2. Using such an old attack method may lull sophisticated countries into a false sense of security. "Oh we have systems to prevent that, it could never happen to us".

They are not necessarily testing the attack weapons so much as the social effect & public/gov response.
3. New York Stock Exchange & Chicago Mercantile Exchange may have tech to prevent DDoS attacks. But these attackers in NZ also went after ski fields, car parking garages, all kinds. There was no financial motive & seems more than just "kids playing" or LOLsec
6. Although Nord rates US cybersecurity highly (#2), its vulnerability score puts it at greater risk than New Zealand. 1 in 4 Americans have been a victim of cybercrime already - seeding the idea with the public.

You can download their full report here

7. A cyber-attack on stock exchanges, traffic lights, and the energy grid was the plot of Live Free or Die Hard (2007) with Bruce Willis

Similar storylines have appeared in entertainment for decades, since Wargames (1983) with Matthew Broderick

"Is it a game, or is it real?"
8. QAnon, arguably itself a new form of cyber-weapon with a distributed "digital army" has frequently referenced the Wargames movie. A search at qmap for the exact phrase "shall we play a game" returns 15 posts
9. Live Free or Die Hard, aka Die Hard 4, was based on this 1997 WIRED magazine article by John Carlin.

Note "weaponry by CNN"

In 2020, it seems that the mainstream media has already been weaponized & used for political destabilization/regime change

11. Two weeks later the Maersk shipping line was hit with another, more serious ("crippling") cyber-attack that was traced to #Ukraine

It shut down radiation monitoring systems at the Chernobyl nuclear plant, dormant since a 1986 disaster but still deadly
14. George Webb's brother "Dave Acton" is an expert in cyber-security. He has written several books since the 2017 attack using it as an example to warn of the vulnerability of our critical infrastructure. Sadly, few seem to have been paying attention. https://www.amazon.com/Avoiding-Digital-Maginot-Line-Modernizing/dp/1701824825
16. Thanks to ZDNet's @campuscodi for pointing out that similar attacks have been happening in the US, India, Austria & Turkey. There IS a ransomware element "DDoS for BTC

Re-using name FANCY BEAR from Guccifer 2.0 LARP https://twitter.com/campuscodi/status/1303438218361286656?s=20
17. The attacks have been quite sophisticated, using 200 Gb/s of DDoS power & targeting vulnerable points like APIs & DNS servers. The attackers claim to have capabilities of 2 Tb/s

18. In February this year Amazon Web Services defended against the biggest DDoS attack in history, 2.3 Tb/s

19. In military tactics a feint is creating the impression of an attack in one direction to disguise sneaking in from somewhere unexpected

In 2014 "low tech" attacks exposed major vulnerabilities in electrical infrastructure. AFAIK nothing's changed since https://www.latimes.com/nation/la-na-grid-attack-20140211-story.html
20. There are many ways to attack a Stock Exchange electronically. DDoS is a direct attack. The Port of Charleston was an indirect attack: asymmetrical warfare. It showed how weaponized social media influencers can create chaos & panic.A run on banks & stocks could cost trillions
21. NZ's Government Communications Security Bureau has issued a "be prepared" advisory warning to ALL businesses in the country.

Australian Prime Minister Scott Morrison in July dedicated $1.4 billion to put the country on a cyber-security "War Footing" https://www.nzherald.co.nz/business/news/article.cfm?c_id=3&objectid=12360876
You can follow @steveouttrim.
Tip: mention @twtextapp on a Twitter thread with the keyword “unroll” to get a link to it.

Latest Threads Unrolled:

By continuing to use the site, you are consenting to the use of cookies as explained in our Cookie Policy to improve your experience.