The Hive ransomware group claims responsibility for the cyberattack that Tata Power disclosed earlier this month.
Tata Power, a subsidiary of the multinational conglomerate Tata Group, is India's largest integrated power company headquartered in Mumbai.
Based on screenshots seen by BleepingComputer, it was determined that the data stolen by Hive operators was from Tata Power. These images also show that the ransom negotiations failed.
See also: Apple fixes new zero-day vulnerability in iPhones and iPads

A few hours ago, the Hive ransomware group began leaking data it claims to have stolen from Tata Power.
The development was reported on Twitter by cybersecurity analyst and researcher Dominic Alvieri.

Another researcher, Rakesh Krishnan, shared a screenshot of the stolen data – which appears to include personally identifiable information (PII) of Tata Power employees, National ID (Aadhar) card numbers, PAN (tax account number) numbers, salary information and more.
See also: There are malicious extensions in Chrome with 1 million installations
According to Krishnan, the data dump also includes engineering drawings, financial and banking records, and customer information.
On October 3, the operators of the Hive ransomware claimed to have encrypted Tata Power's data.
On Friday, October 14, Tata Power announced that it had fallen victim to a cyberattack that affected some of its IT systems.
If a target does not meet ransom or extortion demands, these groups will begin leaking or selling the data they stole during the initial breach.
See also: Black Reward: We stole thousands of emails from the Iranian Atomic Energy Organization
The Hive ransomware group is more active and aggressive than its leak site indicates, showing collaborators attacking an average of three companies every day since the operation became known in late June 2021.
As the FBI has stated in the past, this group uses many different types of tactics, making it extremely difficult for organizations to protect themselves from its attacks.
How to protect yourself?
There are several measures you can take to protect your business from Hive ransomware and other types of malware:
1) Educate your employees about phishing emails and how to spot them. Phishing emails are one of the most common methods attackers use to spread malware.
2) Use strong antivirus software and keep it up to date. Antivirus software can detect and remove many types of malware, including ransomware; however, it must be kept up to date to be effective against new threats like Hive.
3) Back up your data regularly. Make sure to store backups offline so they can’t be encrypted by hackers.
4) Keep your software up to date. Vulnerable software often contains security vulnerabilities that can be exploited by attackers.
5) Implement least privilege access controls. Least-privileged access controls limit users' ability to install applications and make changes to system settings.
Information source: bleepingcomputer.com
