The Hive ransomware gang has claimed responsibility for an attack that hit the systems of Bell Canada subsidiary Bell Technical Solutions (BTS).

See also: Uber hacked: Internal systems breached
BTS is an independent subsidiary with more than 4,500 employees, specializing in the installation of Bell services for residential and small business customers in the provinces of Ontario and Québec.
While the Canadian telecommunications company did not disclose when its network was breached or when the attack occurred, Hive claims in a new entry added to the data leak blog that it encrypted BTS's systems almost a month ago, on August 20, 2022 .
The BTS website, which is usually accessible at bellsolutionstech.ca, is currently inaccessible, however, Bell Canada posted a notice following the incident on its own website.
“We have been made aware that hackers have gained access to certain company and employee in a recent cybersecurity incident targeting Bell Technical Solutions,” Bell said.
See also: Webworm group modifies old malware and tests it in new attacks
“The unauthorized party had access to information that may include the name, address , and phone number of residential and small business customers in Ontario and Québec who booked a technician visit.”
“Bell Technical Solutions took immediate steps to secure the affected systems and we want to assure you that no databases containing customer information, such as credit and debit card, banking or other financial data.”

The Bell subsidiary warned customers about the possibility of being targeted in phishing attacks following this incident and advised them to monitor their accounts for any suspicious activity.
Hive is a Ransomware-as-a-Service (RaaS) operation that has been operating since June 2021 behind attacks against dozens of organizations, counting only those victims whose data was leaked online after they refused to pay the ransom.
See also: US charges three Iranians for cyberattacks on CNI
The Federal Bureau of Investigation (FBI) published some indicators of compromise and technical details related to Hive ransomware attacks in August 2021.
Like many other ransomware gangs that use double blackmail, the FBI said that Hive operators would also steal whatever files they deemed valuable before encryption to pressure their victim into paying the ransom under the threat of data leakage.
Information source: bleepingcomputer.com
