{"id":19412,"date":"2021-07-23T13:24:51","date_gmt":"2021-07-23T17:24:51","guid":{"rendered":"http:\/\/worldjusticenews.com\/news\/?p=19412"},"modified":"2021-07-23T13:24:51","modified_gmt":"2021-07-23T17:24:51","slug":"ransomware-key-obtained-to-unlock-customer-data-from-revil-attack","status":"publish","type":"post","link":"https:\/\/worldjusticenews.com\/news\/2021\/07\/23\/ransomware-key-obtained-to-unlock-customer-data-from-revil-attack\/","title":{"rendered":"Ransomware key obtained  to unlock customer data from REvil attack"},"content":{"rendered":"<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\"><b class=\"ssrcss-hmf8ql-BoldText e5tfeyi3\">A computer key that can unlock the files of hundreds of companies which were hacked in a large-scale cyber-attack has been obtained.<\/b><\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">US IT firm Kaseya &#8211; which was the first to be targeted earlier this month &#8211; said it got the key from a \u201ctrusted third party\u201d.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Ransomware is malicious software that steals computer data and scrambles it so the victim cannot gain access.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">The hackers then ask for payment in return for releasing the files.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Kaseya\u2019s decryptor key will allow customers to retrieve missing files, without paying the ransom.<\/p>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">The company\u2019s spokeswoman Dana Liedholm declined to answer whether Kaseya had paid for access to the key.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">She told tech blog\u00a0<a class=\"ssrcss-9nsdc6-InlineLink e1no5rhv0\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/kaseya-obtains-universal-decryptor-for-revil-ransomware-victims\/\" target=\"_blank\" rel=\"noopener\">Bleeping Computer<\/a>\u00a0that the firm was actively helping customers restore their files.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">The &#8220;supply chain&#8221; attack initially targeted Kaseya, before spreading through corporate networks which use its software.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Kaseya estimated that between 800 and 1,500 businesses were affected, including\u00a0<a class=\"ssrcss-9nsdc6-InlineLink e1no5rhv0\" href=\"https:\/\/www.bbc.co.uk\/news\/technology-57707530\" target=\"_blank\" rel=\"noopener\">500 Swedish Coop supermarkets<\/a>\u00a0and\u00a0<a class=\"ssrcss-9nsdc6-InlineLink e1no5rhv0\" href=\"https:\/\/www.nzherald.co.nz\/nz\/worldwide-ransomware-attack-st-peters-college-and-10-other-schools-hit-by-us-cyber-attack\/JACHAD3OPGUOF7ZIF4PJXDPICA\/\" target=\"_blank\" rel=\"noopener\">11 schools in New Zealand.<\/a><\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">After the attack at the beginning of July, criminal ransomware gang REvil demanded $70m worth of Bitcoin in return for a key that would unlock the stolen files.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">But members of the group\u00a0<a class=\"ssrcss-9nsdc6-InlineLink e1no5rhv0\" href=\"https:\/\/www.bbc.co.uk\/news\/technology-57826851\" target=\"_blank\" rel=\"noopener\">disappeared from the internet<\/a>\u00a0in the days following the incident, leaving companies with no way of retrieving the data until now.<\/p>\n<div class=\"ssrcss-18mjolk-ComponentWrapper e1xue1i89\" data-component=\"image-block\">\n<figure class=\"ssrcss-md0xev-StyledFigure e34k3c23\">\n<div class=\"ssrcss-ab5fd8-StyledFigureContainer e34k3c21\"><span class=\"ssrcss-13t93ir-Placeholder e16icw910\"><img decoding=\"async\" class=\"ssrcss-1drmwog-Image ee0ct7c0\" src=\"https:\/\/ichef.bbci.co.uk\/news\/1536\/cpsprodpb\/C10D\/production\/_114812494_analysis-joe-tidy-nc.png\" srcset=\"https:\/\/ichef.bbci.co.uk\/news\/240\/cpsprodpb\/C10D\/production\/_114812494_analysis-joe-tidy-nc.png 240w, https:\/\/ichef.bbci.co.uk\/news\/320\/cpsprodpb\/C10D\/production\/_114812494_analysis-joe-tidy-nc.png 320w, https:\/\/ichef.bbci.co.uk\/news\/480\/cpsprodpb\/C10D\/production\/_114812494_analysis-joe-tidy-nc.png 480w, https:\/\/ichef.bbci.co.uk\/news\/624\/cpsprodpb\/C10D\/production\/_114812494_analysis-joe-tidy-nc.png 624w, https:\/\/ichef.bbci.co.uk\/news\/800\/cpsprodpb\/C10D\/production\/_114812494_analysis-joe-tidy-nc.png 800w, https:\/\/ichef.bbci.co.uk\/news\/976\/cpsprodpb\/C10D\/production\/_114812494_analysis-joe-tidy-nc.png 976w\" alt=\"Analysis box by Joe Tidy, Cyber reporter\" width=\"1536\" height=\"306.11957796014065\" \/><\/span><\/div>\n<\/figure>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Who is the mystery gifter?<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">That\u2019s the big question in the cyber-security world at the moment.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">But really it is irrelevant for two reasons.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Firstly, giving away the key now is far too late for most of the victims of this massive ransomware attack.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">The most desperate companies would have paid the gang already to get their operations back online, and others would hopefully be on their way to recovering by now without the help of the criminals.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">Secondly, the mystery gifter was most probably linked to &#8211; or working with &#8211; the criminals directly.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">It seems improbable that a well-run and experienced cyber-crime group like REvil would have accidentally leaked its most prized possession, or had it taken by some sort of secret law enforcement operation.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">I\u2019m told by a hacker who claims to be a part of the inner circle that it was &#8220;a trusted partner&#8221; who gave the key away on behalf of the group\u2019s leader, who calls himself Unknown.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">My contact says it\u2019s all part of &#8220;a new beginning&#8221;.<\/p>\n<\/div>\n<\/div>\n<div class=\"ssrcss-uf6wea-RichTextComponentWrapper e1xue1i84\" data-component=\"text-block\">\n<div class=\"ssrcss-18snukc-RichTextContainer e5tfeyi1\">\n<p class=\"ssrcss-1q0x1qg-Paragraph eq5iqo00\">So while some are calling this the end of the REvil group, it could well be the start of something else.<\/p>\n<p>Source: <a href=\"https:\/\/www.bbc.co.uk\/news\/technology-57946117\" target=\"_blank\" rel=\"noopener\">bbc.co.uk<\/a><\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\">A computer key that can unlock the files of hundreds of companies which were hacked in a large-scale cyber-attack has been obtained. US IT firm Kaseya &#8211; which was the first to be targeted earlier <a class=\"mh-excerpt-more\" href=\"https:\/\/worldjusticenews.com\/news\/2021\/07\/23\/ransomware-key-obtained-to-unlock-customer-data-from-revil-attack\/\" title=\"Ransomware key obtained  to unlock customer data from REvil attack\">[&#8230;]<\/a><\/div>\n","protected":false},"author":1,"featured_media":1952,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pmpro_default_level":"","footnotes":""},"categories":[109,2,3],"tags":[5056,7120,2936,6270,6895],"class_list":{"0":"post-19412","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-headline","8":"category-news","9":"category-usa","10":"tag-cyber-attack","11":"tag-cyber-security","12":"tag-hacking","13":"tag-ransomware","14":"tag-revil","15":"pmpro-has-access"},"_links":{"self":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/19412","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/comments?post=19412"}],"version-history":[{"count":2,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/19412\/revisions"}],"predecessor-version":[{"id":19414,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/posts\/19412\/revisions\/19414"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/media\/1952"}],"wp:attachment":[{"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/media?parent=19412"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/categories?post=19412"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/worldjusticenews.com\/news\/wp-json\/wp\/v2\/tags?post=19412"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}