AIRLINK 194.83 Decreased By ▼ -3.14 (-1.59%)
BOP 9.81 Decreased By ▼ -0.23 (-2.29%)
CNERGY 7.36 Increased By ▲ 0.07 (0.96%)
FCCL 38.58 Increased By ▲ 2.58 (7.17%)
FFL 16.45 Decreased By ▼ -0.46 (-2.72%)
FLYNG 27.54 Increased By ▲ 2.50 (9.98%)
HUBC 131.75 Decreased By ▼ -2.28 (-1.7%)
HUMNL 13.86 Decreased By ▼ -0.28 (-1.98%)
KEL 4.66 Decreased By ▼ -0.12 (-2.51%)
KOSM 6.66 Decreased By ▼ -0.28 (-4.03%)
MLCF 45.39 Increased By ▲ 0.41 (0.91%)
OGDC 213.99 Decreased By ▼ -4.24 (-1.94%)
PACE 6.86 Decreased By ▼ -0.08 (-1.15%)
PAEL 40.06 Decreased By ▼ -1.36 (-3.28%)
PIAHCLA 16.79 Decreased By ▼ -0.07 (-0.42%)
PIBTL 8.32 Decreased By ▼ -0.14 (-1.65%)
POWER 9.43 Increased By ▲ 0.04 (0.43%)
PPL 182.19 Decreased By ▼ -3.74 (-2.01%)
PRL 41.83 Increased By ▲ 0.56 (1.36%)
PTC 24.56 Decreased By ▼ -0.21 (-0.85%)
SEARL 102.53 Decreased By ▼ -2.12 (-2.03%)
SILK 1.00 Decreased By ▼ -0.01 (-0.99%)
SSGC 39.44 Decreased By ▼ -1.47 (-3.59%)
SYM 17.33 Decreased By ▼ -0.72 (-3.99%)
TELE 8.76 Decreased By ▼ -0.15 (-1.68%)
TPLP 12.75 Decreased By ▼ -0.09 (-0.7%)
TRG 65.40 Decreased By ▼ -1.20 (-1.8%)
WAVESAPP 11.11 Decreased By ▼ -0.19 (-1.68%)
WTL 1.70 Decreased By ▼ -0.08 (-4.49%)
YOUW 3.94 Decreased By ▼ -0.06 (-1.5%)
BR100 11,988 Decreased By -121.3 (-1%)
BR30 36,198 Decreased By -400.2 (-1.09%)
KSE100 113,443 Decreased By -1598.8 (-1.39%)
KSE30 35,635 Decreased By -564.3 (-1.56%)

PARIS: Hackers were on Monday demanding $70 million in bitcoin in exchange for data stolen during an attack on a US IT company that has shuttered hundreds of Swedish supermarkets.

Researchers believe more than 1,000 companies could have been affected by the attack on Miami-based firm Kaseya, which provides IT services to some 40,000 businesses around the world. The FBI warned Sunday that the scale of the “ransomware” attack — a form of digital hostage-taking where hackers encrypt victims’ data and then demand money for restored access — is so large that it may be “unable to respond to each victim individually”.

Sweden’s Coop supermarket chain was among the most high-profile victims. Most of their 800 stores were still closed three days after the hack paralysed its cash registers, spokesman Kevin Bell told AFP. Coop, like many of the companies affected, is not a direct customer of Kaseya’s, but its IT subcontractor Visma Esscom was hit by the attack.

The few hundred Coop stores that had reopened were relying on alternative payment solutions, such as customers paying using their smartphones, Bell said. Cybersecurity firm ESET said it had identified victims of the hack in at least 17 countries, from South Africa to Britain to Mexico. New Zealand’s education ministry said at least two schools there had been affected.

Experts believe the attack was probably carried out by REvil, a Russian-speaking hacking group known as a prolific perpetrator of ransomware attacks. A post on Happy Blog, a site on the dark web previously associated with the group, claimed responsibility for the attack and said it had infected “more than a million systems”.

The FBI believes that REvil, which also goes by the name Sodinokibi, was behind a ransomware attack last month on global meat-processing giant JBS. The Brazil-based company ended up paying $11 million in bitcoin to the hackers.

The hackers’ blog post said they would release a decryption tool online “so everyone will be able to recover from attack in less than an hour” — if they were handed $70 million in bitcoin. Kaseya said Sunday it believed the damage had been restricted to a “very small number” of customers using its signature VSA software, which lets companies manage networks of computers and printers from a single point.

But cybersecurity firm Huntress Labs said in a Reddit forum that it was working with partners targeted in the attack, and that the software was manipulated “to encrypt more than 1,000 companies”.

Kaseya said it had “immediately shut down” its servers after detecting the attack on Friday and warned its VSA customers to do the same, “to prevent them from being compromised”.

The company has released a tool allowing its customers to find out whether their own computer systems have been compromised by the attack.

In recent months numerous US companies, including the computer group SolarWinds and the Colonial oil pipeline, have been the victims of high-profile ransomware attacks, which the FBI blames on hackers based in Russia.

While Washington officials do not accuse the Russian government of direct involvement in such attacks, they say the country is harbouring hackers who should be arrested.

US President Joe Biden raised the threat in talks with Russian counterpart Vladimir Putin last month, and on Saturday ordered a full investigation into the Kaseya attack.

In the meantime, hundreds of companies are facing the dilemma of whether or not to pay the ransom demanded by the hackers. “In general, it doesn’t pay to pay ransoms,” said Lior Div, CEO of cybersecurity firm Cybereason. It found in a recent study that 80 percent of companies that pay a ransom are hit again. “Overall, paying ransoms only emboldens threat actors and drives up ransom demands,” Div explained. “Still, whether or not to pay a ransom is an individual choice each company needs to make.”

Comments

Comments are closed.