{"id":354585,"date":"2020-06-02T15:15:44","date_gmt":"2020-06-02T13:15:44","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=354585"},"modified":"2020-06-02T15:17:46","modified_gmt":"2020-06-02T13:17:46","slug":"ransomware-attackers-threaten-to-leak-telkom-client-database","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/354585-ransomware-attackers-threaten-to-leak-telkom-client-database.html","title":{"rendered":"Ransomware attackers threaten to leak Telkom client database"},"content":{"rendered":"<p>Telkom has fallen victim to the group behind the Sodinokibi ransomware, also known as REvil, security researchers have told MyBroadband.<\/p>\n<p>The group has taken responsibility for an attack on Telkom and has threatened to leak the Telkom client database in a post on its the Dark Web blog.<\/p>\n<p>Bleeping Computer recently <strong><a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/list-of-ransomware-that-leaks-victims-stolen-files-if-not-paid\/\" target=\"_blank\" rel=\"noopener noreferrer\">reported<\/a><\/strong> that the REvil \/ Sodinokibi group is one of several ransomware operators that steals sensitive data from victims and leaks it on the dark web if their targets don&#8217;t give in to their extortion demands.<\/p>\n<p>The group has recruited a team of affiliates who carry out attacks on corporate networks.<\/p>\n<p>One security researcher, who goes by <strong><a href=\"https:\/\/twitter.com\/ransomleaks\/status\/1267694942270431234\" target=\"_blank\" rel=\"noopener noreferrer\">Ransom Leaks<\/a><\/strong> on Twitter, told MyBroadband that Sodinokibi is a &#8220;ransomware as a service&#8221; platform.<\/p>\n<p>&#8220;Hackers actually sign up as partners or affiliates and deploy this ransomware. When a victim pays for decryption the partner gets like 60% of the ransom,&#8221; the researcher said.<\/p>\n<p>&#8220;This leaking is part of the platform&#8217;s service to its partners to help them win more payments.&#8221;<\/p>\n<p>Ransom Leaks speculated that the Sodinokibi \/ REvil affiliate could easily have tried to extort $1 million (USD) out of Telkom.<\/p>\n<p>&#8220;This ransomware group is known to go &#8216;Big Game Hunting&#8217;, so the ransom could be quite large.&#8221;<\/p>\n<h3 class=\"my-4\">Attack on Telkom<\/h3>\n<div id=\"attachment_354599\" style=\"width: 650px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/06\/Telkom-REvil-ransomware-client-database-leak.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-354599\" class=\"wp-image-354599 size-large\" style=\"border: 1px solid black;\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/06\/Telkom-REvil-ransomware-client-database-leak-640x336.jpg\" alt=\"Screenshot of Sodinokibi \/ REvil leaks blog taking credit for attack on Telkom\" width=\"640\" height=\"336\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/06\/Telkom-REvil-ransomware-client-database-leak-640x336.jpg 640w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/06\/Telkom-REvil-ransomware-client-database-leak-600x315.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/06\/Telkom-REvil-ransomware-client-database-leak-768x403.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/06\/Telkom-REvil-ransomware-client-database-leak-1536x806.jpg 1536w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/06\/Telkom-REvil-ransomware-client-database-leak-1200x629.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2020\/06\/Telkom-REvil-ransomware-client-database-leak.jpg 2048w\" sizes=\"(max-width: 640px) 100vw, 640px\" \/><\/a><p id=\"caption-attachment-354599\" class=\"wp-caption-text\">(Click to enlarge)<\/p><\/div>\n<p>These further reports that <a href=\"https:\/\/mybroadband.co.za\/news\/security\/354295-telkom-outages-caused-by-ransomware-attack-sources.html\"><strong>Telkom was indeed the victim of a ransomware attack<\/strong><\/a> come after the company <a href=\"https:\/\/mybroadband.co.za\/news\/security\/354485-telkom-call-centres-back-online-after-malware-attack.html\"><strong>denied<\/strong><\/a> that its systems had been infected with ransomware.<\/p>\n<p>Telkom later amended its official statement to say that it did not have the PonyFinal ransomware.<\/p>\n<p>This followed industry speculation that Telkom fell prey to the PonyFinal ransomware, for which Microsoft Security Intelligence <strong><a href=\"https:\/\/twitter.com\/MsftSecIntel\/status\/1265674287404343297\">issued an alert<\/a><\/strong> on 27 May.<\/p>\n<p>Industry sources told MyBroadband that downtime across several Telkom systems over the weekend, including its call centre, was due to a ransomware attack.<\/p>\n<p>Staff working remotely were unable to connect to servers or the Telkom virtual private network.<\/p>\n<p>However, Telkom told MyBroadband that it was just dealing with a malware infection, not ransomware.<\/p>\n<p>Telkom said that it became aware of an internal malware infection on Friday, 29 May 2020, and shut down all systems and call centres as a precaution. Its network remained operational during this time, Telkom said.<\/p>\n<p>Some systems were restored on Saturday, though Telkom&#8217;s call centres remained offline. By Monday, Telkom announced that its call centres were back online.<\/p>\n<p>Brett Callow, a threat analyst with Emsisoft, said that Telkom&#8217;s statement that it was not infected with ransomware may be accurate even if\u00a0REvil is responsible for the attack.<\/p>\n<p>&#8220;Actors typically have access to a network for days, weeks or even months attempting to deploy ransomware and use that time to move laterally through the network and, in some cases, steal data,&#8221; Callow said.<\/p>\n<p>&#8220;It\u2019s possible that REvil was able to exfiltrate some data, but Telkom noticed and neutralized the attack prior to ransomware being deployed and having important files encrypted.&#8221;<\/p>\n<h3 class=\"my-4\">Stolen Telkom data will be leaked slowly &#8211; Researcher<\/h3>\n<p>Currently, the Sodinokibi blog on the dark web only contains a placeholder for the Telkom attack.<\/p>\n<p>&#8220;They have never taken credit for something they didn&#8217;t do,&#8221; Ransom Leaks told MyBroadband.<\/p>\n<p>The researcher explained that the group will publish some samples of the Telkom client database, followed by multiple rounds of leaks.<\/p>\n<p>&#8220;They will give Telkom more time to pay to stop the future leaks by breaking it into multiple leaks.&#8221;<\/p>\n<p>Telkom acknowledged MyBroadband&#8217;s request for comment and said it would provide feedback as soon as it was able.<\/p>\n<h3 class=\"my-4\">Now read: <a href=\"https:\/\/mybroadband.co.za\/news\/cloud-hosting\/353473-data-leak-on-uif-covid-19-relief-scheme-website.html\">Data leak on UIF COVID-19 relief scheme website<\/a><\/h3>\n","protected":false},"excerpt":{"rendered":"<p>Telkom has fallen victim to the group behind the Sodinokibi ransomware, also known as REvil, security researchers have told MyBroadband.<\/p>\n","protected":false},"author":15,"featured_media":281321,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[35,64965,64961,64963,109],"class_list":["post-354585","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-headline","tag-ransom-leaks","tag-revil","tag-sodinokibi","tag-telkom"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/354585"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/15"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=354585"}],"version-history":[{"count":2,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/354585\/revisions"}],"predecessor-version":[{"id":354601,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/354585\/revisions\/354601"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/281321"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=354585"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=354585"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=354585"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}