ZeroHour
Ars Technica · Securitypublished ()ingested

Ransomware group reports victim it breached to SEC regulators

highRansomwareimportance 57
Full article377 words · extracted from arstechnica.com · click to collapse

MeridianLink officials declined a request for an interview or to answer questions asking if customer data was breached in a network intrusion or whether a security attack took place that could be considered material. Instead, the company issued a statement that confirmed officials had identified a “cybersecurity incident” and went on to say:

Upon discovery, we acted immediately to contain the threat and engaged a team of third-party experts to investigate the incident. Based on our investigation to date, we have identified no evidence of unauthorized access to our production platforms, and the incident has caused minimal business interruption. If we determine that any consumer personal information was involved in this incident, we will provide notifications, as required by law.

Brett Callow, a security analyst with Emsisoft, noted that a ransomware group known as Maze has previously warned victims that it “keeps the communication with the major Securities and Financial Regulators and will acknowledge them on all data leaks and breaches if the agreement is not reached.”

“I’m not sure whether they ever actually did,” Callow told Ars. “Gangs have also threatened GDPR complaints and, IIRC, one may have actually followed through on that.” He said he’s unaware of any group filing a complaint with the SEC. GDPR is short for the General Data Protection Regulation, a European Union law granting individuals broad privacy protections.

AlphV first appeared in November 2021 and is notable for its use of ransomware, named BlackCat, that’s developed in the Rust scripting language. The group targets both Windows and Linux environments.

“As of April 2023, ALPHV has evolved itself into one of the most prolific ransomware groups in the current threat landscape, only falling behind the Lockbit ransomware group in observed activity,” geopolitical and cybersecurity analyst Chris Lucas wrote in May. “Being primarily a Russia-based group, ALPHV will unlikely target organizations based in the Russian Federation or among the rest of the Commonwealth of Independent States (CIS) that make up the former Soviet Union.”

The group was already known for the uncommon practice of threatening to launch distributed denial-of-service attacks on the targets it had already compromised in an attempt to apply extra pressure to pay up.

In trading on Thursday, MeridianLink shares fell 0.2 percent, or 4 cents, to $18.51.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/11/ransomware-group-reports-victim-it-breached-to-sec-regulators/