Claro Company, the largest telecommunications company in Central and South America, was recently affected by a attack ransomware. Service outages were reported in several regions as a result of the attack. The ransom note indicates that the attackers were the hackers behind the Trigona ransomware.

Since January 25, Claro Telecom customers have been experiencing significant problems network. But it was not until February 2 that the company explained the cause, through its subsidiary Claro Nicaragua. However, the issues were also reported in other Latin American countries, such as El Salvador, Costa Rica, Guatemala and Honduras.
See also: K-12 schools remain vulnerable to ransomware attacks
As the note explains, the company suffered a ransomware attack that caused damage to some of its network components. The company hopes to restore the affected systems as soon as possible. Among the typical issues that have not yet been fully resolved are problems with Internet connectivity, video calls, and payment processing.
As mentioned above, the ransom note indicates that the attack on Claro was carried out by the Trigona ransomware. The group most likely managed to break into the company's system and infiltrate the files. And while file encryption may not be such a big problem, as they can be recovered via backups, data theft is extremely dangerous, considering the importance of user stored on telecom providers' servers.
Trigona ransomware
The hackers behind the Trigona ransomware began their activity in October 2022. Malware analysts call this group the successor to the CryLock ransomware and point to its possible association with the ransomware ALPHV/BlackCat.
See also: Ransomware attacks are increasing despite “crackdowns” by authorities
Like other ransomware gangs, Trigona uses the practice of double extortion. In addition to encrypting files, the hackers steal data and threaten to leak it if they don't receive the ransom they demand.
In October 2023, Trigona was hacked by the Ukrainian Cyber Alliance (UCA). UCA managed to wipe out the entire server infrastructure, including backups. White hat hackers, members of UCA, reportedly managed to obtain the group’s tools, so there is a possibility that a decryption tool could be released in the future. However, this hack did not stop the crooks from continuing their attacks.

What are the consequences of ransomware attacks on telecommunications companies?
Ransomware attacks can cause significant disruption to telecommunications services, as the systems that support their operation can be paralyzed or disabled.
See also: Interpol: Identified 1300 IP addresses related to phishing and ransomware attacks
This can lead to a loss of trust from customers, as service interruptions and data loss can have serious consequences for their personal and professional lives.
Additionally, ransomware attacks can cause significant financial losses, as telecommunications companies may be forced to pay ransoms to restore their systems.
Finally, these attacks can have long-term consequences for the company's competitiveness, as data loss and service interruption can cause permanent damage to the company's image and credibility.
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: gridinsoft.com
