Skip to playerSkip to main content
  • 3 months ago
Instructure the company at the centre of a global cyberattack that affected millions of students this month says it has reached an agreement with the hackers. Almost 9,000 schools and universities were targeted in the data breach which compromised personal details including student ID numbers, email addresses and enrolment information.

Category

📺
TV
Transcript
00:01Well, Joe, I think reached an agreement means paid. I think the company should say that
00:07it paid because reached an agreement is just tricky wording. These hackers, shiny hunters
00:15aren't suddenly becoming nice people and deciding because they've affected 8,800 or so education
00:24institutions around the world and affected millions of students that they might just
00:28give the information back. So it's naive wording, it's improper and it doesn't give people the
00:35right information for them to make their own decisions. There's a few other things. The
00:39company has said it's had the data given back to it. It's not like a car was stolen from
00:44your driveway, Joe, and someone can bring it back and say, sorry for taking it. When someone
00:49steals the digital information, the original stays in the system and criminals steal the
00:54other bits. So to give back a copy of something that they've probably kept a copy of and will
00:59on sell in the criminal black market, giving assurances mean nothing.
01:05Yeah. And so there's no guarantee because it's also said in some kind of statement that the
01:12hackers have destroyed the information, but there is no guarantee that that's happened.
01:17Not at all. I'm extremely sceptical. Police every once in a while actually catch these types of
01:22criminals and execute search warrants and find data that was meant to have been deleted, find records
01:29of where they've onsold that data. These are criminals that stole it in the first place. So they
01:34haven't, as I say, suddenly become good people. So this is where the problem lies. Now I'm not against,
01:41and this might sound controversial, the concept of if computer systems are locked up and people could
01:47die like hospitals or power companies or water companies are locked up. This is what we call
01:53ransomware. I actually think it's a legitimate consideration on the part of a government and of
01:59pieces of critical infrastructure to potentially pay as much as we should avoid it. If there's life
02:04and death situations, this is not a life and death situation. It's a terrible thing that so many
02:10millions of people have been impacted by this hack. But the information is not of such a gravity.
02:17And the situation, as I say, computers aren't locked up and institutions unable to function,
02:23there shouldn't have been a payment in this case. And I think it's a sense of dangerous and bad
02:28precedent. The fact that it's clear there was a payment. And what is that dangerous precedent?
02:33Well, it does, it does fuel the criminal economy. And as I say, I always have a carve out that
02:38says if
02:38someone's going to die, or if it's going to collapse an economy, that you have to consider
02:43occasionally dealing directly with criminals. So don't get me wrong here. And that's even a
02:48controversial thing to a position to have, by the way, some people say you should never pay.
02:52Those people have never dealt with real victims of crime, because every once in a while, you have
02:56to make that concession. But in this case, the companies being cute victims, and there are plenty of
03:03victims in this, the company themselves, the 8,800 plus institutions that were using the services of
03:09this company, and then the millions of students, teachers, professors, and others that are impacted,
03:14whose data has been stolen. So there's an awful lot of victims here for, in structure, the parent
03:21company to say that they've come to an arrangement, and have the data returned is fanciful.
03:26And so what does this highlight about the need for companies to be as cyber secure as possible?
03:32Well, this highlights that we rely on software services that we've never heard of,
03:37from companies that aren't in our jurisdiction, that actually form the fabric that a lot of our
03:43other institutions operate on. So this highlights supply chains, it highlights that there are organisations
03:48that have millions upon millions of records that aren't securing them well enough. It is a wake
03:54up call that there are these massive software, software as a service platforms that we rely upon,
04:00where clearly security can fail, it can always fail. But more needs to be done. This isn't the first of
04:06these types of hacks, and it won't be the last. But it's an indication that as you might tighten some
04:13of
04:13your software type controls, you then need to be ready for these social engineering attacks, which is
04:19what Shiny Hunters, this particular criminal group does. They trick organisations into gaining access,
04:27and then escalate their privileges and commit these types of crimes.
04:30Yeah. And so is it almost impossible to guarantee yourself against hacks now, especially with the
04:35onset of AI enhancing hackers' effectiveness? And to what extent is that happening?
04:41Well, complete computer security has always been a myth. The job of cyber security experts is to reduce
04:50the likelihood of an attack being successful, to detect that hack fast, and to reduce the harm
04:58associated with it. It's a risk reduction exercise, it's not binary secure or insecure. But certainly the
05:04frontier models of AI are making hacking much easier. In this case, it was unlikely to be an AI-based
05:13attack. It was a social engineering attack, where they will trick people out of these credentials,
05:19logins and the like. But yes, AI is making all of the threat environment worse for those of us who
05:27defend systems. So people should be ready, sadly, for a never-ending story of computer crime and losses.
05:37Yeah. And when you link that with an example like this, and the payment of a ransom,
05:42what does that indicate about where this is headed?
05:46Well, there are two big sort of threat actor groups here that we deal with, Joe. There's a vibrant
05:52criminal economy and that relies upon essentially either causing harm in exchange for money or stealing
05:59things that they exchange for money, data and other things. That's this type of incident we're talking
06:03about tonight. Then there's the nation state threat actors who largely steal for strategic reasons,
06:09though we have seen countries like China starting to look at how they can cause actual harm to critical
06:16infrastructure through their cyber means. And AI and the mix of these two lots of threat actors,
06:25there's an increasing blending between them where they'll use fronts for each other's activities,
06:31just makes it more complex. And added on top, of course, Joe, we're using more technologies that
06:37are more complex, including AI. So it just basically makes that risk equation more complex.
06:46The
Comments

Recommended