分類: 其他公告
來源: 圖書資訊處網路管理組 - 楊志偉 - moplay@gms.ndhu.edu.tw - 電話6730
對象: 全校教職員_全校學生
標題: <資安宣導>加密勒索軟體
日期: 2026-06-25  ( 星期四 )  16:30

各位師長、同仁與同學大家好
網路威脅一直存在,再次跟大家宣導
攻擊沒有不見,只是在等待機會

如果不幸被加密勒索軟體(Ransomware)攻擊時,千萬不要驚慌,更不要輕易支付贖金(有時候錢給了,壞人就直接消失了,會落得人財二空的下場)。

發現檔案正在被加密(副檔名改變)或跳出勒索視窗時,首要任務是阻止災情擴大:
實體斷網: * 立刻拔掉網路線、關閉 Wi-Fi。
斷開與 NAS、網路芳鄰、雲端同步硬碟(如 OneDrive, Google Drive)的連線。
原因:防止勒索軟體繼續加密區網內的其他電腦或伺服器。
保護備份: 如果身上插著隨身碟或外接硬碟,立刻拔除,以免備份也跟著被加密。

以下為常見且你也能做到的防範
1. 系統與軟體更新(修補漏洞)
勒索軟體常利用作業系統(Windows/Linux)或常用軟體(如瀏覽器、Office)的漏洞進行自動化傳播。

2. 社交工程演練與資安意識
大多數的勒索軟體都是透過釣魚郵件(Phishing)或惡意下載連結進入內部網路。
#不要點奇怪的連結(網站)或下載免費的軟體

3 . 關閉高風險連接埠與服務
例如:停用 網路芳鄰: 舊版的 Windows 檔案分享協定(如 EternalBlue 漏洞)極易成為勒索軟體在區網內橫向移動的跳板。

4. 核心防禦:3-2-1 備份原則
這是對抗勒索軟體最有效、也是最後的底牌。 就算檔案不幸被加密,只要有乾淨的備份,就能免受駭客勒索。

3 個副本: 包含原始資料,重要檔案至少要有 3 份。
2 種媒介: 將備份儲存在兩種不同的硬體媒介(例如:硬碟、NAS、雲端)。
1 份異地/離線: 至少有一份備份放在遠端(如雲端),或是完全斷網的離線備份(如拔除的行動硬碟)。因為現代勒索軟體會連帶加密網路芳鄰和連線中的 NAS。

請大家不要掉以輕心,平時多做備份,才是良好的資訊素養習慣。
-------------------------------------------------------------------------------------------------
Dear Faculty, Staff, and Students,

Cyber threats are an ongoing reality. We would like to remind everyone once again: Cyber attacks haven't disappeared; hackers are simply biding their time for the right opportunity.

If you unfortunately fall victim to a ransomware attack, do not panic, and never pay the ransom. (In many cases, the criminals vanish as soon as they receive the money, leaving you with both financial loss and unrecovered data).

The moment you notice your files are being encrypted (e.g., file extensions changing) or a ransom note pops up, your top priority is to contain the damage and stop it from spreading:

Disconnect from the Network Immediately:

Unplug the network cable and turn off Wi-Fi right away.

Disconnect from NAS, network shares (network neighborhood), and cloud synchronization drives (such as OneDrive, Google Drive).

Reason: This prevents the ransomware from spreading and encrypting other computers or servers on the local network.

Protect Your Backups: If you have a USB flash drive or an external hard drive plugged into your computer, unplug it immediately to prevent your backups from being encrypted as well.

Key Preventative Measures You Can Take:
1. System and Software Updates (Patching Vulnerabilities)
Ransomware often exploits vulnerabilities in operating systems (Windows/Linux) or commonly used software (such as browsers and Office suites) to spread automatically.

2. Social Engineering Awareness & Cybersecurity Vigilance
The vast majority of ransomware gains access to internal networks through phishing emails or malicious download links.

Rule of thumb: Never click on suspicious links (websites) or download unverified free software.

3. Disable High-Risk Ports and Services
For example, disable outdated network sharing protocols (such as SMBv1): Older Windows file-sharing protocols (vulnerable to exploits like EternalBlue) are highly susceptible to being used by ransomware as a springboard to move laterally across the local network.

4. The Ultimate Defense: The 3-2-1 Backup Rule
This is your most effective defense and last line of security against ransomware. Even if your files are unfortunately encrypted, having a clean backup means you will never be held hostage by hackers.

3 Copies: Keep at least 3 copies of your important files (including the original data).

2 Different Media Types: Store your backups on at least 2 different types of hardware/media (e.g., external hard drive, NAS, or cloud storage).

1 Offsite/Offline Copy: Keep at least 1 copy in a remote location (such as the cloud) or completely offline (such as an unplugged external hard drive). Modern ransomware is capable of encrypting connected network shares and active NAS devices.

Please do not let your guard down. Developing a habit of regular backups is essential for good digital literacy and security.

Best regards,

網路管理組 

【針對此公告】   點擊數:156

 寄公告至下列信箱
      我的學校信箱 其它信箱:

 即時寄信給公告對象
      

 已批次寄出此公告,欲刪除此公告,請洽系統管理者

 反映即時公告信濫用(0人反映)(測試)

 


 

(只需輸入帳號,@後面不需輸入)