Ransomware attack hits over 200 US companies, forces Swedish grocery chain to close
July 5, 2021, 22:00:01 CEST | Wikinews

July 5, 2021, 22:00:01 CEST | Wikinews

Monday, July 5, 2021 
Internet
Related stories
Ransomware attack hits over 200 US companies, forces Swedish grocery chain to close
"Avast ye scurvy file sharers!": Interview with Swedish Pirate Party leader Rickard Falkvinge
European Court of Justice says Facebook must remove 'illegal' posts globally
Millions don't turn up to 'storm' US airbase for extraterrestrial evidence
540 million private Facebook records found on public Internet
More information at Wikipedia:
Internet portal
Internet
History of the Internet
Internet censorship
Internet Protocol
World Wide Web
On Friday, a ransomware attack which initially targeted software company Kaseya spread to over 200 companies in the US through Kaseya's network management software. Huntress Labs, a cybersecurity company, alleged the attack was carried out by REvil, a Russia-based ransomware group. Kaseya told its customers to stop using its services when it learned of the attack.
According to NBC News, the ransomware first spread to about 40 of Kaseya's customers, which are mainly companies that manage Internet services for their customers, some of which manage them for thousands of companies. John Hammond, a security researcher at Huntress Labs, said that "It's reasonable to think this could potentially be impacting thousands of small businesses". Kaseya notified its customers of the attack on Friday afternoon and warned them to stop using its services immediately.
Business Insider reported REvil is a Russian-based organization which provides ransomware-as-a-service. BleepingComputer reported receiving a sample of the ransomware used in REvil's attacks and says that they demand USD five million for the ransomed files to be decrypted, though it is unknown if every victim received a demand for that same amount. Fabian Wosar, Chief Technical Offier (CTO) at the Emsisoft security firm, said affected customers had received demands for USD 44,999.
Swedish grocery chain Coop was also affected by the attack, and had to close all 800 of its stores because its checkout tills could not process payments due to the ransomware. Speaking to Swedish Television, Therese Knapp, a Coop spokesperson, said "We have been troubleshooting and restoring all night, but have communicated that we will need to keep the stores closed today". Swedish company Visma Esscom, which manages servers for businesses, was using Kaseya software, according to Reuters. Railway services in Sweden were also disrupted.
On Saturday, US President Joe Biden directed intelligence agencies to investigate who was behind the attack. He said that "we're not certain" who is behind the attack, adding "[t]he initial thinking was it was not the Russian government but we're not sure yet". The US Cybersecurity and Infrastructure Security Agency stated that it is "taking action to understand and address the recent supply-chain ransomware attack".
Have an opinion on this story? Share it!
Sources[edit]
Matthew Fox. "REvil ransomware group strikes again with attack on hundreds of companies right before long holiday weekend" — Business Insider, July 3, 2021
Robert McMillan. "200 businesses hit by ransomware after breach at Florida IT firm" — Channel News Asia, July 3, 2021
"Cyber attack against U.S. IT provider forces Swedish chain to close 800 stores" — Reuters, July 3, 2021
Trevor Junnicutt. "Biden orders probe of latest ransomware attack" — Reuters, July 3, 2021
Kevin Collier. "Ransomware attack on software manager hits 200 companies" — NBC News, July 2, 2021
Lawrence Abrams. "REvil ransomware hits 200 companies in MSP supply-chain attack" — Bleeping Computer, July 2, 2021
External links[edit]
"Updates Regarding VSA Security Incident" — Kaseya, July 3, 2021
Share this: 
Source: Wikinews
Internet
Related stories
Ransomware attack hits over 200 US companies, forces Swedish grocery chain to close
"Avast ye scurvy file sharers!": Interview with Swedish Pirate Party leader Rickard Falkvinge
European Court of Justice says Facebook must remove 'illegal' posts globally
Millions don't turn up to 'storm' US airbase for extraterrestrial evidence
540 million private Facebook records found on public Internet
More information at Wikipedia:
Internet portal
Internet
History of the Internet
Internet censorship
Internet Protocol
World Wide Web
On Friday, a ransomware attack which initially targeted software company Kaseya spread to over 200 companies in the US through Kaseya's network management software. Huntress Labs, a cybersecurity company, alleged the attack was carried out by REvil, a Russia-based ransomware group. Kaseya told its customers to stop using its services when it learned of the attack.
According to NBC News, the ransomware first spread to about 40 of Kaseya's customers, which are mainly companies that manage Internet services for their customers, some of which manage them for thousands of companies. John Hammond, a security researcher at Huntress Labs, said that "It's reasonable to think this could potentially be impacting thousands of small businesses". Kaseya notified its customers of the attack on Friday afternoon and warned them to stop using its services immediately.
Business Insider reported REvil is a Russian-based organization which provides ransomware-as-a-service. BleepingComputer reported receiving a sample of the ransomware used in REvil's attacks and says that they demand USD five million for the ransomed files to be decrypted, though it is unknown if every victim received a demand for that same amount. Fabian Wosar, Chief Technical Offier (CTO) at the Emsisoft security firm, said affected customers had received demands for USD 44,999.
Swedish grocery chain Coop was also affected by the attack, and had to close all 800 of its stores because its checkout tills could not process payments due to the ransomware. Speaking to Swedish Television, Therese Knapp, a Coop spokesperson, said "We have been troubleshooting and restoring all night, but have communicated that we will need to keep the stores closed today". Swedish company Visma Esscom, which manages servers for businesses, was using Kaseya software, according to Reuters. Railway services in Sweden were also disrupted.
On Saturday, US President Joe Biden directed intelligence agencies to investigate who was behind the attack. He said that "we're not certain" who is behind the attack, adding "[t]he initial thinking was it was not the Russian government but we're not sure yet". The US Cybersecurity and Infrastructure Security Agency stated that it is "taking action to understand and address the recent supply-chain ransomware attack".
Have an opinion on this story? Share it!
Sources[edit]
Matthew Fox. "REvil ransomware group strikes again with attack on hundreds of companies right before long holiday weekend" — Business Insider, July 3, 2021
Robert McMillan. "200 businesses hit by ransomware after breach at Florida IT firm" — Channel News Asia, July 3, 2021
"Cyber attack against U.S. IT provider forces Swedish chain to close 800 stores" — Reuters, July 3, 2021
Trevor Junnicutt. "Biden orders probe of latest ransomware attack" — Reuters, July 3, 2021
Kevin Collier. "Ransomware attack on software manager hits 200 companies" — NBC News, July 2, 2021
Lawrence Abrams. "REvil ransomware hits 200 companies in MSP supply-chain attack" — Bleeping Computer, July 2, 2021
External links[edit]
"Updates Regarding VSA Security Incident" — Kaseya, July 3, 2021
Share this: 
Source: Wikinews
Tags: Wikipedia Portal:Internet internet History of the Internet Internet censorship Internet Protocol World Wide Web ransomware Kaseya cybersecurity REvil Business Insider Coop Cybersecurity and Infrastructure Security Agency Channel News Asia Bleeping Computer
Articles that may interest you:

Grand jury indicts former White House advisor...
United States Politics Related stories Grand jury indicts former White House advisor Stev...
SpaceX Crew Dragon capsule docks with Interna...
Space Related articles 5 March 2019: SpaceX Crew Dragon capsule docks with International ...
Facebook's longest outage
Today, Facebook has suffered the longest outage in history, with many countries around the ...Most popular
Recently Viewed:

Ransomware attack hits over 200 US companies, forces...
Monday, July 5, 2021 Internet Related stories Ransomware attack hits over 200 US compani...

NASA's helicopter Ingenuity survives its first night...
Space Related articles 7 April 2021: NASA's helicopter Ingenuity survives its first night ...

Rust movie set accident leaves one person dead
Saturday, October 23, 2021 Film Related articles Rust movie set accident leaves one pe...

South Australia enters week-long lockdown to contain...
Friday, July 23, 2021 Australia Related articles 23 July 2021: South Australia enters we...

Indonesian Navy declares crew of 53 dead after subma...
Tuesday, April 27, 2021 Indonesia Related articles 27 April 2021: Indonesian Navy declar...