
The University of Utah revealed that it paid $457,059 to a gang ransomware in order to prevent the leak of student information.
This is the latest ransomware attack, where criminals stole sensitive files before encrypting the victim's systems. The criminals threatened the university that if it did not pay the ransom, they would expose the stolen data online.
The University of Utah published a statement on its website , saying that the institution managed to mitigate a serious ransomware attack, as hackers were only able to encrypt 0.02% of the data stored on its servers.
The university said the damage was repaired as backups place. However, the ransomware gang threatened to expose online student data which prompted the university administration to reconsider the situation, as it had initially said that the ransom would not be paid.
"After careful consideration, the university has decided to partner with the cybersecurity insurance provider to pay the ransom to the ransomware gang," the University of Utah said.
"This was done as a precautionary step to ensure that the information would not be released online.".
“The department paid part of the ransom and the university covered the rest. No tuition, grants, donations or government funds were used to pay the ransom,” university officials added.
The University of Utah has revealed some details about the ransomware attack . According to them, the attack took place on July 19, 2020, and affected the network of the university's College of Social and Behavioral Science [CSBS]
However, the university did not reveal which ransomware gang was behind the attack.

All evidence points to it being the NetWalker ransomware
Brett Callow, a threat analyst at security firm Emsisoft, said, although he doesn't have specifics ,that the NetWalker ransomware gang is likely behind the attack.
This particular group, which is believed to have raised more than $25 million in ransoms, is behind a recent wave of attacks targeting university networks (e.g., attacks on Michigan State, University of California at San Francisco, Columbia College Chicago, and City University of Seattle).
However, Callow disagrees with the decision made by the University of Utah. Paying ransoms to hackers to prevent data is not the best practice and certainly not the results.
“Paying a ransom to avoid publishing data makes no sense,” Callow said.
Essentially, organizations pay ransoms to ransomware gangs hoping that the hackers will keep their word and not publish the stolen data or, at best, destroy it. However, it is not very wise to trust someone who has already attacked you and put you in this difficult situation. The most likely thing is that the hacking groups keep the data and use it in subsequent attacks (e.g. phishing) even if they do not publish it online.
