Wannacry Ransomware

On Friday the 12th of May a large cyber attack occurred infecting computers all around the world. In the UK, many NHS systems were affected bringing IT systems to a halt. Researchers indicate it is not clear why this particular event occurred so quickly, it is unlikely to simply be people clicking on links in emails, which is one way these viruses end up on computers. One researcher accidentally found a “Kill Switch” for this virus on Friday afternoon which stopped computers encrypting disks around the world. So while this last major event stopped pretty soon after it started, other variants have already appeared, but have not propagated as quickly as the one on Friday.

I have visited a few of my clients over the years, because of the nature of the business and the low IT budget, computers are often old and frequently not up to date. Another feature is some do not have any anti-virus software running on them either. These circumstances can leave you open to an attack of this type and many other less crippling viruses. 

All of the websites I have built are protected by the WordFence plugin. The WordFence organisation send out alerts which I subscribe to, the most recent one listed some information on Wannacry and what happened.

What is particularly important in this case is Microsoft released a patch in March 2017 for their operating systems which if applied would have prevented Wannacry from working. Those people that automatically or manually updated their computers were protected. In my experience, many systems do not automatically update the operating system. So it is worth taking a couple of minutes to check through this list both for your personal and your charity computer systems to ensure you are protected.

The Wordfence team released the following guidance to Windows users:

Self Help Checklist*

  1. If you use Windows, install the patch that Microsoft has released to block the specific exploit that the WannaCry ransomware is using. You can find instructions on this page in the Microsoft Knowledge Base. You can also directly download the patches for your OS from the Microsoft Update Catalog.
  2. If you are using an unsupported version of Windows like Windows XP, Windows 2008 or Server 2003, you can get the patches for your unsupported OS from the Update Catalog. We do recommend that you update to a supported version of Windows as soon as possible.
  3. Update your Anti-virus** software definitions. Most AV vendors have now added detection capability to block WannaCry.
  4. If you don’t have anti-virus software enabled on your Windows machine, we recommend you enable Windows Defender which is free.
  5. Backup regularly and make sure you have offline backups. That way, if you are infected with ransomware, it can’t encrypt your backups.
  6. For further reading, Microsoft has released customer guidance for the WannaCry attacks and Troy Hunt has done an excellent detailed writeup on the WannaCry ransomware.

* this checklist came from a mailing from Wordfence. You can read the full article here.  

** If you are not running any anti-virus software you should consider a package that includes security as well. I personally use Smart Security from Eset, and have done so now for around 18 years. You can get a substantial discount from Eset if you are a charity. 

Wingrove-Services
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

You can adjust all of your cookie settings by navigating the tabs on the left hand side.

My privacy policy can be located here: Wingrove Media Privacy Policy (opens in a new window)

My Cookies Policy can be found here: Wingrove Media Cookies Policy (opens in a new window)