HomeSecurityMaze Ransomware sued for publishing stolen data

Maze Ransomware sued for publishing stolen data

The hackers behind the Maze Ransomware are accused by a well-known company of illegally accessing its network, stealing data, encrypting computers, and publishing the stolen data as the ransom was not paid.

southwire-sues-maze-hackers-for-data-exposure

The company suing is Southwire, a leading cable manufacturer from Carrollton, Georgia, which fell victim to hackers in December 2019. As part of that attack, ransomware allegedly stole 120GB of data and encrypted 878 devices.

The ransom of 850 bitcoins, or $6 million, was not paid by Southwire, so the Maze hackers published a portion of the stolen data on a “news” site they created.

This website is hosted on an internet service provider in Ireland, which Southwire says it has contacted repeatedly but has not received a response.

Southwire sues Maze creators

On December 31, 2019, Southwire filed a lawsuit in the Northern District of Georgia, U.S. against Maze and sought injunctive relief against the provider in Ireland for hosting the Maze news website and the stolen files.

In a civil lawsuit against all parties responsible, Southwire is seeking injunctive relief and damages against the Maze hackers for encrypting their network and publishing stolen data recovered during the ransomware attack.

“This is an action for damages and injunctive relief against the defendant arising under the Electronic Fraud and Abuse Act and the common law for breach of wireless communications, confidential business information and other sensitive information. The defendant subsequently sought several million dollars to keep the information private, but after Southwire refused to pay it, the defendant posted a portion of Southwire’s confidential information on a public website that it controls.”

While it may seem odd that Maze hackers were sued, several lawyers said the move is intended to establish the company's legal position to receive compensation if the money is recovered from the government. The move could also be a game-changer for any hosting provider or U.S.-based organization that publishes data stolen from Maze.

“The United States Penal Code provides that any person who suffers harm or loss due to a violation may take legal action against the violator to obtain compensation.

The defendant violated the Electronic Fraud and Abuse Act by knowingly and intentionally accessing Southwire's protected computers without permission or beyond any authorization."

Included in the lawsuit are two exhibits: the ransom note and an image that likely depicts Maze's stolen data.

Maze Ransomware sued for publishing stolen data

Southwire seeks injunction in Ireland

Southwire's counsel has sought injunctions from the Irish courts against the company that hosts the Maze news site and the stolen files.

According to sources, Southwire made repeated requests to the web hosting company called World Hosting Farm Limited, which hosts the Maze news site, to remove their stolen data, but never received a response.

Because of this, the company requested injunctive relief for the parties involved.

“The measures require the defendants to remove all data related to Southwire and its customers from the website. It also obliges the defendants to hand over all data stolen from Southwire and to guarantee that nothing related will be published on the internet or anywhere else.”

The interim injunctions were partially granted, but the court did not prohibit the media from mentioning the victim's name in their reporting.

It is not known whether the Maze team will attempt to host their news on another hosting provider or move it to Tor where it will be much harder to delete.

Legal action is a risky move by Southwire, as it could lead the Maze hackers to release all of the stolen data, not just a few files.

“This is a bold, but risky move by Southwire, which could push the Maze team to release all of the company’s data, while deleting the site could lead to an ongoing manhunt, in which the data is published on other, potentially better-known, sites,” Emsisoft analyst Brett Callow said.

With the Maze hackers seeming very willing to publish their actions and stolen data, this is a move that could lead to the publication of more data.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS