Photography and personalized photo giant Shutterfly was attacked by the Conti ransomware group that allegedly encrypted thousands of devices and stole corporate data.
Shutterfly’s photography-related services are aimed at consumer, enterprise, and education customers through various brands such as GrooveBook, BorrowLenses, Shutterfly.com, Snapfish, and Lifetouch.
The company stated that portions of the Lifetouch and BorrowLenses business were affected. They experienced interruptions with Groovebook, manufacturing offices, and some corporate systems as well.
Shutterfly have contacted law enforcement and a cybersecurity company was also hired to help respond to the incident. As part of their ongoing investigation, they are also assessing the full scope of any data that may have been affected.
The company assured that they do not store credit card, financial account information, or the Social Security numbers of the Shutterfly.com, Snapfish, Lifetouch, TinyPrints, BorrowLenses, or Spoonflower customers, and so none of that information was impacted in this incident.
The company added that Shutterfly.com, Snapfish.com, TinyPrints.com and Spoonflower were not impacted by the attack.
It was reported that the attack started about two weeks ago and involves a ransom demand in the millions. The group claimed to have encrypted over 4,000 devices and 120 VMware ESXi servers.
Conti has created a private Shutterfly data leak page containing screenshots of files allegedly stolen during the ransomware attack. The attackers then threaten to make this page public if a ransom is not paid.
Conti is a ransomware group believed to be operated by a Russian hacking group known for other notorious malware infections, such as Ryuk, TrickBot, and BazarLoader.
Image Credits : CNBC














Comments