ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah

    Scheduled Pinned Locked Moved IT Discussion
    mspransomwaresecuritybreach
    111 Posts 21 Posters 14.3k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • 1
      1337 @scottalanmiller
      last edited by 1337

      @scottalanmiller I've seen entire LANs hit by ransomware and it's tough getting it back up because everything is either down by the ransomware or by choice (to avoid it getting worse).

      So your machine will not get an IP address because DHCP is down, you can't log in because AD is down, you can't access backups even if you have them because of the above and DNS is down. And often firewalls and WAN links have been shut down as well. PBX will be down, O365 can't be accessed. Where did we put the emergency plan?

      There are a lot of interdependencies among services that you don't always realize until you have to. So you have to start slowly and unravel everything from one end to the other. It takes A LOT of time.
      For one enterprise I know of it took months and the cost was billions.

      1 Reply Last reply Reply Quote 1
      • P
        proteksupport
        last edited by

        @scottalanmiller said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

        So we heard from customers of Protek Support in Salt Lake City that the MSP has been hit with ransomware that has gone on to hit all of their clients as well. From what we understand, they are currently on four days of customers being without their files and they aren't cleaning them up yet. We would suspect that their internal systems have been hit and they are tied up dealing with that.

        I don't know where you got such information from, but this is simply not true.

        DustinB3403D 1 scottalanmillerS 3 Replies Last reply Reply Quote 0
        • DustinB3403D
          DustinB3403 @proteksupport
          last edited by

          @proteksupport said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

          I don't know where you got such information from, but this is simply not true.

          That's easy to say without having any proof to back it up. Are you secretly Donald Trump?

          Also welcome to the community

          P 1 Reply Last reply Reply Quote 1
          • P
            proteksupport @DustinB3403
            last edited by

            This post is deleted!
            1 Reply Last reply Reply Quote 0
            • 1
              1337 @proteksupport
              last edited by

              @proteksupport said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

              @scottalanmiller said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

              So we heard from customers of Protek Support in Salt Lake City that the MSP has been hit with ransomware that has gone on to hit all of their clients as well. From what we understand, they are currently on four days of customers being without their files and they aren't cleaning them up yet. We would suspect that their internal systems have been hit and they are tied up dealing with that.

              I don't know where you got such information from, but this is simply not true.

              Threads need to be deleted asap. Or company info scrubbed. No need to have the name of the company in the thread actually in either case.

              scottalanmillerS 1 Reply Last reply Reply Quote 1
              • scottalanmillerS
                scottalanmiller @proteksupport
                last edited by

                @proteksupport said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                @scottalanmiller said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                So we heard from customers of Protek Support in Salt Lake City that the MSP has been hit with ransomware that has gone on to hit all of their clients as well. From what we understand, they are currently on four days of customers being without their files and they aren't cleaning them up yet. We would suspect that their internal systems have been hit and they are tied up dealing with that.

                I don't know where you got such information from, but this is simply not true.

                Are you actively cleaning up some customers but not all? Whats the status?

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @1337
                  last edited by

                  @Pete-S said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                  @proteksupport said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                  @scottalanmiller said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                  So we heard from customers of Protek Support in Salt Lake City that the MSP has been hit with ransomware that has gone on to hit all of their clients as well. From what we understand, they are currently on four days of customers being without their files and they aren't cleaning them up yet. We would suspect that their internal systems have been hit and they are tied up dealing with that.

                  I don't know where you got such information from, but this is simply not true.

                  Threads need to be deleted asap. Or company info scrubbed. No need to have the name of the company in the thread actually in either case.

                  Actually its very important so that customers can discuss the issue together so that they are aware that they are not alone.

                  1 Reply Last reply Reply Quote 1
                  • DustinB3403D
                    DustinB3403
                    last edited by

                    @proteksupport now is your chance to clear things up. Otherwise we have to assume the information posted in the OP at least as some basis in truth.

                    If a customer refused to have DR and backup services, literally nothing else needs to be said than "this was due to a customer decision".

                    If it's all false that's just as fine as well, but then we'd have to wonder why @scottalanmiller is supposedly being contacted with this claim.

                    @scottalanmiller are you able to shed any light on who the customer may be or otherwise help unfold this story?

                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                    • EddieJenningsE
                      EddieJennings @RojoLoco
                      last edited by

                      @RojoLoco said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                      @Reid-Cooper I would NEVER hire or even consider an MSP that paid a ransom. That means they are incapable or unwilling to make and test backups, so that's a hard no.

                      I've seen a situation where the ransomware ate most of the backups.

                      DustinB3403D scottalanmillerS RojoLocoR 3 Replies Last reply Reply Quote 1
                      • DustinB3403D
                        DustinB3403 @EddieJennings
                        last edited by

                        @EddieJennings said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                        @RojoLoco said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                        @Reid-Cooper I would NEVER hire or even consider an MSP that paid a ransom. That means they are incapable or unwilling to make and test backups, so that's a hard no.

                        I've seen a situation where the ransomware ate most of the backups.

                        Well that would be because their backups weren't actually protected.

                        1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @EddieJennings
                          last edited by

                          @EddieJennings said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                          @RojoLoco said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                          @Reid-Cooper I would NEVER hire or even consider an MSP that paid a ransom. That means they are incapable or unwilling to make and test backups, so that's a hard no.

                          I've seen a situation where the ransomware ate most of the backups.

                          Can happen when not air gapped.

                          1 Reply Last reply Reply Quote 1
                          • pchiodoP
                            pchiodo
                            last edited by pchiodo

                            As with any company, be it Microsoft, IBM, Facebook, Verisign, Whoever.... We do not protect companies when we have credible knowledge of a company's failure, or on the other hand, accomplishments are reported.

                            In this case, we have first hand knowledge as reported by the OP.

                            Just as I reported, along with many major news outlets, Wells Fargo had an outage affecting a large number of their customers and all of their investors. I would not remove their name, nor the post just because they complain.

                            DustinB3403D 1 Reply Last reply Reply Quote 4
                            • DustinB3403D
                              DustinB3403 @pchiodo
                              last edited by

                              @pchiodo said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                              As with any company, be it Microsoft, IBM, Facebook, Verisign, Whoever.... We do not protect companies when we have credible knowledge of a companies failure, or on the other hand, accomplishments are reported.

                              In this case, we have first hand knowledge as reported by the OP.

                              Just as I reported, along with many major news outlets, Wells Fargo had an outage affecting a large number of their customers and all of their investors. I would not remove their name, nor the post just because they complain.

                              TL:DR Shit happens, and when it should be public knowledge it will be public knowledge.

                              1 Reply Last reply Reply Quote 2
                              • dbeatoD
                                dbeato
                                last edited by

                                I think that if it was VPN, still bad practice to have VPN from MSP or any other systems that unprotected. MSPs should not need to have VPN to customers at all.

                                scottalanmillerS DashrenderD 2 Replies Last reply Reply Quote 1
                                • scottalanmillerS
                                  scottalanmiller @dbeato
                                  last edited by

                                  @dbeato said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                  I think that if it was VPN, still bad practice to have VPN from MSP or any other systems that unprotected. MSPs should not need to have VPN to customers at all.

                                  Absolutely. But unless someone has info that I do not, notnreason to assume the MSP here had one.

                                  1 Reply Last reply Reply Quote 1
                                  • DustinB3403D
                                    DustinB3403
                                    last edited by

                                    So I guess we're to assume that the lack of a response from @proteksupport means that something major is occurring with their client(s).

                                    scottalanmillerS 1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller @DustinB3403
                                      last edited by

                                      @DustinB3403 said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                      So I guess we're to assume that the lack of a response from @proteksupport means that something major is occurring with their client(s).

                                      To be fair, this place is fast. They are not likely used to forums moving this quickly.

                                      DustinB3403D 1 Reply Last reply Reply Quote 1
                                      • DustinB3403D
                                        DustinB3403 @scottalanmiller
                                        last edited by

                                        @scottalanmiller said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                        @DustinB3403 said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                        So I guess we're to assume that the lack of a response from @proteksupport means that something major is occurring with their client(s).

                                        To be fair, this place is fast. They are not likely used to forums moving this quickly.

                                        Fast compared to SpiteWorks, sure I suppose.

                                        dbeatoD 1 Reply Last reply Reply Quote 0
                                        • dbeatoD
                                          dbeato @DustinB3403
                                          last edited by

                                          @DustinB3403 said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                          @scottalanmiller said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                          @DustinB3403 said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                          So I guess we're to assume that the lack of a response from @proteksupport means that something major is occurring with their client(s).

                                          To be fair, this place is fast. They are not likely used to forums moving this quickly.

                                          Fast compared to SpiteWorks, sure I suppose.

                                          MMm it depends what you are talking about.

                                          DustinB3403D 1 Reply Last reply Reply Quote 0
                                          • DustinB3403D
                                            DustinB3403 @dbeato
                                            last edited by

                                            @dbeato said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                            @DustinB3403 said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                            @scottalanmiller said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                            @DustinB3403 said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                            So I guess we're to assume that the lack of a response from @proteksupport means that something major is occurring with their client(s).

                                            To be fair, this place is fast. They are not likely used to forums moving this quickly.

                                            Fast compared to SpiteWorks, sure I suppose.

                                            MMm it depends what you are talking about.

                                            Fast response times.

                                            Not so fast deleting comments made by people that SpiteWorks thinks that they can make money off of. 😄

                                            dbeatoD 1 Reply Last reply Reply Quote 0
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 4 / 6
                                            • First post
                                              Last post