HomeSecurityClaro: Telecommunications company "hit" by Trigona ransomware

Claro: Telecommunications company hit by Trigona ransomware

Claro Company, the largest telecommunications company in Central and South America, was recently affected by a attack ransomware. Service outages were reported in several regions as a result of the attack. The ransom note indicates that the attackers were the hackers behind the Trigona ransomware.

Claro telecommunications

Since January 25, Claro Telecom customers have been experiencing significant problems network. But it was not until February 2 that the company explained the cause, through its subsidiary Claro Nicaragua. However, the issues were also reported in other Latin American countries, such as El Salvador, Costa Rica, Guatemala and Honduras.

See also: K-12 schools remain vulnerable to ransomware attacks

As the note explains, the company suffered a ransomware attack that caused damage to some of its network components. The company hopes to restore the affected systems as soon as possible. Among the typical issues that have not yet been fully resolved are problems with Internet connectivity, video calls, and payment processing.

As mentioned above, the ransom note indicates that the attack on Claro was carried out by the Trigona ransomware. The group most likely managed to break into the company's system and infiltrate the files. And while file encryption may not be such a big problem, as they can be recovered via backups, data theft is extremely dangerous, considering the importance of user stored on telecom providers' servers.

Trigona ransomware

The hackers behind the Trigona ransomware began their activity in October 2022. Malware analysts call this group the successor to the CryLock ransomware and point to its possible association with the ransomware ALPHV/BlackCat.

See also: Ransomware attacks are increasing despite “crackdowns” by authorities

Like other ransomware gangs, Trigona uses the practice of double extortion. In addition to encrypting files, the hackers steal data and threaten to leak it if they don't receive the ransom they demand.

In October 2023, Trigona was hacked by the Ukrainian Cyber ​​Alliance (UCA). UCA managed to wipe out the entire server infrastructure, including backups. White hat hackers, members of UCA, reportedly managed to obtain the group’s tools, so there is a possibility that a decryption tool could be released in the future. However, this hack did not stop the crooks from continuing their attacks.

Trigona ransomware
Claro: Telecommunications company hit by Trigona ransomware

What are the consequences of ransomware attacks on telecommunications companies?

Ransomware attacks can cause significant disruption to telecommunications services, as the systems that support their operation can be paralyzed or disabled.

See also: Interpol: Identified 1300 IP addresses related to phishing and ransomware attacks

This can lead to a loss of trust from customers, as service interruptions and data loss can have serious consequences for their personal and professional lives.

Additionally, ransomware attacks can cause significant financial losses, as telecommunications companies may be forced to pay ransoms to restore their systems.

Finally, these attacks can have long-term consequences for the company's competitiveness, as data loss and service interruption can cause permanent damage to the company's image and credibility.

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: gridinsoft.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS