Technology

Industry

Taiwanese Chipmaker ADATA Attacked by Ragnar Locker Gang

May 15, 2021

The Ragnar Locker ransomware gang published download links for more than 700GB of archived data stolen from chip maker ADATA. A set of 13 archives, allegedly containing sensitive files, have been publicly available at a cloud-based storage service. A total of 1.5TB of data was compromised.

In October 2022 the Ransomhouse gang claimed to have hacked ADATA and published data on leak site. Bleepingcomputer compared the timestamps on the data shared by RansomHouse with the data leaked by Ragnar Locker in June 2021. They found that both sets of stolen data have similar timestamps, with no file being newer than May 2021. ADATA told Bleepingcomputer they were not hacked, and that this is the same data stolen by Ragnar Locker in 2021.

read more

German Energy System Supplier Hit by Ransonware Attack

November 21, 2021

On November 10-11, Kisters AG in Germany was hit by a ransomware attack. Kisters AG is a critical infrastructure supplier for energy systems with the potential for downstream compromise. The software provider, which specializes in the energy industry, has shut down the system “to prevent further damage”. Their website reports a new IT infrastructure was built. Close to normal operations was resumed by January 12, 2022.

read more

REvil Extorts Apple in Supply Chain Attack

April 20, 2021

REvil ransomware gang ransomware group attacked Quanta, a Taiwan-based original design manufacturer (ODM). The attackers attempted to pressure Quanta into paying a ransom. When that didn’t work, they turned their attention to Apple by publicly releasing proprietary blueprints for new Apple devices that they had stolen from the tech giant’s business partner. According to the Tor payment page shared with BleepingComputer, Quanta has to pay $50 million until April 27th, or $100 million after the countdown ends.

Apple contracts Quanta to manufacture Apple Watch, Apple Macbook Air, and Apple Macbook Pro.

read more

REvil Demands $50Million Ransomware from Acer Electronics

March 23, 2021

The Sodinokibi/REvil ransomware gang has reportedly infected Taiwanese multinational electronics corporation Acer and demanded a ransom of $50 million. Those responsible for the Sodinokibi ransomware strain announced on their data leaks website that they had breached the computer giant.

This was the largest ransom ask made to date—many more times higher than what the Conti gang wanted from IoT manufacturer Advantech in November 2020.

read more

Ransomware Attack Disrupts Tyler Technologies’ Operations.

September 23, 2020

Leading government technology services provider Tyler Technologies has suffered a ransomware attack that has disrupted its operations.

Bleepingcomputer reports that local government employees were told by MISAC (Municipal Information Systems Ass.) that Tyler Technologies suffered a ransomware attack affecting their phone ticketing system and support systems.

read more

Konica Minolta hit by RansomEXX

July 30, 2020

Business technology giant Konica Minolta was hit with a ransomware attack at the end of July. It started with customers reporting that the company’s product supply and support site was not accessible. The attack impacted services for almost a week. Some Konica Minolta printers were also displaying a ‘Service Notification Failed’ error.

BleepingComputer reported a source shared a copy of the ransom note used in the attack and reported devices in the company were encrypted. The ransom note belongs to RansomEXX.

read more

RansomEXX Claims Attack on Taiwanese Computer Manufacturer

August 2, 2022

Taiwanese motherboard maker Gigabyte has been hit by the RansomEXX ransomware gang. The ransomware gang threaten to publish 112GB of stolen data unless a ransom is paid. The attack forced the company to shut down systems in Taiwan. The incident also affected multiple websites of the company, including its support site and portions of the Taiwanese website.

read more

Ransomware Attack on ForceNet Communication Platform used by Australian Military

September 10, 2022

Hackers attacked ForceNet’s communications platform used by Australian military personnel and defense staff. The ForceNet service is run by Dialog Information Technology. The Australian Dept. of Veteran Affairs’ website states: “Defence has announced that it has been informed that an external ICT service provider which facilitates ForceNet has been subject to a ransomware attack. ForceNet is a Defence e-communications platform used to connect registered users within secure online communities. To be clear, this is not an attack on Defence ICT”
ITWire in Australia reports on 31 October that Dialog was hit by an attack which used the Agenda ransomware that runs only on Windows. The group behind the attack, Qilin, announced it on the dark web on 19 September.

This is the 9th attack in little over a month, affecting Australia’s biggest companies, likely exposing the details of millions of customers.

read more

Michigan IT Service Provider Victim of Ransomware Attack

October 20, 2022

A ransomware attack took place recently against the Midland Information Technology Consortium (MiTCON). Midland Police Department, along with other law enforcement agencies, is conducting an investigation. The attack affected its clients’ internet and email services as well as phone lines. The MiTCON team quickly contained the threat and has been working diligently to bring back services for its clients.

read more

Samsung Data Breach

March 19, 2020

Samsung admitted what it calls a “small number” of users could indeed read other people’s personal data following an unexplained Find my Mobile notification.
Users said they found strangers’ personal data displayed to them. Find My Mobile is a Samsung app that comes pre-loaded with its Android devices and can only be disabled, not uninstalled. The only way to uninstall Samsung apps is to wipe the operating system completely and install a different ROM.
The company has admitted a data security breach did occur.
A company spokeswoman said, “A technical error resulted in a small number of users being able to access the details of another user. As soon as we became of aware of the incident, we removed the ability to log in to the store on our website until the issue was fixed.”

read more