Hackers are selling data belonging to victims of Sodinokibi ransomware on hacking forums.
Recently, ransomware gangs have been using a new technique. Before encrypting data, they steal it and then threaten victims that they will leak it onlineif they don’t pay the ransom. Some hackers have already started implementing this (the leak). Now, victims have to face another bigger nightmare. Other hackers take the data leaked hacking forums.
One of the first hacking groups to start stealing their victims ' data before encrypting devices was the group behind Maze Ransomware . This technique appeared in 2019.
Shortly after, other ransomware gangs (hackers behind DoppelPaymer, Nemty, Sodinokibi ransomware) began stealing data and threatening to release it.
Recently, the Sodinokibi ransomware hackers released over 12 GB of stolen data, said to belong to a company called Brooks International. The hackers reported that the company had not paid the ransom.

A data breach is already a bad enough scenario, but security Cyble has revealed that other hackers are taking the leaked data of Sodinokibi ransomware victims and selling it on hacking forums.
For example, the image below shows a post on a hacking forum, where the hacker is selling stolen data.
The hackers, who took the stolen data to sell it, said that the information included is very important to them and that they may use it for other activities.
Ransomware attacks are data breaches
Ransomware attacks can now be considered data breaches, since hackers don't just encrypt data, they steal it and publish it.
Therefore, ransomware attacks should be classified as data breach incidents.
The bad news is that it's not just company information that's being leaked, but also customer and employee information. These people need to be notified immediately so they can protect themselves.
Unfortunately, too many attacks go unreported, even to employees themselves.

