Ransomware strikes AXA shortly after insurer announces it will stop covering extortion fees
Full article663 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
AXA joins CNA Insurance as a recent ransomware attack victim in the insurance industry.
Ransomware gangs have now struck two cybersecurity insurers in as many months, with AXA confirming over the weekend that an attack had affected its Asian operations.
AXA joins CNA Insurance, which in April confirmed that a ransomware incident had forced the company to take its operations offline. The attack on AXA, though, comes shortly after the French insurer said it would no longer reimburse ransomware payments under new policies it writes in that country, although a source familiar with the attack said there was no connection between AXA’s decision and the attack on its own networks.
The so-called Avaddon ransomware operators posted screenshots of information online that they said they obtained from AXA’s Asia Assistance subsidiary. The screenshots include a claim that the operators stole three terabytes of data, such as customer medical reports and claims, customer IDs and bank account papers, payments to customers and other health information.
“Asia Assistance was recently the victim of a targeted ransomware attack which impacted its IT operations in Thailand, Malaysia, Hong Kong, and the Philippines,” the subsidiary AXA Partners said of the attack. “As a result, certain data processed by Inter Partners Asia (IPA) in Thailand has been accessed. At present, there is no evidence that any further data was accessed beyond IPA in Thailand.”
AXA Partners said it had dedicated a task force with outside forensic experts to investigate, and has notified regulators and business partners. It did not answer questions about whether it had paid or would pay the attackers.
The Avaddon operators said they would give AXA 10 days to pay up or it would leak company documents, as well as hit AXA with a distributed denial-of-service attack.
Cyber insurers make inviting targets for ransomware attackers, since obtaining customer data could give them information about who’s best able to pay up should the gangs attack policyholders.
“Breaches of insurance companies are especially concerning given that another group, REvil, has previously stated that it uses the exfiltrated data to attack customers before finally encrypting the insurer’s network,” said Brett Callow, a threat analyst at Emsisoft, via email. “Potentially, the data could be used both to select targets and to spear phish those targets.”
Amid the alarm that the attack on Colonial Pipeline caused, some cybercriminals have taken steps to shun ransomware, although the move might merely be an attempt to take the heat off of themselves.
The FBI and the Australian Cyber Security Centre both recently issued alerts about Avaddon ransomware.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/axa-cyber-insurance-ransomware-avaddon-cna/