{"id":2222,"date":"2021-05-13T16:31:41","date_gmt":"2021-05-13T07:31:41","guid":{"rendered":"https:\/\/cyberenso.jp\/?p=2222"},"modified":"2021-07-13T16:39:51","modified_gmt":"2021-07-13T07:39:51","slug":"chemical-distributor-pays-4-4-million-to-darkside-ransomware","status":"publish","type":"post","link":"https:\/\/cyberenso.jp\/en\/chemical-distributor-pays-4-4-million-to-darkside-ransomware\/","title":{"rendered":"Chemical distributor Brenntag pays $4.4 million to DarkSide ransomware Group"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"2222\" class=\"elementor elementor-2222\" data-elementor-post-type=\"post\">\n\t\t\t\t\t\t\t\t\t<section class=\"elementor-section elementor-top-section elementor-element elementor-element-d6e60d4 elementor-section-boxed elementor-section-height-default elementor-section-height-default\" data-id=\"d6e60d4\" data-element_type=\"section\">\n\t\t\t\t\t\t<div class=\"elementor-container elementor-column-gap-default\">\n\t\t\t\t\t<div class=\"elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-5cd2851\" data-id=\"5cd2851\" data-element_type=\"column\">\n\t\t\t<div class=\"elementor-widget-wrap elementor-element-populated\">\n\t\t\t\t\t\t\t\t<div class=\"elementor-element elementor-element-a727725 elementor-widget elementor-widget-text-editor\" data-id=\"a727725\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<p>In May 2021, Chemical distribution company Brenntag suffered a ransomware attack that targeted their North American division. The attack was claimed by the DarkSide ransomware gang who states they have stolen 150GB worth of data. To prove their claims, DarkSide had published a private data leak page containing a description of the types of data stolen and screenshots of some of the files.<\/p><p>Brenntag published a statement that confirmed they had experienced a security incident: \u201cBrenntag North America is currently working to resolve a limited information security incident.\u201d They also informed the public they had \u201cdisconnected affected systems from the network to contain the threat. In addition, third-party cybersecurity and forensic experts were immediately engaged to help investigate. We also informed law enforcement of this incident.\u201d<\/p><p>The initial access to the network was made with stolen credentials that the DarkSide affiliate claims to have purchased on the Dark Web.<\/p><p>The initial ransom was for 133.65 Bitcoins which was valued at approximately $7.5 million USD at the time of the attack. But the ransom demand was negotiated down to $4.4 million that was paid on the 11<sup>th<\/sup> of May 2021.<\/p><p>Updated on 25<sup>th<\/sup> of June 2021.<\/p><p>On the 25<sup>th<\/sup> of June 2021, Brenntag sent data breach notification letters to all the affected individuals which were more than more than 6700 individuals according to info provided to Maine&#8217;s Attorney General. The letters stated that Brenntag had become aware of the attack on April 28<sup>th<\/sup>, 2021, two days after the DarkSide had breached its network.<\/p><p>&#8220;Our investigation confirmed that Brenntag systems were accessed without authorization starting on April 26, 2021, and\/or that some information was taken from our system,&#8221;<\/p><p>Brenntag stated that the data exfiltrated included &#8220;social security number, date of birth, driver&#8217;s license number, and select medical information.&#8221; Brenntag also explained that the third-party cybersecurity forensic experts that were hired to investigate the incident, found no evidence that the stolen information was misused for fraudulent purposes.<\/p>\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t<\/div>\n\t\t\t\t\t\t\t<\/div>\n\t\t<\/section>\n\t\t\t\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>In May 2021, Chemical distribution company Brenntag suffered a ransomware attack that targeted their North American division. The attack was claimed by the DarkSide ransomware gang who states they have stolen 150GB worth of data. To prove their claims, DarkSide had published a private data leak page containing a description of the types of data stolen and screenshots of some<span class=\"excerpt-hellip\"> [\u2026]<\/span><\/p>\n","protected":false},"author":1,"featured_media":4742,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,222,12,16,17,8],"tags":[],"class_list":["post-2222","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-latest_news","category-manufacturing","category-read_article","category-read_case_studies","category-read_contributors","category-industry_sector"],"acf":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/cyberenso.jp\/wp-content\/uploads\/2021\/05\/pollution-4796858_1280.jpg?fit=1280%2C852&ssl=1","_links":{"self":[{"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/posts\/2222"}],"collection":[{"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/comments?post=2222"}],"version-history":[{"count":11,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/posts\/2222\/revisions"}],"predecessor-version":[{"id":4744,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/posts\/2222\/revisions\/4744"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/media\/4742"}],"wp:attachment":[{"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/media?parent=2222"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/categories?post=2222"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyberenso.jp\/en\/wp-json\/wp\/v2\/tags?post=2222"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}