Ransomware Group Threatens Auction of Madonna's Legal Data

gepubliceerd op by Cointele | gepubliceerd op

The ransomware gang REvil has launched an auction feature on the dark web in the past 24 hours, starting with the stolen data from a Canadian company and threatening to auction off information hacked from famous singer Madonna next.

Cointelegraph accessed information from the first auction campaign conducted by REVil, who detailed that the Agromart Group is the "First batch" of data to be put up for auction, which is the data stolen after a ransomware attack.

Madonna's data auction threatAt the bottom of the list, the ransomware gang warned Madonna and "Other people" that they could be the next victims of future auction listings in their campaign.

The reference to Madonna is related to her latest ransomware attack on a high-profile New York entertainment law firm - first reported by Cointelegraph - which represents the private legal affairs of dozens of the world's biggest music stars and world cinema, including Lady Gaga, Elton John and Robert DeNiro.

Ransomware gangs are getting sophisticated with their attacksSpeaking with Cointelegraph, Brett Callow, threat analyst at malware lab Remsisoft, and one of the first experts to unveil the new move by the ransomware gang, said that companies in this situation have no good option available to them.

"The tactics used by ransomware groups are becoming ever more extreme, and this was a logical progression. It enables the criminals to monetize stolen data while also serving as a warning to other companies regarding the consequences of non-compliance."

Callow believes that although ransomware groups have sold and traded data in the past, this is the first time that hacked information is being auctioned under a somewhat formalized process.

Recent REVil's ransomware attacksThe REvil gang has starred in a few attacks recently, aside from the law firm.

Cointelegraph reported on December 5 about a ransomware attack perpetrated against Texas-based data center provider CyrusOne.

On May 22, a report from the UK-based cybersecurity firm Sophos released reports of a new method of human-operated ransomware attack launched by groups like REvil.

x