A large commercial organisation contacted the QinetiQ 24-hour Computer Incident Response team concerned about suspicious activity on their network. The systems administrator had noticed that 'something was not quite right' by the sheer amount of data that was leaving the system. He knew that expert and impartial assistance was needed.
Our team of specialists were able to identify that the source of the problem was inappropriately configured network equipment which allowed the attacker to compromise a number of NT servers and install backdoors which allowed further system compromise.
We carried out a clean re-install and provided expert advice and assistance on implementing security measures to prevent a similar occurrence. With minimal business interruption, the commercial organisation concerned was then in a position to continue to trade more safely.