
IT services company Cognizant said some of its unencrypted data was compromised during a attack Maze Ransomware in April.
Cognizant is one of the largest IT services companies in the world with approximately 300,000 employees and revenues of over $15 billion.
As an MSP, Cognizant remotely manages the issues of many customers (resolving problems, installing updates, monitoring security , etc.).
On April 17, Cognizant began sending emails to its customers warning them that the company had been attacked by the Maze Ransomware. The notification asked them to log out of the company's systems so that they would not be affected by the attack.
This email also contained some evidence of the breach, such as IP addresses used by Maze and file hashes for the files kepstl32.dll, memes.tmp, and maze.dll . These IP addresses and files are known to have been used in previous attacks by the Maze ransomware hackers
While Cognizant stated at the time that the attack came from the Maze gang, the hackers denied being behind the attack.

Breach and likely theft of compromised data
In two data breach notification letters filed with the California Attorney General's Office, Cognizant states that the operators of the Maze Ransomware were active on the company's network between April 9 and 11.
While they had access, “they likely stole a limited amount of data from Cognizant’s systems.”
Before deploying the ransomware and encrypting devices, the operators of the Maze Ransomware spread through the network and steal files.
After stealing the data, the hackers threaten to leak it to a site they have created. On this site, they usually expose the files of victims who do not pay the ransom.
Cognizant warned that hackers may have stolen sensitive personal information such as SSNs, tax information, financial information, driver's licenses and passports.
As for employees, the company said corporate credit cards may also have been exposed.
For those affected, Cognizant is providing the dark web monitoring service free of charge for one year.
