Blog

What happens in production, with sources.

Short notes on cloud, legacy systems, payments and AI in production. Each one starts from a published fact and ends with what a team would do about it.

Page 3 of 3

Ransomware knocked Argentina's immigration control offline, and the attackers demanded $4 million

On August 27, 2020, Netwalker ransomware took down the system that records entries and exits at Argentina's international border crossings, causing delays at the borders. Migraciones, Argentina's national immigration agency, restored operations from a backup and didn't pay the $4 million the attackers demanded. The attackers published data on 25,723 repatriated Argentines anyway. The backup saved operations; it didn't save the data.

He reported a flaw in Buenos Aires's e-voting system. Two days before the election, police raided his home

In 2015, a programmer told the vendor that he had found a vulnerability in the City of Buenos Aires's Boleta Única Electrónica (single electronic ballot) system. On the night of Friday, July 3, two days before the election, police raided his home and took his computers. In 2016, the prosecutor's office recommended dismissing the case against him. The case shows what happens when the person who reports a flaw ends up treated like an attacker.

Ransomware infected about 18,000 Telecom Argentina computers and demanded $7.5 million

In July 2020, the REvil group attacked Telecom Argentina. According to reports, about 18,000 computers were infected, and the ransom was $7.5 million in the Monero cryptocurrency, with a deadline to pay. Attackers don't need to take down customer services to do damage: reaching the computers that run internal operations is enough.

700 GB of Argentine Federal Police data went public, including profiles of undercover officers. The case was closed with no one held responsible

On August 12, 2019, 700 GB of files from Argentina's Federal Police were published: raid reports, wiretaps, and profiles of undercover officers. In November 2021 the case was closed and all 15 suspects were cleared, among them a developer known for pointing out security flaws in government systems. The perpetrator was never identified.