HomeSecuritySangoma company attacked by Conti ransomware

Sangoma company attacked by Conti ransomware

Sangoma has revealed a data breach after files were stolen during a recent Conti ransomware attack.

Sangoma is a provider of voice over IP hardware and software for the popular open source FreePBX PBX phone system that allows organizations to create a low-cost corporate phone system on network .

Conti

Yesterday, the Conti ransomware gang posted over 26GB of data on the ransomware data leak website that was stolen from Sangoma during the recent cyberattack . This leaked data includes files related to the company’s accounting, financials, acquisitions, employee benefits and salaries , and legal documents.

Conti

Today, Sangoma confirmed that a ransomware attack resulted in a data breach after private and confidential information of the company and employees .

“Sangoma Technologies Corporation (TSXV: STC) (or “Sangoma”) announced that, as a result of a ransomware attack on one of the servers , private and confidential data belonging to the company was published online yesterday,” it said in an advisory.

In attacks against software developers, there is always the concern that their products were modified to deliver malware in supply chain attacks, as was the case with the recent SolarWinds cyberattack .

In its data breach disclosure, Sangoma assures its customers and users that there is no indication that customer accounts or products have been compromised due to this attack.

“There is no initial indication that customer accounts have been compromised, nor that Sangoma products or services have been affected as a result of this breach. While the investigation is ongoing and with great caution, the company recommends that customers change passwords ,” the company said in the advisory.

The ransomware operation behind this attack is known as Conti, which was first detected in isolated attacks in late December 2019, with attacks gradually increasing since June 2020.

This ransomware shares code with the Ryuk Ransomware and is known to be distributed by the TrickBot trojan.

Conti attackers breach corporate networks and spread laterally until they gain access to domain admin credentials to deploy the ransomware payloads used to encrypt devices .

The Conti hackers launched their own data leak website publishing the data of twenty-six victims in August 2020 after operating as a private Ransomware-as-a-Service ( RaaS ) business that hires experienced hackers to develop ransomware in exchange for large percentages of the ransom money it collects.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS