
Technology company Konica Minolta fell victim to ransomware attack in late July. The attack affected the company's services for almost a week.
Konica Minolta is a Japanese multinational technology company with nearly 44,000 employees and revenue of over $9 billion in 2019. The company offers a wide variety of services and products that include printing solutions, healthcare technology, provision of managed IT services to businesses, and more.
The ransomware attack began with a disruption of the company's services
On July 30, 2020, customers began reporting that the site was inaccessible and displayed the following message:
“The Konica Minolta MyKMBS customer portal is temporarily unavailable. We are working hard to resolve the issue and apologize for any inconvenience this may have caused you. If you require immediate service assistance, please call our Global Customer Services at 1-800-456-5664 (US) or 1-800-263-4410 (Canada).”.
The site remained down for almost a week , and customers said they couldn't get a simple answer about what caused the outage.
Some Konica Minolta printers also displayed an error.
Some customers began to say that perhaps breach security was responsible for the site and services being down.
Konica Minolta hit by RansomEXX ransomware
Shortly afterwards, a copy of the ransom note left by the hackers at Konica Minolta was released.
The note is called “!! KONICA_MINOLTA_README!!. txt” and as it appears, it clearly targets the company Konica Minolta.

It is said that the company's devices were encrypted and the files were given the extension “.K0N1M1N0”.
The ransom note appears to belong to a relatively new ransomware called RansomEXX. This ransomware was first detected in late June 2020, when it was used in an attack on the Texas Department of Transportation.
As with most ransomware attacks targeting businesses, RansomEXX doesn't work automatically. Hackers . breach networks, and over time, spread to other devices until they obtain administrator credentials
Once they gain administrator rights, they deploy the ransomware to the network and encrypt all of its devices.
According to the RansomEXX ransom note, this ransomware enterprise probably does not steal data before encrypting devices.
