This included all their server patching and security, the automatic shit was disabled because "it's more efficient to do it on the weekends at 6 PM Saturday every week." None of it got done, of course, becuase the "Cybersecurity Expert" Jeets didn't know how and Stack Overflow doesn't have a script to do it for them. We were years behind on patches when the event happened.
In hindsight I should have realized what was going on when I started hearing about Slack cutting us off at random because the "special version" we were installing and not updating was so old Slack was refusing to allow us to connect anymore. And yes, normally Slack auto-updates, unless you specifically get their enterprise edition that doesn't, which means this isn't just stupid, it's intentionally stupid.
One of the head Cybersecurity guys, an American, goes on vacation for the first time in years, and notably goes off the grid. No phone, no email, no laptop, nothing. "Fuck this place I'm out don't call me even if it's on fire" type vacation. Instantly, the entire company is hit with Ransomware. To this day I'm not sure if he was involved or if they were just waiting until the last White American who could take charge and fix shit was unavailable. I lean towards the later because he didn't lose his job and didn't vanish afterwards.
I'm on duty that night and all hell breaks loose exactly at 5 PM when the last Americans (other than me) leave. I realize what's going on within minutes as I'm on the phone with a user, see [head of Cybersecurity] guy has logged in remotely to this woman's device and installed some shit about 5 minutes before everything went to shit, and I see about 30+ voicemails appear in my inbox.
Immediately fire off a SMS, Email, Pager Duty, and fucking flat out call the Jeet on call network guy cause they're not responding to ANY of the P1 "In case of everything on fire pull ripcord and run" levers we have specifically for something like this.
"We have a Randomware worm that is hitting everything, you MUST disable the VPN immediately. TURN IT OFF. We'll turn it back on later, TURN IT OFF NOW."
"Yes very good will investigate and properly handle this emergency with the haste and expedience."
"NO, DO NOT INVESTIGATE. TURN OFF THE FUCKING VPN, NOW, UNDERSTAND?! IF ANYONE COMPLAINS TELL THEM I TOLD YOU TO DO IT, TURN IT OFF, NOW."
"Yes saar I will do the needful thank you very much."
I have the lady I'm on the phone with go to every computer she can reach in her office and disconnect them from Ethernet, Power them down, and yank the power from her office's router. It's too late by then but I do get a gold star for trying later on.
6 hours later when the white IT leadership (a bunch of fat ugly white Karens who aren't from tech but do know how to suck corporate anus) are roused out of their stupor the VPN is finally turned off.
THOUSANDS of laptops are encrypted. Every server is encrypted. Every database is encrypted. Even the "segmented network" that's on a separate, high security domain that contains HIPAA data and mission critical stuff (blueprints, patents, etc) that's supposedly air-gapped and requires jumpboxes and secondary VPNs is encrypted. (We find out later that the Jeet "devops" got tired of doing things right so they set up their own secret VPN that bypassed all that security stuff. HIPAA doesn't exist in India and they don't give a fuck about your laws.) All the "backups" are encrypted as they were either left connected (copying C

new folder to C

new folder backup is a backup, I hear from a fucking idiot jeet a few days later) or effectively nonexistent.
They pay the ransom. It's the exact amount, to the fucking penny, that their cybersecurity insurance covers. 8 figures. We're not supposed to ask about that and I think if the SEC found out they'd have questions they don't want to answer.
One of the India outsourcer companies vanishes overnight. Their website is gone. Domain name doesn't resolve. Only know it exists cause of google cache and wayback machine. NONE of them ever respond to email, call, certified mail, nothing, ever again. A big chunk of contractors that had been working with this shithole company for years suddenly just... fucking gone. And yes, this includes the on call network jeet I spoke with that night.
They learn their lesson, sort of. See, the reason they had all jeets? Cheap, of course, and the small American team could make up the difference. And this made sense because it was a handful of female "IT professionals" with a background in HR and Communications (
not Tech) and a bunch of Jeet brahmin tard wranglers in charge who were wormtounging them. "Oh yes vary good best technicians we shall do job at 1/10th price of silly Americans and you won't have to deal with American IT men anymore yes saar best IT very good sho bob and vageen?"
They don't fire the jeets, of course. No no, that would cost money and they'd have to deal with -- ugh -- techbros! No, the lesson they learn is to install 5 different cybersecurity apps on each and every device (making them effectively unusable for a year or so until that gets dialed back, but each Cybersecurity consultant they go through suggests a different one so they just turn them all on at once), enable every fucking insane security option imaginable (MFA no longer allows push, have to use SMS instead, sessions like Outlook or Slack log you out every 12 to 24 hours, no local admin for anyone, etc) because "more secure is more gooder!" but in reality the women don't have a clue about what to do but they do know they sure as fuck aren't taking blame for this and the Jeets they were going to blame vanished.