The Mexican government has been targeted by an alleged ransomware attack by the RansomHub, which claims to have compromised the federal website gob.mx.

The group announced the attack on its blog, claiming to have obtained 313 GB of data from the website's servers.
The hackers are demanding a ransom, threatening to release the stolen files, which include contracts, insurance, financial and confidential documents. They have already released sample files containing personal information of federal employees, such as names, job titles, photos, emails and phone numbers.
Read more: NoName ransomware: “Collaboration” with the RansomHub group?
In addition, they have published signed government documents, including contracts worth approximately $100,000.
The Palacio Nacional appears to be the work address of many affected employees. The gang has given a ten-day deadline for payment of the ransom before the data is released.
What is RansomHub?

See also: RansomHub introduces EDRKillShifter detection evasion tool
RansomHub is a relatively new presence in the ransomware ecosystem, with its first attack recorded on February 26, 2024. Its rapid rise has caught the attention of authorities, as evidenced by warnings from CISA and the FBI on August 30. RansomHub has been ranked as the third most prolific ransomware group for the first half of 2024, fueling speculation of connections to established players such as BlackCat.
As of September 2024, RansomHub is responsible for nearly a fifth of ransomware attacks, including companies such as Kawasaki Motors Europe and Planned Parenthood of Montana. CISA has identified at least 210 victims since February, a rate of nearly one per day. The victims range from organizations that are critical infrastructure to private companies such as Halliburton and pharmacy chain Rite Aid.
Read more: Is RansomHub behind the attack on Planned Parenthood?
RansomHub uses a ransomware-as-a-service (RaaS) model and double-blackmail tactics, gaining traction after the massive breach of UnitedHealth's Change Healthcare by the ALPHV/BlackCat group. RansomHub, an alleged affiliate of ALPHV/BlackCat, published files obtained from the Change Healthcare attack.
The group recruits affiliates via dark web forums, offering a fixed 10% fee and the ability to collect ransom payments directly from victims. This collaboration model is seen as a response to BlackCat, which caused problems with the distribution of ransoms between groups.

See also: RansomHub surpasses LockBit as the most prolific Ransomware group
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The report also shows that most of RansomHub's victims are in the United States. The group's structure resembles that of traditional Russian ransomware gangs, avoiding targets in Russia and other Kremlin-backed countries. Victims include Clevo, auction house Christie's, and Internet provider Frontier.
Source: cybernews
