February 14, 2022

FBI releases joint Advisory with U.S. Secret Service against BlackByte ransomware

On Friday 11th of February 2022, the US Federal Bureau of Investigation (FBI) released a joint Cybersecurity Advisory with the U.S. Secret Service (USSS) about indicators of compromise associated with BlackByte ransomware. The joint advisory alert details indicators of compromise (IOCs) from previous BlackByte ransomware attack which organisations can use to detect and defend against future BlackByte’s attacks. The joint […]
February 14, 2022

Japanese sports brand Mizuno experiences system outages from possible ransomware attack

On Tuesday 8th of February 2022, Mizuno, a Japanese sports equipment and sportswear company with locations throughout Asia, Europe, and North America started to experience system outages involving phone outages and order delays. It is believed that it is due to a ransomware attack on their US corporate network over the weekend of the 4th of February. Many customers have […]
February 13, 2022

NFL’s San Francisco 49ers experience a Blackbyte ransomware attack

On Saturday 12th of February 2022, the BlackByte ransomware group announced that they had stolen data from the NFL’s San Francisco 49ers team during a ransomware attack. The 49ers have confirmed that they have experienced a cyber-attack which has resulted in disruptions in portions of their IT network. It is believed that the incident involved ransomware as the 49ers stated […]
February 10, 2022

US releases joint advisory warning organisations against observed behaviours and trends of ransomware operations from 2021

On Wednesday 9th of February 2022, Federal Bureau of Investigation (FBI), the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), the Australian Cyber Security Centre (ACSC), and the United Kingdom’s National Cyber Security Centre (NCSC) released a joint cybersecurity advisory where they warned of an increase globalized threat of ransomware as FBI, CISA, NSA, ACSC, and NCSC have […]
February 9, 2022

Egregor, Maze master decryption keys released by alleged developer

On Tuesday 8th of February 2022, the decryption keys for Maze, Egregor, and Sekhmet ransomware operations and the source code for the M0yv ‘modular x86/x64 file infector’ were leaked on the BleepingComputer forums by the alleged malware developer who went by the name of “Topleak” when leaking the keys. The user stated that this leak was planned and had no […]
February 8, 2022

Vodafone Portugal experiences country-wide service outage after cyberattack

On Monday 7th of February 2022, Swissport, Vodafone Portugal suffered a cyberattack which resulted in country-wide service outages, and the disruptions to their 4G/5G data networks, SMS texts, and television services. Vodafone Portugal stated that the incident occurred last on Monday night and was “a deliberate and malicious attack intended to cause damage.” Currently only the 3G network is available […]
February 7, 2022

Free decryptor released by Avast for TargetCompany ransomware victims

On Monday 7th of February 2022, Avast, a Czech cybersecurity software firm released a free decryption tool for TargetCompany ransomware victims. Although Avast has warned that the decryptor can only be used under certain circumstances as the process of using this decryptor is resource intensive and time-consuming. The TargetCompany ransomware decryptor works by cracking the password after comparing an encrypted […]
February 5, 2022

FBI releases flash alert against LockBit 2.0 ransomware

On Friday 4th of February 2022, the US Federal Bureau of Investigation (FBI) released a flash alert about indicators of compromise associated with LockBit 2.0 ransomware. The flash alert details the advances to the LockBit 2.0 since the LockBit ransomware gang became active in September 2019. LockBit 2.0 is the second iteration of the original LockBit ransomware which was released […]
February 4, 2022

Flights suffer delays after ransomware attack hit Swissport

On Thursday 3rd of February 2022, Swissport, one of the largest aviation services companies in the world, announced that it had experienced a ransomware attack which resulted in their IT infrastructure and services being impacted and causing flights to be delayed. The attack was believed to have occurred at 6 AM on Thursday morning and led to minor delays between […]