News: 1586479752

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Ransomware scumbags leak Boeing, Lockheed Martin, SpaceX documents after contractor refuses to pay

(2020/04/10)


Internal confidential documents belonging to some of the largest aerospace companies in the world have been stolen from an industrial contractor and leaked online.

The data was pilfered and dumped on the internet by the criminals behind the DoppelPaymer Windows ransomware, in retaliation for an unpaid extortion demand. The sensitive documents include details of Lockheed-Martin-designed military equipment – such as the specifications for an antenna in an anti-mortar defense system – according to a Register source who alerted us to the blueprints.

Other documents in the cache include billing and payment forms, supplier information, data analysis reports, and legal paperwork. There are also documents outlining SpaceX's manufacturing partner program.

The files were siphoned from Visser Precision by the [1]DoppelPaymer crew, which infected the contractor's PCs and scrambled its files. When the company failed to pay the ransom by their March deadline, the gang – which tends to [2]demand hundreds of thousands to millions of dollars to restore encrypted files – uploaded a selection of the documents to a website that remains online and publicly accessible.

Visser is a manufacturing and design contractor in the US whose clients are said to include aerospace, automotive, and industrial manufacturing outfits – think Lockheed Martin, SpaceX, Tesla, Boeing, Honeywell, Blue Origin, Sikorsky, Joe Gibbs Racing, the University of Colorado, the Cardiff School of Engineering, and others. The leaked files relate to these customers, in particular Tesla, Lockheed Martin, Boeing, and SpaceX.

When asked about the dump, a Lockheed Martin spokesperson provided the following statement. "We are aware of the situation with Visser Precision and are following our standard response process for potential cyber incidents related to our supply chain," El Reg was told.

"Lockheed Martin has made and continues to make significant investments in cybersecurity, and uses industry-leading information security practices to protect sensitive information. This includes providing guidance to our suppliers, when appropriate, to assist them in enhancing their cybersecurity posture."

Why is ransomware still a thing? One-in-three polled netizens say they would cave to extortion demands [3]READ MORE

Visser Precision did not respond to a request for comment on the leak. Tesla, SpaceX, and Boeing did not respond, either.

This is not the first time the DoppelPaymer crew has publicly shared stolen confidential data after a victim failed to pay the ransom demands. In fact, the crooks have a regularly updated website full of internal documents belonging to organizations that didn't pay up, though admittedly most are significantly less interesting than the Visser Precision cache.

The dumps are intended to scare others who are infected with the ransomware into paying the group's demands. The Register will not be linking to the site.

To their slight credit, DoppelPaymer has vowed to [4]lay off attacking hospitals during the coronavirus pandemic. Whether or not this promise was honored is another question.

While law enforcement agencies and security experts uniformly agree that paying a ransom demand is [5]a bad idea and poor substitute for keeping offline backups and properly securing data, some experts have conceded that, when it's your corporate data on the line, caving in and paying up [6]can be an option. ®

Sponsored: [7]Forrester Build a Digital Experience Portfolio



[1] https://malware.wikia.org/wiki/DoppelPaymer

[2] https://www.crowdstrike.com/blog/doppelpaymer-ransomware-and-dridex-2/

[3] https://www.theregister.co.uk/2020/04/02/ransomware_pay_ransomware/

[4] https://www.theregister.co.uk/2020/03/19/ransomware_health_organisations/

[5] https://www.theregister.co.uk/2018/03/09/less_than_half_of_ransomware_marks_get_their_files_back/

[6] https://www.theregister.co.uk/2019/06/06/ransomware_coping_strategy/

[7] https://go.theregister.co.uk/tl/1936/-8554/forrester-build-a-digital-experience-portfolio?td=wptl1936

Anti-mortar system?

mt_head

I'm assuming that uses radar triangulation to determine the firing location, rather than actively try to ward off incoming rounds... unless technology has improved FAR more than I was aware of!

Re: Anti-mortar system?

A random security guy

Damn. I was thinking of a giant badminton racket.

Mark Exclamation

It is total and utter negligence that this contractor has allowed this information to be accessed by unauthorised individuals. Visser Precision should be barred from any further contracts, and whoever is/are responsible for their computer security (depending on if it's due to denied funding or just plain incompetence) should be locked up for a very long time.

That ship has sailed ...

sanmigueelbeer

this contractor has allowed this information to be accessed by unauthorised individuals

Oh that ship has sailed long, long time ago. As a matter of fact, that ship has even reached it's destination port and (may have) offloaded highly-classified cargo before anyone knew about it.

Free treacle

Terrifying to think industry leaders in security practices can be hit so badly by an attack. This must have been highly targetted to access this level of information; I wonder how they did it?

I stand with Lockheed Martin on the handling of the situation though; as soon as the data was lost the worst had already happened. Throwing money down the pit doesn't guarantee the data can be recovered or kept/leaked. Never pay the ransom guys.

You need more time; and you probably always will.