Understanding Cyber Crime and Ransomware Attacks

Russian Ransomware Group Clop Strikes Prominent Companies

Several notable companies, including British Airways, Boots, and the BBC, recently fell victim to a cybercrime group known as Clop, a Russian ransomware gang. This group used ransomware tactics to steal personal and sensitive information from over 100,000 employees across these organizations. Ransomware, cyber threats, and high-profile attacks are at an all-time high in the United States since COVID-19.  

The cybercrime group made their intentions known to the public by disclosing that they had successfully stolen sensitive data from their victims. In a brazen move, they posted about their success on their dark website. This sent shockwaves through the affected companies and individuals. The gravity of the situation became even more apparent when Clop issued a chilling ultimatum to the targeted organizations. They demanded immediate contact before June 14th to enter into negotiations, or else they would unleash the employees’ sensitive information for the world to see.

The stolen data encompassed highly sensitive details that could wreak havoc on the lives of the victims. Names, addresses, national insurance numbers, and bank account information were among the personal and financial data that fell into the hands of the cybercriminals. The potential ramifications of such a massive data breach were staggering. The affected individuals now faced the prospect of identity theft, financial fraud, and other malicious activities that could cause lasting harm. 

The Rise of Doxware and the Complexities of Ransomware Attacks

Clop exploited a vulnerability in a business infrastructure tool called MoveIT, which is used for securely transferring files within internal networks. By exploiting this vulnerability, the hackers entered multiple victims’ systems through one hack. It is worth noting that the trend among cybercriminals is shifting from deploying ransomware to solely stealing data.

In traditional ransomware attacks, hackers would encrypt data and demand companies to pay the ransom for the decryption key. However, a new and more concerning tactic has emerged, known as “Doxware.” Unlike traditional ransomware, Doxware allows hackers to infiltrate systems without leaving any traces until they make their demands, leaving little time to react. 

Why is this a bigger challenge?

Doxware presents a greater hurdle for businesses because it goes beyond simple encryption. With stolen data in the hands of hackers, restoring from backups is no longer a straightforward solution. This means that businesses can no longer ignore ransom demands and must find alternative ways to protect their sensitive information.

Six major organizations have acknowledged being targeted by Clop, and many of these organizations were not even direct users of the MoveIT software. The demands from Clop did not specify a specific amount, only indicating their desire to enter into negotiations. While it is never advisable to give in to hackers and pay ransom demands, there is an unfortunate risk that some victims may succumb to the pressure. However, complying with these demands only perpetuates the cycle of cybercrime and emboldens these criminal groups.  

How do I prevent this and protect myself?

