MSP TODAY NEWS

Homeland Security Warns of Chinese Cyber Attacks on MSPs

By Laura Stotler

MSPs are being targeted as part of an ongoing campaign of cyber attacks linked to the Chinese government. According to information recently released by the Cybersecurity and Infrastructure Security Agency (CISA), the attacks are designed to take advantage of internal vulnerabilities. The use of MSPs as the point of attack only amplifies the impact, making the threat significantly more dangerous.

“The core issue with the compromise of managed service providers is that it really gives the attacker a force-multiplier effect,” said Rex Booth, cyber threat analysis chief for CISA. Booth said the Homeland Security Department has been tracking the APT10 threat group since 2006. The group is sponsored by China’s Ministry of State Security and has strategically shifted its tactics between 2014 and 2018, focusing specifically on MSPs. By the end of 2018 the agency had observed an extreme increase in attacks, and decided it was necessary to notify the public. 

“Now, when you are looking at the opportunity for the attackers to tackle these MSPs, it’s a much more difficult thing to scope out and scale,” said Booth. “You don’t necessarily know who their intended target is because at any provider there might be dozens and dozens of potential targets. It makes the responders’ job a little bit more difficult, and frankly, it creates a much wider swath of potential damage -- not only for the intended victims, or the intended targets from an attacker perspective, but also for collateral damage as well.”

Basically all MSP customers, partners and affiliates are in the line of fire during these types of attacks, including all their data, resources and systems. And the attacks are slated to continue, according to CISA, with China planning to harm a long list of MSPs over the next five years. To combat the attacks, Homeland Security launched a series of webinars earlier this year designed to educate about the threats.

It’s unclear whether APT10 plans to continue to focus on MSPs or will switch tactics as a result of Homeland Security’s efforts. MSPs should certainly be aware of the risks and do whatever they can to ensure the safety of their systems, data and customers.

To provide more information about cybersecurity and other important issues impacting MSP business owners and technology specialists, TMC is hosting its MSP Expo in Fort Lauderdale, FL from February 12-14, 2020. The event will focus on security and backup/disaster recovery as well as how MSPs can grow their networks and drive more recurring revenues.




Edited by Maurice Nagle

MSPToday Contributing Editor

SHARE THIS ARTICLE
Related Articles

MDR Provider for MSPs Huntress Tracks Down $18 Million Funding Round

By: Laura Stotler    2/21/2020

Huntress, a company that provides SaaS managed detection and response (MDR) solutions for MSPs and VARs to deliver to SMBs, has scored an $18 million …

Read More

Pax8 and Novacoast Announce Security Operations Center Strategic Partnership at ITEXPO

By: Arti Loftus    2/21/2020

With all its benefits, cloud hosting, storage, and computing are increasingly vulnerable to cyber threats, and at ITEXPO this week in Ft. Lauderdale, …

Read More

As Digital Transformation Continues in the Enterprise Cybersecurity World, One Company Reaches for the Cloud to Supercharge Analyst Productivity

By: Arti Loftus    2/21/2020

It's no secret that managing security within enterprises, organizations, and small and medium businesses have become exponentially more complex as mor…

Read More

Federated Wireless Launches 4G/5G Private Networks Through Azure and AWS

By: Ken Briodagh    2/21/2020

Federated Wireless recently announced a new Connectivity-as-as-Service offering that reportedly lets U.S. enterprises buy and deploy private 4G and 5G…

Read More

When Labor Markets are Tight, a Blended Workforce Could be the Answer

By: Bill Yates    2/20/2020

Managed Services Providers (MSPs) can gain flexibility and operational efficiency by moving to a blended workforce. By combining full-time staff with …

Read More