Добавить новость

Женщина 43 года провела в тюрьме, куда ее посадили для отмазки полицейского

В прокуратуре проверят данные о подорожании билетов на поезда из Черноморья

В Бурятии на буддийском форуме обучат методам борьбы со стрессом

Улицу в центре Воронежа перекроют до 20 августа

News in English


Новости сегодня

Новости от TheMoneytizer

Columbus ransomware attack: Rhysida announces public leak before changing course

Columbus ransomware attack: Rhysida announces public leak before changing course

View a previous report in the video player above.

COLUMBUS, Ohio (WCMH) - Hackers announced Wednesday morning they would publicly leak over six terabytes of compromised Columbus data, claiming to have passwords and other private information from city servers. But hours later, they changed their mind with a new deadline.

Two cybersecurity experts -- Ohio State assistant professor Carter Yagemann and CMIT Solutions owner Daniel Maldet -- both accessed the Rhysida ransomware group's site on the dark web and independently confirmed to NBC4 that an auction of stolen City of Columbus data ended at 5:35 a.m. The two sources both said Rhysida did not have an apparent buyer, and a screenshot of the site indicated the group was going to publicly leak all 6.5 terabytes of data they had taken from the city.

On a phone call after the leak announcement, a spokesperson for Mayor Andrew Ginther's office said the city was trying to "wrap their arms around" the situation. Without confirming Rhysida's involvement in the hack, the city said it was aware a link was posted to download leaked data, but claimed the link was broken when accessed. The city has repeatedly told NBC4 it is limited on what it can share, citing an active investigation involving the FBI and the U.S. Department of Homeland Security.

Yagemann shared more details on the city's claim, confirming the download link was broken around 10:30 a.m. Checking Rhysida's website, Yagemann and Maldet said the hacking group had restarted their auction, setting it to end around 3:30 a.m. Thursday. For this second sell-off, Rhysida had an identical requested starting bid of 30 bitcoin, which translated to around $1.7 million as of Wednesday.

The change of course is abnormal for Rhysida, who has historically leaked data whenever they did not secure a bidder. Polygon reported on a previous example in December, where the hackers publicly dumped 1.67 terabytes of Insomniac Games’ employee's personal information and projects.

Even before the auction, some city employees were already falling victim to compromised data. Brian Steel, president for the local branch of the Fraternal Order of Police, confirmed to NBC4 that at least 12 Columbus police officers had their bank accounts hacked. While the city did not confirm these were a direct connection to Rhysida's attack, it announced Thursday it would provide free credit monitoring services to employees with the City of Columbus and Franklin County Municipal Court.

Ginther has never named Rhysida or any other hacking group as the suspect in the ransomware attack, referring to the perpetrator only as "an established and sophisticated threat actor operating overseas." The mayor previously told NBC4 that the city's IT staff first detected a hack on July 18, explaining it was the reason for a shutdown of multiple online city services. While they were able to prevent Rhysida from encrypting infected systems, he admitted there was still a possibility data was stolen.

"For non-IT people, folks at home, the best way to describe this would be robbers were in our house,” Ginther said. “They tried to lock us out from our own house, but we stopped them. They took some valuables, data, and we’re in the process of determining the extent, and their value, data, before we notify their owners.”

Yagemann suggested next steps that city employees, or potentially residents with city utility accounts, should take.

"If the leak turns out to be legitimate, it is likely to contain sensitive information that includes passwords and banking information," Yagemann said. "Impacted residents should be on the lookout for unusual activity with their bank accounts and should change their passwords on any accounts that may share the same password."

Cybersecurity watchdogs including Dark Web Intelligence and Ransom Look previously reported Rhysida’s offering on an onion site, commonly used on the dark web and only accessible with the specialized internet browser Tor. A screenshot from when Rhysida first launched the auction showed they claimed a potential buyer would get:

  • Internal logins and passwords for city employees
  • City databases
  • A full dump of servers with emergency services applications for the city
  • Access to city video cameras
  • Full instructions and support, as well as certificates for the databases

Maldet told NBC4 that there could be some truth to Rhysida's claim of hostage data even if the city stopped the attempted encryption. He said they were using a common tactic among ransomware groups called "double extortion."

"They would have exfiltrated sensitive data before initiating the encryption process," Maldet said. "Although Mayor Ginther has stated that they were able to halt the encryption, Rhysida may have already exfiltrated a significant amount of data by that time ... Rhysida is known to exaggerate the volume of data they claim to have stolen, so their claim of 6.5 terabytes might be inflated or include data from other sources or systems."

In this file photo, a laptop displays a message after being infected by a ransomware as part of a worldwide cyberattack on June 27, 2017 in Geldrop. - (Photo by Rob Engelaar / ANP / AFP) / Netherlands OUT (Photo by ROB ENGELAAR/ANP/AFP via Getty Images)

A ransomware attack typically encrypts a computer's hard drive, or vital servers in a business environment, and the infection can spread to other computers from the original host. The data on the infected drives becomes locked and inaccessible to the user. Unless they pay a ransom to the hacker, they can either lose their data permanently, or have it leaked publicly. In a successful attack, hackers restore a victim's data in exchange for large payments in cryptocurrencies like Bitcoin. Ransomware has made for a profitable business venture for hackers, sometimes even earning the sponsorship of governments like North Korea.

Rhysida first emerged in May 2023, according to cybersecurity company SentinelOne. On its onion site, the group created a victim support chat portal where it negotiates with victims trying to retrieve encrypted data. SentinelOne noted the hackers typically deploy their ransomware through phishing campaigns, which is consistent with the "internet website download" of a .zip file that Ginther described as how the city initially fell victim. He didn’t specify whether a city employee initiated the download and subsequent breach, or which department it originated in.

Читайте на 123ru.net


Новости 24/7 DirectAdvert - доход для вашего сайта



Частные объявления в Вашем городе, в Вашем регионе и в России



Smi24.net — ежеминутные новости с ежедневным архивом. Только у нас — все главные новости дня без политической цензуры. "123 Новости" — абсолютно все точки зрения, трезвая аналитика, цивилизованные споры и обсуждения без взаимных обвинений и оскорблений. Помните, что не у всех точка зрения совпадает с Вашей. Уважайте мнение других, даже если Вы отстаиваете свой взгляд и свою позицию. Smi24.net — облегчённая версия старейшего обозревателя новостей 123ru.net. Мы не навязываем Вам своё видение, мы даём Вам срез событий дня без цензуры и без купюр. Новости, какие они есть —онлайн с поминутным архивом по всем городам и регионам России, Украины, Белоруссии и Абхазии. Smi24.net — живые новости в живом эфире! Быстрый поиск от Smi24.net — это не только возможность первым узнать, но и преимущество сообщить срочные новости мгновенно на любом языке мира и быть услышанным тут же. В любую минуту Вы можете добавить свою новость - здесь.




Новости от наших партнёров в Вашем городе

Ria.city

Женщина 43 года провела в тюрьме, куда ее посадили для отмазки полицейского

Ефимов: более 12 километров дорог построили в Москве с начала 2024 года

«Лето в Москве»: для горожан проведут тренировки на развитие координации

В Бурятии на буддийском форуме обучат методам борьбы со стрессом

Музыкальные новости

Уссурийский ЛРЗ Желдорреммаш осваивает ремонт колесной пары для новых серий локомотивов

Путин попросил Иран о сдержанном ответе Израилю на убийство Хании

Премьер-министр РФ Мишустин подписал постановление по эксплуатации беспилотных трамваев

Строительство высокоскоростной железнодорожной магистрали Москва – Санкт-Петербург включёно в перечень самоокупаемых проектов

Новости России

День рождения живописца Васнецова отметили в «Арт-гостиной» в Химках

Строительные итоги первого полугодия: грустный оптимизм

«Лето в Москве»: для горожан проведут тренировки на развитие координации

В Бурятии на буддийском форуме обучат методам борьбы со стрессом

Экология в России и мире

Как спорт влияет на сердце?

Турист искупался в Турции в море и погиб в муках после ампутации ноги в результате подхваченной плотоядной инфекции

Как спорт влияет на сердце?

Как записать бабушку в телефоне

Спорт в России и мире

ATP частично удовлетворила апелляцию Шаповалова. Его оштрафовали, но сохранили призовые и очки

Парижский прииск Новака Джоковича // Он выиграл золото на своей пятой Олимпиаде

Блинкова проиграла Стирнс на старте турнира WTA в Торонто

Я — сноб: теннисистка Надежда Петрова

Moscow.media

Мэр Екатеринбурга назвал причину приостановки работ на развязке у "Калины"

Системный Софт и международный разработчик решений для управления устройствами Scalefusion объявляют о партнерстве

DCLogic инициирует панельную дискуссию по вопросу перехода на российские ИТ-решения

Экс-гендиректор ЧЭМК останется под стражей до середины ноября











Топ новостей на этот час

Rss.plus






В прокуратуре проверят данные о подорожании билетов на поезда из Черноморья

«Лето в Москве»: для горожан проведут тренировки на развитие координации

Ефимов: более 12 километров дорог построили в Москве с начала 2024 года

В Бурятии на буддийском форуме обучат методам борьбы со стрессом