Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 11 submissions in the queue.
posted by Fnord666 on Tuesday January 05 2021, @05:22PM   Printer-friendly
from the just-another-day-at-the-office dept.

TransLink confirms ransomware data theft, still restoring systems:

Metro Vancouver's transportation agency TransLink has confirmed that the Egregor ransomware operators who breached its network at the beginning of December 2020 also accessed and potentially stole employees' banking and social security information.

TransLink announced on December 1, 2020, that the transportation network was experiencing issues with their computing systems following a cyberattack.

These information technology issues impacted the company's phones and online services, as well as the customers' ability to pay for fares with a credit card or debit card. TransLink's transit services were not affected by the IT problems caused by the ransomware attack.

"We are now in a position to confirm that TransLink was the target of a ransomware attack on some of our IT infrastructure," TransLink disclosed in a statement following the incident. "This attack includes communications to TransLink through a printed message."

[...] Egregor is a ransomware operation that partners with affiliates who hack into targets' networks and deploy ransomware payloads, earning 70% of the ransom payments with the Egregor operators getting a 30% revenue share.

The affiliates who infiltrate victims' networks are also known for stealing files before encrypting devices using Egregor ransomware and for using them as leverage under the threat of publicly leaking them unless the ransom is paid.

Egregor started operating in September 2020 after Maze shut down their operation, with many of the Maze affiliates switching to Egregor as threat actors told BleepingComputer.


Original Submission

This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
(1)