There’s an interesting piece by Andrew E. Kramer, Michael Schwirtz and Anton Troianovski in the New York Times: Secret Chats Show How Cybergang Became a Ransomware Powerhouse. The reporters obtained access to the internal dashboard that DarkSide customers used to organize and carry out ransom attacks and their piece provides some insights as to how DarkSide “support” dealt with…
CA: Azusa Police reveal ransomware attack in March
On March 17, the DoppelPaymer threat actors added Azusa Police Department in California to the leak site where they list ransomware victims who have refused to pay their ransom demands. On April 22, the threat actors increased the pressure on the department — or attempted to — by dumping some files as proof that they…
Au: BLK Sport reveals DarkSide attack
On May 26, BLK Sport disclosed that they had been attacked by DarkSide on April 21, 2021. Of note, the firm states that they have to assume that information may have been exfiltrated (because that’s how DarkSide normally operated), but they have been unable to actually determine the extent of any information theft. According to their…
MA: Sturdy Hospital pays ransom after patient information is stolen
Updated June 1: External counsel for the hospital notified the Maine Attorney General’s Office that this incident resulted in notifications to 42,336 people and that those affected were offered two years of Experian credit and identity monitoring services. Updated June 3: It seems that on May 28, they notified HHS that they notified 57,379, so…
It: Municipality of Porto Sant’Elpidio publicly quiet after ransomware attack and partial dump of files
This week, DataBreaches.net reported on a new dedicated leak site and threat actors who had hit Clover Park School District in Washington. The same threat actors, whose name is not even clear (are they PayOrGrief or Grief_List or…) have listed three other victims on their site who presumably did not pay their ransom demands. One…
UMD-Baltimore updates Accellion breach notification after finding PII and PHI involved
On April 1, DataBreaches.net reported that the University of Maryland, Baltimore was one of the educational entities impacted by the CLOP hack and exfiltration of Accellion client data, but that neither UMD nor Accellion even knew that until the last week in March. This week, the university issued an updated press release that reveals that…