$42.180.02
49.230.00
Electricity outage schedules

Don't give hackers a second chance: experts explain why cybercriminals return to hacked networks

Kyiv • UNN

 • 63819 views

Hackers often return to hacked networks if the causes of the hack are not eliminated. CERT-UA experts called for taking into account the mistakes of users that cause repeated cyberattacks.

Don't give hackers a second chance: experts explain why cybercriminals return to hacked networks

Lessons from cyberattacks must be learned, and the best defense is preventive measures. This was stated by the Government Computer Emergency Response Team CERT-UA, reports UNN.

Details

According to experts, hackers often return to already hacked networks. Therefore, CERT-UA called on users to take into account the most common mistakes that cause repeated hacking of previously attacked networks. Typical mistakes made by institutions and organizations:

  • lack of practice in studying and implementing experience (lessons learned);
    • not all recommendations were implemented after the attack investigation;• not all systems were checked;
      • open vulnerabilities after recovery.

        Russian hackers attacked the WUC lecture on debunking the myths of Russian propaganda08.04.25, 13:36 • 8280 views

        Simply recovering from backups after a hack and continuing to work without analyzing the attack itself and eliminating its causes is dangerous, experts emphasized. Hackers return through the same vulnerabilities.

        Even one unclosed "hole" can become an entry point for the enemy. It is necessary to first investigate how the hack occurred and identify vulnerable systems. Then, the identified shortcomings should be eliminated and additional security measures implemented, backups should be checked for compromise and data should be safely restored.

        Attackers can leave backdoors on other devices. Even if they were not used during the attack, these gaps remain open, giving hackers the opportunity to return and gain access in the future.

        The DIU repelled a large-scale cyberattack by Russian special services on the War&Sanctions portal08.04.25, 19:33 • 13308 views

        The following actions will help to avoid repeated hacking:

        • after the attack, do not rush to restore the system - first analyze the situation;
          • close all found vulnerabilities, not just the most obvious ones;
            • check not only the main servers, but also all devices on the network;
              • carefully check backups before restoring from them.

                Let us remind you

                The account of the Prime Minister of the Czech Republic, Petr Fiala, was hacked on the social network X, spreading fakes about the attack of the Russians. The police are investigating the incident and выясняют, how the attackers bypassed the protection.