What to do when the big guys get hit
# What to do when the big guys get hit
My inbox this week looks like a disaster zone. There were 404 stories about data breaches in the last seven days alone. For most of you, that's just noise. You aren't running an airport or a global clothing brand. You don't have a SOC to monitor traffic or a legal team on retainer to draft apology emails.
You have a budget that barely covers the coffee machine and a "server" that is actually just a dusty Dell under someone's desk. When you see headlines about 12.9 million accounts leaked from Carhartt, your first instinct is probably to ignore it because you aren't Carhartt. That’s a mistake. You don't need to worry about how they got hit; you need to worry about what happens now that the data is out there.
Here are three questions from the mailbag.
**Sarah, Des Moines: "I saw the news about the Carhartt breach and those millions of people affected. Should I be spending money on a security audit for my boutique to make sure we aren't vulnerable to the same thing?"**
Sarah, take a breath. You don't need an expensive audit. The attackers who hit a massive retail target aren't looking for your boutique; they're looking for a huge pile of data they can sell or use to get into other systems.
The real risk to you isn't that someone will "hack" your shop using the same method. It's that your employees likely used the same password for their Carhartt account as they do for their work email. Once those 12.9 million records are traded on a forum, criminals start "credential stuffing"—trying those email and password combinations on every other site they can find.
Don't buy an audit. Just make sure every single person in your shop has MFA turned on for their email and accounting software. It's free or cheap, and it stops a stolen password from being a skeleton key to your business.
**Mike, Austin: "The Boston Scientific attack is causing shipment delays for medical gear. I run a small clinic. How do I protect myself when the vulnerability isn't in my system, but in my supplier's?"**
This is where things get ugly. This isn't a data leak; it's a physical failure. When a manufacturer stops shipping devices, the hospitals and clinics downstream are the ones who actually bleed.
Most "vendor risk management" advice you'll find online is written for companies with thousands of employees. They'll tell you to send out 50-page security questionnaires. For a small shop, that's a waste of time. Your supplier probably won't fill it out, and if they do, they'll just lie.
The only real defense here is redundancy. If your entire operation relies on one vendor for a critical piece of equipment, you aren't managing risk; you're gambling. Look at your most critical supplies. If one company goes dark for three weeks—like Boston Scientific has—do you have a second source? Even if the second source is more expensive or slower, that price difference is actually an insurance premium.
**David, Seattle: "I keep seeing things about 'supply chain attacks' and these TeamPCP guys getting arrested in Australia. We don't write software here, so I assume this doesn't apply to us?"**
It absolutely applies to you. You don't have to be a developer to be a victim of a supply chain attack. The TeamPCP group targeted the tools that developers use, but the end result is malware that ends up in the software you buy and install.
Think of it like a food recall. You didn't grow the lettuce, but if the farm used contaminated water, you still get sick when you eat the salad.
The "simply deploy" crowd will tell you to buy an EDR tool to catch this. That costs a fortune in licenses and requires someone to actually watch the alerts. Instead, stick to boring controls. Keep your software updated. I know patching is a chore, but it's the only way to close the holes that these groups exploit.
Look at the CISA KEV list from this week. They just added several flaws, including one for Microsoft SQL Server (CVE-2019-1068) and another for Citrix NetScaler. For federal agencies, the deadline to patch the NetScaler bug was August 29. You aren't a federal agency, but the people attacking those agencies use the same scripts against everyone else.
An enterprise spends millions on "visibility." A small shop survives by reducing the surface area. If you don't need a service facing the public internet, turn it off. If you can't patch it today, put it behind a VPN.
It isn't glamorous work, and it doesn't make for a good slide deck, but it works. Stop looking for a sophisticated solution to a problem that is usually solved by a reboot and a password change.
Check your backup logs this Friday. Not just the "success" checkmark, but actually try to restore one file from last month to make sure the data isn't corrupted.
◼
Sources
The reporting this analysis was built from. Follow the originals before acting on anything here.
- Carhartt data breach exposes information of 12.9 million accounts BleepingComputer
- Australia charges two men for TeamPCP supply-chain hacking spree The Record
- 12.9M Exposed by Carhartt Data Breach - Security Magazine Google News Security
- 2.8M affected in Baylor Genetics breach involving medical data - WLWT Google News Security
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs The Hacker News
- US Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure Attacks SecurityWeek
- Boston Scientific Cyberattack Halts Shipments: Weeks of Device Delays Threaten Hospital Supply - Tech Times Google News Security
- White House bans foreign-made equipment for power generation over cyber backdoor concerns The Record