Danish cloud host says customers ‘lost all data’ after ransomware attack | TechCrunch

https://techcrunch.com/2023/08/23/cloudnordic-azero-cloud-host-ransomware/

In a notice on its website translated from Danish, CloudNordic said: “The attackers succeeded in encrypting all servers’ disks, as well as on the primary and secondary backup system, whereby all machines crashed and we lost access to all data.”

Students’ psychological reports, abuse allegations leaked by ransomware hackers

https://www.nbcnews.com/tech/security/students-psychological-reports-abuse-allegations-leaked-ransomware-hac-rcna79414

Hackers who broke into the Minneapolis Public Schools earlier this year have circulated an enormous cache of files that appear to include highly sensitive documents on schoolchildren and teachers, including allegations of teacher abuse and students’ psychological reports.

Cyberattacks against U.S. hospitals mean higher mortality rates, study finds

https://www.nbcnews.com/tech/security/cyberattacks-us-hospitals-mean-higher-mortality-rates-study-finds-rcna46697

Two-thirds of respondents in the Ponemon study who had experienced ransomware attacks said they disrupted patient care, and 59% of them found they increased the length of patients’ stays, straining resources. Almost one-quarter said they led to increased mortality rates at their facilities.

Costa Rica declares national emergency after Conti ransomware attacks

https://www.bleepingcomputer.com/news/security/costa-rica-declares-national-emergency-after-conti-ransomware-attacks/

Conti published most of the 672 GB dump that appears to contain data belonging to the Costa Rican government agencies.

Hackarar krev løysepengar frå bibliotek – NRK

https://www.nrk.no/vestland/hackarar-krev-loysepengar-fra-bibliotek-_-her-ma-ho-lane-vekk-boker-pa-gamlematen-1.15552766

Systemleverandøren Axiell vart denne veka hacka, som har lamma tenestene til mange lokalbibliotek.

Kring halvparten av alle bibliotek i Noreg er råka av hackinga. Dei store bybiblioteka har eigne system, og er ikkje råka.

Hackarane har bedt om løysepengar, men det er uvisst kva sum det er snakk om. Hillestad har ikkje gått i dialog med hackarane.

– Det er ikkje eit alternativ å betala ut løysepengar for å få tilgang til eigne data. Me samarbeider ikkje med kriminelle på nokon som helst måte.

Dei jobbar no med å få på plass ei backup-løysing, som skal vera klar til bruk frå neste veke av.

U.S. to give ransomware hacks similar priority as terrorism - Reuters

https://www.reuters.com/technology/exclusive-us-give-ransomware-hacks-similar-priority-terrorism-official-says-2021-06-03/

US passes emergency waiver over fuel pipeline cyber-attack - BBC News

https://www.bbc.com/news/business-57050690

The US government issued emergency legislation on Sunday after the largest fuel pipeline in the US was hit by a ransomware cyber-attack.
The Colonial Pipeline carries 2.5 million barrels a day – 45% of the East Coast’s supply of diesel, gasoline and jet fuel.
It was completely knocked offline by a cyber-criminal gang on Friday and work to restore service is continuing.
The emergency status relaxes rules on fuel being transported by road.

Ransomware gang threatens to expose police informants if ransom is not paid - The Record

https://therecord.media/ransomware-gang-threatens-to-expose-police-informants-if-ransom-is-not-paid/

Microsoft Exchange: La igjen bakdør hos trøndersk kollektivselskap

https://nrkbeta.no/2021/03/09/microsoft-exchange-la-igjen-bakdor-hos-trondersk-kollektivselskap/

Norske virksomheter har den siste uken jobbet mot klokka med å installere en kritisk sikkerhetsoppdatering. De som ikke er raske nok kan bli ofre for spionasje og løsepengevirus.
Norsk sikkerhetsmyndighet (NSM) advarer om at en mye brukt Microsoft-løsning for e-post bør anses som «mulig kompromittert» om nødvendige sikkerhetsoppdateringer ikke ble gjort innen onsdag i forrige uke.

Søndag kveld viste undersøkelser gjort av sikkerhetsselskapet Defendable at minst 269 Microsoft-servere i Norge fortsatt manglet disse oppdateringene.

The untold story of a cyberattack, a hospital and a dying woman - WIRED UK

https://www.wired.co.uk/article/ransomware-hospital-death-germany

German prosecutors tried to prove that a ransomware attack on a hospital was to blame for someone losing their life. Their story is a warning

A Ransomware Attack Has Struck a Major US Hospital Chain - WIRED

https://www.wired.com/story/universal-health-services-ransomware-attack/

a hospital and health care network with more than 400 facilities across the United States, Puerto Rico, and United Kingdom

UHS says it has 90,000 employees and treats about 3.5 million patients each year, making it one of the US’ largest hospital and health care networks.

“We are using paper for everything. All computers are completely shut down,”

Garmin reportedly paid multimillion-dollar ransom after suffering cyberattack - The Verge

https://www.theverge.com/2020/8/4/21353842/garmin-ransomware-attack-wearables-wastedlocker-evil-corp

Ransomware gang publishes tens of GBs of internal data from LG and Xerox - ZDNet

https://www.zdnet.com/article/ransomware-gang-publishes-tens-of-gbs-of-internal-data-from-lg-and-xerox/

after failed extortion attempt.

If a victim refuses to pay the fee to decrypt their files and decides to restore from backups, the Maze gang creates an entry on a “leak website” and threatens to publish the victim’s sensitive data in a second form ransom/extortion attempt.

The victim is then given a few weeks to think over its decision, and if victims don’t give in during this second extortion attempt, the Maze gang will publish files on its portal

Garmin outage caused by confirmed WastedLocker ransomware attack

https://www.bleepingcomputer.com/news/security/garmin-outage-caused-by-confirmed-wastedlocker-ransomware-attack/

multiple flyGarmin services used by aircraft pilots are down, including the flyGarmin website and mobile app, Connext Services (weather, CMC, and position reports) and Garmin Pilot Apps (Flight plan filing unless connected to FltPlan, account syncing, and database concierge).

inReach satellite tech (Service Activation and Billing) and Garmin Explore (Explore site and Explore app sign) used for location sharing, GPS navigation, logistics, and tracking through the Iridium satellite network are also down.

Garmin did a hard shutdown of all devices hosted in a data center as well to prevent them from possibly being encrypted.

This company-wide shutdown is what caused the global outage for Garmin Connect and other connected services.

Honda global operations halted by ransomware attack - TechCrunch

https://techcrunch.com/2020/06/09/honda-ransomware-snake/

Ransomware-hit US gas pipeline shut for two days - BBC News

https://www.bbc.com/news/technology-51564905

A malicious link sent to staff at the facility eventually caused the shutdown “of the entire pipeline asset”.

It was so severe in part because the organisation was not prepared for such an attack, the DHS statement said.

Often, the “operational network” which runs computers in the factory is separated from the office IT – but not in this case, meaning the ransomware infection was allowed to spread.

Some ransomware rings have started stealing data before they encrypt to use stolen data as leverage, ensuring that even victims with backups make the payment - Ars Technica

https://arstechnica.com/information-technology/2020/02/why-you-cant-bank-on-backups-to-fight-ransomware-anymore/

Company shuts down because of ransomware, leaves 300 without jobs just before holidays - ZDNet

https://www.zdnet.com/article/company-shuts-down-because-of-ransomware-leaves-300-without-jobs-just-before-holidays/

As a result of the botched ransomware recovery process, the company’s leadership decided to suspend all services, leaving more than 300 employees without jobs.

Over the past two years, there have been many cases where smaller companies decided to shut down for good, lacking the funds to pay a ransom demand to get their data back or lacking the funds needed to rebuild their IT infrastructure

US Coast Guard discloses Ryuk ransomware infection at maritime facility - ZDNet

https://www.zdnet.com/article/us-coast-guard-discloses-ryuk-ransomware-infection-at-maritime-facility/

The maritime facility — believed to be a port authority — was forced to shut down its entire operations for more than 30 hours, the Coast Guard said.

Say Cheese: Ransomware-ing a DSLR Camera - Check Point Research

https://research.checkpoint.com/say-cheese-ransomware-ing-a-dslr-camera/

an attacker in close proximity (WiFi), or an attacker who already hijacked our PC (USB), can also propagate to and infect our beloved cameras with malware