[IT] Vol.25 | Companies in the Crosshairs | Targeted Ransomware That Slips In Through "VPN Holes"
Damage from "targeted ransomware" that singles out specific companies keeps occurring. In many cases, the entry point is a "vulnerability in VPN equipment" or "reused passwords."
This article explains, in about 3 minutes, why attackers get in and what you can do to prevent it.
Background
Ransomware is a cyberattack that encrypts a company's data without permission to make it unusable, then threatens: "If you want it back, pay the ransom."
The recent mainstream is not the old type scattered to unspecified targets, but "targeted ransomware" that picks a target in advance and breaks in. Attackers exploit vulnerabilities (= flaws in programs) in the "VPN equipment" used to connect to internal networks from outside, or poorly managed credentials (IDs and passwords), then spread the infection internally.
Why Is This a Hot Topic Now?
What stands out is that "the entry point is always the same."
Many affected companies share common weaknesses: (1) updates (security patches) for VPN equipment are left undone, and (2) passwords are reused or simple, so leaked credentials are used as-is. On top of that, "LotL (Living off the Land)" attacks—where attackers abuse legitimate tools—are increasing, slipping past detection without using malware.
In other words, the reality is that "gaps in basic defenses" are being exploited, rather than some special cutting-edge attack. Which also means: "if you take measures, you can definitely reduce the risk."
What Happens Next?
For the time being, as long as companies have VPN vulnerabilities and poor credential management, damage is expected to continue.
The countermeasures are simple: (1) keep all software, including VPN equipment, up to date, (2) introduce multi-factor authentication (password plus smartphone authentication, etc.), and (3) keep backups "disconnected from the network." Just these three dramatically lower the odds of being hit.
What Do You Think?
At your workplace, are VPN updates and multi-factor authentication in place?
The biggest risk might be the complacency of thinking "we won't be targeted." What's one thing you could start doing today?
Editor's Note
Honestly, this falls under the domain of the people called IT departments or in-house SEs, so it may be a topic that's hard to feel as "your own." But there are things individuals can do too. As the article says—changing your passwords regularly, not carelessly opening unnecessary emails—such familiar measures end up preventing major damage down the line. Let's all be a little more careful, together.
📂 Read more articles → note.com/news_translator
News Translator|Making complex news easy to understand.
Follow for weekly bilingual news articles.
