FT: Sweden’s Coop shuts grocery stores as more than 1,000 businesses hit by hacking spree

That article is behind a pay wall, the BBC has some coverage:

Coop Sweden says it closed more than half of its 800 stores on Friday after point-of-sale tills and self-service checkouts stopped working.

A spokeswoman for Coop Sweden told the BBC: "We first noticed problems in a small number of stores on Friday evening around 6:30pm so we closed those stores early. Then overnight we realised it was much bigger and we took the decision not to open most of our stores this morning so that our teams could work out how to fix it.

“The whole paying system at our tills and our self-service checkouts stopped working so we need time to reboot the system.”

It’s understood that Coop doesn’t use Kesaya directly on it’s systems but that one of their software providers does.

1 Like

Oops sorry I didn’t know - upon closer look, the site says the article can will be free for first 3 readers… Oh boy this link feature is not all that useful :sweat_smile:

Here’s the full article:

Russia-linked hackers target IT supply chain with ransomware Sweden’s Coop shuts grocery stores as more than 1,000 businesses hit by hacking spree Hackers are weaponising the IT supply chain in order to attack victims at scale by breaching just one provider

Hackers began a global ransomware attack on Friday, hitting more than 1,000 companies, and forcing Sweden’s Coop grocery chain to close hundreds of stores.

In what appears to be one of the largest supply chain attacks to date, hackers compromised Kaseya, an information technology management software supplier, in order to spread ransomware to the managed service providers that use its technology, as well as to their clients in turn.

Cyber security group Huntress Labs said on Saturday that it had identified 20 compromised managed service providers, with more than 1,000 of its clients falling victim to ransomware attacks — where data is encrypted by hackers and only released if a ransom is paid.

Among them, Coop in Sweden said it had closed all but five of its 800 stores on Saturday, after the attack meant its cash register system and self-service checkouts had stopped working. Coop was affected after its managed service provider Vissma Escom was hit, it said.

Huntress attributed the attacks to REvil, the notorious Russia-linked ransomware cartel that the FBI claimed was behind recent crippling attack on beef supplier JBS.

During a trip to Michigan on Saturday, Joe Biden said he had been briefed on the attacks and ordered US government agencies to investigate who was behind them but there was not indication so far that they were state sponsored. “The initial thinking was it was not the Russian government, but we’re not sure yet,” the US president said.

The incident is the latest example of hackers weaponising the IT supply chain in order to attack victims at scale, by breaching just one provider. Last year it emerged that Russian state-backed hackers had hijacked the SolarWinds IT software group in order to penetrate the email networks of US federal agencies and corporations.

Kaseya said in a blog post that it had been the victim of a “sophisticated cyber attack” and that about 40 of its direct 36,000 customers had been affected. It urged those using the compromised “VSA server” tool, which provides remote monitoring and patching capabilities, to shut it down immediately.

“We have been advised by our outside experts, that customers who experienced ransomware and receive communication from the attackers should not click on any links — they may be weaponised,” it said.

“We believe that we have identified the source of the vulnerability and are preparing a patch to mitigate it for our on-premises customers that will be tested thoroughly,” the company added.

On Saturday night the FBI said it was investigating the ransomware attacks and was working with Kaseya and the US Cybersecurity and Infrastructure Security Agency to contact victims.

"We encourage all who might be affected to employ the recommended mitigations and for users to follow Kaseya’s guidance to shut down VSA servers immediately,” the agency said in a statement.

Allan Liska of Recorded Future’s computer security incident response team said that the clients of managed service providers tended to be small and medium size companies seeking IT support, with the attacks highlight the risks of relying on centralised third parties.

"We’ve essentially handed over too much trust so that if something happens to them, it becomes a catastrophic event for your organisation through no fault of your own,” he said. In an alert on Friday, the company said that it was “taking action to understand and address the recent supply-chain ransomware attack”.

The campaign is the latest in a series of audacious ransomware attacks this year, including one on America’s Colonial Pipeline, which have prompted pledges from the Biden administration to crack down on perpetrators.

At last month’s Geneva summit, president Joe Biden urged Russian president Vladimir Putin to rein in ransomware hackers, many of which are believed to operate with impunity in the country.

2 Likes