ϳԹ

Cyber Resilience
August 6, 2020
2020-08-06
2025-02-01
20:28

From decisions to decryption – live the Garmin ransomware attack with ϳԹ

Cyber Crisis Simulation
Contributors
Share

Unless you’ve been hiding under a rock you’ll know that Garmin was crippled by a ransomware attack in July. The smartwatch specialist had to pull the plug on various services after its internal network and production systems were encrypted, which led to planes being , runners losing morale, and the lazy among us quietly rejoicing.

Aside from disrupting athletes, this caused a headache for just about everyone involved in the cleanup. The incident unravelled dramatically in the media, a kind of digital theatre for security types who all agreed on one thing: Garmin’s response was tragic.

In Act One, Garmin’s PR team were so tongue-tied one must assume they forgot their lines. A pair of short tweets broke the silence, and a murky FAQ became the sole touchpoint on a failing website. Customers couldn’t reach the GPS giant via phone, email or online chat either, which, ironically, had them feeling lost.

sought clarity in Act Two, asking if a ransomware attack had caused the outage. Garmin’s spokesperson said the investigation was “ongoing”, though its staff said otherwise, having already shut down machines due to ransomware spreading across the network.

Act Three lasted several days and was lapped up by news outlets globally. Issues continued to plague customers a week after the initial outage, and Garmin’s communication was limited. Only in August did the curtains close, when Garmin paid the offending Evil Corp a multimillion-dollar ransom for a decryption key – bravo!

This incident exemplifies how not to handle a ransomware attack, but Garmin isn’t the first business to crumble (ask ), nor will it be the last. The anxiety and ill-preparedness that characterized its response, however, was the product of inadequate crisis training – so let this be a lesson.

Tackling the Garmin ransomware attack with ϳԹ

Would you and your team have handled things differently? Using our you can stress-test your response capability in a realistic scenario based on the Garmin incident, where you’ll step into the shoes of an incident response handler at a global tech company. With millions of devices and transport systems relying on the data your company provides, you must organize everyone and everything when the incident occurs – and that means some tough decisions under pressure.

The rich, realistic storyline twists and turns based on the choices you and your team make, driving cyber resilience and human readiness while preparing you for the real-world consequences of a cyber incident. True to our underlying platform, this occurs on demand in a browser-based environment.

Incident response incorporates everything from high-level decision making to technical expertise on the ground. Knowing this, we’ve built three labs to complement the Garmin scenario, enabling your team to get up close and personal with the offending WastedLocker ransomware.

The first of these allows you to run and examine the WastedLocker sample that hit Garmin – you’ll even see the original ransom note. The second lab focuses on a deeper, more technical analysis of the malware, while the final exercise allows you to decrypt files using the key that cost Garmin $10 million!

Book a demo to see these labs and our Cyber Crisis Simulator in action. Alternatively, if you already have an ϳԹ license,

Trusted by top
companies worldwide

Customer
Insights

The speed at which Immersive produces technical content is hugely impressive, and this turnaround has helped get our teams ahead of the curve, giving them hands-on experience with serious vulnerabilities, in a secure environment, as soon as they emerge.
TJ Campana
Head of Global Cybersecurity
Operations, HSBC
Realistic simulation of current threats is the only way to test and improve response readiness, and to ensure that the impact of a real attack is minimized. Immersive’s innovative platform, combined with Kroll’s extensive experience, provides the closest thing to replication of a real incident — all within a safe virtual environment.
Paul Jackson
Regional Managing Director,
APAC Cyber Risk, Kroll

Ready to Get Started?
Get a Live Demo.

Simply complete the form to schedule time with an expert that works best for your calendar.