HomeSecurityCognizant: Data breach following ransomware attack

Cognizant: Data breach following ransomware attack

Cognizant

IT services company Cognizant said some of its unencrypted data was compromised during a attack Maze Ransomware in April.

Cognizant is one of the largest IT services companies in the world with approximately 300,000 employees and revenues of over $15 billion.

As an MSP, Cognizant remotely manages the issues of many customers (resolving problems, installing updates, monitoring security , etc.).

On April 17, Cognizant began sending emails to its customers warning them that the company had been attacked by the Maze Ransomware. The notification asked them to log out of the company's systems so that they would not be affected by the attack.

This email also contained some evidence of the breach, such as IP addresses used by Maze and file hashes for the files kepstl32.dll, memes.tmp, and maze.dll . These IP addresses and files are known to have been used in previous attacks by the Maze ransomware hackers

While Cognizant stated at the time that the attack came from the Maze gang, the hackers denied being behind the attack.

ransomware

Breach and likely theft of compromised data

In two data breach notification letters filed with the California Attorney General's Office, Cognizant states that the operators of the Maze Ransomware were active on the company's network between April 9 and 11.

While they had access, “they likely stole a limited amount of data from Cognizant’s systems.”

Before deploying the ransomware and encrypting devices, the operators of the Maze Ransomware spread through the network and steal files.

After stealing the data, the hackers threaten to leak it to a site they have created. On this site, they usually expose the files of victims who do not pay the ransom.

Cognizant warned that hackers may have stolen sensitive personal information such as SSNs, tax information, financial information, driver's licenses and passports.

As for employees, the company said corporate credit cards may also have been exposed.

For those affected, Cognizant is providing the dark web monitoring service free of charge for one year.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS