3 Minute Read
A threat actor once again proved the importance of enforcing strict password management practices by torpedoing a 158-year-old UK transportation company by hacking a password and then effectively shutting it down with ransomware. According to published reports, the threat group Akira gained access to KNP's system in June when it was able to determine a single employee's password. Once access was gained, Akira injected ransomware, which shut down the network and encrypted access to its files and backups. Akira then demanded an estimated £5 million ransom, but this amount was beyond KNP's ability to pay, so it opted to shut down instead. About 700 people are now out of work. This attack reinforces the need for strong passwords and for organizations to frequently check to ensure their staffers are abiding by the rules. Trustwave's Jason Whyte, General Manager for the Pacific, recently noted that passwords are inherently vulnerable, but strengthening them can contribute to a robust security posture. At an organizational level, it's essential that strong password policies be provided to employees with clear instructions on password length, complexity, and expiration guidelines. Trustwave researchers warn that an eight-character password can be cracked in under a day, and sometimes much faster, using brute-force techniques. Simply increasing the length to 10 characters can extend that brute force timeline to potentially hundreds of years. Adding length and complexity, such as uppercase and lowercase letters, numbers, and symbols, goes even further. Of course, remembering something like "dlkjskljfo8w!$^@@" isn't easy. That's why passphrases are a smart choice. Think of a line from your favorite song, a historical quote, or even something you say to your kids, like: "Broccoliisgoodforyou". Whyte suggests using technology to make this task easier. Complex passwords can be difficult to remember, especially when they need to be changed frequently, every 60-90 days is recommended. The solution is a password manager, which generates unique passwords for every account and securely encrypts them. This minimizes the risk of using weak or repeated passwords and ensures that employees only need to remember one strong master password. Not sure if your password or passphrase is strong enough? Free tools like Have I Been Pwned and other password strength checkers can estimate how long it would take to crack a password. For example, a complex passphrase like the one above could take centuries to break. Trustwave employs a multi-faceted approach to identify and address weak passwords: By leveraging Trustwave's cybersecurity services, organizations can significantly reduce the risk of breaches caused by weak passwords. The benefits include: Trustwave's comprehensive cybersecurity services play a crucial role in identifying and mitigating the risks associated with weak passwords. By implementing strong password policies, conducting regular audits, and providing continuous support, Trustwave helps organizations stay one step ahead of cyber threats.
How to Build a Strong Password
Trustwave's Comprehensive Approach
Sign up to receive the latest security news and trends straight to your inbox from Trustwave.Stay Informed