March 18, 2021

DoppelPaymer ransomware group demands $20 Million from Kia Motors America

On February 13th, 2021, Kia Motors America experienced a ransomware attack by the DoppelPaymer ransomware group which led to outages over their nationwide network. The effect of the attack was noticed when customers discovered the Kia Owners Portal was offline and displayed an error message that said:    “We are currently experiencing an IT service outage that has impacted some […]
December 15, 2020

The Role of Admin Credentials in the SolarWinds Attack

I wanted to share my thoughts on the SolarWinds attack that has been used to target government agencies as well as other private/public companies. FireEye has an excellent write-up ( Highly Evasive Attacker Leverages SolarWinds Supply Chain to CompromiseMultiple Global Victims With SUNBURST Backdoor ) and I encourage everyone to read it to familiarize yourself with the exploit and attack paths. […]
July 6, 2020

Capcom hit by Ragnar Locker ransomware with 1TB of data stolen

On 2nd of November, Japanese game developer Capcom experienced a ransomware attack where the company had to shut down portions of their corporate network to prevent the spread of the attack and threat actors claim to have stolen 1TB of sensitive data from their corporate networks in the US, Japan, and Canada. At the time of compromise, Capcom displayed notices […]
March 20, 2020

UK Fintech Firm Finastra announces they were attacked by ransomware.

On the 20th of March 2020, Finastra, a leading financial technology provider from the UK, announced that it had to take several servers offline in response to a security breach they had discovered earlier that day. The announce come out after sources at two different U.S. financial institutions had forwarded a notice, they received from Finastra to cybersecurity writer Brian […]