Top related persons:
Top related locs:
Top related orgs:

Search resuls for: "REvil"


14 mentions found


Brisbane, Australia CNN —Australia has publicly named and imposed cyber sanctions on a Russian hacker for his alleged role in a 2022 ransomware attack, in the country’s first use of the penalty. At the time, the Australian Federal Police said investigators knew the identity of the attackers but declined to name them. On Tuesday, the Australian government revealed the name of the individual sanctioned — Russian national Aleksandr Ermakov, 33, an alleged member of the Russian ransomware gang REvil. When the Medibank attack took place later that year, experts said it could have been perpetrated by a REvil member — which Australian authorities confirmed on Tuesday. An initial ransom demand was made for $10 million (15 million Australian dollars).
Persons: Aleksandr Ermakov, , ” Richard Marles, GCHQ —, Marles, “ REvil, ” Abigail Bradshaw, Medibank, Organizations: Australia CNN —, Australian Federal Police, Medibank, Australian Signals Directorate, FBI, National Security Agency, NSA, United Kingdom’s, Microsoft, JBS Foods, Russia’s Federal Security Service, REvil, Australian Cyber Security, Locations: Brisbane, Australia, Australia CNN — Australia, Russian, United States
More countries are targeting payments made to appease ransomware attackers, according to Gartner. As US Department of Justice investigators and companies beef up their oversight of cybersecurity threats, the impact of ransomware attacks — hackers demand ransom payments from targets — has been blunted, according to a Wall Street Journal report. Ransomware hacks can have high stakes, especially when hackers blackmail targets over private information in order to extract payments. In 2021, the agency created new groups internally, including the National Cryptocurrency Enforcement Team and the Ransomware and Digital Extortion Task Force. Countries are generally also stepping up their oversight of ransomware attacks and trying to improve privacy regulations, according to the research and consulting firm Gartner.
SYDNEY, Nov 12 (Reuters) - Australia on Saturday formalised a new cyber-policing model in a stepped-up effort to "hunt down" cyber criminal syndicates, following recent hacks impacting millions of Australians. Australia's biggest health insurer, Medibank Private Ltd (MPL.AX), last month was hit by a massive cyber attack, as Australia grapples with a rise in damaging hacks. O'Neil said around 100 officers would be part of the new partnership between the two federal agencies, which would act as "a joint standing operation against cyber criminal syndicates". The taskforce would "day in, day out, hunt down the scumbags who are responsible for these malicious crimes", she said. Attorney General Mark Dreyfus, speaking alongside O'Neil in Melbourne, refused to be drawn on whether the ransomware group REvil was responsible for recent cyber attacks on Australians.
SYDNEY, Nov 13 (Reuters) - Australia's Home Affairs Minister Clare O'Neil on Sunday said the government would consider making illegal the paying of ransoms to cyber hackers, following recent cyber attacks affecting millions of Australians. Australia's biggest health insurer, Medibank Private Ltd (MPL.AX), last month suffered a massive cyber attack, as Australia grapples with a rise in hacks. Asked on ABC television on Sunday whether the government planned to look at outlawing ransom payments to cyber criminals, O'Neil said "that's correct". Around 100 officers would be part of the new partnership between the two federal agencies, which would act as a joint standing operation against cyber criminals. The AFP earlier this week said Russia-based hackers were behind the attack on Medibank, which compromised data from around 10 million current and former customers.
Moscow must he held to account for Russian cybercriminals accused of hacking Australia’s largest health insurer and dumping customers’ personal medical records on the dark web, Australian officials said Friday. Australian Federal Police took the unusual step of attributing blame for the unsolved cybercrime that resulted in the personal data of 9.7 million current and former Medibank customers being stolen. An old REvil dark web site had started redirecting traffic to a new site that hosts the stolen Medibank data. A Medibank employee’s stolen username and password, which allowed the hackers to enter the company’s database, had been sold on a Russian dark web forum, Hanson said. “These are real people behind this data and the misuse of their data is deplorable and may discourage them from seeking medical care,” he added.
Medibank says the stolen data belongs to 9.7 million past and present customers, including 1.8 million international customers. Kershaw said police intelligence points to a “group of loosely affiliated cyber criminals” who are likely responsible for previous significant data breaches around the world, without naming specific examples. “These cyber criminals are operating like a business with affiliates and associates who are supporting the business. An initial ransom demand was made for $10 million (15 million Australian dollars), but the company said after extensive consultation with cybercrime experts it had decided not to pay. In his statement on Friday, Kershaw, the AFP Commissioner, said Australian government policy did not condone paying ransoms to cyber criminals.
Nov 8 (Reuters) - Medibank Private Ltd (MPL.AX), Australia's biggest health insurer, said on Wednesday some customer personal data believed to have been stolen from its systems has been released by the hacker on a dark web forum. The leaked data includes names, addresses and phone numbers of its customers, and in the case of some international students, passport numbers. Some health claims data was also released. Local media has reported the leaked data was posted on a blog linked to ransomware crime group REvil, which has links to Russia. read more read moreReporting by Harshita Swaminathan and Himanshi Akhand in Bengaluru; Editing by Shailesh KuberOur Standards: The Thomson Reuters Trust Principles.
Prima consecinţă a acestui atac cibernetic a fost aceea că un mare lanţ de supermarketuri din Suedia a trebuit să închidă sâmbătă peste 800 de magazine, casele sale fiind paralizate de atac. Conform estimării firmei de securitate IT Huntress Labs, "peste 1.000 de companii" au fost afectate de acest atac ransomware. Specialiştii americani în securitate IT suspectează că în spatele acestui atac cibernetic s-ar afla gruparea de hackeri ruşi REvil, informează Reuters. Preşedintele Biden, care a ordonat sâmbătă o anchetă, a afirmat că "primul gând a fost că nu a fost vorba de guvernul rus, dar încă nu suntem siguri". Agenţia americană pentru securitate cibernetică şi securitate a infrastructurii (CISA) "monitorizează îndeaproape situaţia", potrivit unui oficial al instituţiei, Eric Goldstein.
Persons: Reuters, Mulţi, Joe Biden, Vladimir Putin . Preşedintele Biden, Eric Goldstein, Alfred Saikali, Hardy, Bacon Organizations: Kaseya Locations: SUA, Suedia, Miami, Statele Unite, Rusia
Hackerii ruşi ar fi comis un nou atac cibernetic de mare anvergură asupra a 200 de corporaţii şi business-uri din Statele Unite. Pentru le debloca sistemele de operare, hackerii au cerut companiilor sume de la câteva mii până la cinci milioane de dolari. Specialiştii americani în securitate IT spun că în spatele atacului ar sta gruparea de hackeri ruşi REvil. Tot ei ar sta în spatele atacului cibernetic comis, luna trecută, împotriva celui mai mare producător de carne din lume. Compania JBS USA a plătit o răscumpărare de 11 milioane de dolari ca să-i fie deblocat sistemul de operare.
Persons: Hackerii ruşi, Totul Organizations: Specialiştii, USA Locations: Statele Unite, american Florida, Statelor Unite
Около 200 американских фирм пострадали от кибератаки на американскую IT-компанию Kaseya, которая поставляет им программное обеспечение и удаленно управляет им. Одной из первых о кибератаке на Kaseya сообщила компания Huntress Labs, специализирующаяся на кибербезопасности. В свою очередь Huntress Labs оценивает число только американских клиентов Kaseya, затронутых кибератакой, примерно в 200 компаний и отмечает, что это число продолжает расти. По данным Huntress Labs, компания Kaseya стала жертвой вируса-вымогателя, который после этого распространился по корпоративным сетям, использующим ее программное обеспечение. Хакеры требуют от жертв кибератаки перевести им по 45 тысяч долларов в криптовалюте, отмечает Huntress Labs.
Persons: REvil —, JBS Organizations: Labs, Huntress, Huntress Labs, ВВС, ФБР Locations: Россия, США по кибербезопасность и инфраструктура, Техас
Sursa foto: BloombergSUA: Hackerii ruşi au declanşat un atac cibernetic „colosal” şi „neobişnuit de sofisticat” împotriva companiilor americaneÎn jur de 200 de companii şi business-uri americane au fost afectate în urma unui atac cyber „colosal” şi, în acelaşi timp, „neobişnuit de sofisticat”, de tip ransomware. Specialiştii americani în securitate IT suspectează că în spatele acestui atac cibernetic s-ar afla gruparea de hackeri ruşi REvil, informează Reuters. Agenţia federală de Securitate Cibernetică şi Infrastructură IT a Statelor Unite a precizat, într-un comunicat că urmează să investigheze acest atac, scrie Digi24. Grupul de hackeri ruşi REvil (Ransomware Evil) este considerat a fi unul dintre cele mai puternice şi prolifice din lume, în materie de activităţi de criminalitate din domeniul informatic. Hackerii ruşi REvil s-ar fi aflat în spatele uriaşului atac îndreptat luna trecută împotriva celui mai mare producător de carne din lume.
Persons: Hackerii, John Hammond, Biden, Putin, american Joe Biden, Vladimir Putin, Joe Biden Organizations: Reuters, BBC, Reprezentanţii Locations: SUA, Florida, Statelor Unite, Ransomware, Geneva, America de Nord, Australia
В результате массированной кибератаки во всем мире заблокирована работа тысяч компаний. Предполагаемые российские хакеры из группировки REvil, которую подозревают в массированной кибератаке на американскую IT-компанию Kaseya, потребовали выкуп в размере 70 млн долларов за разблокирование зашифрованных в результате взлома данных. В результате одной из крупнейших кибератак, совершенных с целью вымогательства, со второй половины дня 2 июля во всем мире заблокирована работа тысяч различных компаний. От атаки REvil пострадали и компании в Европе. По данным Федерального ведомства по безопасности в сфере информационной техники (BSI), в Германии заблокирована работа тысяч компьютеров.
Persons: VSA Organizations: Федеральное ведомство по безопасности Locations: Европа, Германия
Procesatorul de carne JBS USA a plătit o răscumpărare în Bitcoin echivalentă cu 11 milioane de dolari, după un atac cibernetic, care a afectat o mare parte dintre operaţiunile sale în America de Nord şi Australia, a declarat directorul general al companiei, Andre Nogueira, transmite Reuters, citează digi24.ro. La începutul acestei luni, grupul brazilian JBS SA, cel mai mare furnizor mondial de carne, a informat că a fost nevoit să îşi închidă facilităţile de procesare din SUA ca urmare a unui atac organizat al piraţilor cibernetici asupra unora dintre serverele sale. "Aceasta a fost o decizie foarte dificilă de luat pentru compania noastră şi pentru mine personal. Colonial Pipeline a recunoscut că a plătit o răscumpărare de 4,4 milioane de dolari, sau 75 de bitcoini, atacatorilor cibernetici. Fiecare dintre cele 100 de variante de software maliţios este responsabilă pentru numeroase atacuri de tip ransomware, a declarat Christopher Wray pentru ziarul citat.
Persons: Andre Nogueira, Lisa Monaco, FBI Christopher Wray, Christopher Wray Organizations: Reuters, JBS SA, americană Colonial, Colonial, FBI, Wall Street Journal Locations: America de Nord, Australia, SUA, Rusia
Федеральное бюро расследований (ФБР) США изучает около сотни разных программ-вымогателей, многие из которых созданы в России. Об этом заявил директор ФБР Кристофер Рэй (Christopher Wray) в беседе с The Wall Street Journal. «Я считаю, что страна должна смириться с масштабом этой проблемы», — отметил директор ФБР. Он добавил, что, согласно статистике ФБР, количество инцидентов с программами-вымогателями за последний год увеличилось втрое. Федеральное бюро расследований (ФБР) США приписывает кибератаку сервисам REvil и Sodinokibi.
Persons: Christopher Wray, Кристофер Рэй ( ), Рэй, Карин ЖанПьер Organizations: Street Journal, Colonial Pipeline, Федеральное бюро расследований (ФБР), ФБР, СМИ Locations: США, Россия, Белый дом
Total: 14