Ransomware attacked another pipeline company-70GB data breach

[ad_1]

Be a ransomware hacker Hit the colonial pipeline last month with Turn off gas distribution Along Most of the East Coast of the United States, The world is aware of the danger of digital subversion in the petrochemical pipeline industry. It now appears that another pipeline-focused company was also attacked by ransomware at almost the same time, but it remained quiet even though its 70 GB of internal files were stolen and dumped on the dark web.

Last month, an organization calling itself Xing Team posted a series of documents stolen from LineStar Integrity Services on its dark website. LineStar Integrity Services is a Houston-based company that sells auditing, compliance, maintenance, and maintenance services to pipeline customers. Technical Services.Data, first discovered online WikiLeaks-style transparent organization distributed denial of secretsOr DDoSecrets, which includes 73,500 emails, accounting documents, contracts, and other business documents, approximately 19 GB of software code and data, and 10 GB of human resources files, including scans of employee driving licenses and social security cards. Although the leak did not appear to have caused any damage to infrastructure like the colonial pipeline incident, security researchers warned that the leaked data may provide hackers with a roadmap for more pipeline targets. LineStar did not respond to a request for comment.

DDoSecrets, it makes Data leaked by the Trawl Ransomware Group As part of its mission to disclose data that it considers worthy of public review, 37 GB of company data was released to its leak site on Monday. The organization stated that they have carefully edited potentially sensitive software data and codes — DDoSecrets claims that these data and codes may enable subsequent hackers to discover or exploit vulnerabilities in pipeline software — as well as leaked human resources materials in order to transfer LineStar employees Exclude’sensitive personally identifiable information.

But the unedited files reviewed by WIRED are still online. Joe Slowik, a threat intelligence researcher at the security company Gigamon, believes that it may contain information that can be used for subsequent attacks on other pipelines. He has been focusing on critical infrastructure security for many years and was a former Los Alamos nation. The person in charge of laboratory incident response. Although Slowik pointed out that it is not clear what sensitive information may be contained in the leaked 70 GB, he is concerned that it may contain information about the software architecture or physical equipment used by LineStar customers, because LineStar provides information technology and industrial control system software to pipeline customers .

“You can use it to populate a lot of positioning data, depending on what’s in it,” Slowik said. “This is very worrying because it may not only involve people’s driver license information or other HR-related items, but also data related to the operation of these networks and their more critical functions.”

Xing Team is a relatively new entrant to the ransomware ecosystem. The ransomware Brett Callow stated that although the organization has written its name in Chinese characters on its dark website-and it comes from the word “star” in Mandarin-but this name alone has no reason to believe that the organization is Chinese-anti Key researcher of virus company Emsisoft. Callow said he saw Xing Team use a renamed version of Mount Locker malware to encrypt victims’ files and threatened to leak unencrypted data in order to blackmail the target for payment. As far as LineStar is concerned, Xing Team seems to have followed up on this threat.

This kind of leak, in turn, may become a stepping stone for other ransomware hackers, who often comb through dark web data dumps to obtain information that can be used to impersonate companies and target their customers. “If you are going to steal data from a pipeline company, this may enable you to build a fairly traditional spear phishing email and send it to another pipeline company,” Carlo said. “We absolutely know that the group will do this.”

[ad_2]

Source link