Showing posts sorted by date for query ransomware. Sort by relevance Show all posts
Showing posts sorted by date for query ransomware. Sort by relevance Show all posts

03 September 2026

Code in corporate networks sends commands to passing AI bots

Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware.

The potentially dangerous content is in llms.txt and llms-full.txt files, an emerging convention websites employ to provide machine-readable summaries of the site’s content and its high-level structure. These files are the AI equivalent of the robots.txt standard that instructs search engines how to index the site’s content. 

The files are misconfigured because they list non-existent packages from PyPI, npm, and other registries along with instructions on how to install them. Because the package names are unregistered, an attacker could register one and use it to host ransomware or any other type of harmful package. The vulnerability occurs when a coding agent with permission to run shell commands treats the file as authoritative setup documentation. Some AI agents will then download the package and run it. In other cases, the LLM files point to non-existent domain names. In one case, it was: “As an example of writing integration tests for [redacted] applications you can use the [redacted] test framework.” An attacker can then register the site and plant malicious instructions on it. READ MORE...

www.arstechnica.com


30 April 2026

Nearly half of UK businesses pwned last year as phishing keeps doing the job like it's 2005

Nearly half of UK businesses are still getting breached, and in many cases, the attacker's big breakthrough is an employee clicking "sure, why not" on a fake login page.

The UK government's latest Cyber Security Breaches Survey, released on Thursday, puts the hit rate at 43 percent of businesses and 28 percent of charities reporting a cyber incident in the past year, equating to approximately 612,000 UK businesses and 57,000 UK charities, numbers that have barely budged since the last time it asked.

Most of these breaches do not start with anything especially cutting-edge. Phishing leads "by far," usually via impersonation emails that send staff to fake login pages or get them to click links, open attachments, or hand over sensitive information.

Everything else barely gets a look-in. Around 85 percent of businesses that reported a breach or attack said it involved phishing, leaving malware, ransomware, and unauthorized access trailing some distance behind.

www.theregister.com


18 July 2025

Police dismantle DiskStation ransomware gang targeting NAS devices, arrest suspected ringleader


"Operation Elicius", a joint international law enforcement operation involving Europol and police forces in Italy, France, and Romania, has successfully dismantled a Romanian ransomware gang that targeted network-attached storage (NAS) devices and arrested its suspected leader.

The so-called "DiskStation Security" ransomware group has targeted and compromised NAS devices - particularly those manufactured by Synology - since 2021, leaving the data of businesses and non-profit organisations encrypted, and demanding a ransom for its recovery...

...Synology has been advising users on how to protect their NAS devices from ransomware attacks for several years.  Much of the advice revolves around minimising the exposure of NAS devices to the internet, hardening password security, and ensuring that regular backups are made of critical data.

The accounts used to secure NAS devices are no different from any other when it comes to security - you should ensure that passwords are unique, and not easy-to-crack.  Attackers will often use automated tools to brute force their way into poorly-secured devices, or take advantage of users who have used easy-to-guess, predictable passwords.

Donline supports dozens of business & home clients in specifying, building, deploying & ongoing management of Synology NAS devices. They are excellent, reliable, cost effective devices to manage your network & data. HOWEVER, as with all IT: internet connectivity, credentials, patching, etc - MUST be carefully managed. Got questions about IT? Contact Donline.

www.fortra.com


21 March 2025

Scam Alert: FBI ‘Increasingly Seeing’ Malware Distributed In Document Converters

Threat actors may attempt to distribute malware, including ransomware, by offering free document converters, according to a March 7 report from the FBI’s Denver office. “Agents are increasingly seeing” this type of scam. The scheme has been deployed globally, the FBI warned.

Threat actors behind the document converter scam disguise malicious software as a legitimate tool for file conversion. The software may claim to convert .doc files to .pdf files, merge multiple .jpg files into a single .pdf file, or download MP3 or MP4 audio files. In most cases, the downloaded software performs the advertised conversion. However, it also grants the attacker access to the victim’s computer.

Once installed, the malware allows threat actors to download additional malicious software or access files submitted for conversion. If these files contain identifying information —  such as dates of birth, social security numbers, or phone numbers — the threat actor may exploit them for identity theft. The attacker could scrape the submitted files for banking information, seed phrases and other information associated with cryptocurrency wallets, email addresses, and passwords.

www.techrepublic.com


15 February 2024

Southern Water customer data was stolen in ransomware attack

Southern Water: On Monday 12 February 2024 we announced that data from a limited part of Southern Water’s server estate had been stolen and was at risk following an illegal intrusion into our IT systems. This arose from our ongoing investigation into suspicious activity, as detailed in our statement on 23 January 2024.

We are very sorry that this has happened.

We continue to work with our expert technical advisers to confirm whose data is at risk. Our initial assessment is that this is the case for some of our customers and current and former employees.

We have engaged leading independent cybersecurity experts to monitor the “dark web”. They continue to report to us that, since we were named on the cyber criminals’ site on 22 January 2024, they have found no new evidence of the data potentially involved in this cyber incident being published online. They will continue to carry out their checks for as long as is necessary.

We take data protection and information security very seriously and, in accordance with our regulatory obligations, we are making contact with anyone whose personal data may be at risk.

Based on our forensic investigations so far, which are ongoing, we are notifying in the order of 5 to 10 percent of our customer base to let them know that their personal data has been impacted. We are also notifying all of our current employees and some former employees.

www.southernwater.co.uk


19 May 2023

There are 2 types of people in the world: those who have lost data & those who will loose data!

 

WHAT IS BACKUP? A backup is a second copy of all your important files - for example, your family photos, home videos, documents and emails. Instead of storing it all in one place (like your computer), you keep another copy of everything somewhere safe.

Why should I bother to back up my data?

Hardware can break, get coffee spilt in it, lost, stolen, hacker attack, malware, ransomware, etc…

Hardware can easily be replaced. Recreating your data is NOT easy, and is likely to be impossible!

It is estimated that 70-80% of businesses that suffer a serious data loss, fail within 18 months.

SO HOW DO I BACKUP?

Most people backup their files in one of two ways: to a quality external drive, and/or somewhere on the Internet (Backblaze).

Do you need a hand with getting backup sorted for your important data? Contact Donline

Do not wait until it's too late to backup!

Meanwhile in other newsSanDisk Extreme SSDs keep abruptly failing.

www.taobackup.com


11 April 2023

Western Digital confirms breach, affects My Cloud and SanDisk users

Western Digital, a big brand in digital storage, says it has suffered a "network security incident" - potentially ransomware - which resulted in a breach and some system disruptions in its business operations.

The company identified the incident on March 26 and said an unnamed third party unlawfully accessed several computer systems to steal data. The investigation is ongoing and Western Digital has yet to learn how much was taken. 

Since the incident, Western Digital's consumer cloud and backup service My Cloud has experienced outages, preventing customers from accessing their files. My Cloud Home, My Cloud Home Duo, My Cloud OS5, SanDisk ibi, and SanDisk Ixpand Wireless Charger all experienced service interruptions. 

UPDATE from techcrunch 14 April 2023: The hackers who breached data storage giant Western Digital claim to have stolen around 10 terabytes of data from the company, including reams of customer information. The extortionists are pushing the company to negotiate a ransom - of a “minimum 8 figures” - in exchange for not publishing the stolen data. READ MORE...

www.malwarebytes.com


20 February 2023

Microsoft Defender for Business - help secure what matters

Good enough isn’t enough when it comes to protecting your business from ransomware, malware, phishing, and other threats. Get enterprise-grade endpoint security—designed specifically for small and medium businesses with up to 300 employees—with Microsoft Defender for Business.

CLICK HERE to watch a two-minute video

With a 300 percent increase in ransomware attacks in the last year, and with more than 50 percent of them reaching small businesses, it’s more important than ever to build a secure foundation for your company.

Stay productive and help ensure business continuity with an easy-to-use, cost-effective endpoint security solution that works with your IT—Microsoft Defender for Business. Proactively protect your customers and data with:

Wizard-driven setup with recommended policies to secure devices and servers.

Threat and vulnerability management, with automated, built-in intelligence.

Next-generation antivirus protection.

Simple, streamlined experiences that give actionable insights and recommendations.

A solution that works seamlessly with your Microsoft 365 plan.

Contact Donline to find out how Microsoft Defender for Business can protect your organisation.

www.microsoft.com



13 January 2023

Royal Mail hit by Russia-linked ransomware attack

 

Severe disruption to Royal Mail's overseas deliveries has been caused by ransomware linked to Russian criminals, the BBC has been told.

The cyber-attack has affected the computer systems Royal Mail uses to despatch deliveries abroad. Royal Mail has been warning customers since Wednesday of disruption due to a "cyber-incident". Its latest advice is for people not to try to send international letters and parcels until the issue is resolved.

Ransomware is malicious computer software that encrypts data and locks up systems. The ransomware used in the attack is "Lockbit", according to a source close to the investigation. Computer security firms say the software has been developed and used by criminal gangs with links to Russia.

www.bbc.co.uk


08 September 2022

It's like déjà vu, all over again: QNAP NAS devices under attack - again!

Network hardware-maker QNAP is urging customers to update their network-attached storage devices immediately to protect them from a new wave of ongoing ransomware attacks that can destroy terabytes of data in a single stroke.

Singapore-based QNAP said recently that it has identified a new campaign from a ransomware group known as DeadBolt. The attacks take aim at QNAP NAS devices that use a proprietary feature known as Photo Station. The advisory instructs customers to update their firmware, suggesting there is a vulnerability that’s under exploit, but the company makes no explicit mention of a CVE designation that security professionals use to track such security flaws.

www.arstechnica.com


24 August 2022

7 cybersecurity terms every hybrid employee should know

An employee working from home opens an attachment in an existing email thread with coworkers. Someone else quickly types in a URL to look something up while working on a project, without noticing they made a small typo. A new colleague receives an email that looks like it comes from a payroll company and responds with their Social Security number and bank account information.

Each of these scenarios could be just part of a normal day for an employee who spends most of their time working at a computer. But they’re also opportunities for a cyber attack that could wreak havoc for an entire company, its employees, and its customers. Now that more employees are working remotely for all or part of the work week, outside of the security of a company’s internal IT systems, the threat is even greater. In the first few months of the pandemic, cyber attacks on cloud infrastructure skyrocketed by 600%.

“Employees have a role to play, but more sophisticated attacks make it next-to-impossible to spot them,” says Ian Pratt, global head of security for Personal Systems at HP. “That’s why it’s key that employees feel empowered to inform IT when something looks off.”

1. Ransomware

2. Spear phishing

3. Spoofing

4. Pretexting

5. Typosquatting

6. Shoulder surfing

7. Zero-click attack

Click here to find out more & protect yourself & your business.

www.hp.com



16 February 2022

Follow the money: Russian Cybercriminals Drive Significant Ransomware and Cryptocurrency-based Money Laundering Activity

Russia has long been home to some of the most skilled hackers in the world. According to cybersecurity investigators like Brian Krebs, this is largely due to the country’s excellence in computer science education, combined with low economic prospects even for those who are skilled in the field. Given this background, it may not be surprising that Russia leads the way in ransomware. But the degree to which Russia-based ransomware strains dominate is quite shocking. 

Before we dive into the data, a quick explainer - we generally tie specific ransomware strains to Russian cybercriminals based on one of three criteria:

1) Evil Corp is a Russia-based cybercriminal organization that has been prolific in ransomware, and whose leadership is believed to have ties to the Russian government. 

2) The Commonwealth of Independent States (CIS) is an intergovernmental organization of Russian-speaking, former Soviet countries. Many ransomware strains contain code that prevents the encryption of files if it detects the victim’s operating system is located in a CIS country. In other cases, ransomware operators have even given over decryptors to return file access after learning they inadvertently targeted a Russian organization. We can attribute CIS-avoiding strains to Russian cybercriminals, though with a lesser degree of confidence, as some of them may be based in other CIS countries.

3) There are several other ransomware characteristics that can indicate a strain is likely based in Russia. Examples include ransomware strains that share documents and announcements in the Russian language, or whose affiliates are believed to be located in Russia with a high degree of confidence. 

Overall, roughly 74% of ransomware revenue in 2021 - over $400 million worth of cryptocurrency - went to strains we can say are highly likely to be affiliated with Russia in some way. 

Blockchain analysis combined with web traffic data also tells us that after ransomware attacks take place, most of the extorted funds are laundered through services primarily catering to Russian users.

www.chainalysis.com


08 February 2022

Helping users stay safe: Blocking internet macros by default in Microsoft Office

It’s a challenging time in software security; migration to the modern cloud, the largest number of remote workers ever, and a global pandemic impacting staffing and supply chains all contribute to changes in organizations. Unfortunately, these changes also give bad actors opportunities to exploit organizations:

“Cybercriminals are targeting and attacking all sectors of critical infrastructure, including healthcare and public health, information technology (IT), financial services, and energy sectors. Ransomware attacks are increasingly successful, crippling governments and businesses, and the profits from these attacks are soaring.”

For years Microsoft Office has shipped powerful automation capabilities called active content, the most common kind are macros. While we provided a notification bar to warn users about these macros, users could still decide to enable the macros by clicking a button. Bad actors send macros in Office files to end users who unknowingly enable them, malicious payloads are delivered, and the impact can be severe including malware, compromised identity, data loss, and remote access.

"A wide range of threat actors continue to target our customers by sending documents and luring them into enabling malicious macro code.  Usually, the malicious code is part of a document that originates from the internet (email attachment, link, internet download, etc.).  Once enabled, the malicious code gains access to the identity, documents, and network of the person who enabled it."

For the protection of our customers, we need to make it more difficult to enable macros in files obtained from the internet.

We’re introducing a default change for five Office apps that run macros: VBA macros obtained from the internet will now be blocked by default.

For macros in files obtained from the internet, users will no longer be able to enable content with a click of a button. A message bar will appear for users notifying them with a button to learn more. The default is more secure and is expected to keep more users safe including home users and information workers in managed organizations.

www.microsoft.com


26 January 2022

DeadBolt ransomware targets QNAP NAS (Network Attached Storage) devices

A new DeadBolt ransomware group is encrypting QNAP NAS (Network Attached Storage) devices worldwide using what they claim is a zero-day vulnerability in the device's software.

The attacks started today, January 25th, with QNAP devices suddenly finding their files encrypted and file names appended with a .deadbolt file extension.

Instead of creating ransom notes in each folder on the device, the QNAP device's login page is hijacked to display a screen stating, "WARNING: Your files have been locked by DeadBolt"

What should any computer user (including NAS) do to protect themselves & their irreplaceable data from crooks? Two little words: UPDATES & BACKUP!

www.bleepingcomputer.com


14 January 2022

REvil ransomware gang arrested in Russia

Authorities in Russia say they have dismantled the ransomware crime group REvil and charged several of its members.

The United States had offered a reward of up to $10m (£7.3m) for information leading to the gang members, following ransomware attacks.

Russia's intelligence bureau FSB said the group had "ceased to exist". However, it does not appear that any Russian members of the gang will be extradited to the United States.

The agency said it had acted after being provided with information about the REvil gang by the US. According to the Russian state news service Tass, REvil "developed malicious software" and "organised the theft of money from the bank accounts of foreign citizens".

The FSB said it had seized more than 426 million rubles (£4m), including about £440,000 worth of crypto-currency. It also seized more than 20 "premium cars" which had been purchased with the proceeds of crime.

www.bbc.co.uk


12 January 2022

Hotel chain switches from Windows and Mac to Chrome OS to recover from ransomware attack

A Scandinavian hotel chain that fell victim to a ransomware attack last month said it took a novel approach to recover from the incident by switching all affected systems to Chrome OS.

Nordic Choice Hotels, which operates 200 hotels across Northern Europe, fell victim to a ransomware attack on December 2, when hackers encrypted some of its internal systems using the Conti ransomware strain.

The attack prevented staff from accessing guest reservation data and from issuing key cards to newly arriving guests, as one of the hotel’s guests told The Record in an interview last month.

But in a press release, Nordic Choice said that instead of contacting the hackers and negotiating a ransom for the decryption key that would have unlocked the infected devices, the hotel chose to migrate its entire PC fleet from Windows to Chrome OS.

Nordic Choice said they used a tool called CloudReady, which can prepare and port old Windows and macOS computers to Chrome OS setups.

www.therecord.media


30 September 2021

In RansomWare news: crooks complain that crooks are acting like... crooks!

Security intelligence vendor Flashpoint claims to have found forum comments from customers of the REvil ransomware-as-a-service gang, and they’re not happy. The gang's malware may contain backdoors that REvil uses to restore encrypted files itself.

REvil's modus operandi is to rent its malware to other evildoers, in return for a hefty cut of any ransoms paid by victims.

Flashpoint writes that the "Exploit" forum has recently featured posts from a threat actor complaining about the backdoor, and the fact its presence meant that REvil could let its customers do all the hard work of arranging an infection, then subvert communications with victims and keep the entire ransom for itself.

Other chat in the forum, Flashpoint asserts, includes complaints about REvil's behaviour, and the futility of attempting to negotiate with the gang.

www.theregister.com


17 September 2021

Free REvil ransomware master decrypter released for past victims

A free master decryptor for the REvil ransomware operation has been released, allowing all victims encrypted before the gang disappeared to recover their files for free.

The REvil master decryptor was created by cybersecurity firm Bitdefender in collaboration with a trusted law enforcement partner.

While Bitdefender could not share details about how they obtained the master decryption key or the law enforcement agency involved, they told BleepingComputer that it works for all REvil victims encrypted before July 13th.

www.bleepingcomputer.com


01 July 2021

UK arm of international charity The Salvation Army hit by ransomware attack

Criminals infected The Salvation Army in the UK with ransomware and siphoned the organisation's data, The Register has learned.

A Salvation Army spokesperson confirmed the evangelical Christian church and charity was compromised, and said it alerted regulators in the UK. She told us: “We are investigating an IT incident affecting a number of our corporate IT systems. We have informed the Charity Commission and the Information Commissioner’s Office, are also in dialogue with our key partners and staff and are working to notify any other relevant third parties... We can also confirm that our services for the vulnerable people who depend on us are not impacted and continue as normal.”

Sally Army staff and volunteers should keep a close eye on bank statements for mysterious transactions, and for correspondence suggesting new accounts have been opened with financial service providers. Ransomware gangs typically resell stolen information to other criminals for further exploitation.

www.theregister.com


23 April 2021

If you have a QNAP NAS, stop what you're doing right now and install latest updates

QNAP has urged its customers to install and run its latest firmware and malware removal tools on their Network-attached storage (NAS) boxes amid a surge in ransomware infections.

Two file-scrambling nasties, Qlocker and eCh0raix, are said to be tearing through vulnerable QNAP storage equipment, encrypting data and demanding ransoms to restore the information.

In response, QNAP said on Thursday users should do this to avoid falling victim to this malware.

www.theregister.com