The AlphaLocker ransomware operation, also known as BlackCat, has released screenshots of internal emails and video conferences stolen from Western Digital, suggesting they likely maintained continued access to the company's systems despite the company's response to the breach.
The leak came after the threat actor warned Western Digital on April 17 that it would hit it until it “couldn’t take it anymore” if a ransom was not paid.
See also: Ransomware attack affects Spartanburg County services

March cyberattack
On March 26, Western Digital suffered a cyberattack in which threat actors breached its internal network and stole corporate data - however, no ransomware was deployed and files were not encrypted.
In response, the company shut down its cloud services, including My Cloud, My Cloud Home, My Cloud Home Duo, My Cloud OS 5, SanDisk ibi, and SanDisk Ixpand Wireless Charger, along with their connected mobile, desktop, and web apps, for two weeks.
TechCrunch first reported that an anonymous group of hackers breached Western Digital, claiming to have stolen ten terabytes of data.
The threat actor reportedly shared samples of the stolen data with TechCrunch, which included files signed with stolen Western Digital code signing keys, unlisted corporate phone numbers, and screenshots of other internal data.
The hackers also claimed to have stolen data from the company's SAP Back-office application.
While the attacker claimed not to be affiliated with the ALPHV ransomware operation, a message soon appeared on the gang's data leak website warning that Western Digital's data would be leaked if the ransom was not negotiated.
See also: T-Mobile: New data breach affects many customers
Alphv mocks Western Digital
In a further attempt to mock and embarrass Western Digital, security researcher Dominic Alvieri told BleepingComputer that the hackers published twenty-nine screenshots of emails, documents, and video conferences related to the company's response to the attack.
When a company discovers it has been breached, one of the first countermeasures is to find out how the threat actor gained access to the network and block that route.
However, sometimes there is a gap between detection and response, allowing an adversary to continue to have access even after an attack is detected. This access allows them to monitor the company's response as well as steal more data.
From the screenshots leaked by ALPHV, the threat actors imply that they had ongoing access to some of Western Digital's systems, as the screenshots show video conferences and emails related to the attack.
Included with the leaked data is another message from the perpetrators, claiming to have personal customer information and a full backup of WD's SAP Backoffice application.
See also: New LOBSHOT malware gives hackers covert VNC access to Windows devices
While the data appears to belong to Western Digital, BleepingComputer was unable to independently verify its source or whether it was stolen during the attack.
At present, Western Digital is not negotiating a ransom to prevent the leak of stolen data, which has prompted further threats from hackers.
Western Digital declined to comment on the leaked screenshots and the alleged threats.
Information source: bleepingcomputer.com
