British NHS DDOS attacks itself via email sent to 1.2M staff(telegraph.co.uk)
telegraph.co.uk
British NHS DDOS attacks itself via email sent to 1.2M staff
http://www.telegraph.co.uk/news/2016/11/14/nhs-it-blunder-sees-system-clogged-after-email-sent-to-12-millio/
8 comments
Somewhat odd that in setups this large emails to all are unregulated. I'd expect those to go through some "approval" channel.
This happened at Qualcomm once. Some IT email was sent out to most of the corp and then people's vacation/out-of-office auto-reply-to-all propagated it more. Then people would send reply-all messages like "remove me from this list!" it went on for most of the day.
Also happened at IBM when I worked there. A guy named Armando changed his phone and manage to send a notice to everyone in the company using a maillist. People didn't know about the maillist and started to ask to be removed, turns out it was not possible... It took weeks to solve and everyone at IBM pretty much lost access to email during the period due to the overload. Even worse, at the time a lot of internal systems at IBM were based in Lotus Notes that is a weird framework email client mashup and those systems were also affected.
This happened in 2007
This happened in 2007
Can anyone explain why people leave their servers configured to allow arbitrarily long To: lists? Any large organization is just one mistake away from a Reply-All apocalypse.
At the very least, the operations accounts, security, newsletters and Simon Stevens himself should have the ability to send a network-wide email - outside of that there's no good reason for Johnny intern to be sending an email to that many people.
This is not a ddos attack. More like ddos mistake or accident.
This is reminiscent of at least one IT Crowd episode (I forget the title), and so typical...
Two stories about this topic on the front-page right now. Merge them?
[0] https://blogs.technet.microsoft.com/exchange/2004/04/08/me-t...