HomeSecurityIllinois government agencies attacked by ransomware group CL0P

Illinois government agencies attacked by ransomware group CL0P

According to the Illinois Department of Innovation and Technology, hackers from the ransomware group CL0P had access to systems used by Illinois government agencies for a few hours on May 31. The department said on Friday that it is not yet clear which information was accessed or affected, but they expect it will impact a “large number” of people.

CL0P ransomware

Federal authorities attributed the attack to the CL0P ransomware gang, which last month attacked many large companies worldwide. CL0P hackers gained access to the MOVEit software, entering the Illinois network for about three hours, authorities said.

Sanjay Gupta, Chief Information Officer of Illinois, said that the state's security teams have verified that “the vulnerability can no longer be exploited in the system”.

The officials have not provided information regarding which data could be vulnerable or whether a ransom was demanded for the information that was put at risk, as the gang has done in the past.

Recently, the BBC, British Airways, and Boots informed hundreds of thousands of employees that payroll data may have been taken during the same attack on the MOVEit systems used by their payroll provider.

The CL0P ransomware is considered “one of the largest phishing and malspam distributors worldwide” by the Federal Cybersecurity and Infrastructure Security Agency after being accused of breaching more than 8,000 organizations worldwide since 2019.

The latest attack on MOVEit systems was launched in May, according to the Cybersecurity and Infrastructure Security Agency. It was first reported to the company on May 28, according to a MOVEit spokesperson.

A separate attack was carried out by the ransomware group in January, using phishing scams and threats to release information. The ransom notes were sent to “senior executives” of the companies affected by the scam, with the emails claiming to have stolen “important information” from more than 100 victims, federal officials said.

“If you ignore us, we will sell your information on the dark web and publish it on our blog”, the ransom note threatened.

Source of information: chicago.suntimes.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS