Doug Levin recently wrote on Infosec.Exchange: Rant incoming. The frequency with which I read folks asserting that ‘education’ and in particular ‘U.S. K-12 schools’ are the most frequent ransomware target is so frustrating. Of course, that’s a nonsense assertion – and not supported by any reasonable read of the data. It is almost like the…
Cyber Executive Who Spoke to FBI Due to be Sent to Russia
Jeff Stone reports: Russia’s effort to bring its hackers back home is gaining traction. For years, the US and Russia have sparred over the fate of alleged cybercriminals. There was Yevgeniy Nikulin, a Russian man who broke into LinkedIn, Dropbox and Formspring a decade ago and eventually became the subject of competing extradition requests from the rival…
Swedish Retail and Grocery Provider Coop Hit by Cactus Ransomware Gang
Pierluigi Paganini reports: Coop is one of the largest retail and grocery providers in Sweden, with approximately 800 stores across the country. The stores are co-owned by 3.5 million members in 29 consumer associations. All surplus that is created in the business goes back to the members or is reinvested in the business, which creates a…
The State of Ransomware in the U.S.: Report and Statistics 2023
Data analyses and commentary by Emsisoft begins: “From 2016 to 2021, we estimate that ransomware attacks killed between 42 and 67 Medicare patients.” — McGlave, Neprash, and Nikpay; University of Minnesota School of Public Health1 In 2023, the U.S. was once again battered by a barrage of financially-motivated ransomware attacks that denied Americans access to…
Operation Triangulation: The last (hardware) mystery
Boris Lairn reports: Today, on December 27, 2023, we (Boris Larin, Leonid Bezvershenko, and Georgy Kucherin) delivered a presentation, titled, “Operation Triangulation: What You Get When Attack iPhones of Researchers”, at the 37th Chaos Communication Congress (37C3), held at Congress Center Hamburg. The presentation summarized the results of our long-term research into Operation Triangulation, conducted with our…
Parathon by JDA e-Health: what we still don’t know about their July ransomware incident
On August 1, DataBreaches noticed that Parathon by JDA e-Health had been listed on the Akira ransomware leak site. Neither Akira nor Parathon responded to DataBreaches’ inquiries at the time, as DataBreaches reported on August 6. On October 30, Parathon issued a notice of security incident. The notice stated, in part: On July 27, 2023,…