Portuguese media empire struck in the latest cyberattack on news outlets
Full article575 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The Impresa Group joins the Jerusalem Post and the largest news organization in Norway among the recent victims.
The websites of the top newspaper and TV station in Portugal remained down Tuesday after a cyberattack that began over the weekend, following in a string of recent attacks on media organizations.
Impresa Group said its Expresso newspaper and SIC TV stations were the victim of a computer attack. A ransomware group suspected as the culprit, known as Lapsus$, initially defaced the websites with a ransom demand.
The outfit also sent tweets from Expresso’s Twitter account to declare itself the president of Portugal, and sent text messages to the news organizations’ customers hyping its success in an apparent bid to pressure its victims into paying.
“For safety reasons, we ask that you do not access or forward any of the various communications that are being sent on behalf of the Impresa group brands,” the company said in a Facebook post on Monday. “We continue to take necessary actions and measures to resolve the situation as soon as possible.”
It’s one of a number incidents afflicting media organizations in the past couple weeks, although none of the attacks seem connected. The Jerusalem Post was hacked and defaced on Monday. The largest news organization in Norway got hit last week.
It’s also among several more publicly-reported suspected ransomware attacks on media entities over the past several months. “Most ransomware attacks are not targeted, so it is likely there are security deficiencies shared by other media orgs,” tweeted Allan Liska, director of threat intelligence at the Record Future cybersecurity firm.
Continuing my thought from yesterday. In the last 6 months there have been at least 5 *publicly reported* ransomware attacks against major media companies. Most ransomware attacks are not targeted, so it is likely there are security deficiencies shared by other media orgs. pic.twitter.com/GMujEER9Bv
— Allan “Ransomware Sommelier🍷” Liska (@uuallan) January 3, 2022
The Lapsus$ Group apparently struck Brazil’s health ministry in December, and may have the same month been connected to a hack of the Federal Police there.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/portugal-expresso-sic-impresa-ransowmare-lapsus/