Advertisement

We need your help now

Support from readers like you keeps The Journal open.

You are visiting us because we have something you value. Independent, unbiased news that tells the truth. Advertising revenue goes some way to support our mission, but this year it has not been enough.

If you've seen value in our reporting, please contribute what you can, so we can continue to produce accurate and meaningful journalism. For everyone who needs it.

Coop supermarket stores in Sweden have been hit by the attack. Ali Lorestani/TT

Hackers demand $70m (€58.9m) after US IT company ransomware attack

More than 1,000 companies have been affected in the US based Kaseya attack.

HACKERS ARE DEMANDING $70 million (€58.9m) in bitcoin in exchange for data stolen during a “gargantuan” attack on a US IT company that shut hundreds of Swedish supermarkets.

Researchers believe more than 1,000 companies could have been affected by the attack on Miami-based firm Kaseya, which provides IT services to some 40,000 businesses around the world.

The FBI warned yesterday that the scale of the “ransomware” attack, a form of digital hostage-taking where hackers encrypt victims’ data and then demand money for restored access, is so large that it may be “unable to respond to each victim individually”.

“It’s probably the biggest ransomware attack of all time,” said Ciaran Martin, cybersecurity professor at the University of Oxford.

“Because of the nature of the attack there’s still a lot of uncertainty over its impact,” he stressed.

But he added that because this was a “supply chain attack”, targeting a company serving thousands of firms, many of whom in turn provide IT support to smaller businesses such as car dealerships, the total number of victims was potentially huge.

Sweden’s Coop supermarket chain was among the indirect victims, with its cash registers paralysed since Friday when its IT subcontractor Visma Esscom was hit by the attack.

Most of Coop’s 800 stores were still closed today, spokesperson Kevin Bell told AFP, with the few hundred that have reopened relying on alternative payment solutions such as customers paying using their smartphones.

Cybersecurity firm ESET said it had identified victims of the hack in at least 17 countries, from South Africa to Britain to Mexico. New Zealand’s education ministry said at least two schools there had been affected.

REvil hackers suspected

Experts believe the attack was probably carried out by REvil, a Russian-speaking hacking group known as a prolific perpetrator of ransomware attacks.

A post on Happy Blog, a site on the dark web previously associated with the group, claimed responsibility for the attack and said it had infected “more than a million systems”, which if true would make this attack “absolutely gargantuan in scale”, according to Martin.

The FBI believes that REvil, which also goes by the name Sodinokibi, was behind a ransomware attack last month on global meat-processing giant JBS. The Brazil-based company ended up paying $11 million in bitcoin to the hackers.

The hackers’ blog post said they would release a decryption tool online “so everyone will be able to recover from attack in less than an hour” — if they were handed $70 million in bitcoin.

The hackers have also been reaching out to individual victims and demanding smaller ransoms, Martin added.

“As far as I understand it, they’ve been issuing demands that are about $50,000 for smaller organisations, rising to $5 million for larger organisations,” he told AFP. “We don’t know who’s paid.”

Kaseya said on Sunday it believed the damage had been restricted to a “very small number” of customers using its signature VSA software, which lets companies manage networks of computers and printers from a single point.

But cybersecurity firm Huntress Labs said in a Reddit forum that it was working with partners targeted in the attack, and that the software was manipulated “to encrypt more than 1,000 companies”.

Kaseya said it had “immediately shut down” its servers after detecting the attack on Friday and warned its VSA customers to do the same, “to prevent them from being compromised”.

The company has released a tool allowing its customers to find out whether their own computer systems have been compromised by the attack.

‘State-tolerated’ hacking 

In recent months numerous US companies, including the computer group SolarWinds and the Colonial oil pipeline, have been the victims of high-profile ransomware attacks, which the FBI blames on hackers based in Russia.

The HSE in Ireland was also a victim of a similar attack, with suspicions centred on Russian hackers.

While Washington officials do not accuse the Russian government of direct involvement in such attacks, they say the country is harbouring hackers who should be arrested.

US President Joe Biden raised the threat in talks with Russian counterpart Vladimir Putin last month, and on Saturday ordered a full investigation into the Kaseya attack.

“”Most experts would take the view that it’s highly unlikely that it’s state-directed,” Martin said of this latest cyber-assault. “It’s state-tolerated.”

© AFP 2021

Additional reporting Niall O’Connor.

Author
View 25 comments
Close
25 Comments
This is YOUR comments community. Stay civil, stay constructive, stay on topic. Please familiarise yourself with our comments policy here before taking part.
Leave a Comment
    Install the app to use these features.
    Mute dublindamo
    Favourite dublindamo
    Report
    Jul 5th 2021, 10:29 PM

    Without Crypto currencies these hackers can’t extort money. I can see the regulations tightening for all cryptos in the future

    89
    Install the app to use these features.
    Mute Mickety Dee
    Favourite Mickety Dee
    Report
    Jul 6th 2021, 7:06 AM

    @dublindamo: The beauty of crypto is that it is outside the control of any Central authority

    9
    Install the app to use these features.
    Mute Philip King ⚡️
    Favourite Philip King ⚡️
    Report
    Jul 6th 2021, 7:36 AM

    @Mickety Dee: you mean Bitcoin. All other crypto currencies have a central control point.

    10
    See 3 more replies ▾
    Install the app to use these features.
    Mute Colin
    Favourite Colin
    Report
    Jul 6th 2021, 8:47 AM

    @Philip King ⚡️: that’s not true, Monero, Litecoin, Ethereum, all decentralised. There’s a bunch of them.

    5
    Install the app to use these features.
    Mute Philip King ⚡️
    Favourite Philip King ⚡️
    Report
    Jul 6th 2021, 10:46 AM

    @Colin: all great until they get rugged.

    2
    Install the app to use these features.
    Mute Fiona Fitzgerald
    Favourite Fiona Fitzgerald
    Report
    Jul 6th 2021, 6:21 PM

    @Colin: This bunch aren’t bringing those into disrepute though. It’s Bitcoin they want.

    1
    Install the app to use these features.
    Mute Tony Gordon
    Favourite Tony Gordon
    Report
    Jul 5th 2021, 10:13 PM

    Ban cyber currency?

    64
    Install the app to use these features.
    Mute Daithi De Roiste
    Favourite Daithi De Roiste
    Report
    Jul 5th 2021, 10:51 PM

    @Tony Gordon: cyber currency, ffs you don’t even know what it’s called

    33
    Install the app to use these features.
    Mute Tony Gordon
    Favourite Tony Gordon
    Report
    Jul 5th 2021, 10:54 PM

    @Daithi De Roiste: crypto is a cyber currency. Dope.

    63
    See 4 more replies ▾
    Install the app to use these features.
    Mute The Divils Avocado
    Favourite The Divils Avocado
    Report
    Jul 5th 2021, 10:57 PM

    @Daithi De Roiste: is that relevant? Do you not know what he means by cyber currency? Why be nasty?

    64
    Install the app to use these features.
    Mute Brian Lyons
    Favourite Brian Lyons
    Report
    Jul 5th 2021, 11:14 PM

    @Daithi De Roiste: it’s called? FFS You don’t even know there’s more than one.

    34
    Install the app to use these features.
    Mute Ally Mc Culladgh
    Favourite Ally Mc Culladgh
    Report
    Jul 6th 2021, 12:17 AM

    @Daithi De Roiste: Are you the type of person that likes to make fun of people who don’t know the in and outs of something? To show us uneducated people that you know it all?

    26
    Install the app to use these features.
    Mute Mickety Dee
    Favourite Mickety Dee
    Report
    Jul 6th 2021, 7:03 AM

    @Ally Mc Culladgh: I think his point is that the poster is calling for something to be banned that they don’t even understand.

    9
    Install the app to use these features.
    Mute Paul Furey
    Favourite Paul Furey
    Report
    Jul 5th 2021, 10:04 PM

    If an US IT can fall to a cyber attack, what chance had the HSE against a concentrated attack.

    55
    Install the app to use these features.
    Mute Big bad bull
    Favourite Big bad bull
    Report
    Jul 5th 2021, 10:27 PM

    ‘Tis time to plug out the internet

    32
    Install the app to use these features.
    Mute Will
    Favourite Will
    Report
    Jul 6th 2021, 8:40 AM

    @Big bad bull: And then plug it back in again!

    10
    Install the app to use these features.
    Mute Liam Mc Meel
    Favourite Liam Mc Meel
    Report
    Jul 5th 2021, 9:47 PM

    Not bad for a day’s work

    24
    Install the app to use these features.
    Mute James Gorman
    Favourite James Gorman
    Report
    Jul 5th 2021, 10:09 PM

    Putin’s proxy war

    36
    Install the app to use these features.
    Mute pkunzip doom2.zip
    Favourite pkunzip doom2.zip
    Report
    Jul 5th 2021, 11:52 PM

    They should get the HSE negotiator to get them the decryption key!

    21
    Install the app to use these features.
    Mute Mick Tobin
    Favourite Mick Tobin
    Report
    Jul 5th 2021, 9:55 PM

    Common wisdom used to be that if you’ve got your company’s security up to date, you’ll be fine. But now the bottleneck is the weakest link in your supply chain, which is very worrying. Thankfully the white hat hacker community managed to somewhat mitigate matters over a stressful weekend, but in the end it was the bad guys that won the final sprint.

    21
    Install the app to use these features.
    Mute T Dawg
    Favourite T Dawg
    Report
    Jul 5th 2021, 10:05 PM

    Just get Norton antivirus…… Can’t go wrong!

    15
    Install the app to use these features.
    Mute David Grey
    Favourite David Grey
    Report
    Jul 6th 2021, 3:37 AM

    I’m in the wrong Job!…..

    5
    Install the app to use these features.
    Mute keano
    Favourite keano
    Report
    Jul 6th 2021, 8:39 AM

    @David Grey: stick with writing music !

    9
    Install the app to use these features.
    Mute Dave Kelly
    Favourite Dave Kelly
    Report
    Jul 6th 2021, 4:02 AM

    Cyber polygon incoming.

    2
Submit a report
Please help us understand how this comment violates our community guidelines.
Thank you for the feedback
Your feedback has been sent to our team for review.

Leave a commentcancel

 
JournalTv
News in 60 seconds