{"id":36037,"date":"2023-07-06T19:52:26","date_gmt":"2023-07-06T19:52:26","guid":{"rendered":"https:\/\/zpesystems.com\/?p=36037"},"modified":"2023-11-08T21:34:05","modified_gmt":"2023-11-08T21:34:05","slug":"the-biggest-ransomware-attack-you-havent-heard-of-yet","status":"publish","type":"post","link":"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/","title":{"rendered":"The Biggest Ransomware Attack You Haven&#8217;t Heard of&#8230;Yet"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; custom_margin=&#8221;0px||||false|false&#8221; custom_padding=&#8221;0px||||false|false&#8221; da_disable_devices=&#8221;off|off|off&#8221; global_colors_info=&#8221;{}&#8221; da_is_popup=&#8221;off&#8221; da_exit_intent=&#8221;off&#8221; da_has_close=&#8221;on&#8221; da_alt_close=&#8221;off&#8221; da_dark_close=&#8221;off&#8221; da_not_modal=&#8221;on&#8221; da_is_singular=&#8221;off&#8221; da_with_loader=&#8221;off&#8221; da_has_shadow=&#8221;on&#8221;][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg&#8221; alt=&#8221;James Cabe CISSP&#8221; title_text=&#8221;James Cabe CISSP&#8221; _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.21.2&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<p><em>This article was written by <a href=\"https:\/\/www.linkedin.com\/in\/jamescabe\/\">James Cabe, CISSP<\/a>, whose cybersecurity expertise has helped major companies including Microsoft and Fortinet.<\/em><\/p>\n<p><span style=\"font-weight: 400;\">MOVEit over SolarWinds \u2014 The largest and most successful ransomware attack ever recorded is happening. Right now. It\u2019s attacking healthcare and financial institutions with high rates of success, and recently <a href=\"https:\/\/techcrunch.com\/2023\/08\/14\/millions-americans-health-data-moveit-hackers-clop-ibm\/?guccounter=2&amp;guce_referrer=aHR0cHM6Ly9zdGF0aWNzLnRlYW1zLmNkbi5vZmZpY2UubmV0Lw&amp;guce_referrer_sig=AQAAAET1m944Fuc6m-oz7VyS-1WkpfZOUsPPOihk3xVN7ibxk_hHCvRAEGxd1xOeXJDQvfeLBV7DapRUe-le2gxKso3NaLHARjEvNS2gzhikhdRD_i52Dninx6me3ibb1yee4NC8RXXuzK12Ij4oc-sisyHAnmCtHdVLiYcyjVfEmtlo\" target=\"_blank\" rel=\"noopener\">stole sensitive data of 4 million more healthcare patients<\/a>. It uses something called CL0P ransomware, and the threat actor is a well-known criminal group with the name FIN11. Many organizations are finding it difficult to stop the attack because they have no way to access infected devices, take them offline, patch, or even replace them. So, what exactly is going on?<\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][et_pb_row column_structure=&#8221;3_5,2_5&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;3_5&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1>The group responsible for the attack<\/h1>\n<p><span style=\"font-weight: 400;\">FIN11 is a cybercriminal group that has been active since 2016 or before, originating from the <\/span><a href=\"https:\/\/www.britannica.com\/topic\/Commonwealth-of-Independent-States\"><span style=\"font-weight: 400;\">Commonwealth of Independent States (CIS)<\/span><\/a><span style=\"font-weight: 400;\">. While the group has historically been associated with widespread phishing campaigns, their focus has shifted towards other initial access vectors. FIN11 often runs high-volume operations targeting industries in North America and Europe for data theft and ransomware deployment, primarily leveraging CL0P (aka CLOP).<\/span><\/p>\n<p><span style=\"font-weight: 400;\">FIN11 is responsible for multiple widespread, high-profile intrusion campaigns leveraging zero-day vulnerabilities, and the group likely has access to the networks of many more organizations than it is able to successfully monetize. Despite this, they\u2019re currently attacking MOVEit, a well-known SaaS provider who relies on a file transfer appliance called Accellion lFile Transfer Appliance (FTA). This legacy product remains unpatched, which has led to the breach of many Fortune 100 companies and state and federal agencies.<\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][et_pb_column type=&#8221;2_5&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_image src=&#8221;https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/FIN11.webp&#8221; alt=&#8221;FIN11&#8243; title_text=&#8221;FIN11&#8243; _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_image][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h2>How did the ransomware attack start?<\/h2>\n<p><span style=\"font-weight: 400;\">The ransomware attack began with several Accellion FTA customers, including those in industries like healthcare, legal, finance, retail, and telecom. Companies such as Jones Day Law, Kroger, Singtel, and many others had no idea that they had been attacked, because the initial breach was quiet and headless.<\/span><span style=\"font-weight: 400;\"><br \/><\/span><\/p>\n<p><span style=\"font-weight: 400;\">Their only indication came after receiving a threatening email aimed at extortion.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In this email, the group threatened to publish stolen data on the \u201cCL0P^_- LEAKS\u201d .onion website, according to an investigation from Accellion. The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint CSA to disseminate known CL0P ransomware IOCs and TTPs identified through FBI investigations as recently as June 2023.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">According to the investigation, four zero-day security holes were exploited in the attacks:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CVE-2021-27101 \u2013 SQL injection via a crafted Host header<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CVE-2021-27102 \u2013 OS command execution via a local web service call<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CVE-2021-27103 \u2013 SSRF via a crafted POST request<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">CVE-2021-27104 \u2013 OS command execution via a crafted POST request<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">And, the published victim data appears to have been stolen using a \u201cWEB SHELL\u201d. These web shells give remote administrative access to the web server and create a jumping off point to attack the rest of the internal network. Mandiant, a well-known cyber investigation arm of Google, added, \u201cThe exfiltration activity has affected entities in a wide range of sectors and countries\u201d (Threatpost). Exfiltration is the unauthorized removal of important or damaging data from an organization.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">However the biggest problem is that these web shells are what researchers call \u201cPERSISTENCE\u201d. This means that an attacker can remain in your network indefinitely to continue damaging and attacking your resources. Researchers call these \u201cAPTs,\u201d or Advanced Persistent Threats.<\/span><\/p>\n<h2>Why is the ransomware attack still going strong?<\/h2>\n<p><span style=\"font-weight: 400;\">The ransomware attack is still going strong because there\u2019s no patch available. According to open source information, beginning on May 27, 2023, CL0P Ransomware Gang began exploiting a previously unknown SQL injection vulnerability (<\/span><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2023-34362\"><span style=\"font-weight: 400;\">CVE-2023-34362<\/span><\/a><span style=\"font-weight: 400;\">) in Accelion\u2019s appliance that is the backbone of a solution known as Progress Software&#8217;s MOVEit Transfer service. Internet-facing MOVEit Transfer web applications were infected with a web shell named LEMURLOOT, which was then used to steal data from underlying MOVEit Transfer databases. In similar spates of activity, TA505, which is the group responsible for the Dridex trojan and Locky ransomware, conducted zero-day-exploit-driven campaigns against Accellion FTA devices in 2020 and 2021, and Fortra\/Linoma GoAnywhere MFT servers in early 2023.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">What most organizations want to know is: How do you quickly respond to issues like these? How can you be properly prepared to respond to an issue you didn\u2019t cause or didn\u2019t expect?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Patching is a good response. However, it takes an average of 205 days to patch a recently known zero-day exploit like the MOVEit vulnerability. While patching alone is typically the ideal response, it isn\u2019t automatic nor can it be done quickly.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Another approach involves removing the offending software or appliance, or cutting off access to the software or appliance. But once you remove this access, how do you continue normal operations, and how can you easily bring the software\/appliance back online? Without adequate infrastructure in place, physically deploying to each site is not practical, especially for distributed organizations.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">CISA and the FBI encourage organizations to implement the recommendations in the Mitigations section of this <\/span><a href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-158a\"><span style=\"font-weight: 400;\">CSA<\/span><\/a><span style=\"font-weight: 400;\"> to reduce the likelihood and impact of CL0P ransomware and other ransomware incidents. The Mitigations section describes many approaches, including patching, removing software\/appliance access, and implementing a recovery plan. But all of these take too much time and too many resources, which leaves organizations vulnerable as they scramble to create an adequate response.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The great news is, organizations can cover all their bases without having to reinvent the wheel. This approach is recommended in one of CISA\u2019s recent directives, and gives organizations somewhat of a silver bullet that allows them to quickly defeat ransomware and remain prepared for any future attack.<\/span><\/p>\n<h2>What approach does CISA recommend to address ransomware attacks?<\/h2>\n<p><span style=\"font-weight: 400;\">CISA\u2019s recent directive (<\/span><a href=\"https:\/\/www.cisa.gov\/news-events\/directives\/binding-operational-directive-23-02\"><span style=\"font-weight: 400;\">23-02<\/span><\/a><span style=\"font-weight: 400;\">), which addresses the vulnerability of Internet-exposed management interfaces, calls for organizations to create an isolated management infrastructure (IMI) via out-of-band connectivity. This is a drop-in solution that the military, telcos, and hyperscalers\/cloud companies use to respond to widespread ransomware and other issues impacting security and resilience. This approach \u2014 which ZPE Systems has perfected in the last decade with the help of Big Tech \u2014\u00a0gives organizations a completely separate control plane through which they can monitor and manage their entire IT infrastructure in a safe and dedicated fashion.<\/span><\/p>\n<h3>What is isolated management infrastructure?<\/h3>\n<p><span style=\"font-weight: 400;\">Isolated management infrastructure consists of the hardware and software that create a management network that\u2019s fully separate from other production and management networks. The key to this is in out-of-band connectivity, which is defined as connectivity other than TCP\/IP. Out-of-band can include direct USB, serial, or even non-routed zero-trust connections to crown-jewel assets.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Essentially, the IMI gives an organization complete oversight and control of their widespread IT infrastructure, in a way that is secure and accessible only to their IT teams.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In this diagram, the production infrastructure (blue ring) sits at each distributed location. The out-of-band infrastructure for LAN (OOBI-LAN) is the green ring and surrounds the production infrastructure with one layer of isolated management. The OOBI-WAN (orange ring) is what provides a second layer of isolated management, which teams can access from a central or remote location, to gain access to the OOBI-LAN and ultimately the production infrastructure.<\/span><\/p>\n<p><img decoding=\"async\" class=\"wp-image-35255 alignnone size-full\" src=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/microsoftteams-image-8-1.webp\" alt=\"ZPE Automation\" width=\"1917\" height=\"1077\" srcset=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/microsoftteams-image-8-1.webp 1917w, https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/microsoftteams-image-8-1-1280x719.webp 1280w, https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/microsoftteams-image-8-1-980x551.webp 980w, https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/05\/microsoftteams-image-8-1-480x270.webp 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) and (max-width: 1280px) 1280px, (min-width: 1281px) 1917px, 100vw\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Knowing these assets and providing access across the organization can be easy and does not have to disrupt current operations.\u00a0<\/span><\/p>\n<h2>How can IMI stop the FIN11 ransomware attack?<\/h2>\n<p><span style=\"font-weight: 400;\">In the ongoing FIN11 ransomware attack, Internet-facing applications are targets of the zero-day exploit. This means that no amount of security solutions can pre-mitigate the attack (i.e., there\u2019s nothing you can do to stop it). This is where IMI shines.<\/span><\/p>\n<p><img decoding=\"async\" class=\"wp-image-36055 alignnone size-full\" src=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/Isolated-Management-Network-Diagram.png\" alt=\"Isolated Management Network diagram sitting beside production infrastructure\" width=\"2000\" height=\"1125\" srcset=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/Isolated-Management-Network-Diagram.png 2000w, https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/Isolated-Management-Network-Diagram-1280x720.png 1280w, https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/Isolated-Management-Network-Diagram-980x551.png 980w, https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/Isolated-Management-Network-Diagram-480x270.png 480w\" sizes=\"(min-width: 0px) and (max-width: 480px) 480px, (min-width: 481px) and (max-width: 980px) 980px, (min-width: 981px) and (max-width: 1280px) 1280px, (min-width: 1281px) 2000px, 100vw\" \/><\/p>\n<p><span style=\"font-weight: 400;\">Remember the OOBI-LAN\/OOBI-WAN diagram? Here\u2019s a zoomed-in view of the isolated management infrastructure sitting beside the production infrastructure. The IMI connects via serial, Ethernet, and USB to production gear, and provides the necessary functions (routing, storing golden images, hosting jumpbox tools, etc.) to recover from attack. But how?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">IT teams can use OOBI-WAN to remotely access their OOBI-LAN and production gear. They can pull affected devices offline and bring them in for forensics, which takes place in an <\/span><a href=\"https:\/\/zpesystems.com\/build-an-isolated-recovery-environment-zs\/\"><span style=\"font-weight: 400;\">Isolated Recovery Environment (IRE)<\/span><\/a><span style=\"font-weight: 400;\">. This means these assets and networks are still reachable by analysts and responders, but isolated from other vulnerable assets. This allows an organization to quickly and even automatically deploy tools and resources inside of this environment through devices like ZPE Systems\u2019 Nodegrid.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">To combat the FIN11 attack, organizations don\u2019t need to unplug cables or shut their devices off. They can instead deploy their IMI as the framework for closing the attack surface while maintaining access and critical data to aid in recovery.<\/span><\/p>\n<h2>Get the blueprint for isolated management infrastructure<\/h2>\n<p><span style=\"font-weight: 400;\">Don\u2019t wait until the next attack to shore up your defenses. ZPE Systems has worked with Big Tech for ten years developing the isolated management infrastructure. It\u2019s now available inside the Network Automation Blueprint, and walks you through how to implement your own IMI. Download the blueprint now to stay ready for any attack.<\/span><\/p>\n<p>[\/et_pb_text][et_pb_button button_url=&#8221;https:\/\/zpesystems.com\/network-automation-blueprint\/&#8221; button_text=&#8221;Download blueprint&#8221; _builder_version=&#8221;4.21.0&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_button][\/et_pb_column][\/et_pb_row][et_pb_row _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; width=&#8221;100%&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.17.6&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_text admin_label=&#8221;Text&#8221; _builder_version=&#8221;4.23.1&#8243; _module_preset=&#8221;default&#8221; hover_enabled=&#8221;0&#8243; global_colors_info=&#8221;{}&#8221; sticky_enabled=&#8221;0&#8243;]<\/p>\n<h2>Get in touch with me!<\/h2>\n<p><span style=\"font-weight: 400;\">True security can only be achieved through resilience, and that&#8217;s my mission. If you want help shoring up your defenses, building an IMI, and implementing a Resilience System, get in touch with me. Here are links to my social media accounts:<\/span><\/p>\n<ul>\n<li><a href=\"https:\/\/www.linkedin.com\/in\/jamescabe\/\">James Cabe &#8211; CISSP on LinkedIn<\/a><\/li>\n<li><a href=\"https:\/\/twitter.com\/how2cloud?lang=en\">@how2cloud on X &#8211; James Cabe<\/a><\/li>\n<\/ul>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The most successful ransomware attack ever is happening right now. See why isolated management infrastructure is the only way to save your organization.<\/p>\n","protected":false},"author":5,"featured_media":36041,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","content-type":"","footnotes":""},"categories":[98,103,156,101,93,82,96,162,35,158,97,134],"tags":[],"class_list":["post-36037","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-data-logging","category-improve-network-security","category-micro-segmentation","category-minimize-impact-of-disruptions","category-network-automation","category-out-of-band-management","category-sd-wan","category-secops","category-sase","category-security-service-edge-sse","category-user-management","category-zero-trust-security"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.0 (Yoast SEO v26.0) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>The Biggest Ransomware Attack You Haven&#039;t Heard of...Yet<\/title>\n<meta name=\"description\" content=\"The most successful ransomware attack ever is happening right now. See why isolated management infrastructure is the only way to save your organization.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The Biggest Ransomware Attack You Haven&#039;t Heard of...Yet\" \/>\n<meta property=\"og:description\" content=\"The most successful ransomware attack ever is happening right now. See why isolated management infrastructure is the only way to save your organization.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/\" \/>\n<meta property=\"og:site_name\" content=\"ZPE Systems\" \/>\n<meta property=\"article:published_time\" content=\"2023-07-06T19:52:26+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-11-08T21:34:05+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"627\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Jordan Baker\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Jordan Baker\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/\",\"url\":\"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/\",\"name\":\"The Biggest Ransomware Attack You Haven't Heard of...Yet\",\"isPartOf\":{\"@id\":\"https:\/\/zpesystems.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg\",\"datePublished\":\"2023-07-06T19:52:26+00:00\",\"dateModified\":\"2023-11-08T21:34:05+00:00\",\"author\":{\"@id\":\"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567\"},\"description\":\"The most successful ransomware attack ever is happening right now. See why isolated management infrastructure is the only way to save your organization.\",\"breadcrumb\":{\"@id\":\"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/#primaryimage\",\"url\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg\",\"contentUrl\":\"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg\",\"width\":1200,\"height\":627,\"caption\":\"James Cabe, CISSP headshot\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/zpesystems.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The Biggest Ransomware Attack You Haven&#8217;t Heard of&#8230;Yet\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/zpesystems.com\/#website\",\"url\":\"https:\/\/zpesystems.com\/\",\"name\":\"ZPE Systems\",\"description\":\"Rethink the Way Networks are Built and Managed\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/zpesystems.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567\",\"name\":\"Jordan Baker\",\"url\":\"https:\/\/zpesystems.com\/author\/jordan\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The Biggest Ransomware Attack You Haven't Heard of...Yet","description":"The most successful ransomware attack ever is happening right now. See why isolated management infrastructure is the only way to save your organization.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/","og_locale":"en_US","og_type":"article","og_title":"The Biggest Ransomware Attack You Haven't Heard of...Yet","og_description":"The most successful ransomware attack ever is happening right now. See why isolated management infrastructure is the only way to save your organization.","og_url":"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/","og_site_name":"ZPE Systems","article_published_time":"2023-07-06T19:52:26+00:00","article_modified_time":"2023-11-08T21:34:05+00:00","og_image":[{"width":1200,"height":627,"url":"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg","type":"image\/jpeg"}],"author":"Jordan Baker","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Jordan Baker","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/","url":"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/","name":"The Biggest Ransomware Attack You Haven't Heard of...Yet","isPartOf":{"@id":"https:\/\/zpesystems.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/#primaryimage"},"image":{"@id":"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/#primaryimage"},"thumbnailUrl":"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg","datePublished":"2023-07-06T19:52:26+00:00","dateModified":"2023-11-08T21:34:05+00:00","author":{"@id":"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567"},"description":"The most successful ransomware attack ever is happening right now. See why isolated management infrastructure is the only way to save your organization.","breadcrumb":{"@id":"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/#primaryimage","url":"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg","contentUrl":"https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg","width":1200,"height":627,"caption":"James Cabe, CISSP headshot"},{"@type":"BreadcrumbList","@id":"https:\/\/zpesystems.com\/the-biggest-ransomware-attack-you-havent-heard-of-yet\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/zpesystems.com\/"},{"@type":"ListItem","position":2,"name":"The Biggest Ransomware Attack You Haven&#8217;t Heard of&#8230;Yet"}]},{"@type":"WebSite","@id":"https:\/\/zpesystems.com\/#website","url":"https:\/\/zpesystems.com\/","name":"ZPE Systems","description":"Rethink the Way Networks are Built and Managed","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/zpesystems.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/zpesystems.com\/#\/schema\/person\/822694040abba23b5253766566cd1567","name":"Jordan Baker","url":"https:\/\/zpesystems.com\/author\/jordan\/"}]}},"rttpg_featured_image_url":{"full":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg",1200,627,false],"landscape":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg",1200,627,false],"portraits":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg",1200,627,false],"thumbnail":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP-150x150.jpg",150,150,true],"medium":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP-300x157.jpg",300,157,true],"large":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP-1024x535.jpg",1024,535,true],"1536x1536":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg",1200,627,false],"2048x2048":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg",1200,627,false],"et-pb-post-main-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP-400x250.jpg",400,250,true],"et-pb-post-main-image-fullwidth":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP-1080x627.jpg",1080,627,true],"et-pb-portfolio-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP-400x284.jpg",400,284,true],"et-pb-portfolio-module-image":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP-510x382.jpg",510,382,true],"et-pb-portfolio-image-single":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP-1080x564.jpg",1080,564,true],"et-pb-gallery-module-image-portrait":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP-400x516.jpg",400,516,true],"et-pb-post-main-image-fullwidth-large":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg",1200,627,false],"et-pb-image--responsive--desktop":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP.jpg",1200,627,false],"et-pb-image--responsive--tablet":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP-980x512.jpg",980,512,true],"et-pb-image--responsive--phone":["https:\/\/zpesystems.com\/wp-content\/uploads\/2023\/07\/James-Cabe-CISSP-480x251.jpg",480,251,true]},"rttpg_author":{"display_name":"Jordan Baker","author_link":"https:\/\/zpesystems.com\/author\/jordan\/"},"rttpg_comment":0,"rttpg_category":"<a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/data-logging\/\" rel=\"category tag\">Data Logging<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/\" rel=\"category tag\">Improve Network Security<\/a> <a href=\"https:\/\/zpesystems.com\/category\/micro-segmentation\/\" rel=\"category tag\">Micro-segmentation<\/a> <a href=\"https:\/\/zpesystems.com\/category\/minimize-impact-of-disruptions\/\" rel=\"category tag\">Minimize Impact of Disruptions<\/a> <a href=\"https:\/\/zpesystems.com\/category\/increase-productivity\/network-automation\/\" rel=\"category tag\">Network Automation<\/a> <a href=\"https:\/\/zpesystems.com\/category\/remote-network-management\/out-of-band-management\/\" rel=\"category tag\">Out of Band Management<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/sd-wan\/\" rel=\"category tag\">SD-WAN<\/a> <a href=\"https:\/\/zpesystems.com\/category\/secops\/\" rel=\"category tag\">SecOps<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/sase\/\" rel=\"category tag\">Secure Access Service Edge (SASE)<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/security-service-edge-sse\/\" rel=\"category tag\">Security Service Edge (SSE)<\/a> <a href=\"https:\/\/zpesystems.com\/category\/improve-network-security\/user-management\/\" rel=\"category tag\">User Management<\/a> <a href=\"https:\/\/zpesystems.com\/category\/zero-trust-security\/\" rel=\"category tag\">Zero Trust Security<\/a>","rttpg_excerpt":"The most successful ransomware attack ever is happening right now. See why isolated management infrastructure is the only way to save your organization.","_links":{"self":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/36037","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/comments?post=36037"}],"version-history":[{"count":10,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/36037\/revisions"}],"predecessor-version":[{"id":38182,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/posts\/36037\/revisions\/38182"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/media\/36041"}],"wp:attachment":[{"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/media?parent=36037"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/categories?post=36037"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zpesystems.com\/wp-json\/wp\/v2\/tags?post=36037"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}