Incident: Title: Cognizant Technology Solutions Hit by Maze Ransomware Attack

Published Date: 2020-04-18

Postmortem Analysis
Timeline 1. The software failure incident of Cognizant Technology Solutions Corp being hit by "Maze" ransomware happened on April 18, 2020, as reported in Article 99371.
System The system that failed in the software failure incident reported in Article 99371 was: 1. Cognizant Technology Solutions Corp's systems affected by the "Maze" ransomware attack [99371].
Responsible Organization 1. The "Maze" ransomware hackers were responsible for causing the software failure incident at Cognizant Technology Solutions Corp [99371].
Impacted Organization 1. Cognizant Technology Solutions Corp was impacted by the "Maze" ransomware attack, resulting in service disruptions for some of its clients [99371].
Software Causes 1. The software cause of the failure incident was the "Maze" ransomware attack on Cognizant Technology Solutions Corp, resulting in service disruptions for some of its clients [99371].
Non-software Causes 1. Ransomware attack by "Maze" hackers [99371]
Impacts 1. Service disruptions for some of Cognizant Technology Solutions Corp's clients were experienced as a result of the "Maze" ransomware attack [99371].
Preventions 1. Implementing robust cybersecurity measures such as regular security audits, penetration testing, and employee training to prevent ransomware attacks [99371]. 2. Ensuring timely software updates and patches to address known vulnerabilities that ransomware can exploit [99371]. 3. Utilizing strong encryption methods to protect sensitive data from being accessed in case of a breach [99371].
Fixes 1. Implementing robust cybersecurity measures to prevent ransomware attacks in the future [99371]
References 1. Statement from Cognizant Technology Solutions Corp 2. Cyber defense companies assisting in containing the incident 3. Law enforcement agencies 4. Reporting by Shubham Kalia in Bengaluru [99371]

Software Taxonomy of Faults

Category Option Rationale
Recurring one_organization (a) The software failure incident having happened again at one_organization: - Cognizant Technology Solutions Corp was hit by "Maze" ransomware, resulting in service disruptions for some of its clients [Article 99371]. This incident indicates that Cognizant Technology Solutions Corp experienced a ransomware attack, specifically the "Maze" ransomware, which can be considered a software failure incident that has happened again within the same organization.
Phase (Design/Operation) design, operation (a) The software failure incident in Article 99371 was due to the development phase, specifically the introduction of the "Maze" ransomware into Cognizant Technology Solutions Corp's systems. This ransomware caused service disruptions for some of its clients, highlighting a failure introduced during the system's development or updates [99371]. (b) Additionally, the article mentions that ransomware attacks like Maze are used by hackers to take down systems that control various operations, such as hospital billing and manufacturing. This indicates that the failure was also influenced by the operation or misuse of the system, as hackers exploit vulnerabilities in the operational aspects of the targeted systems [99371].
Boundary (Internal/External) within_system (a) within_system: The software failure incident reported in Article 99371, where Cognizant Technology Solutions Corp was hit by "Maze" ransomware, can be categorized as a within_system failure. The ransomware attack directly impacted the company's systems and services, leading to disruptions for some of its clients. Cognizant Technology Solutions Corp mentioned taking steps to contain the incident, indicating that the failure originated from within the system itself [99371].
Nature (Human/Non-human) non-human_actions (a) The software failure incident in Article 99371 was caused by non-human actions, specifically the "Maze" ransomware attack. The ransomware was deployed by hackers to take down systems, resulting in service disruptions for Cognizant Technology Solutions Corp and its clients. The attack was not a result of human actions but rather a malicious program introduced by external actors [99371].
Dimension (Hardware/Software) software (a) The software failure incident reported in Article 99371 was due to a ransomware attack known as "Maze." Ransomware is a type of malicious software that is typically deployed by hackers to take down systems. In this case, Cognizant Technology Solutions Corp was hit by the Maze ransomware, resulting in service disruptions for some of its clients. This incident was not caused by hardware failure but rather by the malicious software deployed by hackers [99371].
Objective (Malicious/Non-malicious) malicious (a) The software failure incident reported in Article 99371 was malicious in nature. It was caused by the "Maze" ransomware, which is a type of malicious program used by hackers to take down systems and demand hefty payments from affected companies. The hackers behind Maze even go as far as posting online the names of companies that refuse to pay the ransom, indicating a clear intent to harm the systems of their targets [99371].
Intent (Poor/Accidental Decisions) poor_decisions (a) The intent of the software failure incident related to poor_decisions: - The software failure incident involving Cognizant Technology Solutions Corp being hit by "Maze" ransomware can be attributed to poor decisions made by hackers who deploy Maze ransomware to take down systems and demand hefty payments [99371].
Capability (Incompetence/Accidental) development_incompetence, unknown (a) The software failure incident reported in Article 99371 is related to a ransomware attack on Cognizant Technology Solutions Corp. This incident was caused by the "Maze" ransomware, which is a type of malicious program used by hackers to disrupt systems and demand hefty payments. The attack resulted in service disruptions for some of Cognizant's clients. This can be attributed to development incompetence as the attack exploited vulnerabilities in the system that may have been introduced due to a lack of professional competence in securing the software [99371]. (b) The accidental aspect of the software failure incident is not explicitly mentioned in the article.
Duration temporary The software failure incident reported in Article 99371 was temporary. Cognizant Technology Solutions Corp experienced service disruptions for some of its clients due to the "Maze" ransomware attack. The company mentioned that it was taking steps to contain the incident with the help of cyber defense companies and had engaged with law enforcement. This indicates that the disruption was not permanent but rather caused by specific circumstances such as the ransomware attack [99371].
Behaviour crash, omission, other (a) crash: The software failure incident reported in the article is related to a ransomware attack on Cognizant Technology Solutions Corp, resulting in service disruptions for some of its clients. This can be categorized as a crash where the system lost its state and was unable to perform its intended functions [99371]. (b) omission: The ransomware attack caused service disruptions for some clients of Cognizant Technology Solutions Corp, indicating that the system omitted to perform its intended functions at that instance [99371]. (c) timing: The article does not mention any specific timing-related failure in this software incident. (d) value: The ransomware attack did not lead to the system performing its intended functions incorrectly; rather, it caused service disruptions [99371]. (e) byzantine: The article does not mention any inconsistent responses or interactions by the system in this software failure incident. (f) other: The behavior of the software failure incident in this case can be categorized as a security breach leading to service disruptions and potential data compromise due to the ransomware attack [99371].

IoT System Layer

Layer Option Rationale
Perception None None
Communication None None
Application None None

Other Details

Category Option Rationale
Consequence unknown (a) death: People lost their lives due to the software failure (b) harm: People were physically harmed due to the software failure (c) basic: People's access to food or shelter was impacted because of the software failure (d) property: People's material goods, money, or data was impacted due to the software failure (e) delay: People had to postpone an activity due to the software failure (f) non-human: Non-human entities were impacted due to the software failure (g) no_consequence: There were no real observed consequences of the software failure (h) theoretical_consequence: There were potential consequences discussed of the software failure that did not occur (i) other: Was there consequence(s) of the software failure not described in the (a to h) options? What is the other consequence(s)? The article does not mention any direct consequences such as death, harm, basic needs impact, or property loss resulting from the Maze ransomware attack on Cognizant Technology Solutions Corp. The primary consequence mentioned is service disruptions for some clients [99371].
Domain information (a) The failed system was intended to support the information industry as Cognizant Technology Solutions Corp, an information technology services provider, was hit by "Maze" ransomware, resulting in service disruptions for some of its clients [99371].

Sources

Back to List