HomeSecurityBlackCat ransomware: Gang sues victim who failed to disclose breach

BlackCat ransomware: Gang sues victim who failed to disclose breach

The ALPHV/BlackCat ransomware gang is taking extortion to the next level, after filing a complaint with the U.S. Securities and Exchange Commission (SEC) against one of its alleged victims for failing to disclose the cyberattack within four days. Yesterday, the gang added software company MeridianLink to its data leak site with the threat of leaking stolen data if a ransom is not paid within 24 hours.

BlackCat ransomware US Securities and Exchange Commission (SEC)

MeridianLink offers digital solutions for financial institutions such as banks, credit unions and loan companies.

Hackers turn to the SEC

According to DataBreaches.net, the ALPHV ransomware gang said it breached network on November 7 and stole data without encrypting the company's systems.

See also: Henry Schein: Was it attacked by BlackCat ransomware?

The hackers said that MeridianLink appears to have been contacted, but a payment has not yet been negotiated.

The alleged lack of response from the company likely prompted the hackers to pile on the pressure, filing a complaint with the U.S. Securities and Exchange Commission (SEC). The complaint alleges that MeridianLink failed to disclose the breach, which affected “customer data and business information”.

To prove the validity of the complaint, the hackers posted on their website a screenshot of the form they filled out on the Tips, Complaints, and Referrals SEC's

The ALPHV/BlackCat ransomware gang told the SEC that MeridianLink suffered a “material breach” and failed to disclose it as required in its Form 8-K, item 1.05.

Increased cyberattacks

Following the steady increase in cyberattacks on US organizations, the SEC adopted new rules requiring publicly traded companies to report security incidents with a significant impact (i.e. when they affect investment decisions).

Cybersecurity incident reporting must occur “incident is determined cybersecurity to be significant,” the new rule states.

However, the SEC's new cybersecurity rules are set to take effect on December 15, 2023.

BlackCat also showed the response it received from the Securities and Exchange Commission to the complaint against MeridianLink, to show that the submission was received.

See also: Seiko: BlackCat ransomware attack led to data breach

MeridianLink
BlackCat ransomware: Gang sues victim who failed to disclose breach

According to BleepingComputer, MeridianLink said that after detecting the incident, it immediately acted to mitigate the threat and hired experts to launch an investigation.

The company is still working to determine if any customer personal information was exposed. If it determines this is the case, it will notify individuals immediately.

“Based on our investigation to date, we have not identified any evidence of unauthorized access to our production platforms and the incident has caused minimal disruption to operations,” MeridianLink said.

Interestingly, a ransomware group has resorted to the SEC to further pressure its victim. So far, we have seen hackers leak data or even contact the victims’ customers and report the breach. What the BlackCat ransomware gang has done now shows that hackers are ruthless and will do anything they can to get money.

So, once again, we see that ransomware attacks are a serious threat. To prevent such attacks, certain security. One of the most important measures is to regularly update software and operating systems. Security updates provided by software manufacturers usually include fixes for known security issues and it is important to apply them promptly.

User education and awareness are also crucial. Users should be aware of security practices and avoid opening unsolicited emails or clicking on suspicious links . Also, using strong passwords and renewing them regularly is important to protect personal data.

See also: BlackCat: Uses the 'Munchkin' virtual machine for stealth attacks

Additionally, implementing a layered security approach is important. This means using multiple layers of security, such as advanced prevention and detection systems, rights-based access systems for each user, and data encryption. Regular data backups are also important for recovering data in the event of a breach.

Finally, partnering with specialized security companies can help detect and respond to ransomware attacks and data breaches. These companies can provide specialized security solutions and monitor system security to detect and respond to attacks.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS