As reported previously on this site, Hall County, Georgia had revealed a ransomware attack on October 7, but until now, we didn’t know who attacked them. Now the threat actors known as DoppelPaymer have added Hall County to their dedicated leak site. In their updates, the county had reported: At this time, there is no…
Category: Malware
Privacy nightmare for Toledo Public Schools: Hackers dumped student and employee data
By mid-September, it was clear that school districts were under increased threat of ransomware attacks. In fact, when Clark County School District (CCSD) in Las Vegas and Fairfax County Public Schools (CFPS) in Virginia were added to the Maze cartel’s leak site, it seemed to portend potentially big data dumps. Since that dump, Maze dumped…
CISA and MS-ISAC Release Joint Guide on Ransomware
Trisha Anderson, Ashden Fein and James Yoon of Covington & Burling write: On September 30, 2020, the Cybersecurity and Infrastructure Security Agency (“CISA”) and the Multi-State Information Sharing and Analysis Center (“MS-ISAC”) released a joint guide synthesizing best practices to prevent and respond to ransomware. This guide was published the day before OFAC and FinCEN released their…
FIN11: Widespread Email Campaigns as Precursor for Ransomware and Data Theft
Genevieve Stark, Andrew Moore, Vincent Cannon, Jacqueline O’Leary, Nalani Fraser, and Kimberly Goody of FireEye write: Mandiant Threat Intelligence recently promoted a threat cluster to a named FIN (or financially motivated) threat group for the first time since 2017. We have detailed FIN11’s various tactics, techniques and procedures in a report that is available now by…
Universal Health Services reports restoration of services and its IT network three weeks after massive ransomware attack
Universal Health Services issued an update to its status following a massive ransomware attack on September 27. Here is the full text of their October 12 update: Universal Health Services (UHS) confirms that the UHS IT Network has been restored at Corporate and across all Acute Care hospitals, enabling connections to all major systems and…
UK: Hackney Hacked as Council Investigates Attack
Dan Raywood reports: London’s Hackney Council has reported it has “been the target of a serious cyber-attack which is affecting many of our services and IT systems.” According to a statement from Philip Glanville, mayor of Hackney, council officers have been working closely with the National Cyber Security Centre, external experts and the Ministry of Housing, Communities and Local…