A cyberattack on DESFA by foreign hackers, via Ragnar Locker ransomware and data theft, took place on August 19, 2022 at 18:42. The hackers infected the systems of the National Natural Gas System Operator with ransomware and managed to steal sensitive data and information of employees and customers.

The hackers-blackmailers have posted the above message on a darknet website:

According to exclusive information from SecNews, behind the cyberattack is a hacking group that uses the Ragnar Locker ransomware as its main method of attacking state infrastructure, services, government systems, and large businesses worldwide.

The cyberattack on DESFA was first detected by researcher Dominic Alvieri on the darknet, according to the collaborating website suspectfile and the Twitter profile.
The hacker-extortionists have been essentially stealing files from DESFA for a long time, as it seems, which they are threatening to share if the ransom is not paid. At the moment, according to www.suspectfile.com, DESFA documents are circulating on the darknet, part of which was posted on SecNews and which we are publishing with the relevant concealment. Among the stolen files, there seems to be a particularly large amount of personal data!
In the files leaked by the Ragnar locker ransomware gang, some data/information has been blurred by the SecNews technical team.





A similar ransomware and data breach attack took place in the US in 2021 with great impact. The reason was the cyberattack on Colonial Pipeline, the largest fuel pipeline in the US, a hack that caused public outrage for quite some time, while according to US officials, Colonial Pipeline paid a ransom of $5 million to hackers who affected some of its networks.
Learn more here:
Colonial Pipeline: Ransomware attack hits largest US fuel pipeline
Colonial Pipeline: Most of the ransom paid to DarkSide recovered
Colonial Pipeline CEO: Paying the ransom was the right decision for the country
Ragnar Locker ransomware hackers
The Ragnar Locker ransomware gang has compromised critical infrastructure of 52 organizations.
In a publication issued by the FBI in coordination with DHS/CISA, the FBI says it has identified at least 52 organizations across 10 critical infrastructure sectors affected by the Ragnar Locker ransomware, including organizations in manufacturing, energy, financial services, government, and information technology.
In the past, the group behind Ragnar Locker has explicitly warned victims not to contact the FBI or other law enforcement agencies about the attack. In September 2021, the ransomware operators threatened to publish all data of victimized organizations that seek help from law enforcement or investigators following ransomware attacks.
However, in the wake of recent high-profile cyberattacks and ransomware, Congress and the Biden administration have joined forces to push through policy changes that would require organizations to report certain cyber incidents to the federal government. Importantly, the legislation would give organizations 72 hours to report a cyber incident.
DESFA is required to report ransomware incidents to authorities. Doing so provides researchers and analysts with the critical information they need to track hackers and prevent future attacks.
Details about RAGNAR LOCKER
"The cybercriminals behind the RagnarLocker ransomware are constantly trying to evade detection by common security countermeasures with stealth techniques," the FBI said in a related alert.
Additionally, the FBI found that the operators behind Ragnar Locker have included a special mechanism in the ransomware they developed, so that if the terminals targeted are from certain countries, mainly Russia, they will not cause any damage. There is information that the operators of the Ragnar Locker gang are Russian or are based and operating from Russia
If the victim's location is determined to be from Azerbaijan, Armenia, Belarus, Kazakhstan, Kyrgyzstan, Moldova, Tajikistan, Russia, Turkmenistan, Uzbekistan, Ukraine or Georgia then the malware is deactivated. This raises questions as to why DESFA was targeted at this particular time
DESFA
The National Natural Gas System Operator (DESFA) S.A. is responsible for the operation, management, exploitation and development of the National Natural Gas System (NSGS) and its interconnections, in a technically sound and economically efficient manner and with the aim of optimally serving its Users with safety, reliability and adequacy.
By contributing decisively to the security of supply and the diversification of supply sources in the wider region, DESFA also facilitates the development of competition in the Greek energy market, consistently ensuring the reduction of greenhouse gas emissions.
With extensive experience and highly trained human resources, DESFA is becoming a reliable partner in the context of ongoing international energy projects in Southeastern Europe.
