HomeSecurityRagnar Locker ransomware: Attack on TAP Air Portugal

Ragnar Locker ransomware: Attack on TAP Air Portugal

The Ragnar Locker ransomware gang has admitted to carrying out an attack on Portuguese carrier TAP Air Portugal, revealed by the airline after its systems were hit on Thursday night.

See also: TikTok Android: Vulnerability allowed accounts to be compromised

Ragnar Locker ransomware: Attack on TAP Air Portugal

The company said the attack was blocked and added that it found no evidence to suggest that the attackers gained access to customer information stored on affected servers.

See also: Apple: Fixes zero-day bug affecting older iPhones

"No evidence has been found that would allow us to conclude that there was inappropriate access to customer data. The website and app continue to experience some instability," the company said in a statement on Friday via its official Twitter account.

On Monday, the airline also posted a notice saying that its website and app are unable to function due to Thursday's cyberattack.

He also added that customers could book flights, manage previous bookings , and check-in and download their boarding passes without logging in.

Although TAP Air Portugal has yet to confirm whether it was a ransomware attack, the Ragnar Locker ransomware gang today published a new entry on the data leak website, claiming to be behind cyberattack that hit TAP's network.

The ransomware group says it has "reasons" to believe that hundreds of Gigabytes of data may have been compromised in the incident and has threatened to provide "irrefutable evidence" to refute TAP's statement that its customers' data was not stolen

“Several days ago Tap Air Portugal published a press release claiming with certainty that it had successfully repelled the cyberattack and that no data was compromised (but we have some reason to believe that this is not the case),” the team says.

The Ragnar Locker group also shared a screenshot of a spreadsheet containing what appears to be customer information stolen from TAP's servers, including names, dates of birth, emails, and addresses.

Ragnar Locker

Ragnar Locker ransomware payloads were first observed in attacks against several targets in late December 2019

Attackers using Ragnar Locker ransomware have also encrypted the systems of Portuguese multinational energy giant Energias de Portugal (EDP) and demanded a ransom of 1580 BTC (equivalent to more than $10 million at the time).

A list of Ragnar Locker's earliest victims includes Japanese gaming company Capcom, computer chip maker ADATA , and aerospace giant Dassault Falcon.

See also: Interworks cloud official statement regarding cyberattack

In March, the FBI said that the Ragnar Locker ransomware had been deployed to the networks of at least 52 organizations from multiple critical infrastructure in the US since April 2020.

TAP (abbreviation of Transportes Aéreos Portugals) is the largest airline in Portugal, accounting for more than 50% of arrivals and departures at Lisbon International Airport in 2019.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS