WASHINGTON: Hackers suspected to be behind a mass extortion attack that affected hundreds of companies worldwide late on Sunday demanded $70 million to restore the data they are holding ransom, according to a posting on a dark web site.
The demand was posted on a blog typically used by the REvil cybercrime gang, a Russia-linked group that is counted among the cybercriminal world's most prolific extortionists.
The gang has an affiliate structure, occasionally making it difficult to determine who speaks on the hackers' behalf, but Allan Liska of cybersecurity firm Recorded Future said the message "almost certainly" came from REvil's core leadership.
The group has not responded to an attempt by Reuters to reach it for comment.
REvil's ransomware attack, which the group executed on Friday, was among the most dramatic in a series of increasingly attention-grabbing hacks.
The gang broke into Kaseya, a Miami-based information technology firm, and used their access to breach some of its clients' clients, setting off a chain reaction that quickly paralyzed the computers of hundreds of firms worldwide.
An executive at Kaseya said the company was aware of the ransom demand but did not immediately return further messages seeking comment.
About a dozen different countries were affected, according to research published by cybersecurity firm ESET.
In at least one case, the disruption spilled out into the public domain when Swedish Coop grocery store chain had to close hundreds of stores on Saturday because its cash registers had been knocked offline as a consequence of the attack..
Earlier on Sunday, the White House said it was reaching out to victims of the outbreak "to provide assistance based upon an assessment of national risk."
The impact of the intrusion is still coming into focus.
Those hit included schools, small public-sector bodies, travel and leisure organizations, credit unions and accountants, said Ross McKerchar, chief information security officer at Sophos Group Plc.
McKerchar's company was one of several that had blamed REvil for the attack, but Sunday's statement was the group's first public acknowledgement that it was behind the campaign.
Ransom-seeking hackers have tended to favor more focused shakedowns against single, high-value targets like Brazilian meatpacker JBS, whose production was disrupted last month when REvil attacked its systems. JBS said it ended up paying https://jbsfoodsgroup.com/articles/jbs-usa-cyberattack-media-statement-june-9 the hackers $11 million.
Liska said he believed the hackers had bitten off more than they could chew by scrambling the data of hundreds of companies at a time and that the $70 million demand was an effort to make the best of an awkward situation.
"For all of their big talk on their blog, I think this got way out of hand," he said.
Reuters
Mon Jul 05 2021
The demand was posted on a blog typically used by the REvil cybercrime gang, a Russia-linked group that is counted among the cybercriminal world's most prolific extortionists. REUTERSpic
Denmark stands firm on Greenland after Rubio says Trump's interest is no joke
Trump vows to make Denmark's autonomous territory part of the US, not ruling out military or economic pressure to acquire it.
On-site investigation of burned-out Air Busan plane to begin
Passengers evacuated from the Air Busan plane will get their baggage back after authorities deemed the jet safe for a full investigation.
Myanmar junta extends state of emergency to support election preparations
The junta plans this year to hold an election, which critics have derided as a sham to keep the generals in power through proxies.
Malaysia to receive visits from world leaders beginning next week - PM
We need more strategic partners at this time, says Datuk Seri Anwar Ibrahim.
'Stubborn' Sarawak flood victims urged to evacuate immediately
Deputy Premier Datuk Amar Douglas Uggah Embas says some individuals are still reluctant to move to the nearest relief centres.
Taylor Swift unveiled as presenter at Sunday's Grammys
Taylor Swift is nominated for the Grammy Awards for Album of the Year with her album 'The Tortured Poets Department', and five other awards.
Microsoft, Meta back big AI spending despite DeepSeek's low costs
CEOs of Microsoft and Meta defends massive spending saying it was crucial to staying competitive in the new field.
Israel releases Palestinian prisoners after delay over chaotic hostage handover
Hamas frees three Israeli and five Thai hostages in Gaza, and Israel releases 110 Palestinian prisoners in the latest prisoner-hostage swap.
New minimum wage order comes into force tomorrow, benefiting 4.37 million workers - KESUMA
Failure to comply with the Minimum Wage Order is an offence and may result in a fine.
Honda, Nissan to unveil detailed merger plan in mid-Feb.
Japan's second- and third-largest carmakers by volume, have agreed to begin talks on merging under a holding company.
Investigators cautious of jet fuel still aboard wrecked South Korean plane
The investigation is being slowed by a large amount of fuel and oxygen still on board, according to an air crash investigation official.
Malaysia's official reserve assets at US$116.22 bil as at end-December 2024 - BNM
According to Bank Negara Malaysia, projected foreign currency inflows amount to US$2.49 billion in the next 12 months.
Investigators seek to salvage aircraft after deadly Washington crash
Divers aim to "salvage the aircraft" and find additional components on Friday, Washington's fire department said.
PM calls on people to prioritise national interest
Prime Minister Datuk Seri Anwar Ibrahim says Malaysia should also serve as a model for strong racial unity.
Trump repeats tariffs threat to dissuade BRICS nations from replacing US dollar
Trump warns BRICS member countries from replacing the US dollar as a reserve currency by repeating a 100%-tariffs threat.
UN chief demands evacuation of 2,500 Gaza children at 'imminent risk' of death
The doctors said they are advocating for a centralised process for medical evacuations with clear guidelines.
US looking into whether DeepSeek used restricted AI chips, source says
Current restrictions on Nvidia artificial intelligence processors are meant to stop its most sophisticated chips from reaching China.
Number of evacuees continues to rise in flood-hit Sabah, Sarawak
In Sarawak, the number of evacuees rose to 9,398 from 2,725 families this morning.
Investigators find black boxes after deadly Washington plane crash, continue search for answers
Investigators recovered the so-called black boxes from the American Airlines Bombardier jet carrying 60 passengers and four crew members.
Malaysia among nine nations to meet in The Hague over alleged Israeli law violations
Nations expected to plan "coordinated legal, economic, and diplomatic actions" to hold Israel accountable for violating international law.