

Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Offline and pull based backups FTW... This is why I advocate for a pull or at least push/pull model for backups... where the remote system pulls backups out of your production environment, or otherwise from a drop point. Because a corrupt production system that controls backups can corrupt backups.
If your production system at most runs a backup to a drop site, then your backup facilities pull down versioned backups from there, you can better ensure older backup files are intact. More so by not allowing the two to see each other at all and not using backup accounts from a system that can access production resources.
by tracker1 - > This is why I advocate
No need to advocate on established best practices. The 3-2-1 rule and its variations are already common place and often mandated by standards/investors and partner contracts.
https://connection-technologies.co.uk/help/backup-disaster-r...
by khurs - Enterprise storage arrays have immutable snapshot functionality that makes ransomware easy to recover from.by UltraSane
- What does it take to delete a snapshot?by iAMkenough
- The UK used to have a distributed system - everyone had to have a solicitor store "deeds" of their property, which were a sort of paper blockchain of all the transactions the land had been in since - I don't know, since records began I guess. Since we got a centralised land registry cheaper solicitors have binned these, but some properties still have them as a historical record.by ajb
- You’ll see this as a plot device in some Regency pieces. Someone gets ahold of the physical deed to a property and now there’s drama.by hinkley
- Not sure what you mean by 'binned'. In some Common Law jurisdictions the deed document represents the property and whoever psychically holds of the deed controls the property. Any centralized recording system merely records the last known status of the deed and additional information such as the nominal owner, mortgage holders, etc.by nutjob2
- > since records began I guess
Possibly since 1086
by mr_toad - Poor password practice and policy, and likely a lack of 2FA / physical token security, seem to have contributed to this breach.
Posts and screenshots apparently by the alleged attacker show "P@ssw0rd" and other well-known / readily-guessable passwords from the hacked systems:
<https://spear.cx/Thread-Selling-RO-Thy-arss-shall-be-spanked...>
<https://drive.google.com/file/d/1iZc93XfViOk7izusgIG1ni7Kmsx...>
Originally noted, without references, by ExoticPearTree here: <https://news.ycombinator.com/item?id=48978836>.
NB: If you're going to point out stupidity verging on cliched tropes, do so with sufficient evidence that it doesn't read as a tired and unsubstantiated canard. The fact that this does happen (and apparently did) doesn't mean it's necessarily the case in any specific instance.
by dredmorbius - For me the first 2FA devices I’d had were for work but for my friends it was for a world of Warcraft. And it was years until my bank offered 2FA. I still think about that every time there is a breach.
Blizzard gave hardware tokens out to the entire convention one year. Smart phones became a variable not long after and then they didn’t make them mandatory but game guilds almost universally did. Especially for officers.
by hinkley - The same thing happened to Slovakia not that long ago.by Squarex
- how did they solve it?by boringg
- Accounts at the time:
"1T+ in assets are frozen as Slovakia's Land Registry faces ransomware attack" <https://spectator.sme.sk/politics-and-society/c/news-digest-...> (9 Jan 2025) HN discussion (1 comment): <https://news.ycombinator.com/item?id=42650343>
"Ransomware Attack Paralyzes Slovakian Land Registry, Souring Slovakia-Ukraine Relations" <https://dailysecurityreview.com/security-spotlight/slovakian...> (January 14, 2025)
"Slovakia Hit by Historic Cyber-Attack on Land Registry " <https://www.infosecurity-magazine.com/news/slovakia-hit-by-l...> (10 January 2025)
Apparently tied to Ukraine in this case.
by dredmorbius - The Slovak land register was hacked in January 2025. Hackers uknown encrypted the database, asking for an undisclosed 7-figure amount as ransom.
The whole country's real estate market was paralyzed for about a month. It took couple of months to restore everything from backups and paper agenda and resume normal operation of the land register office.
It was the largest cyber attack in Slovakia's history. The authorities to this day haven't provided any information on who might be behind it. The investigation is still ongoing. Several government figures including the PM were however very eager to immediately point on Ukraine, without any sort of proof.
by martin_ky - The backups got wiped together with the systems, so they were reachable from same network. A backup the attacker can reach is not a backup. Good they had an offline copy, but a system this important should have that as regular schedule, not depend on luck.by osinix
- Any guidelines on how to back up such that the attacker cannot reach (when the hacker otherwise had some valid credentials)?by alok-g
- That was my thought exactly on reading that line: that is not a backup. (Ok, the word isn't strictly defined, but you know what I mean.) They have said there's a "real" (offline) backup as well, luckily, but that just reinforces that the "pretend" backup was irrelevant and wasn't even worth mentioning in the writeup.by abanana
you can have append-only backup systems.> backup the attacker can reach is not a backupby teravor- Well, the land registry database in Serbia hasn't been working for two months now; the government hasn't issued any announcement so far, except for generic system-issue information we get from LRD support. Weird, hopefully we weren't hit tooby puritanicdev
- Tangentially reminds me of what happened to the South Korean gov data center [1] where a no-backup ~900TB data center got erased due to a battery fire.
Withno external backups piecing together all the lost functions must havebeen hair raising, and more forensic archeolgy than data recovery.
Last i heard i think they had restored a quarter of the lost services/data.
by rzerowan
If I was an evil hacker, I would only hack countries my country hated or did not have extradition agreements with. Like the Russian hackers do.Security firm KELA... has doxxed the hacker as Zakaria Mahdjoub, an individual from Oran, Algeria.Algeria has a extradition treaty with Romania:
https://periodicos.processus.com.br/index.php/egjf/article/v...
by khurs- Or just have Opsec.by basilikum
- Romanian friends have told me that this is really due to corruption.
Specifically:
- government gives IT/data contracts to cronies
- cronies don't actually do any real security work to protect the data
- things like this happen
by alexpotato - It's always amusing how this is always attributed to the corruption.
It's even more funny on Reddit when you can see the person who is blaming cronies in his Romania but has posts of him doing some blue-collar work in the Midwest.
- They said this in the article:
> Sources told Risky Business that the hacker entered using valid credentials
by LelouBil - Somebody vibed an explainer dashboard with what surfaced online about the incident https://ancpi-atac.mariuscomper.uk/en/by pax
- This is the same in the UK too. Governments everywhere are the same. It's just humans motivated by greed and easily corruptible.by varispeed
- "It's corruption and cronies" is a generic cop-out answer that doesn't explain anything.
Like whenever someone gets caught in a compromising situation they say they "were hacked", as if saying that means anything.
- Same thing is rampant in other Eastern European countries as well. Tips on how to address this for those of us that are publicly minded?by dmos62
- It is not corruption. Or not just corruption.
A close relative, government employee, was in charge of building a new application. They have nobody in that entire organization of several thousands people that know how to write specifications for an IT application, nobody that knows how to design, test and deploy it. This is because some government employees have decent salaries, but in IT the private sector is paying a lot more, so almost anyone remotely competent is going to the private sector. So in this case an organization of non-IT people had to deal with the contract and all the associated problems - there is no need to guess, it did not go well. That kind of project could have been done properly with ~ 10% of the budget in the same timeline.
I have a friend that worked as a developer in such a government IT project. The project cost was ~ 5-10 times what was worth, a chain of sub-contractors did the work, less than ten competent people doing the project, charged by the bid winner for over 100 people and actual staff was around 70 at most, for a short period of time.
Both projects above are in Romania. Lack of competent people in the projects, especially in decision roles, was the main problem.
by AdrianB1