Security News > 2020 > April > ‘Double Extortion’ Ransomware Attacks Spike

Victims of ransomware attacks now face a double whammy of headaches.
The ransomware tactic, call "Double extortion," first emerged in late 2019 by Maze operators - but has been rapidly adopted over the past few months by various cybercriminals behind the Clop, DoppelPaymer and Sodinokibi ransomware families.
A November 2019 ransomware attack against Allied Universal, a large American security staffing company, set the precedent for "Double extortion." After the company was hit by a Maze ransomware attack, and refused to cough up the 300 Bitcoin ransom, the attackers threatened to use sensitive information extracted from Allied Universal's systems, as well as stolen email and domain name certificates, for a spam campaign impersonating Allied Universal.
Attackers using the Sodinokibi ransomware have created a "Happy Blog" where they have recently published details of ransomware attacks on 13 targets, as well as company information stolen from the targeted organizations.
"With their focus on coronavirus patients, addressing a double extortion ransomware attack would be very difficult. We issue caution to hospitals and large organization, surging them to back up their data and educate their staff."
News URL
https://threatpost.com/double-extortion-ransomware-attacks-spike/154818/
Related news
- SANS Institute Warns of Novel Cloud-Native Ransomware Attacks (source)
- ⚡ THN Weekly Recap: Router Hacks, PyPI Attacks, New Ransomware Decryptor, and More (source)
- BlackLock ransomware claims nearly 50 attacks in two months (source)
- TechRepublic EXCLUSIVE: New Ransomware Attacks are Getting More Personal as Hackers ‘Apply Psychological Pressure” (source)
- Texas State Bar warns of data breach after INC ransomware claims attack (source)
- Sensata Technologies hit by ransomware attack impacting operations (source)
- Ransomware attack cost IKEA operator in Eastern Europe $23 million (source)
- Kidney dialysis firm DaVita hit by weekend ransomware attack (source)
- Ahold Delhaize confirms data theft after INC ransomware claims attack (source)
- Interlock ransomware gang pushes fake IT tools in ClickFix attacks (source)