Growing Risk of Data Sabotage: Protecting Law Enforcement Agencies
By Michael Gregg, M.B.A.
While cybersecurity becomes more important for law enforcement organizations across the country, one specific threat—the data-sabotage attack—should be prioritized above all others. Recently, several local agencies experienced one type of assault known as “ransomware.”1 In these attacks, cybercriminals lock agencies’ files and other types of data behind almost unbreakable walls of encryption, rendering them entirely inaccessible and unusable. Recent strikes targeted police and sheriff’s departments in Massachusetts, Maine, Illinois, and Tennessee.2 In all of these incidents, the criminals had financial motivations—the targeted agencies paid ransoms to the perpetrators, and the files were decrypted.3
What if these hackers were not motivated by money?4 What if they refused to decrypt the data, and police departments never could access it again?5 What would happen if the files included autopsy reports, witness statements, or crime scene photographs?6 Law enforcement professionals must prepare for these possibilities. Changes in society and criminal culture have created an environment that could promote more vicious data-sabotage attacks in the future.
Recognizing the Goal
Two categories of data sabotage exist—the “crypto,” or encryption attack exemplified best by ransomware, and the “wiper” assault, which does not lock up files, but deletes them and destroys the computers and servers where they reside.7 The number of ransomware viruses (e.g., CryptoLocker, CryptoWall, TeslaCrypt, and AlphaCrypt) continues to grow.8
Security vendors have ascertained ways to mitigate some types of ransomware; however, certain versions remain impenetrable and are not removable without destroying the data that was held hostage.9 Cybercriminals with monetary goals primarily hold responsibility for these attacks. Several law enforcement organizations across the United States paid ransoms to get their files back.10
The wiper is designed to excise documents and data and cripple the computers and servers that store them.11 This type of attack recently struck several major U.S. corporations and affected businesses around the world, including energy conglomerates, gas companies, banks, and television stations.12 Wiper assaults typically result from politically sponsored hacking groups.
Mr. Gregg is a consultant and
the founder and CEO of a cybersecurity company in Houston, Texas.
Understanding the Threat
Ransomware and wipers have existed for years, so why do they pose a greater threat to law enforcement now? There are several important changes occurring within society and amidst the criminal economy. When viewed independently these cause concern; however, when considered as part of a larger entity, law enforcement can understand the severity of the threat.
- The black market for cybercrime, where criminals purchase hacking tools—referred to as “crimeware”—is highly organized.13
- Black markets also sell ransomware and wiper malware.14
- There is an increase in hacker-for-hire services, with a number of Internet sites offering to connect people with hackers who can handle sensitive jobs, ranging from hacking a spouse’s social media password to erasing a criminal record.15
- Antagonism is growing between law enforcement and local communities, with current policing methods facing increased scrutiny.
- Online activism progressively is becoming more a part of police protests, with “hacktivists”—online activists and hackers focused on social or political causes—threatening to release sensitive information about officers or departments.16
- Crimeware surpassed user errors and insider abuse as the top cyberthreat for law enforcement agencies, courts, and other government bodies. It was 2.4 times higher in 2015 than in 2014, while other categories decreased.17
These trends indicate that hacking tools are becoming substantially more powerful and sophisticated. Almost anyone can access them, and citizens frequently view attacks on police as justifiable.
The main reason ransomware attacks on police departments have not been detrimental is because the hackers were motivated by money—once they were paid, they moved on. Law enforcement professionals should be concerned when a perpetrator who is not compelled by money, but instead wants to cause as much damage as possible, launches this type of assault. Data sabotage, whether a wiper or encryption virus, fits the motivation of hacktivists and criminals who want to thwart a law enforcement investigation or disrupt an agency.
There are no technological obstacles to launching these assaults. Law enforcement departments are fortunate because they have not been targets of widely destructive cyberattacks. However, cultural changes increase the likelihood that such strikes could occur in the future. Agencies must prepare for the worst-case scenario.
In the vast majority of cases, a malware infection stems from an employee opening a malicious e-mail—a “phishing” attempt—and clicking on an embedded link or downloading an attachment.18 However, this is not the only way for ransomware, wipers, and other dangerous malware to infiltrate law enforcement organizations.
Increasingly, criminals corrupt legitimate websites with malicious code that hacks a computer as soon as someone visits a webpage on it.19 If a perpetrator already infected an agency’s system with a “trojan,” which provides a backdoor to the network, the malefactor can use this to install ransomware or wipers the same way an individual runs updates on the computer.20
There is no room for error when dealing with a data-sabotage attack because of the potential for catastrophic damage. The best protection is a layered defense.
First, agencies must establish formidable perimeter security, including a strong firewall and a robust antivirus or malware-exposure program with built-in phishing detection. They should schedule both the firewall and antivirus to update automatically and ensure all other software is current. Organizations also can use e-mail “whitelisting” to prevent employees from receiving e-mails from anyone except trusted contacts. In addition, they can install application-whitelisting software on computers, which will prevent unwanted programs from running on the network. Individuals should apply “password managers,” which securely store access codes for all of their accounts. This encourages use of strong, unique passwords. Another way to boost the perimeter defense is to replace some of the department’s standard computers with “thin clients.” These do not store data or programs locally on the computer; instead, everything is done by connecting to the server or using cloud-based tools. This dramatically reduces the risk of an attack.
Second, organizations must establish a strong backup defense in case attackers sneak past the perimeter. The best way to do this is to ensure that employees have their own dedicated storage on regularly backed-up servers. Data caching must occur routinely, at least once a day; however, individuals should not leave these devices on the network at all times because malware also could infect them. Network segmentation prevents an infection from spreading laterally across the entire agency.21 Departments should not allow any one employee to have excessive access to critical data or networks.
Finally, if possible, agencies should set up intrusion-detection and -prevention systems (IDS/IPS) and exfiltration monitoring. These tools continually scan the network for any unusual activity indicating a system breach by a hacker.
Considering the Worst-Case Scenario
If a ransomware or wiper attack occurs, the entire network must be shut down immediately.22 No one should attempt to restart the network until a cyber-incident response team—either government or private—assesses the situation. It is imperative to have an emergency-contact sheet and incident-response plan prepared beforehand.
In cases with a ransom demand, agencies must consider the pros and cons before deciding to negotiate. Cybercriminals may or may not release the data or target the same agency again.23 Usually, the offenders give back the files once the ransom is paid. They operate these schemes like businesspersons and do not want a negative reputation. These individuals want people to pay them, and with a reputation diminished by not following through on a decryption promise, fewer people will pay. If the information is such that the department wants to make a ransom attempt, it is important for them to consult with an IT-security professional who can work to prevent any secondary infections.
Law enforcement agencies face a growing number of cyberthreats from a variety of criminal groups, but the most critical risk is the data-sabotage attack. Currently, this threat occurs most often in ransomware assaults by cybercriminals out to make money. Due to the changing criminal environment and current society, these attacks could become more malicious and destructive in the future. Because these cyberattacks could undermine investigations and disrupt operations, it is important for law enforcement administrators to prioritize this threat when developing their IT-security programs. It is impossible to prevent every attack; however, by creating a layered defense that focuses equally on prevention and postinfection damage control, departments can protect their most critical operations and assets from serious harm.
For additional information the author may be contacted at firstname.lastname@example.org.