Sage 100

 View Only
Expand all | Collapse all

Ransomware attack and Summit Hosting

  • 1.  Ransomware attack and Summit Hosting

    Posted 01-21-2020 11:32
    Anyone hear any information regarding this?

    Had one of my largest clients call me first thing Monday and said they couldn't get into their Sage 100.   Logged into their server remotely and discovered that Saturday afternoon they had a ransomware attack.  I figured that in the cloud hosting environment they should have good snap shot backups to restore to for what I suspect is a virtual machine.

    Checked in with them again today and it appears there servers in Atlanta had been hit and it affected 1000's (I don't know how accurate that number is) of clients.

    As of this morning my client is still down and don't have an ETA.  :(

    ------------------------------
    Thomas Rogers (TomTarget)
    Target System Technology, Inc.
    Spokane Valley WA
    ------------------------------


  • 2.  RE: Ransomware attack and Summit Hosting

    Posted 01-21-2020 11:50
    I don't have any news of particulars but here is their online status page 

    https://summithosting.statuskeeper.io/


    ------------------------------
    Wayne Schulz - Schulz Consulting - 860-516-8990
    ------------------------------



  • 3.  RE: Ransomware attack and Summit Hosting

    Posted 01-21-2020 12:28

    I reached out to Summit to ask what was going on and this is what they provided: 

    Summit is experiencing a problem that's impacted approximately 300 of our 5000 servers. There was an attack, and our security system caught it before it could spread and now we're just being extra cautious as we bring the servers back up. We expect that the majority will be back up by tomorrow morning at the latest.



    ------------------------------
    Wayne Schulz - Schulz Consulting - 860-516-8990
    ------------------------------



  • 4.  RE: Ransomware attack and Summit Hosting

    Posted 01-22-2020 07:16
    It is now Wednesday morning and multiple clients are still down.  They have had issues last week on a different section of their clients.  They have had issues a year or so ago and said they had evaluated their systems and resolved the issues and strengthen their controls.  My companies install is impacted.  I am in the busiest week of the year and have no access since Saturday.

    ------------------------------
    Larry Bradford
    Accounting Technology LLC Consultant and Owner
    Accounting Technology, LLC
    Fairfax VA
    703-913-3500
    ------------------------------



  • 5.  RE: Ransomware attack and Summit Hosting

    Posted 01-23-2020 18:34
    Thursday afternoon and my client is still down.  No ETA provided.  :(

    Getting (well it already is) painful.

    ------------------------------
    Thomas Rogers (TomTarget)
    Target System Technology, Inc.
    Spokane Valley WA
    ------------------------------



  • 6.  RE: Ransomware attack and Summit Hosting

    Posted 01-23-2020 18:45
    Finally back up and they are restoring to Wednesday Night.  You should be seeing them back up very soon.

    ------------------------------
    Larry Bradford
    Accounting Technology LLC Consultant and Owner
    Accounting Technology, LLC
    Fairfax VA
    703-913-3500
    ------------------------------



  • 7.  RE: Ransomware attack and Summit Hosting

    Posted 01-24-2020 11:24
    I hope so.

    ------------------------------
    Thomas Rogers (TomTarget)
    Target System Technology, Inc.
    Spokane Valley WA
    ------------------------------



  • 8.  RE: Ransomware attack and Summit Hosting

    Posted 01-27-2020 19:17
    Worst case scenario for my client!   NO BACKUPS of their data drives!  So much for the sense of security that your cloud server provider is keeping you safe.    :(     #$%&@#$^#^$#$^

    I found a two year old copy of their system on my servers.   Will help in trying to reestablish a system but this won't recover their data. :(


    ------------------------------
    Thomas Rogers (TomTarget)
    Target System Technology, Inc.
    Spokane Valley WA
    ------------------------------



  • 9.  RE: Ransomware attack and Summit Hosting

    Posted 01-27-2020 19:59
    What?!?!? No backup?

    Sent from my iPhone

    ------Original Message------

    Worst case scenario for my client!   NO BACKUPS of their data drives!  So much for the sense of security that your cloud server provider is keeping you safe.    :(     #$%&@#$^#^$#$^

    I found a two year old copy of their system on my servers.   Will help in trying to reestablish a system but this won't recover their data. :(


    ------------------------------
    Thomas Rogers (TomTarget)
    Target System Technology, Inc.
    Spokane Valley WA
    ------------------------------


  • 10.  RE: Ransomware attack and Summit Hosting

    Posted 01-27-2020 20:15
    Apparently they were backing up the c: drive,  but not the d: drive where all the data was.  Unbelievable.

    Not clear but,  I don't think they have anything.   Word,  excel, whatever.  This is the kind of thing that puts companies out of business.

    Scuttlebutt I heard is that they managed to recover most of the clients affected but there are a handful in this situation.   Ransomware people want millions of dollars to recover the entire Summit servers because they want it for everything not just the clients that could not be recovered.

    ------------------------------
    Thomas Rogers (TomTarget)
    Target System Technology, Inc.
    Spokane Valley WA
    ------------------------------



  • 11.  RE: Ransomware attack and Summit Hosting

    Posted 01-28-2020 07:57
    We need to stop calling them "backup" systems - they are "restore" systems.  If you don't test a restore periodically when you don't actually need it you don't know if it will be there when you do need it.  This applies no matter who or where your Id10T  department is...

    ------------------------------
    Phil McIntosh
    President
    Friendly Systems, Inc.
    Asheville NC
    678.273.4010 ext 5
    ------------------------------



  • 12.  RE: Ransomware attack and Summit Hosting

    Posted 01-28-2020 10:41
    Exactly.  If you don't test your redundant systems / storage, then you don't know the resources will be there when REALLY needed.
    Nobody wants to talk in detail about backups until disaster strikes (at which point it's too late to make changes).

    Business user: I need backups.
    Tech provider: we can do X.
    Business user (full of naive trust): OK.
    <end of discussion>

    *facepalm*

    ------------------------------
    Kevin Moyes
    Technical Systems Analyst
    Munjal White Consulting Co.
    Toronto ON
    ------------------------------



  • 13.  RE: Ransomware attack and Summit Hosting

    Posted 01-28-2020 09:05
    Tom, any word on your client? A two year old copy!  I hate to think a ransom will get paid.  That shoots us all in the foot.  I'm recommending a good old fashioned local copy once a week as a fail safe.  But who wants to go back to those days?

    ------------------------------
    ==================
    Rhonda McNamara
    Customer Success Manager
    Stewart Technologies, Inc.
    rsm@stewarttechnologies.com
    ------------------------------



  • 14.  RE: Ransomware attack and Summit Hosting

    Posted 01-28-2020 08:09
    Once I heard about another ransomware attack on a cloud host I suggested to an existing user that they request a way to download at least their \MAS90 folder. We could download through the RDP connection but the host ( Applianz ) suggested they create an SFTP. Still waiting to hear back.

    I know my clients who rely on shipping would be absolutely crazy/insane if their shippers were sitting idle for more than a day.

    I suggest that from the client-side disaster recovery means having a reasonably current full copy of data that does NOT rely on the cloud host to provide in an emergency. Offline storage is dirt cheap. You can buy TB sized USB drives for under $100. Just copying the data monthly could save hundres of thousands of dollars of business interruption losses.

    As I think we've seen/heard -- during ransomware or any other type of disaster --  the cloud hosts are too busy "keeping the plane flying" to provide onesie and twosie copies of backups. 




    ------------------------------
    Wayne Schulz - Schulz Consulting - 860-516-8990
    ------------------------------



  • 15.  RE: Ransomware attack and Summit Hosting

    Posted 01-28-2020 09:48
    Should be an interesting affiliate session at MOTM.

    ------------------------------
    Jeff Schwenk
    FORMER 90M Board Member
    Bottomline Software, Inc.
    Waynesboro VA
    540-221-4444
    ------------------------------



  • 16.  RE: Ransomware attack and Summit Hosting

    Posted 01-28-2020 09:51


    ------------------------------
    Wayne Schulz - Schulz Consulting - 860-516-8990
    ------------------------------



  • 17.  RE: Ransomware attack and Summit Hosting

    Posted 01-28-2020 14:22
    I'm definitely changing my approach to backups.   Sad to say it is now trust no one even the big cloud hosting companies.

    I'm not entirely sure if there were backups at one time and somehow they got turned off inadvertently or what.

    ------------------------------
    Thomas Rogers (TomTarget)
    Target System Technology, Inc.
    Spokane Valley WA
    ------------------------------



  • 18.  RE: Ransomware attack and Summit Hosting

    Posted 01-28-2020 14:46
    Edited by Rhonda McNamara 01-28-2020 14:46
    I'm no expert on ransomeware or viruses, but i imagine if you backup to the same box every day, you stand a fair chance of infecting your backup if you don't quarantine those servers in time.

    ------------------------------
    ==================
    Rhonda McNamara
    Customer Success Manager
    Stewart Technologies, Inc.
    rsm@stewarttechnologies.com
    ------------------------------



  • 19.  RE: Ransomware attack and Summit Hosting

    Posted 01-28-2020 15:04
    Just talked to the client a few minutes ago.

    They indicated they had done some restore from backups in the last couple of weeks.  So it begins to sound like the ransomware somehow infected the backups or is preventing them from getting into the backups.

    ------------------------------
    Thomas Rogers (TomTarget)
    Target System Technology, Inc.
    Spokane Valley WA
    ------------------------------



  • 20.  RE: Ransomware attack and Summit Hosting

    Posted 01-28-2020 15:10
    Online, connected, always available backups may protect against hardware failures, but not viruses.

    ------------------------------
    Kevin Moyes
    Technical Systems Analyst
    Munjal White Consulting Co.
    Toronto ON
    ------------------------------



  • 21.  RE: Ransomware attack and Summit Hosting

    Posted 01-29-2020 01:37

    Here's an interesting tid bit that I can share as one of those providers. 

    We have started including this option as of last year when the wave of ransomeware started hitting: 

    on our fully managed plans (which is most of our clients), we offer a 1 time per year test fail over request from a client. (Not to be confused with restoring their data in place, which is also possible), but rather failing them over to a data center in the opposite side of the country and allowing them to access their hosting service from that data center and verify things. 

    It is offered as part of what they are paying for their peace of mind. 

    Now, please take a guess how many of these clients have taken us up on this offer. *cough* zero *cough*

    p.s we still do our test fail overs internally on a routine basis, but the above information should also be an indicator that not only is it the cloud hosting provider that is not doing enough, but the business owners themselves don't put enough importance on their own data until it's too late. Granted, I don't know how many cloud hosting providers offer such a service. 



    ------------------------------
    George Khairallah
    CTO | gotomyerp, LLC
    george.k@gotomyerp.com | 877-888-5525
    http://gotomyerp.com/
    ------------------------------