{"id":407220,"date":"2021-07-23T12:05:16","date_gmt":"2021-07-23T10:05:16","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=407220"},"modified":"2021-07-23T21:21:25","modified_gmt":"2021-07-23T19:21:25","slug":"new-details-about-transnet-cyberattack","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/407220-new-details-about-transnet-cyberattack.html","title":{"rendered":"New details about Transnet cyberattack"},"content":{"rendered":"<p>Transnet has been the victim of a ransomware attack, eNCA journalist Sli Masikane has <strong><a href=\"https:\/\/twitter.com\/Sli_Masikane\/status\/1418160550786342912\" target=\"_blank\" rel=\"noopener\">reported<\/a><\/strong>.<\/p>\n<p>The report stated that Transnet employees received notices to disconnect all their devices from the state-owned logistics company&#8217;s network and not to access their emails on their phones.<\/p>\n<p>Masikane also posted a screenshot of the ransomware note left by the attackers containing an address to a chat service on the dark web.<\/p>\n<p>News emerged yesterday from within the freight and logistics industry in South Africa that <a href=\"https:\/\/mybroadband.co.za\/news\/security\/407048-transnet-hacked-south-africas-port-systems-offline.html\"><strong>Transnet had been the victim of a cyberattack<\/strong><\/a> and its IT systems were offline.<\/p>\n<p>This led to speculation regarding whether Transnet was hit with a regular ransomware attack or whether the attack is related to the recent public violence in South Africa.<\/p>\n<p>President Cyril Ramaphosa has characterised the riots and looting that gripped parts of KwaZulu-Natal and Gauteng earlier this month as <a href=\"https:\/\/mybroadband.co.za\/news\/government\/406704-six-arrested-for-instigating-insurrection-in-south-africa.html\"><strong>a failed insurrection<\/strong><\/a>.<\/p>\n<p>The acting minister in the Presidency, Khumbudzo Ntshavheni, said during a recent media briefing that government is currently treating the attack on Transnet as unrelated to the insurrection.<\/p>\n<p>&#8220;We are investigating, and when information comes to the fore, we will either confirm or dispel whether the incident is related,&#8221; Ntshavheni said.<\/p>\n<p>Masikane posted screenshots of two messages that were reportedly sent to Transnet employees yesterday. The first stated:<\/p>\n<blockquote><p>URGENT! Please communicate to all your teams to shutdown all laptops, desktops &amp;<br \/>\ntablets connected to the domain. Also DO NOT access emails on your phones until further notice. No MS Teams meetings until further notice<\/p><\/blockquote>\n<p>The second message was as follows:<\/p>\n<blockquote><p>Good Morning All. Urgent message from ICTM. Transnet systems have been hacked and compromised. Please disconnect from the Transnet network immediately untill advised<br \/>\notherwise. This impacts remote access via APN\/VPN (3g or home Wifi) or direct access via LAN if you are in the office. This will also include Outlook (emails). You can continue to<br \/>\nonly work offline on your machine.<\/p><\/blockquote>\n<p>MyBroadband visited the address and tried to contact the attackers, but the chat service prompts for an account name and password.<\/p>\n<p>We received no other response to the messages we posted on the chat service than the login prompt.<\/p>\n<p><a  data-lightbox=\"post-image\" href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/07\/Transnet-hack-dark-web-chat-service-via-Sli-Masikane.jpg\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-407226\" style=\"border: 1px solid black;\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/07\/Transnet-hack-dark-web-chat-service-via-Sli-Masikane.jpg\" alt=\"\" width=\"1670\" height=\"710\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/07\/Transnet-hack-dark-web-chat-service-via-Sli-Masikane.jpg 1670w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/07\/Transnet-hack-dark-web-chat-service-via-Sli-Masikane-600x255.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/07\/Transnet-hack-dark-web-chat-service-via-Sli-Masikane-640x272.jpg 640w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/07\/Transnet-hack-dark-web-chat-service-via-Sli-Masikane-768x327.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/07\/Transnet-hack-dark-web-chat-service-via-Sli-Masikane-1536x653.jpg 1536w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/07\/Transnet-hack-dark-web-chat-service-via-Sli-Masikane-1200x510.jpg 1200w\" sizes=\"(max-width: 1670px) 100vw, 1670px\" \/><\/a><\/p>\n<p>Transnet downplayed the severity of the impact on its operations, saying that its freight rail, pipelines, engineering, and property divisions reported normal activity.<\/p>\n<p>It said port terminals are operational except for container terminals, as the Navis system on the trucking side has been affected.<\/p>\n<p>However, Transnet also admitted that the Ports Authority only continues to operate because vessels moving in and out of the port are being recorded manually.<\/p>\n<p>According to Transnet\u2019s statistics for June 2021, it processed 13,135 containers per day at its terminal facilities.<\/p>\n<p>The economic impact of an extended outage of its IT systems would be devastating.<\/p>\n<p>Navis issued a statement emphasising that its system was not the source of the disruption affecting Transnet.<\/p>\n<p>It said in its statement that Transnet shut down all its systems, including the servers running Navis&#8217; N4 application, as a precautionary measure.<\/p>\n<p>&#8220;Navis [&#8230;] is in close contact with the Transnet team as they work to identify and isolate the cause of the disruption and restore operations,&#8221; the company stated.<\/p>\n<p>Jayson O&#8217;Reilly, the head of Atvance Intellect&#8217;s cybersecurity division, told Bruce Whitfield on 702 that unless Transnet was properly prepared for a cyberattack, it could take weeks or even months to recover its systems.<\/p>\n<p>O&#8217;Reilly said that how quickly Transnet recovers from the attack depends on how well it has been practising standard IT hygiene:<\/p>\n<ul>\n<li>Has Transnet been applying regular security patches to its systems?<\/li>\n<li>Does it have recent backups, and were those backups kept in a location where the attackers couldn&#8217;t corrupt them?<\/li>\n<\/ul>\n<p>He noted that when looking at the recent example of the <a href=\"https:\/\/mybroadband.co.za\/news\/security\/395501-virgin-active-south-africa-hit-by-cyber-attack.html\"><strong>attack on Virgin Active<\/strong><\/a> in May 2021, it took them six to eight weeks to get their systems up and running.<\/p>\n<p>O&#8217;Reilly said that the recent civil might have painted a target on South Africa&#8217;s back.<\/p>\n<p>&#8220;The reality is \u2014\u00a0we were in the news for seven days,&#8221; said O&#8217;Reilly.<\/p>\n<p>&#8220;That&#8217;s exactly the kind of media attention cybercriminals look for.&#8221;<\/p>\n<div id=\"attachment_407228\" style=\"width: 810px\" class=\"wp-caption aligncenter\"><a  data-lightbox=\"post-image\" href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/07\/Jason-OReilly.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-407228\" class=\"size-full wp-image-407228\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/07\/Jason-OReilly.jpg\" alt=\"\" width=\"800\" height=\"533\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/07\/Jason-OReilly.jpg 800w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/07\/Jason-OReilly-600x400.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/07\/Jason-OReilly-640x426.jpg 640w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2021\/07\/Jason-OReilly-768x512.jpg 768w\" sizes=\"(max-width: 800px) 100vw, 800px\" \/><\/a><p id=\"caption-attachment-407228\" class=\"wp-caption-text\">Jayson O&#8217;Reilly, Atvance Intellect, Head of Cyber Security<\/p><\/div>\n<p>O&#8217;Reilly said that the attackers might not have set out to target Transnet specifically.<\/p>\n<p>&#8220;A lot of these attacks are built on machine learning,&#8221; he said.<\/p>\n<p>&#8220;They don&#8217;t know who they&#8217;re attacking in many cases until the vulnerability is flagged and they get into the organisation and use their reconnaissance techniques&#8221;.<\/p>\n<p>According to O&#8217;Reilly, ransomware groups tend to run sophisticated, well-funded environments.<\/p>\n<p>&#8220;They are multi-jurisdictional, and they anonymise their activities,&#8221; he said.<\/p>\n<p>However, just because the attackers have sophisticated capabilities, that does not mean the attack they used against Transnet was advanced.<\/p>\n<p>&#8220;We&#8217;d like to think that they are really advanced attacks, but in some cases, they are the simplest social engineering attacks,&#8221; said O&#8217;Reilly.<\/p>\n<p>&#8220;They are looking at soft targets. They are looking at people that are not managing their environments.&#8221;<\/p>\n<p>O&#8217;Reilly said that there had been a trend of ransomware gangs targeted national governments, such as the recent attack on Colonial Pipeline in the US.<\/p>\n<p>Bloomberg reported that the hack that took down the largest fuel pipeline in the US and led to shortages across the East Coast resulted from <a href=\"https:\/\/mybroadband.co.za\/news\/security\/400357-one-compromised-password-let-attackers-break-into-colonial-pipeline.html\"><strong>a single compromised password<\/strong><\/a>.<\/p>\n<p>&#8220;They are looking at how they can bring down critical infrastructure, and that is becoming a worrying factor that we&#8217;re seeing across the globe,&#8221; said O&#8217;Reilly.<\/p>\n<p>&#8220;Whether they think they can get money or not and whether they understand our economy or not \u2014 they are going to try.&#8221;<\/p>\n<p>MyBroadband has repeatedly tried to reach Transnet for comment but received no response from the state-owned company.<\/p>\n<p><iframe loading=\"lazy\" src=\"https:\/\/omny.fm\/shows\/the-money-show\/transnet-s-operations-survive-a-cyber-attack\/embed\" width=\"100%\" height=\"180px\" frameborder=\"0\"><\/iframe><\/p>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/security\/406906-ramaphosas-phone-identified-in-leaked-pegasus-spy-project-records.html\">Ramaphosa&#8217;s phone identified in leaked Pegasus spy project records<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>The recent public violence in KwaZulu-Natal and Gauteng painted a target on South Africa&#8217;s back, an information security expert has said.<\/p>\n","protected":false},"author":15,"featured_media":407050,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[65381,1952,35,71002,17402,71010],"class_list":["post-407220","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-atvance-intellect","tag-cyril-ramaphosa","tag-headline","tag-jayson-oreilly","tag-khumbudzo-ntshavheni","tag-navis"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/407220"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=407220"}],"version-history":[{"count":0,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/407220\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/407050"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=407220"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=407220"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=407220"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}