Skip to main content

Toronto Public Library service offline until 2024 :(


Geoff Burke
Forum|alt.badge.img+22

A huge ransomware attack on the Library system of North America’s 4th largest city 😓. It happened a few weeks ago but was devastating. It would be interesting to know what backups they had and how they were setup. 

 

https://www.cbc.ca/news/canada/toronto/toronto-public-library-cybersecurity-attack-services-restored-january-1.7038567

 

 

10 comments

TylerJurgens
Forum|alt.badge.img+7
  • Influencer
  • 161 comments
  • November 24, 2023

Hope they had a good backup/dr plan


Geoff Burke
Forum|alt.badge.img+22
  • Author
  • Veeam Legend, Veeam Vanguard
  • 1318 comments
  • November 24, 2023
TylerJurgens wrote:

Hope they had a good backup/dr plan

Judging by how long it will take to get services backup.. I don’t know. I don’t think there is any instant recovery here that is for certain. Unless they are concerned that the attackers got access before the backup retention and just sat tight watching. 


dips
Forum|alt.badge.img+7
  • Veeam Legend
  • 808 comments
  • November 24, 2023

Chris.Childerhose
Forum|alt.badge.img+21
  • Veeam Legend, Veeam Vanguard
  • 8512 comments
  • November 24, 2023

Wow that definitely is not good.  Maybe someone needs to contact them about Veeam. 😁


Geoff Burke
Forum|alt.badge.img+22
  • Author
  • Veeam Legend, Veeam Vanguard
  • 1318 comments
  • November 24, 2023
Chris.Childerhose wrote:

Wow that definitely is not good.  Maybe someone needs to contact them about Veeam. 😁

Yeah I mean where are those sales reps when you really need them 🤣


CarySun
Forum|alt.badge.img+7
  • Veeam Vanguard
  • 200 comments
  • November 25, 2023

Interesting hacker. Why attack the library not a business company??? I don’t think they will get money from the library. The library won’t care when will re-open. 😀


regnor
Forum|alt.badge.img+14
  • Veeam MVP
  • 1354 comments
  • November 25, 2023

@CarySun They're now targeting our knowledge and preventing us from reading all the IT books to defend ransomware 😉


dips
Forum|alt.badge.img+7
  • Veeam Legend
  • 808 comments
  • November 25, 2023
CarySun wrote:

Interesting hacker. Why attack the library not a business company??? I don’t think they will get money from the library. The library won’t care when will re-open. 😀

For some groups, they are ransoming the data rather than the actual infrastructure itself. Others are two-pronged. Exfiltrate the data, ransom the infrastructure and then hold the data they got to ransom and threaten to release unless the organisation pays. 


Geoff Burke
Forum|alt.badge.img+22
  • Author
  • Veeam Legend, Veeam Vanguard
  • 1318 comments
  • November 25, 2023

I believe it is as mentioned about for extortion purposes. I don’t think many script kiddies are doing this. Mainly organised crime and bad state actors. The goal is mainly to get paid, although there is the disruption affect (in the case of state actors). Hopefully yet another wake up call. Just my humble opinion but such a long outage means that the DR plan was not well setup. Most likely due to lack of funds or not properly channelling funds. Speculation of course.


dips
Forum|alt.badge.img+7
  • Veeam Legend
  • 808 comments
  • November 25, 2023
Geoff Burke wrote:

I believe it is as mentioned about for extortion purposes. I don’t think many script kiddies are doing this. Mainly organised crime and bad state actors. The goal is mainly to get paid, although there is the disruption affect (in the case of state actors). Hopefully yet another wake up call. Just my humble opinion but such a long outage means that the DR plan was not well setup. Most likely due to lack of funds or not properly channelling funds. Speculation of course.

I’d agree. Funding will definitely be a factor as well