Insurance company Shirbitwas the victim of a cyberattack on Tuesday by the hacking group Black Shadow. The group demanded a ransom of 50 bitcoins (or $961,110) within 24 hours from the company, in a message posted on its Telegram on Wednesday evening.

The group stated that if the money is paid, it will not disclose any more data and will not sell it to anyone, while it has published large collections of files containing the personal information of customers and employees.
Black Shadow warned that if the money is not sent within 24 hours by 9 a.m. Thursday morning, the ransom will increase to 100 bitcoins ($1,922,220). If another 24 hours pass, it will reach 200 bitcoins ($3,847,680). “After that, we will sell the data to third parties,” the hackers, adding that more data will be leaked at the end of each 24-hour period.
Shortly after the message was published, the group released more files, including faxes and IDs.
The National Cyber Directorate and the Capital Market Authority said on Tuesday that it was working with Shirbit to investigate the suspected attack and that an initial check found that insurance data was also leaked.

Black Shadow began posting the first stolen documents on a Telegram channel at 9 p.m. on Monday.
Shirbit reportedly has many government officials among its clients, including the president of the Tel Aviv District Court, Gilad Noitel.
The attack comes amid a surge in ransomware targeting insurance companies, with dozens of them in the US reporting such attacks just last week, according to ransomware removal and cybersecurity service MonsterCloud.
Attackers in the US have demanded ransoms ranging from $100,000 to millions of dollars. “Based on recent incidents here in the US, the attacks are driven by money,” MonsterCloud CEO Zohar Pinhasi The Jerusalem Post. “Even if the victim has backups, the attacker will extort a ransom to prevent data leakage, which is very serious when it comes to insurance companies.”
