XP95 ransomware group hits Stats SA

Jan

Who's the Boss?
Staff member
Joined
May 24, 2010
Messages
14,887
Reaction score
13,571
Location
The Rabbit Hole
Anybody got the stats on the likelihood of this happening?
x9#@!KdlP02$%^&*()_+ASDlkj23r9f0as9df8a7sdf98a7sdf
QWErty12345!@#$%^&*()_+zxcvbnmASDFGHJKLpoiuytrewq
9f8a7s6d5f4g3h2j1k0l;:'",.<>?/|\[]{}=-0987asdfgh
ZxCvBnM!@#$%^&*(1234567890qwertyuiopLKJHGFDSA
mnbvcxz0987654321poiuytrewqlkjhgfdsamnbvcxz
A1B2C3D4E5F6G7H8I9J0K!L@M#N$O%P^Q&R*S(T)U_V+W=X
0a9s8d7f6g5h4j3k2l1p0o9i8u7y6t5r4e3w2q1zxcvb
▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒▒
ÐÏࡱá;þÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿÿ
~!@#$%^&*()_+{}|:"<>?[];',./`1234567890-=qwerty
pO9iU8yT7rE6wQ5zX4cV3bN2m1A0sD9fG8hJ7kL6
1q2w3e4r5t6y7u8i9o0p!@#$%^&*()QWERTYUIOP
asdfghjkl;'zxcvbnm,./1234567890-=!@#$%^&*()
ZXCVBNMASDFGHJKLQWERTYUIOP1234567890
0P9O8I7U6Y5T4R3E2W1Q!@#$%^&*()_+
lkjhgfdsapoiuytrewq0987654321mnbvcxz
XxYyZzAaBbCcDdEeFfGgHhIiJjKkLlMmNnOoPp
RANDOMBYTESRANDOMBYTESRANDOMBYTES1234567890
!@#$%^&*()_+|~`-=\\[]{}:";'<>?,./
f83jf93jf93jf93jf93jf93jf93jf93jf93jf93j
000111222333444555666777888999AAAABBBB
a9d8f7g6h5j4k3l2p1o0i9u8y7t6r5e4w3q2
++++====----____////||||\\\\~~~~
ENCRYPTED_DATA_BLOCK_START
9a8b7c6d5e4f3g2h1i0jklmnopqrstuvwx
yZ0123456789!@#$%^&*()abcdefghijkl
mnopqrstuvwxYZ0123456789!@#$%^&*()
GIBBERISHGIBBERISHGIBBERISHGIBBERISH
1a2b3c4d5e6f7g8h9i0j!k@l#m$n%o^p&q*r
ZZYYXXWWVVUUTTSSRRQQPPOONNMMLLKKJJII
HGFEDCBA0987654321poiuytrewqlkjhgfd
~!~!~!~!~!~!~!~!~!~!~!~!~!~!~!~!~!
abc123XYZ789!@#def456UVW012$%^ghi
[[[[{{{{((((<<<<>>>>))))}}}}]]]]
0000FFFF1111EEEE2222DDDD3333CCCC
ABCD1234EFGH5678IJKL9012MNOP3456
qrstuvwx9876543210zyxwvutsrqponm
0123456789abcdefghijklmnopqrstuvwxyz
!@#$%^&*()_+!@#$%^&*()_+!@#$%^&*()
DEADBEEFCAFEBABE1234567890ABCDEF
randomrandomrandomrandomrandom
xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
zzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz
12312312312312312312312312312312
98798798798798798798798798798798
AaAaAaAaAaAaAaAaAaAaAaAaAaAaAaAa
BbBbBbBbBbBbBbBbBbBbBbBbBbBbBbBb
CcCcCcCcCcCcCcCcCcCcCcCcCcCcCcCc
DdDdDdDdDdDdDdDdDdDdDdDdDdDdDdDd
EeEeEeEeEeEeEeEeEeEeEeEeEeEeEeEe
FfFfFfFfFfFfFfFfFfFfFfFfFfFfFfFf
GgGgGgGgGgGgGgGgGgGgGgGgGgGgGgGg
HhHhHhHhHhHhHhHhHhHhHhHhHhHhHhHh
IiIiIiIiIiIiIiIiIiIiIiIiIiIiIiIi
JjJjJjJjJjJjJjJjJjJjJjJjJjJjJjJj
KkKkKkKkKkKkKkKkKkKkKkKkKkKkKkKk
LlLlLlLlLlLlLlLlLlLlLlLlLlLlLlLl
MmMmMmMmMmMmMmMmMmMmMmMmMmMmMmMm
NnNnNnNnNnNnNnNnNnNnNnNnNnNnNnNn
OoOoOoOoOoOoOoOoOoOoOoOoOoOoOoOo
PpPpPpPpPpPpPpPpPpPpPpPpPpPpPpPp
QqQqQqQqQqQqQqQqQqQqQqQqQqQqQqQq
RrRrRrRrRrRrRrRrRrRrRrRrRrRrRrRr
SsSsSsSsSsSsSsSsSsSsSsSsSsSsSsSs
TtTtTtTtTtTtTtTtTtTtTtTtTtTtTtTt
UuUuUuUuUuUuUuUuUuUuUuUuUuUuUuUu
VvVvVvVvVvVvVvVvVvVvVvVvVvVvVvVv
WwWwWwWwWwWwWwWwWwWwWwWwWwWwWwWw
XxXxXxXxXxXxXxXxXxXxXxXxXxXxXxXx
YyYyYyYyYyYyYyYyYyYyYyYyYyYyYyYy
ZzZzZzZzZzZzZzZzZzZzZzZzZzZzZzZz
END_OF_ENCRYPTED_BLOCK

The stat is in there, I promise
 
Last edited:
Update from Stats SA. They will not pay the ransom:

Stats SA will not pay any ransom. Deployment of state financial resources is done in line with PFMA. Stats SA will notify the information regulator and will be guided by their processes.
 
Who is their service provider and cybersecurity provider?
Would be interesting to know. I see Orange mentioned again in the article but i think that's because they pay for advertising here.
 
Would be interesting to know. I see Orange mentioned again in the article but i think that's because they pay for advertising here.
Its Fortinet supplied by XON according to the tenders page.

Fortinet is the most hacked infrastructure on the planet and the should rather be called FortiSeive. Supplied by XON.

They should rather not use a Silicon Valley backdoor solution.
 
The sample leak is entirely HR-related, primarily ID documents and qualification certificates. Most probably submission for employment or similar. Definite PII though including addresses and mobile no's etc. Wonder if they specifically hit an HR machine or that is just the folder they chose to share as a sample. metadata has largely been stripped out.
 
Would be interesting to know. I see Orange mentioned again in the article but i think that's because they pay for advertising here.
Happy to quote you. Drop me an email — [email protected] — preferably with stats about Cyber Extortion in South Africa to help add context to the article.
 
Does Section 22 of the POPIA not require that each potentially affected individual is informed as soon as possible, and have all the people included in these government data breaches been informed?
 
Ok, who opened the "PDF" attachment.
If only.

They were promised USD4,500 by DJT and clicked ALL the links and entered their credentials which naturally have zero MFA or CA protections....

They do, however, have a hugely expensive Cloudflare bill which they imagine means they're immune to this sort of "hack"
 
Top
Sign up to the MyBroadband newsletter
X