June 7, 2022

Mandiant confirms no evidence of an attack from the LockBit ransomware group

On Monday 6th of June, the LockBit ransomware gang published a new page on their data leak website that named Mandiant, a major American cybersecurity firm as the victim where they claimed to have stolen 356,841 files from Mandiant. On further investigation of the new page, there is a 0-byte file named ‘mandiantyellowpress.com.7z’ displayed on the page which appears to […]
June 6, 2022

The municipality of Palermo suffers major disruptions due to a ransomware attack

On Friday 3rd of June, the municipality of Palermo in Southern Italy suffered a cyberattack which resulted in a wide range of operations and services used by both citizens and visiting tourists being impacted. The systems have remained offline for the past three days even though local IT experts have been trying to restore the systems. According to multiple local […]
June 2, 2022

Evil Corp attempts to evade sanctions by switching to LockBit ransomware

On Thursday 2nd of June 2020, Mandiant revealed that the Evil Corp cybercrime group has now switched to deploying LockBit ransomware on targets’ networks to evade sanctions imposed by the U.S. Treasury Department’s Office of Foreign Assets Control (OFAC). The cybercrime group has been active since 2007 and was originally known for using the Dridex malware but in more recent […]
June 2, 2022

Victim’s website hacked to display ransom note in a new extortion strategy

A new extortion strategy which is being used by the Industrial Spy has been identified where they gain access to their victim’s corporate websites to publicly display ransom notes. The first incident of this new strategy was seen on Thursday 2nd of June 2020, when Industrial Spy started to sell data, which they claim was stolen from the French company, […]
June 2, 2022

Foxconn confirms disruptions to production in Mexico as a result of a ransomware attack

Recently, the electronics manufacturer, Foxconn has confirmed that one of its production plants in Tijuana, Mexico has been impacted by a ransomware attack in late May. The plant is considered a key plant for Foxconn as it acts as a critical supply hub for the U.S. state of California which is a significant electronics consumer. A Foxconn spokesperson also revealed […]
May 31, 2022

Costa Rica’s public health suffers Hive ransomware attack

On Tuesday, 31st of May, the Costa Rican Social Security Fund (CCCS), Costa Rica’s public health service suffered a ransomware attack which resulted in all the computers on their network being taken offline. The impact of the incident was revealed by employees who had reported on social media that they were told to shut down their computers and unplug them […]
May 6, 2022

AGCO, US agricultural machinery maker announces they suffered a ransomware attack

On Thursday 5th of May 2022, AGCO, one of the leading US-based agricultural machinery producers suffered a ransomware attack which resulted in some of their production facilities being impacted. This incident was announced on Friday 6th of May 2022 in a press release where AGCO stated that their business operations will be affected for several days whilst they repair their […]
April 29, 2022

A Possible ransomware attack against the service provider of a popular online Library app, Onleihe led to problems

On Tuesday 26th of April 2022, Onleihe, a popular Library lending app announces they experienced problems which could have been related to their service provider, EKZ who suffered a cyber-attack on Monday 18th of April 2022. The incident led to the outage of EKZ systems which impacted the websites: ekz.de, ekz.at, ekz.fr, divibib.com, the divibib user forum, the divibib Pentaho […]
April 28, 2022

Austin Peay State University announces ransomware attack via Twitter

On Wednesday 27th of April 2022, Austin Peay State University (APSU) confirmed that they had suffered a ransomware attack via their official Twitter account. Since the initial announcement, APSU has reassured the public that the incident was in the process of being contained and that their Learning Management System, D2L had online backups. The incident hasn’t seemed to have an […]