unknown ransomware, but unsegmented domain

According to the source, a “domain admin” — a user with the highest level of privileges on the network — clicked on a malicious link while they were logged in, which triggered the file-encrypting malware, according to Tech Crunch report. Because the thousands of computers on the network were on the same, unsegmented domain, the ransomware quickly spread to every CPI office, including its on-site backups, the source said.

Ryuk ransomware

Ryuk ransomware has been an ongoing issue across all industries. Once an attacker gets in through any means possible — the enterprise, the physical security network, building automation, outside vendors and contractors, or the operational technology network — it can pivot and start its attack to take over and own whatever network it wants to control.

Unknown ransomware variant

Threat actors targeted Mattel with an unnamed ransomware variant, which impacted some of its business functions in July 2020. However, the company stated that attackers did not exfiltrate any data. This incident highlights the continued threat of ransomware for large organizations.