The criminals behind the Sodinokibi ransomware are threatening to release data they stole from an automotive company. The company did not pay the ransom demanded by the hackers , and so their data was not decrypted.
According to the Sodinokibi hackers, the data was stolen from GEDIA Automotive Group, a German car company with production plants in Germany, China, Hungary, India, Mexico, Poland, Spain, and the US.
GEDIA is a very large company with more than 4,300 employees worldwide.
Sodinokibi operators wrote on a Russian hacking forum that all GEDIA computers have been affected, as the entire network is encrypted. “50 GB of data has been stolen, including employee, customer, etc.”
A few days ago, the same hackers published files (337 MB) that they had stolen from Artech Information Systems, a US IT company.
The operators of the Sodinokibi Ransomware have stated that they will start selling stolen Artech data on platforms used by cybercriminals .

Ransomware gangs are now causing data leaks as well
Recently, experts have noticed that ransomware gangs are using a new tactic: They steal data before encrypting systems and then threaten to expose it online.
If victims do not pay the ransom, hackers start exposing parts of the stolen data, to blackmail victims into paying. If the money is not given, all the data will be leaked.
This new trend was started by the Maze Ransomware in late November 2019. It has now been adopted by the hackers behind Sodinokibi, Nemty Ransomware, and BitPyLock.
Until November, no hacking group had released details of the victims, even though the data was accessible. The first was the Maze ransomware hackers, who published documents they had stolen from Allied Universal.
Until now, ransomware attacks have not been combined with breaches . So companies were at risk from either threat. In the future, however, we will see more and more combined attacks, which is why organizations need to strengthen their security.
