{"id":291274,"date":"2021-07-05T17:18:48","date_gmt":"2021-07-05T14:18:48","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/hackers-demand-70-mn-after-kaseya-ransomware-attack\/"},"modified":"2021-07-05T17:18:48","modified_gmt":"2021-07-05T14:18:48","slug":"hackers-demand-70-mn-after-kaseya-ransomware-attack","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/hackers-demand-70-mn-after-kaseya-ransomware-attack\/","title":{"rendered":"#Hackers demand $70 mn after Kaseya ransomware attack"},"content":{"rendered":"<p>&#8220;<strong>#Hackers demand $70 mn after Kaseya ransomware attack<\/strong>&#8221;<\/p>\n<div>\n<div class=\"article-gallery lightGallery\">\n<div data-thumb=\"https:\/\/scx1.b-cdn.net\/csz\/news\/tmb\/2021\/a-coop-supermarket-in.jpg\" data-src=\"https:\/\/scx2.b-cdn.net\/gfx\/news\/2021\/a-coop-supermarket-in.jpg\" data-sub-html=\"A Coop supermarket in Sweden has a sign reading &quot;Temporarliy closed - We have an IT-disturbance and our systems are not functioning&quot; posted in the window following a cyberattack that targeted a US provider of IT services.\">\n<figure class=\"article-img\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/scx1.b-cdn.net\/csz\/news\/800a\/2021\/a-coop-supermarket-in.jpg\" alt=\"A Coop supermarket in Sweden has a sign reading &amp;quot;Temporarliy closed - We have an IT-disturbance and our systems are not fun\" title=\"A Coop supermarket in Sweden has a sign reading &quot;Temporarliy closed - We have an IT-disturbance and our systems are not functioning&quot; posted in the window following a cyberattack that targeted a US provider of IT services.\" width=\"800\" height=\"530\"\/><figcaption class=\"text-darken text-low-up text-truncate-js text-truncate mt-3\">\n                A Coop supermarket in Sweden has a sign reading &#8220;Temporarliy closed &#8211; We have an IT-disturbance and our systems are not functioning&#8221; posted in the window following a cyberattack that targeted a US provider of IT services.<br \/>\n            <\/figcaption><\/figure>\n<\/div>\n<\/div>\n<p>Hackers were on Monday demanding $70 million in bitcoin in exchange for data stolen during an attack on a US IT company that has shuttered hundreds of Swedish supermarkets.<\/p>\n<p>                                                                                Researchers believe more than 1,000 companies could have been affected by the attack on Miami-based firm Kaseya, which provides IT services to some 40,000 businesses around the world. <\/p>\n<p>The FBI warned Sunday that the scale of the &#8220;ransomware&#8221; attack\u2014a form of digital hostage-taking where hackers encrypt victims&#8217; data and then demand money for restored access\u2014is so large that it may be &#8220;unable to respond to each victim individually&#8221;.<\/p>\n<p>Sweden&#8217;s Coop supermarket chain was among the most high-profile victims. Most of their 800 stores were still closed three days after the hack paralysed its cash registers, spokesman Kevin Bell told AFP. <\/p>\n<p>Coop, like many of the companies affected, is not a direct customer of Kaseya&#8217;s, but its IT subcontractor Visma Esscom was hit by the attack.<\/p>\n<p>The few hundred Coop stores that had reopened were relying on alternative payment solutions, such as customers paying using their smartphones, Bell said. <\/p>\n<p>Cybersecurity firm ESET said it had identified victims of the hack in at least 17 countries, from South Africa to Britain to Mexico. New Zealand&#8217;s education ministry said at least two schools there had been affected.<\/p>\n<p><b>REvil hackers suspected<\/b><\/p>\n<p>Experts believe the attack was probably carried out by REvil, a Russian-speaking hacking group known as a prolific perpetrator of ransomware attacks. <\/p>\n<p>A post on H<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>y Blog, a site on the dark web previously associated with the group, claimed responsibility for the attack and said it had infected &#8220;more than a million systems&#8221;.<\/p>\n<p>The FBI believes that REvil, which also goes by the name Sodinokibi, was behind a ransomware attack last month on global meat-processing giant JBS. The Brazil-based company ended up paying $11 million in bitcoin to the hackers.<\/p>\n<p>The hackers&#8217; blog post said they would release a decryption tool online &#8220;so everyone will be able to recover from attack in less than an hour&#8221;\u2014if they were handed $70 million in bitcoin. <\/p>\n<p>Kaseya said Sunday it believed the damage had been restricted to a &#8220;very small number&#8221; of customers using its signature VSA software, which lets companies manage networks of computers and printers from a single point.<\/p>\n<p>But cybersecurity firm Huntress Labs said in a <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">Reddit<\/a> forum that it was working with partners targeted in the attack, and that the software was manipulated &#8220;to encrypt more than 1,000 companies&#8221;.<\/p>\n<p>Kaseya said it had &#8220;immediately shut down&#8221; its servers after detecting the attack on Friday and warned its VSA customers to do the same, &#8220;to prevent them from being compromised&#8221;.<\/p>\n<p>The company has released a tool allowing its customers to find out whether their own computer systems have been compromised by the attack.<\/p>\n<p><b>&#8216;Emboldened&#8217; hackers<\/b><\/p>\n<p>In recent months numerous US companies, including the computer group SolarWinds and the Colonial oil pipeline, have been the victims of high-profile ransomware attacks, which the FBI blames on hackers based in Russia.<\/p>\n<p>While Washington officials do not accuse the Russian government of direct involvement in such attacks, they say the country is harbouring hackers who should be arrested.<\/p>\n<p>US President Joe Biden raised the threat in talks with Russian counterpart Vladimir Putin last month, and on Saturday ordered a full investigation into the Kaseya attack.<\/p>\n<p>In the meantime, hundreds of companies are facing the dilemma of whether or not to pay the ransom demanded by the hackers. <\/p>\n<p>&#8220;In <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/general\/\" data-internallinksmanager029f6b8e52c=\"3\" title=\"General\" target=\"_blank\" rel=\"noopener\">general<\/a>, it doesn&#8217;t pay to pay ransoms,&#8221; said Lior Div, CEO of cybersecurity firm Cybereason. It found in a recent study that 80 percent of companies that pay a ransom are hit again. <\/p>\n<p>&#8220;Overall, paying ransoms only emboldens threat actors and drives up ransom demands,&#8221; Div explained. &#8220;Still, whether or not to pay a ransom is an individual choice each company needs to make.&#8221;\n                                                                                                                        <\/p>\n<hr\/>\n<div class=\"article-main__explore my-4 d-print-none\">\n<p>                                            EXPLAINER: Ransomware and its role in supply chain attacks\n                                        <\/p><\/div>\n<hr class=\"mb-4\"\/>\n<p class=\"article-main__note mt-4\">\n                                                \u00a9 2021 AFP<\/p>\n<p>                                        <!-- print only --><\/p>\n<div class=\"d-none d-print-block\">\n<p>                                                 <strong>Citation<\/strong>:<br \/>\n                                                 Hackers demand $70 mn after Kaseya ransomware attack (2021, July  5)<br \/>\n                                                 retrieved  5 July 2021<br \/>\n                                                 from https:\/\/techxplore.com\/<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">news<\/a>\/2021-07-hackers-demand-mn-kaseya-ransomware.html<\/p>\n<p>                                            This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no<br \/>\n                                            part may be reproduced without the written permission. The content is provided for information purposes only.<\/p><\/div>\n<\/p><\/div>\n<p><script id=\"facebook-jssdk\" async=\"\" src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more Like this articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/science\/\" target=\"_blank\" rel=\"noopener\">Science category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/techxplore.com\/news\/2021-07-hackers-demand-mn-kaseya-ransomware.html\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Hackers demand $70 mn after Kaseya ransomware attack&#8221; A Coop supermarket in Sweden has a sign reading &#8220;Temporarliy closed &#8211; We have an IT-disturbance and our systems are not functioning&#8221; posted in the window following a cyberattack that targeted a US provider of IT services. Hackers were on Monday demanding $70 million in bitcoin in&#8230;<\/p>\n","protected":false},"author":1,"featured_media":291275,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/scx2.b-cdn.net\/gfx\/news\/2021\/a-coop-supermarket-in.jpg","fifu_image_alt":"","footnotes":""},"categories":[16],"tags":[],"class_list":["post-291274","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sciencee"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/291274","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=291274"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/291274\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/291275"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=291274"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=291274"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=291274"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}