HomeSecurityPSI Software confirms ransomware attack

PSI Software confirms ransomware attack

PSI Software SE, a German provider of software for complex production and logistics, has confirmed that the security incident it announced last week was a ransomware attack that affected its internal infrastructure.

See also: Rock County investigates ransomware attack

PSI Software ransomware

The company operates internationally with a staff of over 2,000 people and specializes in software solutions for large energy suppliers. It also provides system control solutions for operations management, network utilization, pipeline management, leak detection and detection, portfolio management, energy trading and energy sales.

On February 15, PSI Software announced that a cyberattack forced it to disconnect several IT systems, including email, as a measure to reduce the risk of data loss.

In an update yesterday, PSI Software confirmed that the disruption was caused by a ransomware attack targeting its systems. The company has not yet identified the group that attacked it.

PSI says the investigation has so far uncovered no evidence to suggest the attacker had access to customer systems. Authorities were notified of the incident and experts from the Federal Office of Security Intelligence have been assisting PSI's response and response efforts since February 16.

See also: Orbcomm faces ransomware attack

PSI Software confirms ransomware attack

Although PSI Software has not shared specific details about the ransomware group responsible for the attack, the Hunters International ransomware hacker group claims the leak.

The threat actors posted the PSI Software on their Dark Web on February 17, two days after the attack. The hackers claim to have stolen 36,133 files from PSI’s systems, totaling 88 GB in size. No data samples have been released yet, so the validity of the claim has not been confirmed.

PSI Software is not the only one to fall victim to the ransomware group. Hunters International is a ransomware-as-a-service that emerged in October 2023, likely as a rebranding of Hive. Since then, the malicious actors have posted several victims on the extortion portal, including Austral USA and the Fred Hutchinson Cancer Center. In the case of the Fred Hutch cancer research center, the hackers showed low moral standards and even threatened patients personally.

See also: Toyota: We were not attacked by ransomware
What are the different forms of Ransomware as a Service?

Ransomware as a Service (RaaS) is a form of attack offered as a service in cyberspace. There are different forms of RaaS, depending on the complexity, flexibility and effectiveness of the attack. The simplest form of RaaS is the trojan, where the attacker provides a virus that can be installed on a computer via a seemingly harmless piece of software or link. Another form is the loader, where the attacker provides software that can install multiple viruses on a computer, increasing the likelihood of the attack being successful. 'Cryptographic RaaS' is a more complex form, where the attacker uses advanced encryption techniques to lock the victim's data, demanding a ransom for its decryption. Finally, 'Internet RaaS' is a form where the attacker uses the internet to carry out the attack, using techniques such as phishing and spear phishing to mislead the victim and convince them to do something that will allow the virus to be installed.

Source: bleepingcomputer

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS