Ransomware group ‘Hades’ claims more victims as investigators seek answers

A ransomware group that targets billion-dollar companies — but that has stubbornly defied attribution consensus among cybersecurity researchers — has claimed at least seven victims since its discovery late last year. What’s more, it has taken additional steps in an apparent bid to baffle investigators who have tried to pin down who, exactly, the operators are, according to Accenture Security research released Tuesday. The update on the operators of the self-proclaimed Hades ransomware variant adds to its mystery as much as it subtracts from it. Accenture said it “is not yet able to confidently make attribution claims,” though other researchers have variously described Hades as a new group, suggested  it is connected to a wel known Russian ransomware gang, or linked the Hades activity to a Chinese nation-state hacking outfit thought to be behind this year’s Microsoft Exchange Server attack. What Accenture says it knows is this: First, the Hades […]

The post Ransomware group ‘Hades’ claims more victims as investigators seek answers appeared first on CyberScoop.

Continue reading Ransomware group ‘Hades’ claims more victims as investigators seek answers

Cyber insurance giant CNA hit by ransomware attack

Insurance firm CNA Hardy says that it has suffered a “sophisticated cybersecurity attack” that has impacted its operations, including its email system. According to a statement posted on the firm’s website, CNA determined it had falle… Continue reading Cyber insurance giant CNA hit by ransomware attack

Ransomware in 2020: A Banner Year for Extortion

From attacks on the UVM Health Network that delayed chemotherapy appointments, to ones on public schools that delayed students going back to the classroom, ransomware gangs disrupted organizations to inordinate levels in 2020. Continue reading Ransomware in 2020: A Banner Year for Extortion

US advisory meant to clarify ransomware payments only spotlights widespread uncertainty

If a Treasury Department advisory threatening financial penalties against anyone paying ransomware hackers was intended to send a clear message, it may have done the exact opposite. The Oct. 1 advisory from the Office of Foreign Assets Control warned that paying or helping to pay ransoms to anyone on its cyber sanctions list could incur civil penalties. Across some of the industries mentioned in the advisory — like cybersecurity incident response firms and insurance providers — reactions have ranged from confusion to silence, from yawns to raised eyebrows, from praise to fear of a blizzard of potentially unintended consequences. The worst case scenarios involve ransomware victims in the health sector having to make a life-or-death decision on whether to pay to unlock their systems while at risk of incurring Treasury’s wrath, or situations where victims try even harder to keep attacks quiet to avoid OFAC fines, which sometimes total millions […]

The post US advisory meant to clarify ransomware payments only spotlights widespread uncertainty appeared first on CyberScoop.

Continue reading US advisory meant to clarify ransomware payments only spotlights widespread uncertainty

Ransomware Victims That Pay Up Could Incur Steep Fines from Uncle Sam

Companies victimized by ransomware and firms that facilitate negotiations with ransomware extortionists could face steep fines from the U.S. federal government if the crooks who profit from the attack are already under economic sanctions, the Treasury Department warned today. Continue reading Ransomware Victims That Pay Up Could Incur Steep Fines from Uncle Sam

Garmin Pays Ransom to Evil Corp – Despite Russian Sanctions

It’s emerged that Garmin caved into pressure and paid several million dollars’ ransom to WastedLocker-wielding criminals.
The post Garmin Pays Ransom to Evil Corp – Despite Russian Sanctions appeared first on Security Boulevard.
Continue reading Garmin Pays Ransom to Evil Corp – Despite Russian Sanctions

Smashing Security podcast #189: DNA cock-up, Garmin hack, and virtual kidnappings

Why are students faking their own kidnappings? What’s the story behind Garmin’s ransomware attack? And a genetic genealogy website suffers a hack or two.
All this and much more is discussed in the latest edition of the award-winning “… Continue reading Smashing Security podcast #189: DNA cock-up, Garmin hack, and virtual kidnappings

Garmin confirms ransomware attack, keeps quiet on possible Evil Corp. involvement

Finally, Garmin customers who have put off their exercise routine because of outages on the website and mobile app can lace up their running shoes again. Garmin said in a statement Monday that it has started restoring services following a ransomware attack that locked “some” systems on July 23. While the company says it has no indication that scammers accessed customer data, the attack did interrupt website functionality, customer support services, user apps and corporate communications, according to the statement. “Affected systems are being restored and we expect to return to normal operation over the next few days,” Garmin said. “We do not expect any material impact to our operations or financial results because of this outage.” The official update confirms prior reporting that hackers had infiltrated Garmin’s systems and demanded an extortion fee to allow the company to resume activity as normal. Garmin previously said its mobile app was […]

The post Garmin confirms ransomware attack, keeps quiet on possible Evil Corp. involvement appeared first on CyberScoop.

Continue reading Garmin confirms ransomware attack, keeps quiet on possible Evil Corp. involvement