News: 1670974211

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

LockBit threatens to leak confidential info stolen from California's beancounters

(2022/12/14)


LockBit claims it was behind a cyber-attack on the California Department of Finance, bragging it stole data during the intrusion.

The notorious ransomware gang boasted it exfiltrated 76GB from the state agency, which apparently included databases, confidential information, financial and IT documents, and, oddly enough, "sexual proceedings in court." LockBit has promised to publish "all available data" on December 24, presumably unless the California state government pays a ransom, although no information has been released about any monetary demand.

To be clear: cybercriminals aren't the most trustworthy people. As Emsisoft threat analyst Brett Callow [1]said , "It should be noted that not all of LockBit's past claims have been true."

[2]#LockBit has listed the State of California's Finance Department. It should be noted that not all of LockBit's past claims have been true. 1/2 [3]#ransomware [4]pic.twitter.com/jmf5ap15xz — Brett Callow (@BrettCallow) [5]December 12, 2022

Officials in the US state did not go into much detail about the affair other than to confirm there had been a "cybersecurity incident." The California Cybersecurity Integration Center (Cal-CSIC) said it is "actively responding" to an intrusion into the Finance Department's IT network.

No state funds have been compromised, and the Department of Finance is continuing its work

The security breach was "proactively identified" through a coordinated state and federal effort, according to a [6]statement . "Upon identification of this threat, digital security and online threat-hunting experts were rapidly deployed to assess the extent of the intrusion and to evaluate, contain and mitigate future vulnerabilities," the center added.

The response team includes the Governor's Office of Emergency Services, Department of Technology, California Military Department and California Highway Patrol.

[7]

"While we cannot comment on specifics of the ongoing investigation, we can share that no state funds have been compromised, and the Department of Finance is continuing its work to prepare the Governor's Budget that will be released next month," the statement said.

[8]

[9]

A spokesperson for the Governor's Office of Emergency Services declined to share any other details about the intrusion or to confirm LockBit's claims.

[10]Inadequate IT partly to blame for NHS doctors losing 13.5 million working hours

[11]LockBit gang hit by DDoS attack after threatening to leak Entrust ransomware data

[12]LockBit ransomware gang claims it ransacked Italy's tax agency

[13]Lockbit wins ransomware speed test, encrypts 25,000 files per minute

Ransomware groups have attacked at least 101 state and local government agencies in the US this year, and at least 22 of those have had data stolen, according to Callow.

The LockBit gang has been around since [14]2019 , deploying its malware against [15]high-profile targets in multiple nations. According to US prosecutors, this ransomware strain has been deployed against more than 1,000 entities, and members of the gang have extracted [16]"tens of millions" of dollars in ransom payments.

Last month, Canadian authorities [17]arrested Mikhail Vasiliev, a suspected member of the infamous ransomware mob. The Canadian and Russian national is awaiting extradition to the US for his alleged involvement with LockBit. ®

Get our [18]Tech Resources



[1] https://twitter.com/BrettCallow/status/1602325828096098305

[2] https://twitter.com/hashtag/LockBit?src=hash&ref_src=twsrc%5Etfw

[3] https://twitter.com/hashtag/ransomware?src=hash&ref_src=twsrc%5Etfw

[4] https://t.co/jmf5ap15xz

[5] https://twitter.com/BrettCallow/status/1602325828096098305?ref_src=twsrc%5Etfw

[6] https://news.caloes.ca.gov/statement-on-cybersecurity-incident/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y5lYdk5bLmKIIa5Bwj@F@QAAAAM&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y5lYdk5bLmKIIa5Bwj@F@QAAAAM&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y5lYdk5bLmKIIa5Bwj@F@QAAAAM&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2022/12/09/inadequate_it_systems_contribute_to/

[11] https://www.theregister.com/2022/08/22/entrust_lockbit_ddos_ransomware/

[12] https://www.theregister.com/2022/07/26/lockbit-italy-ransomware-attack/

[13] https://www.theregister.com/2022/03/23/ransomware_encryption_speed/

[14] https://www.theregister.com/2022/07/26/lockbit-italy-ransomware-attack/

[15] https://www.theregister.com/2022/10/14/nhs_software_hosting_provider_advanced_ransomware_lockbit/

[16] https://www.justice.gov/usao-nj/pr/russian-and-canadian-national-charged-participation-lockbit-global-ransomware-campaign

[17] https://www.theregister.com/2022/11/12/in_brief_security/

[18] https://whitepapers.theregister.com/



101 State and Local Government Agencies

Lil Endian

Ransomware groups have attacked at least 101 state and local government agencies in the US this year, and at least 22 of those have had data stolen....

How many agencies have reinforced ransomware attacks as "a good idea" by paying the ransom (with tax payers' money)?

How much has been paid?

Did the payouts result in return of data?

bugs in the RAID