ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah

    IT Discussion
    msp ransomware security breach
    21
    111
    12.7k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • scottalanmillerS
      scottalanmiller
      last edited by

      I noticed that the only management that they have is someone with sales, but no IT experience. Nothing wrong with that, most successful MSPs are run by non-IT people, but it appears after digging into their people list, that they lack any IT leadership people and it is just a loose collection of relatively green bench techs working for a sales guy. So lots of customers, and very little protection, is kind of an obvious result.

      1 Reply Last reply Reply Quote 1
      • black3dynamiteB
        black3dynamite
        last edited by

        Is there a possibility that some of the clients have an on-site IT too? I saw that list of employees, maybe of some them use to work in IT but decided to move on to the business side instead can help with re-imaging computers.

        scottalanmillerS 1 Reply Last reply Reply Quote 0
        • DustinB3403D
          DustinB3403
          last edited by DustinB3403

          I wonder if this company even has any DR plans for their customers and services. Pretty much DRaaS. Even a free tool like UrBackup would speed up the process of recovery for every client if it was in place prior to this occurring.

          1 Reply Last reply Reply Quote 0
          • scottalanmillerS
            scottalanmiller @black3dynamite
            last edited by

            @black3dynamite said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

            Is there a possibility that some of the clients have an on-site IT too? I saw that list of employees, maybe of some them use to work in IT but decided to move on to the business side instead can help with re-imaging computers.

            Possible, but chances are the other people are tied up trying to put out the account fires.

            DustinB3403D 1 Reply Last reply Reply Quote 0
            • DustinB3403D
              DustinB3403 @scottalanmiller
              last edited by

              @scottalanmiller said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

              account fires

              Those aren't able to be "put out" as the account has absolutely nothing to do with poor MSP support and planning. Or a lack of business DR planning.

              They have a right to be ticked off and shouting.

              1 Reply Last reply Reply Quote 0
              • DustinB3403D
                DustinB3403
                last edited by

                I'm curious what systems Protek has in place that, their vulnerability was spread to their clients data.

                Simple passwords? Hosted Services? Shared Services?

                scottalanmillerS 1 Reply Last reply Reply Quote 1
                • scottalanmillerS
                  scottalanmiller @DustinB3403
                  last edited by

                  @DustinB3403 said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                  I'm curious what systems Protek has in place that, their vulnerability was spread to their clients data.

                  Simple passwords? Hosted Services? Shared Services?

                  No idea. Maybe VPNs for remote management. That's the most common vector for this. Or we've heard that unpatched ConnectWise is a popular target for it too.

                  1 Reply Last reply Reply Quote 2
                  • DustinB3403D
                    DustinB3403
                    last edited by

                    TeamViewer maybe?

                    I'm honestly just not sure how and where a risk like this could be spread so quickly. Unless there was something so blatantly obvious that it's borderline intentional to have caused this.

                    @scottalanmiller said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                    No idea. Maybe VPNs for remote management. That's the most common vector for this. Or we've heard that unpatched ConnectWise is a popular target for it too.

                    Yeah those are possibilities.

                    Their website says "Protek provides unlimited onsite and remote support from local certified technicians." meaning some type of remote access.

                    I'm curious if they kept all of their client passwords in an unprotected excel spreadsheet too. . .

                    scottalanmillerS ObsolesceO 3 Replies Last reply Reply Quote 1
                    • scottalanmillerS
                      scottalanmiller @DustinB3403
                      last edited by

                      @DustinB3403 said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                      TeamViewer maybe?

                      I'm honestly just not sure how and where a risk like this could be spread so quickly. Unless there was something so blatantly obvious that it's borderline intentional to have caused this.

                      Doesn't necessarily have to spread quickly. Might have taken its time and triggered all at once.

                      1 Reply Last reply Reply Quote 1
                      • DustinB3403D
                        DustinB3403
                        last edited by

                        Oh right on their website

                        https://protek.screenconnect.com/

                        coliverC 1 Reply Last reply Reply Quote 0
                        • scottalanmillerS
                          scottalanmiller @DustinB3403
                          last edited by

                          @DustinB3403 said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                          Their website says "Protek provides unlimited onsite and remote support from local certified technicians." meaning some type of remote access.

                          We know that they do remote management, but that's all that we know.

                          1 Reply Last reply Reply Quote 0
                          • coliverC
                            coliver @DustinB3403
                            last edited by

                            @DustinB3403 said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                            Oh right on their website

                            https://protek.screenconnect.com/

                            Hosted Screenconnect. That should have been patched by Connectwise.

                            scottalanmillerS DustinB3403D 2 Replies Last reply Reply Quote 3
                            • Reid CooperR
                              Reid Cooper
                              last edited by

                              What would MSPs do in a situation like this? It must be case by case, but do you pay the ransom and hope that the data really gets unlocked? That's a huge risk.

                              If they have good backups and processes, hopefully they don't need to pay the ransom. But it doesn't sound like they do if they have been down for so long and are not progressing yet.

                              RojoLocoR 1 Reply Last reply Reply Quote 0
                              • scottalanmillerS
                                scottalanmiller @coliver
                                last edited by

                                @coliver said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                @DustinB3403 said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                Oh right on their website

                                https://protek.screenconnect.com/

                                Hosted Screenconnect. That should have been patched by Connectwise.

                                Good catch. Might just be one of many tools that they use, though.

                                1 Reply Last reply Reply Quote 1
                                • DustinB3403D
                                  DustinB3403
                                  last edited by

                                  It's funny how their website is setup. Each portal is different from the last, none that are remotely similar.

                                  Just as a customer that would raise a red flag for me when having been through the selection process. Something else is that all of their support pages make the boast that "local certified support".

                                  Which, no problem, everyone needs to eat. But what if a bus just happens to come crashing through your office. All support is gone.

                                  Throw some global support options in there. Especially since they have ScreenConnect. Literally 0 reason to require local on-site only staff.

                                  LilAngL scottalanmillerS 2 Replies Last reply Reply Quote 1
                                  • LilAngL
                                    LilAng @DustinB3403
                                    last edited by

                                    @DustinB3403 said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                    It's funny how their website is setup

                                    You should see the get to know us page and hover over the pictures.

                                    1 Reply Last reply Reply Quote 3
                                    • DustinB3403D
                                      DustinB3403 @coliver
                                      last edited by

                                      @coliver said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                      @DustinB3403 said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                      Oh right on their website

                                      https://protek.screenconnect.com/

                                      Hosted Screenconnect. That should have been patched by Connectwise.

                                      Yeah, but still wouldn't do anything to prevent bad password policy.

                                      1 Reply Last reply Reply Quote 0
                                      • RojoLocoR
                                        RojoLoco @Reid Cooper
                                        last edited by

                                        @Reid-Cooper I would NEVER hire or even consider an MSP that paid a ransom. That means they are incapable or unwilling to make and test backups, so that's a hard no.

                                        DustinB3403D scottalanmillerS EddieJenningsE 3 Replies Last reply Reply Quote 1
                                        • DustinB3403D
                                          DustinB3403 @RojoLoco
                                          last edited by

                                          @RojoLoco said in Protek Support MSP Ransomware Hits Customers in Salt Lake City, Utah:

                                          @Reid-Cooper I would NEVER hire or even consider an MSP that paid a ransom. That means they are incapable or unwilling to make and test backups, so that's a hard no.

                                          And taking and testing backups is literally one of the things that they say they do!

                                          So to have taken this long to get up and running means either they are lying about their capabilities, their backups were hit as well or that they've never taken any backups!

                                          RojoLocoR 1 Reply Last reply Reply Quote 1
                                          • RojoLocoR
                                            RojoLoco @DustinB3403
                                            last edited by

                                            @DustinB3403 ransomware can't hit those air-gapped, offsite backups... oh, wait.

                                            1 Reply Last reply Reply Quote 3
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 1 / 6
                                            • First post
                                              Last post