Cyber Hacking News

Dragos discloses a failed extortion attempt

0

Industrial cybersecurity firm Dragos revealed that a ransomware group attempted and failed to breach its infrastructure and extort it.

The incident occurred on May 8, 2023, where the cybercriminals compromised the personal email address of a new sales employee prior to his/her start date, and used the obtained personal information to impersonate the Dragos employee and accomplish the initial steps in the employee onboarding process.

The intruders had access to resources that are usually available to new employees in the sales department. The attackers were able to access SharePoint and the Dragos contract management system.

In one instance, the attackers managed to access a report with IP addresses associated with a customer, however, Dragos immediately informed the customer.

The company assured that the attackers did not compromise its network or the Dragos Platform.

The cybercriminal group failed to deploy ransomware, then pivoted to attempting to extort the company to avoid public disclosure. The group sent various messages and an extortion email to Dragos executives, but the company avoided getting in touch with the criminals.

The compromised account was blocked and the company immediately activated its incident response retainer with a leading service provider and engaged third-party Monitoring, Detection & Response (MDR) provider to manage incident response efforts.

The company states that the security controls in place have prevented threat actors from performing malicious activities once gained a foothold in its network.

The investigation process is ongoing and the company also shared Indicators of Compromise (IoCs) for this attack.

Image Credits : Industrial Cyber

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

North Korean hackers breached Seoul’s top hospital

Previous article

WordPress Elementor plugin flaw poses 1M sites at risk of hacking

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *