Dimension Data 2019 global threat intelligence report showed that known vulnerabilities between 2016 and 2018 grew from 6,447 to 16,555.
“Alarmingly, the report also shows that the time businesses take to install patches for critical vulnerabilities is 129 days, while businesses took up to 195 days to install patches for high vulnerabilities.”

Prof Basie von Solms, the University of Johannesburg’s cyber security centre director, said while companies were helpless with regards to stopping vulnerabilities from developing and hackers exploiting them, many SA businesses were sloppy about applying patches to protect themselves against hackers.
“Regarding cyber security, the country faces major problems. SA is third in the world when it comes to the number of cyber crime victims. SA is one of the worst cyber insecure countries in the world.
“This is because of SA’s naiveté with regards to cyber security awareness. It is not only the man in the street who is so vulnerable, but also companies. SA’s companies are just not aware of cyber security risks that they face, which is what makes this Microsoft attack so bad for the country.”
SA information regulator adv Pansy Tlakula said while aware of the vulnerabilities of the Microsoft e-mail exchange server, the company had not yet reported it to the regulator.
“If the Microsoft e-mail exchange server was indeed compromised, such a breach would be considered as a material data breach due to the number of e-mail transactions that occur on the Microsoft e-mail exchange server.
“Not only the banking industry’s personal information would be susceptible to a security compromise, but multiple industries that make use of Microsoft e-mail services would be affected.”
She said SA businesses were becoming increasingly susceptible to cyber attacks.
“This is supported by the widely reported data breaches that have occurred at various companies including Experian.
“Even though adequate safeguards are put in place, security compromises can still occur through physical attacks or a compromise of hard copy files which are not adequately safeguarded.”






Would you like to comment on this article?
Sign up (it's quick and free) or sign in now.
Please read our Comment Policy before commenting.