Brian Krebs reports: The victim shaming website operated by the cybercriminals behind 8Base — currently one of the more active ransomware groups — was until earlier today leaking quite a bit of information that the crime group probably did not intend to be made public. The leaked data suggests that at least some of website’s code was…
Search Results for: ransomware
Visiting Physician’s Network in Texas silent about ransomware attack and incident response
One of the newer ransomware groups to open a leak site is “ThreeAM.” Bleeping Computer recently reported that the ThreeAM malware is written in Rust, and on at least one occasion, researchers discovered that when LockBit failed, ThreeAM (aka 3AM) was successfully deployed. Symantec has more details on the malware and the group’s methods. ThreeAM…
BlackCat ransomware hits Azure Storage with Sphynx encryptor
Sergiu Gatlan reports: The BlackCat (ALPHV) ransomware gang now uses stolen Microsoft accounts and the recently spotted Sphynx encryptor to encrypt targets’ Azure cloud storage. While investigating a recent breach, Sophos X-Ops incident responders discovered that the attackers used a new Sphynx variant with added support for using custom credentials. Read more at BleepingComputer.
Suspected ransomware attack hits Auckland Transport’s Hop cards
1News reports: A suspected ransomware attack is affecting Auckland Transport’s Hop card system, impacting card top-ups and leaving customer service centres with limited functionality. “Early indications are that this is a ransomware attack however our investigations are ongoing,” an Auckland Transport (AT) spokesperson told 1News. No personal or financial data has been accessed. Read more…
HC3: Sector Alert: Akira Ransomware
September 12, 2023 TLP:CLEAR Report: 202309121400 Akira Ransomware Executive Summary Akira is a Ransomware-as-a-Service (RaaS) group that started operations in March 2023. Since its discovery, the group has claimed over 60 victims, which have typically ranged in the small- to medium-size business scale. Akira has garnered attention for a couple of reasons, such as their…
Chambersburg Area School District answers some questions about ransomware attack, won’t say if they paid hackers
A statement and FAQ by the Chambersburg Area School District, as shared by TriState Alert, appears below.The district offers its reasons (translation: excuses) for not answering the questions parents and the public really want to know: did the district pay ransom, and was personal information acquired by the attackers? Although the district did not name…