Security News > 2021 > March > FBI Warns of PYSA Ransomware Attacks on Education Institutions in US, UK
An alert issued on Tuesday by the FBI warns about an increase in PYSA ransomware attacks on education institutions in the United States and the United Kingdom.
According to the FBI, PYSA attacks have been launched by "Unidentified cyber actors" against higher education, K-12 schools and seminaries in a dozen U.S. states, as well as the U.K. The threat actors behind PYSA attacks are known to encrypt data on compromised systems, but they also steal information from victims and threaten to leak it in an effort to increase their chances of getting paid.
PYSA ransomware attacks have been observed against government organizations, educational institutions, the healthcare sector and private businesses.
Victims of PYSA ransomware attacks have been advised to file a report with the FBI. "Educational institutions are big targets for hackers as thousands of people's sensitive information is potentially involved, and the substantial shift towards e-learning has made them even more appealing to hackers and ransomware," James Carder, CSO at LogRhythm, told SecurityWeek.
"This FBI warning is an important reminder that educational institutions need to take a proactive approach and invest in cybersecurity solutions that detect malicious behavior and enable network infrastructure to block any further access attempts. Institutions should patch aggressively, create backups, prepare a response plan, and prioritize educational training to ensure they are equipped to handle attacks and proceed without disruption," Carder added.
Over the past year, the FBI issued advisories to warn organizations about attacks involving DoppelPaymer, NetWalker and Egregor ransomware.
News URL
Related news
- AutoCanada says ransomware attack "may" impact employee data (source)
- US sanctions crypto exchanges used by Russian ransomware gangs (source)
- Microsoft Identifies Storm-0501 as Major Threat in Hybrid Cloud Ransomware Attacks (source)
- Embargo ransomware escalates attacks to cloud environments (source)
- JPCERT shares Windows Event Log tips to detect ransomware attacks (source)
- Ransomware attack forces UMC Health System to divert some patients (source)
- Underground ransomware claims attack on Casio, leaks stolen data (source)
- US, UK warn of Russian APT29 hackers targeting Zimbra, TeamCity servers (source)
- Healthcare attacks spread beyond US – just ask India's Star Health (source)
- Casio confirms customer data stolen in a ransomware attack (source)