ZeroHour

Search: “commit”

3 stories in the last 30d

Cyberattack encrypts systems at Bavarian municipal utility

Hackers encrypted the central IT network of Bavarian utility Stadtwerke Landsberg, disrupting office systems but not electricity or water services.

Stadtwerke Landsberg said hackers encrypted its central IT network overnight on Sept. 1, prompting disconnection from the internet, crisis-team activation and external forensic support. Essential electricity and water services were unaffected, but staff availability was limited and customer data such as names, addresses and bank details may have been accessed. No ransomware group was named and no extortion demand was confirmed. The attack follows a similar late-June encryption incident at a North Rhine-Westphalia municipal utility, and the BSI consistently ranks ransomware among Germany's most serious cyber threats.

The Record · 8d agoRansomware in the wild

Berlin investigates new data leak after hackers publish stolen login credentials

Berlin investigates a fresh leak after Rhysida hackers published stolen login credentials; the city refuses to pay the ransom demand.

Berlin confirmed hackers published additional stolen data, including login credentials, from a mid-August cyberattack on two city ministries responsible for urban development/housing and transport/climate. The Rhysida ransomware group claimed the breach in late August, saying it stole 5.79 TB of data including contracts, emails, passwords and classified information; Berlin acknowledged an extortion demand but refused to pay. Berlin's data protection regulator said the leak includes personal data on public employees and possibly residents, such as names, addresses, dates of birth and bank information. Germany's BSI separately linked the campaign to the TerminalFix fake-CAPTCHA technique and the LoremIpsumLoader/AxolotLoader malware tied to financially motivated Rhysida-associated hackers, days before Berlin's Sept. 20 election.

The Record · 9d agoRansomware in the wild1

How Ransomware Gangs Use Automation, and How You Can Beat It

Recorded Future outlines ten automation strategies ransomware gangs use, from credential marketplaces to bulletproof hosting, urging intelligence-led defense.

A Recorded Future blog post promoting an Insikt Group report and webinar describes how ransomware gangs leverage automation across their attack cycles. The Insikt Group identified ten key strategies, including selling breached credential databases on underground forums, checkers and brute-forcers for validating stolen credentials, loaders and crypters for evading antivirus, banking injects, exploit kits, spam and phishing services, bulletproof hosting services, sniffers, and automated marketplaces for selling stolen credentials and digital fingerprints. The post argues defenders should adopt intelligence-led automation to counter the speed and scale of automated criminal tooling.

Recorded Future · 29d agoRansomware