LockBit Attack Help!

Anyone been hit with a lock bit attack and best way to deal with it?

Is there a way to make paymentsense integration work without disabling the firewall?

If you’ve been hit with this EVERY computer on your network should be considered compromised.

You’ll need to completely wipe each computer then reinstall windows.

Hopefully, you have off-site backups of your database.

1 Like

Hi @Memo

Thanks for your reply.

Yes I had to completely wipe out the pc and reinstall everything from scratch lucky I had a recent DB backup.

I was running windows 10 with firewall disabled. My firewall was disabled by SambaPOS support team in order for my Paymentsense integration to work at the time.

Is this why I was exposed to attack?

I would strongly recommend everyone to take database backups and save to cloud service or even a usb.

Losing your SambaPOS Menu and customisations is not something you want to take a gamble with.

Great that you have a backup!

Keep in mind that if you have, for example, kitchen display and/or cashier that those terminals will need to be wiped as well. They should be kept disconnected from the network until they are cleaned.

As for the windows firewall being disabled, it only poses an issue in the following circumstances:

  • guest, employees, untrusted users are on the same network
  • the router between the network and the internet has ports forwarded or the terminal with firewall disabled is set as a DMZ host.

So long as you keep your POS, printers, etc. on a segregated network the attack surface is very small.

1 Like

I now have Windows 11 with latest updates and all protection systems in place and all user accounts now have passwords.

I do have ports for RDP and VNC, how could these be made more secure? Is Windows protection sufficient or de we need additional software to protect our systems?

Windows defender (or whatever it’s called these days) is usually just fine.

As for having open RDP and VNC ports, keeping the terminal(s) on a segregated network is usually all one needs.

1 Like