Security News > 2020 > July > Citrix denies dark web claim of network compromise and ransomware attack

Citrix has taken the unusual step of rebutting dark web discourse that alleges its networks have been compromised.
A Wednesday post penned by CISO Fermin J Serna says the company is aware of a "Threat intelligence report circulated concerning claims made on the dark web by a threat actor alleging compromise of the Citrix network, exfiltration of data, and attempts to escalate privileges to launch a ransomware attack."
Serna said Citrix is investigating the claims but has found "No evidence that the threat actor compromised the Citrix network."
"Once that action was complete, the author of the threat intelligence report reported that the threat actor's unauthorized access was terminated. The third party is now conducting its own investigation and remediation, and is committed to keeping Citrix advised of any developments, and Citrix is ready to assist as necessary."
"As recently as today, there are reports of Citrix data for sale on the dark web," the CISO added, before reinforcing that "Based on our investigation, the source of this data is the same third party referenced above. Many of these reports today erroneously imply a Citrix compromise." .
News URL
https://go.theregister.com/feed/www.theregister.com/2020/07/15/citrix_denies_new_network_compromise/
Related news
- Everest ransomware's dark web leak site defaced, now offline (source)
- CERT-UA Warns of UAC-0173 Attacks Deploying DCRat to Compromise Ukrainian Notaries (source)
- Southern Water says Black Basta ransomware attack cost £4.5M in expenses (source)
- Qilin ransomware claims attack at Lee Enterprises, leaks stolen data (source)
- Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks (source)
- Hackers Exploit Paragon Partition Manager Driver Vulnerability in Ransomware Attacks (source)
- Hunters International ransomware claims attack on Tata Technologies (source)
- Toronto Zoo shares update on last year's ransomware attack (source)
- Ransomware gang creates tool to automate VPN brute-force attacks (source)
- SANS Institute Warns of Novel Cloud-Native Ransomware Attacks (source)