Security News > 2021 > October > 30 Mins or Less: Rapid Attacks Extort Orgs Without Ransomware

In less time than it takes to get a stuffed crust pizza delivered, a new group called SnapMC can breach an organization's systems, steal their sensitive data, and demand payment to keep it from being published, according to a new report from NCC Group's threat intelligence team - no ransomware required.
Last July SonicWall issued a patch for a bug in its old VPN models no longer supported by the company after attacks came to light - which were part of an ongoing wider campaign to exploit.
Oliver Tavakoli, CTO with Vectra, said that getting rid of the encryption piece of the attack altogether is a "Natural evolution" of the ransomware business model.
The NCC team likewise predicts the trend toward simple attacks on shorter timelines is likely to continue.
"NCC Group's Threat Intelligence team predicts that data-breach extortion attacks will increase over time, as it takes less time, and even less technical in-depth knowledge or skill in comparison to a full-blown ransomware attack," the team said.
"Therefore, making sure you are able to detect such attacks in combination with having an incident response plan ready to execute at short notice, is vital to efficiently and effectively mitigate the threat SnapMC poses to your organization."
News URL
https://threatpost.com/rapid-attacks-extort-ransomware/175445/
Related news
- Preventing the next ransomware attack with help from AI (source)
- Ransomware on ESXi: The mechanization of virtualized attacks (source)
- OneBlood confirms personal data stolen in July ransomware attack (source)
- Enzo Biochem settles lawsuit over 2023 ransomware attack for $7.5M (source)
- Medusa ransomware group claims attack on UK's Gateshead Council (source)
- Ransomware attack forces Brit high school to shut doors (source)
- Ransomware gangs pose as IT support in Microsoft Teams phishing attacks (source)
- Security pros more confident about fending off ransomware, despite being battered by attacks (source)
- Only 13% of organizations fully recover data after a ransomware attack (source)
- Ransomware attack at New York blood services provider – donors turned away during shortage crisis (source)