ACHR News
search
Ask ACHR NEWS AI
cart
facebook twitter instagram linkedin youtube
  • Sign In
  • Subscribe
  • Sign Out
  • My Account
ACHR News
  • NEWS
    • Breaking News
    • New HVAC Products
    • Featured Products
    • Manufacturer Reports
    • HVAC Data
    • Legislation
    • ACHR NEWS Centennial
  • RESIDENTIAL
    • Air Conditioners
    • Furnaces
    • Residential Heat Pumps
    • Ductless
    • Residential IAQ
    • Testing, Monitoring, Tools
    • Components & Accessories
  • COMMERCIAL
    • Air Handlers
    • Rooftop Units
    • Chillers and Cooling Towers
    • Commercial Heat Pumps
    • Boilers and Hydronics
    • VRF/Ductless
    • Commercial IAQ
  • REFRIGERATION
    • Refrigerants
    • Refrigerant Regulations
    • Leak Management
  • CONTRACTOR PRO
    • Geothermal
    • Homeowner Study
    • VRF and VRV Ductless
    • Unitary Trends
  • EDUCATION
    • Training and Education
    • Business Management
    • Service and Maintenance
    • Continuing Education
    • Market Research >
      • HVAC Brand Awareness Report
      • VRV, VRF, VRVZ Report
      • Unitary Trends Report
      • Water Heat Professionals Report
    • Webinars
    • Sponsor Insights
    • eProducts Info
    • White Papers
  • EVENTS
    • HVAC Contractor Forum
    • Industry Events and Webinars
  • MEDIA
    • Videos
    • AHR Expo 2025 Videos
    • Podcasts >
      • ACHR News Podcast
      • HARDI Podcasts
      • AHR Expo Podcasts
      • ACCA Podcasts
    • Interactive Spotlights
    • Quizzes
    • eBooks
    • HVAC Talkback
  • HVAC GROUP
    • ACHR NEWS >
      • Current Issue
      • Digital Edition
      • Subscribe
    • Distribution Trends
    • SNIPS NEWS >
      • Join SNIPS NEWS
    • Engineered Systems News >
      • Join ES News
    • HVACR Directory
    • Contests
    • Newsletters
    • Contact
    • Advertise
    • My Account
HVAC ContractingNewsBusiness Management

Ransomware is Rampant: Is Your HVAC Business Safe?

HVAC contractors should consider outsourcing cybersecurity to a third-party firm

Cybersecurity.
September 26, 2021

With ransomware attacks on high profile businesses like Colonial Pipeline and JBS Foods in the headlines, HVAC businesses are increasingly asking, “Are we vulnerable too?” or even “Are we next?”

According to the U.S. Cybersecurity & Infrastructure Security Agency (CISA), “Ransomware is an ever-evolving form of malware designed to encrypt files on a device, rendering any files and the systems that rely on them unusable. Malicious actors then demand ransom in exchange for decryption. Ransomware actors often target and threaten to sell or leak exfiltrated data or authentication information if the ransom is not paid.”

Although there are various measures that HVAC businesses can take to reduce the risk of becoming a ransomware victim — which can involve a loss of data and production for an indefinite period until it is resolved — managers shaken by the scope of the problem are increasingly turning to expert third-party cybersecurity firms for guidance and protection.

 

Any HVAC Business a Potential Victim

When Colonial Pipeline was targeted by the DarkSide gang in a ransomware attack this April, it disrupted gas supplies along the U.S. East Coast, causing widespread shortages in multiple states. Colonial Pipeline paid $4.4 million dollars in Bitcoin to release their billing system and internal business network, although U.S. law enforcement later recovered much of the payment.

JBS Foods, one of the world’s largest meat processing companies, suffered a ransomware attack this May and paid an $11 million ransom. The Russia-based hacking group REvil is suspected to be behind the attack.

Global ransomware damage costs are predicted to hit $20 billion in 2021, up from $11.5 billion in 2019, $5 billion in 2017, and just $325 million in 2015, according to the Cisco/Cybersecurity Ventures 2019 Cybersecurity Almanac.

Cybersecurity Ventures expects that businesses will fall victim to a ransomware attack every 11 seconds in 2021, up from every 14 seconds in 2019, and every 40 seconds in 2016.

Looking for quick answers on air conditioning, heating and refrigeration topics? Try Ask ACHR NEWS, our new smart AI search tool. Ask ACHR NEWS →

Concern over the danger to businesses has even risen to the international stage. NPR reports that at a recent summit in Geneva, “President Biden called on Russian President Vladimir Putin to crack down on cybercrimes. But the Russian leader has shown little interest in combatting an emerging criminal industry in his country that's called ‘ransomware-as-a-service.’”

In the battle against ransomware, the challenge is that essentially any HVAC business with older PCs, networks, firewalls, or operating systems is vulnerable, particularly those that do not immediately update to the latest software to “patch” security issues, according to Yuriy Tatarintsev, manager, Technical Operations at BTI Communications Group.

 

Safeguarding HVAC Businesses of All Sizes

While keeping the entire HVAC business’s IT infrastructure and software fully up to date is the goal, even one PC running an older, unsupported version of Windows, for instance, can be “a chink in the defensive armor that invites intrusion,” said Tatarintsev.

So, the fight against ransomware begins with having a companywide process to ensure that all machines are patched with the latest security updates from Microsoft and other applications as soon as they are released.

Next, defending critical HVAC business processes from attack goes beyond simple anti-virus protection that solely reacts to known threats, and that leaves operations vulnerable to yet unidentified risks.

“We recommend a new generation of advanced antivirus software that does not always depend on identifying known threats or ‘signatures.’ Instead, such software uses artificial intelligence to analyze which PC programs and processes are affected and as soon malicious activity is detected, stops it,” said Tatarintsev.

According to Tatarintsev, email security is also of critical importance today because insufficient precaution in this area is perhaps the leading cause of companies getting ensnared in ransomware.

“Statistically most HVAC companies acquire ransomware when an employee receives a suspicious email that seems legitimate and clicks on an embedded link. This starts the ransomware attack, which then spreads throughout the company network,” said Tatarintsev.

To protect against this hazard, Tatarintsev recommends that HVAC businesses use advanced email spam protection tools that offer significantly more defensive capability than earlier, more rudimentary options.

“The advanced tools not only filter out all potentially malicious emails, but also stop users from going to dangerous website destinations by clicking on links that could start a ransomware attack,” he said. He explained that the tools rewrite all the embedded link Uniform Resource Locators (URLs). So, if a user clicks a URL in an email, instead of linking to a potentially dangerous website, he or she is redirected to a safe location or “sandbox.” The URL is analyzed to determine if it is dangerous, and if it is safe the user is allowed to go to the original website destination.

Since deceptive phishing emails designed to start a ransomware attack can appear so similar to authentic emails, Tatarintsev advises that all HVAC employees receive periodic security awareness training. This not only teaches employees how to distinguish the latest potentially dangerous emails, but also sends safe, simulated phishing emails to test their responses on an as needed basis. Employees who fail the test are given additional training, so they will not compromise the business when an actual phishing email-ransomware assault occurs.

If all these defenses fail and ransomware does infect and shut down a HVAC company’s IT network, a reliable back up system should be in place that can quickly restore all critical data.

“If a business’s vital server data is encrypted by ransomware, with a good backup solution data can be restored from the backup,” said Tatarintsev. He noted, however, that some data will be lost, depending on the frequency of backup. Unless these are virtually continuous, a day or even a week or more of current data could be lost.

Moreover, care must be taken as to how data is transferred and saved, so ransomware does not have access to storage sites connected to company networks.

While HVAC businesses can attempt to fight the growing scourge of ransomware in-house, most IT departments do not have the time, resources, or expertise available to deter the constantly evolving threat on a 24/7 basis.

As an alternative, an increasing number of HVAC businesses are cost-effectively protecting against ransomware by outsourcing to professional, third-party firms that remotely and continually provide layers of protection with a comprehensive, integrated IT approach.

This strategy can continually deter and detect threats as well as resolve vulnerabilities. Additionally, this eliminates the need to dedicate internal IT staff to these types of tasks. It also minimizes potential loss and even liability if serious harm were to be caused by disrupted company services.

However, even outsourced IT solutions and services are at risk of ransomware attacks and so must be prepared with advanced monitoring and prevention tools. On the weekend of July 3, 2021, Russia-linked hackers were suspected of a mass ransomware attack on Kaseya, a company that provides IT management software. The hackers demanded $70 million.

However, the first and primary goal of a third-party, integrated IT service is to deliver the foremost level of technical quality that can be delivered reliably for a client’s budget.

Only carefully selected software tools and technical solutions should be utilized to ensure its clients are always operating in a high-performance, reliable, and secure IT environment.

With the menace of ransomware continuing to escalate, HVAC businesses of all sizes would be wise to examine options for deterring the threat before being victimized.

Content courtesy of BTI Communications Group.

KEYWORDS: cybersecurity HVAC contractor best practices safety and HVAC

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

 

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • HVAC-enrollment

    The Trades Are Back: HVACR Programs See Nearly 30% Enrollment Spike

    A new wave of future technicians is entering the pipeline.  
    News
    By: Matt Jachman
  • 2025 Top 40 Under 40

    2025 Top 40 Under 40 HVACR Professionals List

    The 11th annual Top 40 Under 40 list highlights those...
    News
    By: Hannah Belloli-Oster
  • LG Ductless Mini-Split Systems

    The 9 Types of Heat Pumps

    As the U.S. moves toward electrification, heat pumps are...
    HVAC Residential Market
    By: Joanna R. Turpin
Subscription Center
  • Create an Account
  • Start a Subscription
  • Manage My Account
  • Sign Up for Newsletters
  • Visit Customer Service
  • Update Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to The News audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of The News or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Piggy Bank
    Sponsored byWatercress Financial

    Energy Prices, Inflation, and HVAC: What Today’s Homeowners Care About

  • Refrigerated Food
    Sponsored bySolstice Advanced Materials

    R-455A Refrigeration: A Cold Storage Solution for the Future

  • Airex Rooftop Units
    Sponsored byAirex Manufacturing Inc

    Consolidating Roof Penetrations: A Growing Trend in Multifamily HVAC Design

Popular Stories

HVAC-Price-Increase-graphic

HVAC Price Increase List: June 2026

Trump-Section-232.jpg

Trump Reduces Section 232 Tariffs on HVAC Equipment to 15%

Refrigerants-and-gauge.jpg

HVAC Industry Warns of Counterfeit Refrigerants Entering U.S. Supply Chain

U.S. Supreme Court building

95% Furnace Efficiency Rule to Get New Hearing

Midea-training.jpg

HVAC Workforce Crisis Expands Beyond Technicians to Instructor Shortages

View The ACHR NEWS
Centennial Anniversary Timeline

The ACHR News Timeline Chart
Submit a Letter
Submit a letter to our editors.

Events

November 6, 2025

Next-Gen Data Center Cooling: HVAC Innovation and Real-World Solutions

On Demand As AI workloads and high-density computing push traditional cooling methods to their limits, the data center industry is accelerating the adoption of next-generation HVAC technologies.

June 17, 2026

Decarbonization Without Disruption

This webinar will explore practical HVAC decarbonization strategies that minimize disruption while maximizing long-term performance and ROI.

View All Submit An Event

Poll

Summer Staff

Are you fully staffed for the summer season?
View Results Poll Archive

Products

BNI Mechanical/Electrical Square Foot Costbook, 2026 Edition

BNI Mechanical/Electrical Square Foot Costbook, 2026 Edition

See More Products
Decarbonization Without Disruption - Free Webinar - 6/17/2026

Related Articles

  • Eric Brackett

    Ransomware is Rampant: Is Your HVAC Business Safe?

    See More
  • gas-pipe-installation.jpeg

    The Hidden Threat to Your HVAC Business: Is Your Subcontractor Supply Chain Safe?

    See More
  • How is your HVAC Contracting Business Different?

    See More

Related Products

See More Products
  • front cover only.jpg

    How to Market Your HVAC Business

  • new cover.jpg

    Profit is An Attitude: The Strategies You Need to Optimize Profits

  • HVAC Customer Service Handbook, 4th Edition

See More Products

Related Directories

  • Your Bargain Mart

    We are a MRCOOL Dealer and carry contractor-grade HVAC equipment, air handlers, condensers, heat pumps, gas furnaces, evaporator coils and heat pumps, gas, and electric packaged units.
×

Sign Up. Stay Informed.

The #1 trusted source for the HVACR industry since 1926

SUBSCRIBE
  • RESOURCES
    • Advertise
    • Contact Us
    • Advisory Board
    • Classifieds
    • Submit a Letter
    • Directories
    • Store
  • ACCOUNT CENTER
    • Create an Account
    • Start a Subscription
    • Manage My Account
    • Sign Up for Newsletters
    • Visit Customer Service
    • Update Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • Instagram
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing