IT and business consulting firm HTC Global Serviceshas been hit by a ransomware attack by the ALPHV/BlackCat gang. The hackers have begun leaking screenshots of stolen company data.

HTC Global Services offers services to various organizations in the healthcare, automotive, manufacturing and financial industries.
The company confirmed the cyberattack via a post on X, without providing many details.
“ HTC has experienced a cybersecurity incident ,” reads the tweet posted on HTC’s X account . “ Our team is actively investigating and addressing the situation to ensure the security and integrity of user data. We have deployed cybersecurity experts and are working to resolve this. Your trust is our priority .”
See also: Protecting higher education from cyberattacks
This announcement came shortly after HTC Global Services was placed on the data leak site of the ALPHV (BlackCat) ransomware gang.
Screenshots of the stolen data show passports, contact lists, emails and confidential documents, which according to the hackers, have been stolen from HTC.
No details about the attack, but cybersecurity expert Kevin Beaumont believes the company was breached using the Citrix Bleed. According to Beaumont, one of HTC's business units, CareTech, was operating a vulnerable Citrix Netscaler, and the breach likely started there.
ALPHV/BlackCat ransomware: Frequent attacks
The ALPHV/BlackCat ransomware operation began in November 2021 and is believed to be a rebrand of the DarkSide and BlackMatter.
As DarkSide, the group gained international attention after the Colonial Pipeline, leading to intense pressure from law enforcement agencies worldwide.
See also: Capital Health: IT systems in hospitals outages due to cyberattack
After renaming themselves BlackMatter in July 2021, their activities suddenly ceased in November when authorities seized their servers and security firm Emsisoft created a decryptor for the ransomware.

This is how we are believed to have arrived at ALPHV/BlackCat ransomware. This ransomware operation targets organizations all over the world and hackers are constantly improving their techniques.
Protection against ransomware and subsequent data leakage
One of the first steps in preventing a ransomware attack is to educate and inform users. Users should be aware of the latest threats and characteristics of ransomware attacks, as well as the basic principles of cybersecurity.
Another important step is to apply software updates. Software companies often release updates that contain fixes for known security bugs. Updating software on all devices and applying the updates can reduce the risk of a ransomware attack.
See also: Staples: Cyberattack caused temporary disruption to online orders
Additionally, implementing effective security policies is crucial to preventing a ransomware attack. These policies should include using strong passwords ,limiting access to sensitive data , and performing regular backups. Finally, using reliable security is essential to preventing a ransomware attack. Security software can detect and block malware before it can cause damage. Additionally, regularly scanning devices for potential threats is important to prevent ransomware attacks.
Source: www.bleepingcomputer.com
