HomeSecurityYellow Pages Canada confirms cyberattack as BlackBasta leaks...

Yellow Pages Canada confirms cyberattack as BlackBasta leaks its data

Yellow Pages Canada confirms the cyberattack as BlackBasta leaks its data.

Yellow Pages Group, a Canadian directory publisher, confirmed that it has been hit by a cyberattack.

The Black Basta ransomware gang and extortionists took responsibility for the attack and published sensitive documents and data over the weekend.

The Yellow Pages Group, founded in 1908, now owns and manages the websites YP.ca and YellowPages.ca, as well as the online service Canada411.

See also: NCR ransomware attack disrupts many POS systems

Yellow Pages

The threat actors stole customer and employee data.

Of course, directory services like Yellow Pages collect and provide largely public data - however, that doesn't mean they don't have personal or private corporate data.

Last week, threat intelligence analyst Dominic Alvieri spotted the Black Basta Ransomware gang sharing information about the Yellow Pages group on the data leak.

BleepingComputer analyzed Black Basta's online post and can confirm that the ransomware group leaked a sample of sensitive documents, exposing personal information, including, but not limited to, the following:

  • Identity documents (such as scans of passports and driver's licenses) that reveal date of birth and address
  • Tax documents—exposing the Social Insurance Number (SIN)
  • Purchase agreements
  • Spreadsheet ‘Accounts Receivable’ dated February 28, 2023
  • Budget and debt forecast dated December 2022

“Yellow Pages recently fell victim to a cyberattack,” Franco Sciannamblo, Senior Vice President and Chief Financial Officer of YP, confirmed in a statement to BleepingComputer.

“As soon as we were informed of the attack, we immediately launched a thorough investigation into the matter, with the assistance of external cybersecurity experts , to contain the incident and ensure that our systems were secured.”

“Based on our investigation to date, we have reason to believe that an unauthorized third party stole certain personal information from servers containing YP employee data and limited data relating to our business customers.”

“ We have notified the individuals affected and reported this incident to all appropriate privacy regulators . Essentially all of our services have now been restored.

Based on the dates present in the few documents that leaked and were seen by BleepingComputer – especially the most recent ones – it appears that the cyberattack occurred on March 15, 2023 or later.

See also: Bumblebee malware: Distributed via Google Ads and used for ransomware attacks

BlackBasta

Earlier this month, the Black Basta group claimed responsibility for a cyberattack on Capita, a UK-based professional outsourcing services provider. The extortion group threatened to sell the stolen data to interested buyers unless Capita paid the ransom.

Last year, Black Basta breached the Canadian grocery retail giant Sobeys, causing IT problems and POS malfunction.

See also: Hackers breach networks using data on corporate routers

The ransomware group has been quick to act over the past year, sometimes posting multiple high-profile victims at once on data breach portal . Cybersecurity analysts have theorized that Black Basta is a rebranding of the Conti ransomware based on negotiation tactics .

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS