Security News > 2021 > February > Dutch Research Council (NWO) confirms ransomware attack, data leak

The recent cyberattack that forced the Dutch Research Council to take its servers offline and suspend grant allocation processes was caused by the DoppelPaymer ransomware gang.
Since NWO does not cooperate with cybercriminals, DoppelPaymer published proof of the stolen internal data on their leak site.
NWO is currently working on restoring the network, which indicates that systems have been encrypted, typical to most ransomware actors.
A FAQ from the organization informs that the cyberattack impacted network disks with data processed by NWO, the NWO-I office, the National Governing Body for Practice-oriented Research SIA, and the Netherlands Initiative for Education Research.
The UK Research and Innovation agency, which has the same mission as NWO, has also been hit by a ransomware attack in January that encrypted data and affected some of its services.
While NWO still has some work to do to restore services and operations, UKRI announced that it restored services provided by its UK Research Office based in Brussels.
News URL
Related news
- FBI, Europol, and NCA Take Down 8Base Ransomware Data Leak and Negotiation Sites (source)
- Qilin ransomware claims attack at Lee Enterprises, leaks stolen data (source)
- Ransomware on ESXi: The mechanization of virtualized attacks (source)
- OneBlood confirms personal data stolen in July ransomware attack (source)
- Enzo Biochem settles lawsuit over 2023 ransomware attack for $7.5M (source)
- Medusa ransomware group claims attack on UK's Gateshead Council (source)
- Ransomware attack forces Brit high school to shut doors (source)
- Ransomware gangs pose as IT support in Microsoft Teams phishing attacks (source)
- Security pros more confident about fending off ransomware, despite being battered by attacks (source)
- Only 13% of organizations fully recover data after a ransomware attack (source)