teiss – News – Why ransomware is increasingly becoming an operational threat | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


Ransomware has traditionally been associated with encrypted files, locked computers and demands for payment. But recent attacks show how the threat is increasingly extending beyond data and into the physical operations that businesses depend on.

 

That was demonstrated by a recent attack on Coca-Cola-owned dairy company fairlife, which was forced to temporarily suspend production across its US facilities after attackers gained access to parts of its network, including production-related systems.

 

According to a filing with the US Securities and Exchange Commission, fairlife identified unauthorised third-party access connected to a ransomware incident on 16 July. Coca-Cola activated its incident response and business continuity procedures and brought in external cybersecurity specialists while production was suspended. Product quality and safety were not affected.

 

The disruption illustrates why operational environments have become particularly attractive ransomware targets. For a manufacturer, the cost of an attack is no longer limited to recovering data or rebuilding IT systems. If production stops, losses can accumulate through downtime, delayed orders and wider disruption to supply chains.

 

IBM has previously estimated that unplanned downtime caused by incidents such as ransomware can cost industrial organisations as much as $125,000 per hour. Manufacturing has also remained the most targeted industry in its threat research for five consecutive years.

 

In fairlife’s case, the attackers also appear to have combined operational disruption with another familiar pressure tactic. The Anubis ransomware group claimed responsibility and said it had stolen around 1TB of data, threatening to publish it unless a ransom was paid. Coca-Cola did not confirm the group’s claims. Reuters reported that Anubis has previously been associated with attacks designed to cause particularly severe disruption.

 

This combination of data theft and operational impact gives attackers more leverage than encryption alone. Organisations may be able to restore encrypted data from backups, but restoring production is a different challenge when compromised systems are connected to manufacturing processes and have to be checked carefully before operations can safely resume. Fairlife eventually restored most production at four US facilities after the shutdown.

 

The incident is another reminder that ransomware resilience increasingly depends on more than protecting data. For organisations whose digital systems are closely tied to physical operations, business continuity, segmentation between IT and operational environments and the ability to restore critical processes quickly are becoming just as important as preventing encryption itself.

——————————————————–


Click Here For The Original Source.

.........................