HomeSecurityHacking group Dunghill Leak takes responsibility for data breach...

Dunghill Leak hacking group takes responsibility for Sabre data breach

The giant travel booking company Sabre announced that it is investigating the allegations of a cyberattack, after the appearance of a large file on the leak site of the hacking group Dunghill Leak, which is claimed to have breached the company.

See also: Hackers stole Microsoft signing key from Windows crash dump

Dunghill Leak hacking group takes responsibility for Sabre data breach

See also: Malicious Google ads trick Mac users into installing Atomic Stealer malware

«Sabre is aware of the claims of a data breach by the threat group and we are currently investigating to determine their validity», said Saber spokesperson Heidi Castle in an email.

The hacking group Dunghill Leak claimed responsibility for the apparent cyberattack in a posting on its dark web leak site, claiming to have taken about 1.3 terabytes of data, including databases on ticket sales and passenger rotation, personal data and corporate financial information.

The group published a portion of the files they claim to have stolen, demanding that the entire “treasure” will become “available soon”.

Sabre is a travel reservation system and leading provider of airline and hotel reservation data, whose software and data are used to support airline and hotel reservations, check-ins, and applications. Many airlines and hotel chains in the United States rely on the company's technology.

Screenshots seen by TechCrunch reveal the existence of multiple database names related to booking and billing details, containing tens of millions of records, although it is not known whether the hackers had access to the databases.

Some of the images contained records related to employees, including their emails and work locations. One of the images contained the employees’ names, citizenship, passport numbers, and visa numbers. Several other images show various I-9 forms of employees authorized to work in the United States. Several passports found in the cache corresponded to Sabre employees, including a Sabre vice president, according to their LinkedIn.

It is not known when the alleged breach occurred, but the screenshots posted by the hacking team show data that appears to be from July 2022.

See also: Tesla: First on Mozilla's list of the most "creepy" industries

Little is known about Dunghill Leak, other than the fact that it is a relatively new ransomware and extortion group that originated or reshaped the Dark Angels ransomware, which originated from the Babuk ransomware, according to security researchers at Malwarebytes. To date, the Dunghill Leak hacking group has claimed responsibility for attacks on Incredible Technologies, a maker of coin-operated gaming machines, Sysco, a major food company, and Gentex, a manufacturer of automotive products.

Dunghill Leak hacking group takes responsibility for Sabre data breach

It is not uncommon for ransomware and extortion groups to avoid encrypting files altogether, focusing instead on threatening to release sensitive data if the ransom is not paid. The FBI and international law enforcement authorities have long encouraged victims of ransomware and extortion not to pay the ransom.

The last security incident reported by Sabre was in 2017, when hackers stole one million credit cards from its hotel reservation system. The company paid $2.4 million to resolve the lawsuits that had been filed by several states after the breach.

Information source: techcrunch.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS