HomeSecurityConti ransomware gang demands $20 million from Irish HSE

Conti ransomware gang demands $20 million from Irish HSE

Ireland's public health system ( Health Service Executive -HSE) is refusing to pay $20 million to the Conti ransomware gang that targeted its systems. The HSE was forced to shut down its IT systems on Friday to prevent the spread of ransomware.

See also: Hackers targeted Ireland's public health system (HSE)

HSE Ireland

Authorities have launched an investigation into the incident and are working to determine the extent of the breach.

The ransomware attack caused cancellations and disruptions in services at many hospitals in the country.

The HSE took to Twitter on Friday to update the public about the ransomware attack. The attack affected doctors' access to files , but other medical equipment and COVID-19 vaccinations do not appear to have been affected.

According to new information released in the media, the Irish health system (HSE) has shut down all of its IT systems due to an attack by the Conti ransomware gang.

See also: New threat: Ransomware attacks with triple extortion

According to BleepingComputer, the Conti ransomware gang demanded $20 million from the HSE. A security researcher shared with BleepingComputer a screenshot of a conversation between the Conti gang and the Irish HSE.

In the screenshot, the Conti ransomware gang claims to have accessed the HSE network for two weeks. During that time, it claims to have stolen 700GB of unencrypted files. In the end, the hackers said they would offer a decryption tool and delete the stolen data if the HSE paid $19,999,000.

Conti ransomware

It is also said that during the conversation, the criminals also shared a sample of the stolen data.

Useful information: Ransomware: What you need to know about this major threat!

In a statement on Friday, Micheál Martin (Taoiseach), Prime Minister of Ireland, said that the ransom would not be paid.

Conti ransomware gang demands $20 million from Irish HSE

Conti ransomware

It is said that a Russian- based criminal group known as Wizard Spider is behind the Conti ransomware

This group uses phishing attacks to install the TrickBot and BazarLoader trojans, which provide remote access to infected machines.

Using this remote access, hackers spread across networks, stealing credentials and unencrypted data.

After stealing all the valuable data and gaining access to Windows domain credentials, they deploy ransomware on the network to encrypt all of its devices.

The Conti gang then threatens to leak the stolen data to force the victim to pay the ransom.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS