HomeSecurityHive ransomware: Says it attacked Bell Technical Solutions

Hive ransomware: Says it attacked Bell Technical Solutions

The Hive ransomware gang has claimed responsibility for an attack that hit the systems of Bell Canada subsidiary Bell Technical Solutions (BTS).

Hive ransomware: Says it attacked Bell Technical Solutions

See also: Uber hacked: Internal systems breached

BTS is an independent subsidiary with more than 4,500 employees, specializing in the installation of Bell services for residential and small business customers in the provinces of Ontario and Québec.

While the Canadian telecommunications company did not disclose when its network was breached or when the attack occurred, Hive claims in a new entry added to the data leak blog that it encrypted BTS's systems almost a month ago, on August 20, 2022 .

The BTS website, which is usually accessible at bellsolutionstech.ca, is currently inaccessible, however, Bell Canada posted a notice following the incident on its own website.

“We have been made aware that hackers have gained access to certain company and employee in a recent cybersecurity incident targeting Bell Technical Solutions,” Bell said.

See also: Webworm group modifies old malware and tests it in new attacks

“The unauthorized party had access to information that may include the name, address , and phone number of residential and small business customers in Ontario and Québec who booked a technician visit.”

“Bell Technical Solutions took immediate steps to secure the affected systems and we want to assure you that no databases containing customer information, such as credit and debit card, banking or other financial data.”

Hive ransomware: Says it attacked Bell Technical Solutions

The Bell subsidiary warned customers about the possibility of being targeted in phishing attacks following this incident and advised them to monitor their accounts for any suspicious activity.

Hive is a Ransomware-as-a-Service (RaaS) operation that has been operating since June 2021 behind attacks against dozens of organizations, counting only those victims whose data was leaked online after they refused to pay the ransom.

See also: US charges three Iranians for cyberattacks on CNI

The Federal Bureau of Investigation (FBI) published some indicators of compromise and technical details related to Hive ransomware attacks in August 2021.

Like many other ransomware gangs that use double blackmail, the FBI said that Hive operators would also steal whatever files they deemed valuable before encryption to pressure their victim into paying the ransom under the threat of data leakage.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS