Rectron struck by cyberattack

mylesillidge

Journalist
Joined
Jul 29, 2021
Messages
4,151
Reaction score
4,430
Major South African tech distributor hit by cyberattack

South African technology distributor Rectron confirmed that it was affected by a cyberattack in a statement issued on Wednesday, 22 July.

"Rectron regrets to inform you that we have become the latest victim of a cyberattack — an all-too-familiar phenomenon in South Africa and indeed around the world," it said.
 
There's a lot said that isn't said.

"contacted external forensic specialists" - implies they don't havae the complete picture, and these guys will likely be getting logs, identifying attack vectors and persistence mechanisms, assessing what (if anything) was accessed, imaging disks for forensic analysis, etc.

"containment" - implies the attacker had or may still have access, and this will likely involve isolation, resetting credentials, rebuilding AD, etc before systems are brought back online

"recovery" - implies the current dataset is unusable, which suggests ransomware

"notified the Information Regulator of South Africa" - strongly implies that personal information has been compromised, or at least there's a possibility thereof
 
There are other suppliers.
True, and I did try them, but they either did not have the specific component in stock, or were overpriced, so I was forced to patronise the Pakistani mafia to make budget. Rectun should get its house in order.
 
True, and I did try them, but they either did not have the specific component in stock, or were overpriced, so I was forced to patronise the Pakistani mafia to make budget. Rectun should get its house in order.
they not pakistani dude (not with that surname)

You got PC int that side as well and not like i keep physical stock myself but wootware isnt a bad choice eitherway unless you were in a rush in JHB.
 
There's a lot said that isn't said.

"contacted external forensic specialists" - implies they don't havae the complete picture, and these guys will likely be getting logs, identifying attack vectors and persistence mechanisms, assessing what (if anything) was accessed, imaging disks for forensic analysis, etc.

"containment" - implies the attacker had or may still have access, and this will likely involve isolation, resetting credentials, rebuilding AD, etc before systems are brought back online

"recovery" - implies the current dataset is unusable, which suggests ransomware

"notified the Information Regulator of South Africa" - strongly implies that personal information has been compromised, or at least there's a possibility thereof
External forensic specialists should be the norm. An independent analysis and hunt for evidence is a good thing. Very few companies would have someone with this skillset on staff.
 
External forensic specialists should be the norm. An independent analysis and hunt for evidence is a good thing. Very few companies would have someone with this skillset on staff.
wouldnt this take more time for investigating since an outsider is probing someone else's stuff etc.

just asking since im curious.
 
wouldnt this take more time for investigating since an outsider is probing someone else's stuff etc.

just asking since im curious.
As I said most companies wouldn't have the skills to fully investigate. It does take time but it also gives you the assurance that the hole has been closed, any lateral movement has been identified, backdoors or Trojans identified and eliminated, data exfiltration identified, so you can make a full and accurate report to whoever has a stake in this.
 
Top
Sign up to the MyBroadband newsletter
X