The Times Australia
Fisher and Paykel Appliances
The Times World News

.

As Russia wages cyber war against Ukraine, here's how Australia (and the rest of the world) could suffer collateral damage

  • Written by Paul Haskell-Dowland, Professor of Cyber Security Practice, Edith Cowan University
As Russia wages cyber war against Ukraine, here's how Australia (and the rest of the world) could suffer collateral damage

The Australian Cyber Security Centre[1] is asking organisations and businesses to be on high alert amid Russia’s cyber attack bombardment of Ukraine[2].

The United Kingdom’s National Cyber Security Centre issued a similar warning[3], as have New Zealand[4] and the United States Department of Homeland Security[5].

The Australian Cyber Security Centre has said it is not aware of any specific direct threat to Australia, but that the country could be affected by “unintended disruption or uncontained malicious cyber activities”.

It wouldn’t be the first time a Russian cyber attack has caused serious collateral damage to nations that aren’t its intended target.

Attacks so far

Ukraine has suffered through a sustained digital assault from Russia over the past few weeks. One of the most penetrative attacks came on Wednesday, cutting off access[6] to several Ukrainian government and banking websites – followed by more on Thursday.

These were distributed denial of service attacks, in which the perpetrator knocks targeted websites offline by flooding them with bot traffic.

Meanwhile, experts at the internet security company ESET identified[7] a malicious data-wiping malware called “HermeticWiper” circulating on hundreds of computers in Ukraine, Latvia and Lithuania – which they said may have been months in the making.

According to reports[8], experts from software company Symantec found the malware had affected Ukrainian government contractors in Latvia and Lithuania and a Ukrainian bank.

Read more: Russia is using an onslaught of cyber attacks to undermine Ukraine's defence capabilities[9]

How the impact will be felt

Australia’s risk in the face of ongoing cyber attacks from Russia would almost certainly come in the form of a “spill over” effect.

For example, if a Ukrainian bank is targeted and goes offline, this would still impact Australians who use that bank to receive or send money to Ukraine. Attacks on banks are particularly alarming when you consider Ukraine’s dire need for financial aid and economic support[10] right now.

All global business conducted with, or through, the bank will be affected – and the impact could reach virtually anywhere in the world. Similarly, distributed denial of service attacks on Ukrainian news media would also have global ramifications, by limiting the exchange of crucial information.

Another concern is the potential for Russia to cut off gas supplies flowing through Ukraine to Europe, either directly or through a cyber-enabled attack (the Colonial Pipeline[11] attack being a recent example). This also introduces significant market instability, resulting in shortages and driving up prices (including for Australia[12]).

Australian companies are a part of global supply chains. Many will have interests in Russia and/or Ukraine. Thus they will also have digital, and potentially even direct network connections with them, through a virtual private network – which allows users to establish a private network over a public internet connection (and which can be used to spread malware between connected devices).

Once a “wiper” malware – the likes of that currently circulating in Ukraine – gets enough footing, it can spread across countries within minutes. If an office in Canberra with a virtual private network connection based in Ukraine becomes compromised, it can allow the malware to jump countries.

The NotPetya malware attack in 2017 is a pertinent example. This “self-propogating” malware spread globally and caused billions of dollars’ worth of damage. It, too, was attributed to a Russian source by investigators, and traced back to the update mechanism for a tax-accounting software application used widely in Ukraine[13].

Read more: Three ways the 'NotPetya' cyberattack is more complex than WannaCry[14]

Leveraging the chaos

Apart from malicious Russian state-sponsored cyber crime, the current mayhem unfolding in Ukraine provides opportunity for cyber criminals more generally, too.

It’s very difficult to attribute cyber crime. While experts can analyse code taken from malware, this is usually a slow and costly process. Cyber criminals the world over may want to take advantage of the chaos, and try to carry out attacks they may not otherwise get away with.

Among all the noise, and with so many Ukrainians (including cyber security professionals) either displaced or fleeing, the chances of being caught may be lower. Also, it is likely any major cyber affliction will be blamed on Russia – at least initially.

At the same time, we might see an increase in phishing and scam attempts as a result of the crisis. Opportunistic criminals use global narratives to add credibility to their scams. For instance, they may send phishing emails posing as a Ukrainian citizen desperate for emergency funds.

How can businesses protect themselves?

A critical step in a defensive posture for companies and organisations in Australia is to determine their exposure level. This means being acutely aware of any direct or indirect connection with Ukraine and Russia, and the online systems and supply chains these countries partake in.

Employers also have a duty of care to employees who may have loved ones or other connections in Ukraine, and may be more vulnerable to various forms of cyber attacks exploiting the current situation.

And of course, the most basic cyber security advice is once more relevant. That is, individuals, businesses and organisations must take special care to ensure all devices are up-to-date and have software patches installed.

The 2017 NotPetya attacks were, in part, successful because the malware exploited a vulnerability in Microsoft Windows – even though a patch to fix it was available at the time. But the massive number of devices that hadn’t been patched meant NotPetya could spread without constraint.

In the case of Ukraine, where pirated software is common[15], this issue is particularly prevalent. Complications with (or a lack of) proper software licensing means updates may not be accessed or installed.

References

  1. ^ Australian Cyber Security Centre (www.cyber.gov.au)
  2. ^ bombardment of Ukraine (theconversation.com)
  3. ^ warning (www.ncsc.gov.uk)
  4. ^ New Zealand (www.cisa.gov)
  5. ^ Department of Homeland Security (www.cisa.gov)
  6. ^ cutting off access (apnews.com)
  7. ^ identified (www.reuters.com)
  8. ^ to reports (www.theguardian.com)
  9. ^ Russia is using an onslaught of cyber attacks to undermine Ukraine's defence capabilities (theconversation.com)
  10. ^ financial aid and economic support (www.politico.eu)
  11. ^ Colonial Pipeline (theconversation.com)
  12. ^ Australia (theconversation.com)
  13. ^ in Ukraine (arstechnica.com)
  14. ^ Three ways the 'NotPetya' cyberattack is more complex than WannaCry (theconversation.com)
  15. ^ pirated software is common (outsourcingreview.org)

Read more https://theconversation.com/as-russia-wages-cyber-war-against-ukraine-heres-how-australia-and-the-rest-of-the-world-could-suffer-collateral-damage-177909

Active Wear

Times Magazine

World Kindness Day: Commentary from Kath Koschel, founder of Kindness Factory.

What does World Kindness Day mean to you as an individual, and to the Kindness Factory as an organ...

In 2024, the climate crisis worsened in all ways. But we can still limit warming with bold action

Climate change has been on the world’s radar for decades[1]. Predictions made by scientists at...

End-of-Life Planning: Why Talking About Death With Family Makes Funeral Planning Easier

I spend a lot of time talking about death. Not in a morbid, gloomy way—but in the same way we d...

YepAI Joins Victoria's AI Trade Mission to Singapore for Big Data & AI World Asia 2025

YepAI, a Melbourne-based leader in enterprise artificial intelligence solutions, announced today...

Building a Strong Online Presence with Katoomba Web Design

Katoomba web design is more than just creating a website that looks good—it’s about building an onli...

September Sunset Polo

International Polo Tour To Bridge Historic Sport, Life-Changing Philanthropy, and Breath-Taking Beau...

The Times Features

How airline fares are set and should we expect lower fares any time soon?

Airline ticket prices may seem mysterious (why is the same flight one price one day, quite anoth...

What is the American public’s verdict on the first year of Donald Trump’s second term as President?

In short: the verdict is decidedly mixed, leaning negative. Trump’s overall job-approval ra...

A Camping Holiday Used to Be Affordable — Not Any Longer: Why the Cost of Staying at a Caravan Park Is Rising

For generations, the humble camping or caravan holiday has been the backbone of the great Austra...

Australia after the Trump–Xi meeting: sector-by-sector opportunities, risks, and realistic scenarios

How the U.S.–China thaw could play out across key sectors, with best case / base case / downside...

World Kindness Day: Commentary from Kath Koschel, founder of Kindness Factory.

What does World Kindness Day mean to you as an individual, and to the Kindness Factory as an organ...

HoMie opens new Emporium store as a hub for streetwear and community

Melbourne streetwear label HoMie has opened its new store in Emporium Melbourne, but this launch is ...

TAFE NSW empowers women with the skills for small business success

Across New South Wales, TAFE NSW graduates are turning their skills into success, taking what they h...

The median price of residential land sold nationally jumped by 6.8 per cent

Land prices a roadblock to 1.2 million homes target “The median price of residential land sold na...

Farm to Fork Australia Launches Exciting 7th Season on Ten

New Co-Host Magdalena Roze joining Michael Weldon, Courtney Roulston, Louis Tikaram, and Star Guest ...