JokoNord
Member
OP
- Joined:
- Jun 2024
- Posts:
- 190
- From:
- Jakarta, ID
You all see this? Hetzner down since Friday, still not fully up. They say ransomware, encrypted backup servers too.
I made VPS with them last month for testing, now cannot access anything. Thank you very much sir to anyone who shares more news.
My real servers are at Contabo, but this makes me worried. How does ransomware get into backup system also? I thought backup is separate network.
https://status.hetzner.com
traffic worse than my packet loss
bellaauc
Member
3-2-1 Believer
- Joined:
- Jun 2024
- Posts:
- 190
- From:
- Auckland, NZ
How does ransomware get into backup system
Oh honey, that's the oldest story in the book. Did they test their restore? I'll bet they didn't. The 3-2-1 rule exists because of exactly this:
- 3 copies of data
- 2 different media types
- 1 offsite and offline
If your "backup server" is just another VM on the same network with the same credentials, it's not a backup. It's a delay.
Someone on Twitter says their snapshot system was reachable from production VLAN. That's not architecture, that's hope.
3-2-1 or you're already dead
larryjeong
Member
- Joined:
- Jun 2024
- Posts:
- 179
- From:
- Texas, US
This is the thing right there
They had their backup API keys in lastpass
The threat actor got the lastpass vault
Now they own everything
Even the airgapped stuff had credentials in the notes field
Because someone needed to remember the tape rotation schedule
Line breaks are free people
Use them
$3/year. 128MB RAM. Pure happiness.