A Charlotte story
The Tuesday the member file started leaving at 2:09
the founder of a 35-person statement-printing and software firm in South End that serves eleven credit unions
It is a Tuesday in August, 94 degrees and thick, and the founder of a South End firm that prints and hosts statements for eleven credit unions is reading a letter from the largest one. Their vendor-risk team will review the firm in thirty days. The first attachment is a 140-question spreadsheet. The second is a reminder that the contract allows termination for a failed review.
Each month the credit unions upload member files to the firm's file-transfer server. It sits at the edge of the network, facing the internet, running software that was current in 2022. A flaw in that software has been on the government's known-exploited list since spring. The vendor emailed a patch notice. It is in a folder.
On Tuesday at 2:09 p.m. a computer in another country, scanning the whole internet for that one flaw, finds the server on the first try. It logs in without a password. It opens the folder for the largest credit union and starts to download 61,000 member records.
At 2:11 p.m. the download is a third of the way through, and the only thing that decides the ending is whether anyone is watching.
What changes the ending
- Internet-facing systems inventoried and known-exploited flaws patched within days, with the notice going to a person, not a folder (CIS 7 Continuous Vulnerability Management)
- A protection agent and a named engineer watching the network around the clock, so a foreign login to the transfer server is killed in seconds, with the member file still on the disk (CIS 13 Network Monitoring and Defense)
- Member files encrypted at rest, held only as long as the job needs and deleted on a schedule, so a breach of one server is not a breach of eleven credit unions (CIS 3 Data Protection)