By Ray Birch
JESUP, Ga.—Another credit union has allegedly been hit with a ransomware attack, and one security expert is warning similar attacks targeting smaller organizations are showing no signs of slowing down.
The $65-million Altamaha CU here has allegedly been hit by a ransomware attack from the criminal organization known as Egregor. The security expert, speaking on the condition of anonymity, told CUToday.info the criminals posted 421 megabytes of data stolen from the credit union, sharing several of the documents allegedly from Altamaha with CUToday.info.
Those documents included invoices from Altamaha vendors and healthcare/human resources documents.
CUToday.info reached out to Atlamaha CU for comment, but credit union did not respond by press time.
We Didn’t Forget You
At the top of the Egregor website page that carries a link to the credit union’s data is the warning: “If you are a client who refused to conclude a contract and did not find information about yourself on our website or did not find some of your files, this does not mean that we forgot about you, it only means that your information was sold and only therefore it did not appear in free access!”
What the hackers do, experts have stated, is steal an organization’s data and post a sample of it on the web, warning the company/CU that more will be posted unless a ransom is paid. In the past, ransomware was limited to crooks who wouldlock down an organization’s data until a ransom was paid. But with businesses becoming more savvy in their defenses against ransomware, including employing better backup strategies, more organizations have been able to restore their data without paying the ransom.
In response, the crooks changed strategies after stealing the data by posting some of the sensitive personal data on the web and threatening to post more if the ransom is not paid. Experts have stated criminal groups that take this approach may or may not also encrypt the company’s data.
Lower Bar to Entry
The threat has been growing and is no longer limited to more sophisticated criminal organizations. Inexpensive ransomware kits are available on the dark web and have made it easier for criminals without a great deal of skill to pull off data encryption attacks.
Brett Callow, threat analyst at security firm Emsisoft, told CUToday.info that since the beginning of the year, more and more ransomware groups have started to steal data and use the threat of its release as extra leverage to extort payment.
“Should the victim not pay or not pay quickly enough, the data is posted online, typically in a series of installments,” he confirmed. “As a result, about 50% of all ransomware incidents are also data breaches, which can result in additional reputational damage, regulatory penalties and class action lawsuits. In other words, the risks associated with these incidents are much, much greater than they were last year.”
No Good Options
Callow added that, unfortunately, companies faced with a data theft situation are without good options.
“Whether they pay or not doesn’t change the fact that they’ve experienced a data breach,” said Callow, who in a previous CUToday.info report stated payment of the ransom to avoid additional data posting from the crooks is akin to paying for a “pinkie swear” from the crooks.
Callow emphasized it’s more critical than ever for companies to adhere to security best practices.
“That is, disable PowerShell (a task automation and configuration management framework from Microsoft) when it’s not needed. Use multi-factor authentication everywhere it can be used. And patch promptly,” he said. “In the past, companies with lax security could often escape unpunished, but now they’re far more likely to be made to pay the price, both literally and figuratively.”
As CUToday.info has reported, another credit union and a vendor that supports CUs were allegedly hit by ransomware attacks in the past year. The $270-million Columbus Metro in Columbus, Ohio, and CU Collections in Manassas, Va., were allegedly hit with an attack from the criminal group Maze.
Surge in Attacks
The third quarter of the year has seen a huge surge in ransomware attacks. Globally, a total of 199.7 million ransomware attacks have been reported in the third quarter of 2020, reported Security Boulevard.
Security Boulevard added ransomware attacks have increased 40% to 199.7 million cases globally in Q3 of this year. It further cited additional concerning statistics:
- The U.S. observed 145.2 million ransomware hits in Q3, which is a 139% year-over-year increase
- Cybersecurity researchers have detected new ransomware, Ryuk, with 5,123 attacks in just Q3 2019
- Ryuk ransomware attacks have increased to 67.3 million in Q3 2020, which is 33.7% of all ransomware attacks this year
