HomeSecurityDoppelPaymer Ransomware: Creation of a site to leak victims' data

DoppelPaymer Ransomware: Site created to leak victims' data

The hackers behind the DoppelPaymer Ransomware have set up a websitethat they plan to use to "sham" victims who choose not to pay the ransom. This means that the hackers will start posting files that they stole from systems before they began encrypting them.

This extortion was started by the hackers behind the Maze Ransomware. The criminals started stealing files before encryption, in order to blackmail victims in case they did not want to pay the ransom.

If the ransom is not paid, ransomware gangs publish the stolen files on a news site to expose the victim. This can cause a lot of problems. The victim can receive fines , lawsuits , and can be accused of data breaches and other people (e.g. if the victim is a business that handles customer and employee data )

DoppelPaymer Ransomware

After the Maze Ransomware hackers, other groups began to follow the same tactic (Sodinokibi, Nemty and DoppelPaymer).

The group behind DopplePaymer ransomware creates site to leak data

The site created by the hackers is called 'Dopple Leaks' and will be used to leak files and expose victims who do not pay the ransom.

Hackers created this site to threaten victims and make them believe that their data and names will be leaked online.

The ransomware gang stated that the site is currently in a testing phase.

Currently, there are four companiesthat, according to the hackers, did not pay the ransom:

  • A company based in the US (with operations abroad as well). Ransom: 15 bitcoins (~$150K).
  • A French telecommunications and cloud services company. Ransom: 35 bitcoins (~ $ 330K).
  • A logistics company based in South Africa. Ransom: 50 bitcoins (~ $ 500K).
  • state-owned oil company Pemex was attacked by the DoppelPaymer ransomware gang on November 10, 2019. The attackers demanded 568 bitcoins ($4.9 million at the time).

Most of the files available to the hackers belong to Pemex.

For the other three companies, they only stole a few files because there was "nothing interesting" or because "it wasn't our target," as the hackers said.

The hackers said that now that they have this site they will carry out further information thefts.

DoppelPaymer Ransomware

Treat ransomware attacks as data breaches!

Ransomware attacks must be treated as data breaches.

For years, it has become known that ransomware gangs steal files before encrypting computers, to threaten victims.

However, this tactic has only recently begun to be implemented. For this reason, companies must announce information theft and treat these attacks as data breaches.

This must be done because hackers do not steal only corporate data, but also data of suppliers, customers, and employees.

Transparency important , as hiding ransomware attacks puts many people at risk.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS