Cyber Incident Victim: West Bengal State Electricity Distribution Company
Date:
May 2017
Location:
India
Summary
The West Bengal State Electricity Distribution Company was affected by the WannaCry ransomware attack, which spread quickly among computers on the same network, encrypting files and demanding ransom in Bitcoin. The attack exploited a Microsoft Windows vulnerability, allowing the ransomware to spread and install encryption software. The company confirmed infections at four of its offices, but the extent of the damage is unclear. The attack was part of a global WannaCry outbreak that affected numerous organizations.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
The West Bengal State Electricity Distribution Company was one of the many organizations affected by the WannaCry ransomware attack, a global cyber incident that caused widespread disruption and damage. The attack began with the exploitation of a vulnerability in the Microsoft Windows operating system, which allowed the ransomware to spread quickly among computers on the same network. The vulnerability, known as EternalBlue, was discovered by the National Security Agency (NSA) and was later stolen and released publicly by hackers.

The WannaCry ransomware was designed to encrypt files on infected computers, making them inaccessible to users. The attackers then demanded a ransom in Bitcoin, a cryptocurrency, in exchange for the decryption key. The ransom demands were relatively small, ranging from $300 to $600 per affected computer. However, the attackers also included a "kill switch" in the malware, which was designed to stop the spread of the attack once a certain domain was registered.
The attack on the West Bengal State Electricity Distribution Company was part of a larger outbreak that affected numerous organizations around the world. The company confirmed that infections had been detected at four of its offices, but the extent of the damage is unclear. The attack was likely spread through phishing emails or other social engineering tactics, which allowed the attackers to gain access to the company's network.
Once inside the network, the ransomware spread quickly, encrypting files and demanding ransom. The attackers used a combination of encryption algorithms, including AES and RSA, to lock the files and make them inaccessible to users. The ransom demands were displayed on the infected computers, along with instructions on how to pay the ransom.
The WannaCry attack was notable for its speed and scale, with reports of infections coming in from over 150 countries. The attack affected a wide range of organizations, including hospitals, banks, and government agencies. The attack also highlighted the importance of keeping software up to date, as the vulnerability exploited by the attackers had been patched by Microsoft several months earlier.
The West Bengal State Electricity Distribution Company was not the only energy company affected by the attack. Other energy companies, including Iberdrola and Petrobras, also reported infections. The attack on the energy sector was particularly concerning, as it highlighted the potential for cyber attacks to disrupt critical infrastructure.
The WannaCry attack was eventually slowed by the registration of the "kill switch" domain, which was discovered by a security researcher in the UK. However, the attack had already caused significant damage, and many organizations were left to deal with the aftermath. The attack highlighted the importance of cybersecurity and the need for organizations to take steps to protect themselves against cyber threats.
The West Bengal State Electricity Distribution Company's response to the attack is not publicly known, but it is likely that the company took steps to contain the attack and restore affected systems. The company may have also worked with cybersecurity experts to investigate the attack and identify the root cause.
The WannaCry attack was a significant cyber incident that highlighted the importance of cybersecurity and the need for organizations to take steps to protect themselves against cyber threats. The attack was notable for its speed and scale, and it affected a wide range of organizations around the world. The attack also highlighted the potential for cyber attacks to disrupt critical infrastructure, and it underscored the need for organizations to prioritize cybersecurity.
