Ransomware crew dumps stolen Optionis files online
- Reference: 1644582546
- News link: https://www.theregister.co.uk/2022/02/11/optionis_stolen_data/
- Source link:
Optionis Group houses brands including Parasol Group, Clearsky, SJD Accounting and NixonWilliams.
The Vice Society ransomware gang dumped what appears to be thousands of files onto their dark web blog as downloadable links, as seen by The Register .
[1]
The vast cache was published shortly before Optionis Group, which also houses an umbrella company popular with tech contractors alongside its accounting businesses, [2]emailed its tech contractor customers saying "some data belonging to Optionis was copied from our system."
[3]
[4]
Although we can't publish a screenshot here because doing so would expose filenames which themselves refer to sensitive data, The Reg has seen spreadsheets with names suggesting they contain the management accounts of some customers' companies. Other files appear to be timesheets for contractors, as well as letters to and from HM Revenue and Customs discussing customers' tax status.
"These types of attacks can have far-reaching effects, resulting in numerous freelancers not being paid, or companies being unable to pay employees on time. Clearly, the knock-on effects of this are employees suffering the consequences and potentially not being able to pay for essential living costs," said infosec firm Cyjax in a client note addressing the breach.
[5]
Several contractors that we spoke to who use the payroll services provided by Parasol, the umbrella company in Optionis, told us they had only been partially paid for freelance work undertaken in January.
Vice Society previously hit the public radar after [6]targeting the Spar supermarket chain , triggering a wave of shutdowns. Cisco Talos, in a [7]blog post last summer, described the crew as targeting American schools and similar educational institutions. The threat intel business noted that Vice Society tended to target VMware ESXi virtualization servers, as well as using the [8]PrintNightmare Windows spooler vuln .
[9]Spar shops across northern England shut after cyber attack hits payment processing abilities
[10]Vice Society said to be behind digital break-in at UK umbrella and accounting group
[11]UK, US, Australia issue joint advisory: Ransomware-as-a-service on the loose, critical national infrastructure affected
[12]Azure Site Recovery points now live for 15 days in case undetonated ransomware lurks
The dumping of contractors' data online is the usual step when a targeted organisation refuses to pay a ransom, in what experts have dubbed the "double extortion" ransomware method. In this model, not only are an organisation's files encrypted so the crims can demand payment for the decryptor, but files are exfiltrated – allowing the crooks to demand a second ransom to prevent their publication.
Optionis previously claimed to have 13,000 contractors on its books. The accounting firm was breached back in January, as it said [13]after discovering "unauthorised activity" on its networks and pulling the plug.
Optionis did not respond to The Register 's request for comment, but we will update this article when it does. We have asked the ICO to comment. ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YgaWOPhf06rZ0ZCtmwghOAAAAJM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.theregister.com/2022/02/08/optionis_vice_society/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YgaWOPhf06rZ0ZCtmwghOAAAAJM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YgaWOPhf06rZ0ZCtmwghOAAAAJM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YgaWOPhf06rZ0ZCtmwghOAAAAJM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/12/06/spar_cyber_attack/
[7] https://blog.talosintelligence.com/2021/08/vice-society-ransomware-printnightmare.html
[8] https://www.theregister.com/2021/08/11/printnightmare_mitigation/
[9] https://www.theregister.com/2021/12/06/spar_cyber_attack/
[10] https://www.theregister.com/2022/02/08/optionis_vice_society/
[11] https://www.theregister.com/2022/02/09/uk_us_au_ransomware_warning/
[12] https://www.theregister.com/2022/02/08/azure_site_recovery/
[13] https://www.theregister.com/2022/01/17/umbrella_company_parasol_group_confirms/
[14] https://whitepapers.theregister.com/
I bet it all comes down to services!
Welcome to the world where CEOs see in house IT as a financial dirty black hole, farm it out to rock bottom service companies they have CEOs that think in house IT is a financial dirty black hole, so farm it out to....
You get the idea. The second you crap on your in house staff by telling them their skills cost too much and you're buying services in, kiss goodbye to goodwill and all those little things that people do when they feel safe in their jobs that keep thousands of companies going. You dial in 20 mins early, you clean up that filesystem, you fix that housekeeping jobs, you remove that back param or data that will mess up the batch run, all as a little extra to keep things running smoothly.
My first day in a service company after 10 years in a private firm a fellow techie told me over lunch, "Don't ever fix anything yourself. If we can charge for it, write it up, log it and pass it to the customer and the account manager for the monthly review. Fixes are not your job unless they're on your work sheet for that day, pass it along and if it's important and they can afford it, they will pay for it.".
6 months later, bored out of my skull not learning anything or doing anything useful, I went screaming back to contract work in private companies and never looked back, that was 20 years ago.
Here we are in 2022 and financial companies are getting data tapped for info that simply gets copied out in mins and dumped on the open market like a bloody carcass into a pack of baying jackals. Retirement on the horizon, can't wait.
Re: I bet it all comes down to services!
In house IT teams will generally put in a bit more effort to keep things ticking over; it's in their interest, after all, since it's job stability, performance bonuses and share options in many cases. Outsourced IT workers will generally do the minimum required to meet the SLA and service improvements won't happen unless it's billable (at an appropriate markup, obviously).
"Optionis previously claimed to have 13,000 contractors on its books"
I wonder how many they will claim next time.
I hope they can pay the ICO fine?
How do I know if my company / personal data has been accessed?
Can the punters claim against their Insurance?
Time to log your time and effort getting through to them, pay your bills when you only received a token payment, the stress you are going through.
Changing Umbrella company or Accountants just before the end of UK tax year. Confirming if your Self assessment or VAT return has been submitted.