
The hackers behind the DopplePaymer ransomware congratulated SpaceX and NASA on the first manned rocket launch and then announced that they had infected the network of a NASA IT partner and gained access to files its.
The ransomware gang announced via a blog post that it successfully breached the network of Digital Management Inc. (DMI), a Maryland-based company that provides IT and cyber-security services.
According to the company itself, DMI's client list includes many Fortune 100 companies and many government agencies, including NASA.
At this time, we do not know how deep the hackers DMI's network and how many customer networks they managed to compromise. DMI has not yet commented on the ransomware gang's breach.

What seems clear is that the hackers gained access to files related to NASA. This means they breached DMI infrastructure related to the space agency.
To support their claims about breaching and obtaining NASA files, the operators of the DopplePaymer ransomware published 20 files on a dark web portal.
The files include everything from HR documents to project plans (as can be seen in a screenshot of the files). Additionally, the employee information included in these files matches LinkedIn's public records.
The ransomware gang also published a list of 2,583 servers and workstations that are said to be part of DMI's internal network . The hackers have encrypted the systems and are demanding a ransom from the victim.
The purpose of publishing all these files is blackmail. Lately, the gang (like many others) has been operating a “leak site”, where it publishes the stolen files of victims who refuse to pay the ransom.
Initially, the hackers publish some small samples and if the victim still does not pay, they publish all the files, in revenge.
In this case, it's not just DMI that's at risk, but also NASA, whose files have already been exposed. It's likely that other customers of the company are at risk as well.
