{"id":579025,"date":"2025-01-21T18:02:59","date_gmt":"2025-01-21T16:02:59","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=579025"},"modified":"2025-01-21T18:31:39","modified_gmt":"2025-01-21T16:31:39","slug":"the-hacking-group-holding-cell-c-ransom","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/579025-the-hacking-group-holding-cell-c-ransom.html","title":{"rendered":"The hacking group holding Cell C ransom"},"content":{"rendered":"\n<p>The group behind the recent Cell C data breach, RansomHouse, infiltrates organisations through phishing attacks, exploiting vulnerabilities, or leveraging poor cybersecurity practices.<\/p>\n\n\n\n<p>Cell C disclosed that it was the <a href=\"https:\/\/mybroadband.co.za\/news\/cellular\/577699-cell-c-hacked.html\" data-type=\"link\" data-id=\"https:\/\/mybroadband.co.za\/news\/cellular\/577699-cell-c-hacked.html\">victim of a cyberattack<\/a> that exposed the data of a limited number of people on 8 January 2025, and roughly two days later, it revealed that RansomHouse had claimed responsibility for the attack.<\/p>\n\n\n\n<p>Fortunately for the South African mobile operator, the group, which emerged in March 2022, claims to focus on data theft rather than encrypting victims&#8217; systems to distinguish itself from traditional ransomware groups.<\/p>\n\n\n\n<p>This is according to Diana Selck-Paulsson, lead security researcher at Orange Cyberdefense, who added that RansomHouse exfiltrates sensitive data from breached systems and demands payment for not leaking it.<\/p>\n\n\n\n<p>Rather than encrypting systems, this approach allows RansomHouse group members to avoid detection for longer, as there is no immediate operational disruption.<\/p>\n\n\n\n<p>The group has significantly impacted South Africa in recent years, attacking Checkers owner Shoprite in June 2022 and Cell C in November 2024.<\/p>\n\n\n\n<p>&#8220;However, given the fact that these Cyber Extortion (Cy-X) operations operate globally, we don&#8217;t see South Africa proportionally heavily impacted by this particular Cy-X operation,&#8221; said Selck-Paulsson.<\/p>\n\n\n\n<p>She added that there are currently no other known RansomHouse victims exposed in South Africa but noted that the victimisation process can take several weeks or months.<\/p>\n\n\n\n<p>RansomHouse posted a sample of the data it stole from Cell C on the dark web, revealing that it had infiltrated 2TB of data from the mobile operator&#8217;s systems.<\/p>\n\n\n\n<p>&#8220;Our investigation into this matter is still ongoing, and we are working diligently to gather all the facts,&#8221; <a href=\"https:\/\/mybroadband.co.za\/news\/security\/577864-details-revealed-about-cell-c-hack.html\" data-type=\"link\" data-id=\"https:\/\/mybroadband.co.za\/news\/security\/577864-details-revealed-about-cell-c-hack.html\">said Cell C<\/a>.<\/p>\n\n\n\n<p>&#8220;We can confirm that the threat actors involved in this incident have identified themselves as Ransomhouse.&#8221;<\/p>\n\n\n\n<p>It added that it had no additional verified information regarding the attackers&#8217; identities and that its forensic experts are investigating.<\/p>\n\n\n\n<p>The <a href=\"https:\/\/mybroadband.co.za\/news\/cellular\/578225-what-hackers-stole-from-cell-c.html\" data-type=\"link\" data-id=\"https:\/\/mybroadband.co.za\/news\/cellular\/578225-what-hackers-stole-from-cell-c.html\">list of files in the RansomHouse sample<\/a> includes what appear to be customer call records, identity document scans belonging to a former exco member, and the front pages of non-disclosure agreements involving Cell C.<\/p>\n\n\n\n<p>Also included were the first pages of several customer contracts and screenshots that appear to show Cell C&#8217;s financial data, including a balance sheet and statements showing revenue and profit.<\/p>\n\n\n\n<p>However, Cell C has told MyBroadband that the compromised data is unstructured, making it difficult to analyse.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/08\/Cell-C-new-branding-on-building.jpg\" alt=\"\" class=\"wp-image-555893\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/08\/Cell-C-new-branding-on-building.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/08\/Cell-C-new-branding-on-building-600x338.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2024\/08\/Cell-C-new-branding-on-building-768x432.jpg 768w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">South Africa is a prominent target for cybercrime<\/h2>\n\n\n\n<p>Orange Cyberdefense said it has identified South Africa as an increasingly prominent target for cyberattacks.<\/p>\n\n\n\n<p>Its latest CyXplorer report, which focuses on cyber extortion, revealed that Africa experienced a 100% increase in threats between April 2023 and April 2024.<\/p>\n\n\n\n<p>It notes that South Africa accounted for the majority of incidents.<\/p>\n\n\n\n<p>&#8220;In our latest investigation of the ongoing Cy-X threat in our Security Navigator 2025 report, we found Africa to be the 11th most impacted region, 40% of the victims were from South Africa,&#8221; said Selck-Paulsson.<\/p>\n\n\n\n<p>However, the firm observed a slight decrease in threats between October 2023 and October 2024.<\/p>\n\n\n\n<p>&#8220;This is a very typical development of this very dynamic ecosystem that often goes about their criminal business based on opportunities they can leverage,&#8221; added Selck-Paulsson.<\/p>\n\n\n\n<p>She warned that the Cy-X landscape is evolving rapidly. New actors, aggressive threats, and increasing cross-border threats are emerging globally.<\/p>\n\n\n\n<p>Companies, particularly those in countries like South Africa, must take proactive action to mitigate the risks of these dynamic threats.<\/p>\n\n\n\n<p>&#8220;Signs of desperation in the Cy-X ecosystem are evident, such as last year&#8217;s attack on South Africa&#8217;s National Health Laboratory Service (NHLS) during a health outbreak,&#8221; said Selck-Paulsson.<\/p>\n\n\n\n<p>&#8220;This underscores the critical need to protect vital infrastructure against increasingly aggressive and indiscriminate threats.&#8221;<\/p>\n\n\n\n<p>Organisations must enhance their resilience with robust cybersecurity strategies and implement real-time threat monitoring, incident response planning, and collaboration across all sectors to protect themselves.<\/p>\n\n\n\n<p>&#8220;Cy-X actors are now targeting sensitive sectors, exposing private communications, and naming individuals, amplifying harm and creating psychological and reputational impacts,&#8221; said Selck-Paulsson.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>RansomHouse emerged in March 2022 and has claimed responsibility for attacks on two prominent South African organisations since.<\/p>\n","protected":false},"author":341076,"featured_media":501095,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[355,98506,98505,26872,98504,65918,79138],"class_list":["post-579025","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-cell-c","tag-cyber-attack-2","tag-cyber-extortion","tag-data-breach","tag-diana-selck-paulsson","tag-orange-cyberdefense","tag-ransomhouse"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/579025"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341076"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=579025"}],"version-history":[{"count":5,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/579025\/revisions"}],"predecessor-version":[{"id":579309,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/579025\/revisions\/579309"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/501095"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=579025"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=579025"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=579025"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}