October 22, 2021

A data breach investigated by GPDP after ransomware attack on SIAE

On Thursday 21st of October 2021, the Italian data protection authority Garante per la Protezione dei Dati Personali (GPDP) announced they were investigating a data breach of Società Italiana degli Autori ed Editori which is Italy’s copyright protection government agency. Currently the GPDP is stating that the investigation is looking at whether threat actors were able to steal the personal […]
October 21, 2021

Evil Corp launch new Macaw Locker ransomware to evade US sanctions

Recently, a new ransomware called Macaw Locker launched by Evil Corp, has entered the ransomware space. It is believed that Evil Corp have released this new ransomware to evade US sanctions that prevent victims from making ransom payments. This is not the first time that Evil Corp have released a new ransomware to evade the US sanctions that were placed […]
October 21, 2021

Carbanak hacking group enters ransomware space by creating a fake cybersecurity company

On Thursday 21st of October 2021, researchers at Gemini Advisory released a blog detailing evidence that FIN7 (aka ‘Carbanak’) hacking group has set up a fake cybersecurity company known as Bastion Security which was being used to hire pentesters and system administrators to conduct pre-encryption stages of ransomware attacks. Researchers discovered Bastion Security website was made up of stolen and […]
October 19, 2021

Free BlackByte ransomware decryptor released after AES encryption key was reused

On Thursday 15th of October 2021, a free decryptor for the BlackByte ransomware and a SpiderLabs blog detailing the process of decrypting the ransomware was released to the public to allow past victims to recover their files for free. Researchers had found that the ransomware was downloading an image file called ‘forest.png’ from a remote malicious site under the control […]
October 18, 2021

Attacks on ten Israeli hospitals attributed to Chinese threat actors

On the 17th of October 2021, the Ministry of Health and the National Cyber Directorate in Israel released a joint announcement details a spike in ransomware attacks over the weekend of the 16th that has seen by targeting systems of nine health institutes in Israel. The Israeli government have stated that the attempts had resulted in no damage to the […]
October 17, 2021

REvil ransomware group’s Tor sites shut down after being hijacked

On the 17th of October 2021, the Tor sites of REvil ransomware gang went offline after an unknown person hijacked the Tor onion domains with the same private keys as REvil’s Tor sites and may have backups of the sites. One of the threat actors “0_neday”, affiliated with the REvil operation has confirmed that someone has hijack the ransomware gang’s […]
October 14, 2021

University of Sunderland experience long-term outage after cyber attack

On Wednesday 13th of October 2021, the University of Sunderland in the UK announced they were experience IT issues that had led to most of their IT systems being taken down. The university stated the IT issues all indicated that they were experiencing a cyber-attack. The first signs of the incident were seen on Tuesday morning but weren’t investigated straight […]
October 8, 2021

American media conglomerate, Cox Media Group disclose ransomware attack.

On Friday 8th of October 2021, Cox Media Group, an American media conglomerate disclosed that they experienced a ransomware attack that led to TV and radio broadcast streams to be taken down in June of 2021. The attack disclosed to the public via mail that was sent to over 800 individuals who have had their personal information exposed during the […]
October 2, 2021

Sandhills Global experience disrupt to operations, caused by Conti ransomware attack

On Thursday 30th of September 2021, Sandhills Global, a US-based trade publication and hosting company catering to the transportation, agriculture, aircraft, heavy machinery, and technology industries, was hit by a Conti Ransomware attack that caused Sandhills Global to shut down all their IT systems to prevent the spread of the ransomware attack. “Sandhills Global is currently responding to a ransomware […]