Bangkok Airways hit by LockBit ransomware attack, loses lotsa data after refusing to pay
- Reference: 1630386904
- News link: https://www.theregister.co.uk/2021/08/31/bangkok_airways_hit_by_lockbit/
- Source link:
Bangkok Airways' [1]announcement about the matter came last Thursday, a day after LockBit posted a message on its dark web portal threatening the airline to pay a ransom or suffer a data leak.
The airline was given five days to sort payment, but instead of coughing up it disclosed the breach. LockBit responded by publishing the lot. Competing claims about the resulting data dump rate it at 103GB and over 200GB.
[2]
The data mostly contained business-related documents, but there was some passenger personal data in the mix. The personal data may have included names, nationalities, gender, phone number, email, address, passport information, travel history, partial credit card numbers and even meal preferences.
[3]
[4]
The Thai regional carrier said no operational or aeronautical security systems were impacted.
The airline said it is investigating the incident and has informed law enforcement agencies and customers. The latter group was advised to beware of scammers – especially anyone posing as Bangkok Airways asking for information like credit card details.
[5]
"For primary prevention measures, the company highly recommends passengers to contact their bank or credit card provider and follow their advice and change any compromised passwords as soon as possible," reads the company's canned statement.
[6]Un-carrier? Definitely Unsecure: T-Mobile US admits 48m customers' details stolen after downplaying reports
[7]Kaseya obtains REvil decryptor, starts sharing it with afflicted customers
[8]Northern Train's ticketing system out to lunch as ransomware attack shuts down servers
LockBit mostly targets organizations like enterprises and governments that will be disrupted enough by ransomware that paying up is the easy way out.
Earlier this month the gang hit outsourcing and accounting firm [9]Accenture . Rumors swirled that the cybercrims demanded $50 million in cryptocurrency from the consulting MNC. The deadline was continually moved forward until Accenture concluded the stolen data was not significant.
Another LockBit target was UK train operator [10]Merseyrail , which fell victim in April 2021. Trains continued to run on time, but the criminals got bragging rights after reportedly pwning a company director's Office 365 account and using it to email employees and journalists about their achievement. ®
Get our [11]Tech Resources
[1] https://www.bangkokair.com/press-release/view/clarifies-the-incident-of-a-cybersecurity-attack
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YS395jiGhmPLFCf@37R3ZwAAAI0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YS395jiGhmPLFCf@37R3ZwAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YS395jiGhmPLFCf@37R3ZwAAAI0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YS395jiGhmPLFCf@37R3ZwAAAI0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/08/18/t_mobile_us_admits_hack_48m_users/
[7] https://www.theregister.com/2021/07/23/kaseya_obtains_revil_decryptor_starts/
[8] https://www.theregister.com/2021/07/20/northern_trains_ticketing_system/
[9] https://www.theregister.com/2021/08/12/accenture_lockbit_ransomware/
[10] https://www.theregister.com/2021/04/28/merseyrail_ransomware_claim/
[11] https://whitepapers.theregister.com/
Don't mess with Dr Prasert
They don't know who they're dealing with. Bangkok Airways owner (also owner of Samui airport), Dr Prasert is a tough cookie. He'd never pay, and more, he'd go after the hackers. I hope they're not Thai or they'll be sleeping with the fishes.
Re: Don't mess with Dr Prasert
I worry about this. So I back up my data every week and scp it to a remote disk.
If I am ever hit with this I will only lose one week's data, which while painful isn't too bad. I never miss a backup, because my data is important to me. Also, for my bank account login details I never save them on my laptop, so if they do get my data they still won't be able to log in to my accounts.
Finally, I lock my other logins with a master password on Firefox. I'm not sure how safe that is but at least it is one more hurdle for them to overcome.
Re: Don't mess with Dr Prasert
And hackers look for precisely this behavior. A backup is worthless if it is not "tested". It is only if you can recreate the information you backed up can you trust that the hacker hasn't tampered with something in your backup process.
It could something simple, like modifying your scp to encrypt using a public key before storing the file on the other side. Or it could be just storing 0's.
That is something simple. Hackers are a lot more creative.
loses lotsa data after refusing to pay
Nope, the data were lost before refusing to pay.
Bangkok Airways was right not to pay. Even if it did, it could expect having the data sold to other miscreants anyway.