Synology® And Twcert/Cc Jointly Announce Their Collaboration With International Cybersecurity Organizations



Synology® and the Taiwan Computer Emergency Response Team / Coordination Center (TWCERT/CC) jointly announced the recent ransomware attack, where the attacker obtained admin credentials by brute force and encrypted the data on various brands of NAS (Network Attached Storage), was under control after they took down the C&C server on July 22, thanks to the collaboration with international cybersecurity organizations. Synology and the TWCERT/CC urge all NAS users to reinforce system security settings to keep their data safe.

“Synology has always made protecting user data our first priority,” said Ken Lee, Manager of Security Incident Response Team at Synology Inc. “As a long-term active participant in the international cybersecurity community, Synology was able to promptly collaborate with international cybersecurity organizations when the attack launched, preventing it from turning into an outbreak.”

Synology began to receive user reports since July 19 indicating that the data on their NAS was encrypted by ransomware. The investigation report showed that the attacks weren’t based on DSM system vulnerabilities. Instead, they targeted those using weak passwords of the system default admin accounts. After the attacker gained admin access, they encrypted the files and asked for ransom. On July 22, there were dozens of affected Synology users reporting this attack to the Global Technical Support Department, and Synology estimated that over ten thousand different brands of NAS around the world may be exposed to risks and can be potential targets in this attack. On the same day, Synology traced and connected to the attacker’s C&C server, notifying the TWCERT/CC at the same time to initiate international collaboration. On July 26, with the information provided and forwarded by Synology and TWCRET/CC respectively, CFCS-DK identified the source of the attack and removed the C&C server.

“TWCERT/CC reacted promptly, obtained incident reports to initiate the international collaboration, and controlled the situation at an early stage, all thanks to our long-term partnership,” said Joy Chan, the director of the TWCERT/CC. “We look forward to seeing more brands follow in Synology’s footsteps to set up product safety teams and actively interact with cybersecurity organizations.”

Even though this matter is already under control, Synology suggested that all NAS users regardless of the brands strengthen data security by taking the following measures:
• Enable firewall and only connect to the Internet when necessary.
• Set up 2-step verification to prevent unauthorized login attempts.
• Disable the system default "admin" account.
• Use a strong password, and apply password strength rules to all users.
• Enable Auto Block in Control Panel to block IP addresses with too many failed login attempts.
• Run Synology Security Advisor to make sure there is no weak password in the system.
• Perform multi-version backup using Synology Hyper Backup, backing up the data on your NAS to multiple destinations such as on-premises storage, remote folders, and public cloud.

Event timeline
• Synology received user reports saying that the data on their NAS was encrypted by ransomware.
• The report investigation ruled out possibilities that the attacks resulted from DSM system vulnerabilities; instead, the attacks were launched using brute force.

• Dozens of affected Synology users reported this attack to the Global Technical Support Department.
• Investigated and estimated that over ten thousand different brands of NAS around the world may be exposed to risks and can be potential targets in this attack.
• Synology traced and connected to the attacker’s C&C server.
• Synology notified the TWCERT/CC to request an international collaboration.

• The TWCERT/CC reported and collaborated with the CFCS-DK in Denmark, and took down the attacker’s C&C server according to the IP address.
• Follow-up observation showed that the number of attacked users is slowing down.

Latest Press Releases

Get 15 months instead of 12 months of access for purchases until October 31st



42nd Melbourne Marathon Festival held in the Australian city



Unveiled a Privilege Card offering a host of exclusive benefits



An innovative fuel service from ENOC – delivering fuel at the doorstep of businesses and fleets



The coveted accolade was presented by H.H. Sheikh Abdullah bin Salem bin Sultan Al Qasimi



Most Viewed Recent Press Releases

Vistara, India’s finest full-service carrier and a JV of Tata and Singapore Airlines, yesterday inaugurated ...


Moorfields endorses taking precautions to get the most out of the season while decreasing any risk


? Students in the UAE will receive their results on the morning of Thursday, August 22, 2019.


Emirates Aviation University has introduced an “international student study package”, offering financial ...


The 9-1 grading scale was applied across all Pearson Edexcel International GCSE subjects this year


An innovative fuel service from ENOC – delivering fuel at the doorstep of businesses and fleets


Related Links_

Google ADS

Other Info_


Health Care

Multi Specialty medical facilities, government hospitals & private clinics



Nurseries, Kindergardens, Schools, Colleges, Universities & Higher Education


Popular Restaurants

Dining in Dubai - selection of restaurants where you can relax & enjoy a variety of cuisines of choice

Jobs at Dubai_

Find latest Dubai Jobs & Vacancies from placement agencies, employers & recruitment consultants in Dubai, Abu Dhabi & other Emirates in UAE.

Dubai Tours & Packages_

Book quality Dubai tours, best Dubai holiday packages with visas & Dubai hotel booking with special offers & discounts


Unsupported Browser

This website includes CSS elements that your browser does not support. Please upgrade your browser to a current version, then come back and try again.

Upgrade your Browser for more experience

Chrome Firefox Safari Edge