HomeSecurityBlackCat/ALPHV ransomware: Asks for $5 million to unlock Carinthia

BlackCat/ALPHV ransomware: Demands $5 million to unlock Carinthia

Carinthia (the southernmost Austrian state) was hit by the BlackCat ransomware gang, also known as ALPHV, which demanded $5 million to unlock encrypted computer systems.

BlackCat/ALPHV ransomware: Demands $5 million to unlock Carinthia

See also: Marketplace Industrial Spy enters the ransomware game

The attack occurred on Tuesday and caused a severe disruption to government services, as thousands of workstations were reportedly locked by the threat actor.

Carinthia's website and email service are currently offline and the administration cannot issue new passports or traffic fines.

In addition, the cyberattack also disrupted the processing of COVID-19 and contact tracing carried out through the region's administrative offices.

The hackers offered to provide a working decryption tool for $5 million. A state spokesman, Gerd Kurath, told Euractiv that the attacker's demands would not be met.

The spokesperson said that there is currently no evidence that the BlackCat ransomware operation has actually managed to steal data from the systems of the state of Carinthia and that the plan is to restore the machines from available backups.

See also: Linux ransomware 'Cheers': Targets VMware ESXi servers

Kurath said that of the 3,000 systems affected, the first are expected to become available again today.

At the time of writing, the BlackCat ransomware data leak website, where hackers post files stolen from victims who did not pay the ransom, does not show any data from Carinthia. This may indicate that negotiations with the victim have not been completed.

BlackCat ransomware Carinthia

ALPHV/BlackCat

The ALPHV/BlackCat ransomware gang emerged in November 2021 as one of the most sophisticated ransomware operations. It is a rebrand of the DarkSide/BlackMatter responsible for the Colonial Pipeline last year.

In early 2022, affiliates of the BlackCat ransomware attacked high-profile entities and brands such as fashion group Moncler and airline cargo handling service provider Swissport.

At the end of the first quarter of this year, the FBI published an alert warning that the BlackCat operation had compromised at least 60 entities worldwide, suggesting that it would become one of the most active and dangerous ransomware in the future.

See also: SpiceJet flights affected by ransomware attack

The attack on Carinthia and the large ransom demands show that the threat actor is focused on organizations that can pay a lot of money to decrypt their systems and avoid additional financial losses resulting from prolonged operational disruption.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS