Ransom in Texas

Jesus Beltran II


On May 14, 2020, ransomware halted the use of the Crash Information System (CRIS) of the Texas Department of Transportation. This is the system that puts together all vehicle crash information from law enforcement in the state of Texas. When you need a report for your insurance claim or lawsuit, this is the system where you order a copy. According to a news release from Texas Department of Transportation,

“[T]here was unauthorized access to the agency’s network in a ransomware event. TxDOT immediately took steps to isolate the incident and shut down further unauthorized access. In addition, the agency promptly began working with federal law enforcement... to find the individual(s) responsible and prosecute them to the fullest extent of the law.”

REQUESTED UPDATES

On June 15, TxDOT Media Relations replied to my request for more information, explaining, in part,

“We're pleased to report that TxDOT has made significant progress in its remediation and recovery efforts with enhanced security in place. You can now safely reconnect to TxDOT systems. TxDOT continues to work closely with its third-party incident response partners, Microsoft and AT&T, as well as local authorities and the U.S. Federal Bureau of Investigation. TxDOT and its incident response partners have determined and validated that no personally identifiable information or data was copied, transferred or retrieved during the incident.”

Because the TxDOT press release is very light on actual facts and the initial email response peaked my interest about the third-party incident response partners, Microsoft and AT&T, as well as the FBI involvement, I pressed for more information.

This sort of back and forth via email takes time, but usually yields more information. TxDOT Media Relations is not disclosing information about ransom or methods.

QUESTIONS TO ASK

Is the aim of the press release and emails to assure the public that everything is OK? If so, I have to give the responses a low grade. Information is your friend, unless you have something to hide. So, what should the public be told? Basically,

  1. Would hackers know how to hide whether they copied data or not?
  2. In prior attacks on Texas governmental systems (yes, there have been many more before this one), were Microsoft and AT&T also involved with determining whether data was copied or corrupted? If so, who double-checks the work that these two companies are doing?

WHERE TO SEARCH

Usually, emails or calls to higher level department heads would be in order. But, based on experience, they will continue to hold back useful information. If TxDOT reaches out with information after reading this, then that will be shared. After a few quick searches, I found the Texas Department of Information Resources (DIR) website. The DIR handles all information systems for Texas agencies.

In 2013, Texas Senate Bill 1102 modified the state Cybersecurity code chapter by adding three sections. These three sections are the creation of the management structure for the Texas Cybersecurity Council. Basically, like many oversight groups, the Texas Cybersecurity Council makes recommendations and guides.

The DIR website explains every agency and department needs to make up their version of an incident response plan. The DIR’s Incident Response Guide & Templates provides a “framework for organizations in creating their own incident response plans and procedures and should be completed and modified to meet the business needs of the organization.”

FINAL THOUGHTS

Makers of the operating system and internet service provider, should have their work double-checked. Specialists need to independently verify whether there was a data breach and report that to the public.

Transparency is key. Citizens are asked to trust agencies that, as an immediate response, is to withhold information ~but trust must be earned. And even if there is trust, keep in mind the translation of a Russian phrase President Reagan kept repeating, “Trust, but verify.”

 


Comments

Popular posts from this blog

Teaching Alternative Certification and Teaching away from home

Untruths from a Credit Union