LockBit brags: We'll leak thousands of SpaceX blueprints stolen from supplier
- Reference: 1678750812
- News link: https://www.theregister.co.uk/2023/03/13/lockbit_spacex_ransomware/
- Source link:
The prolific cybercrime crew also mocked the SpaceX supremo, and threatened to leak or sell on the blueprints from March 20 if the gang's demands to pay up aren't met. This may therefore be a bill Musk can't avoid to reconcile, [1]unlike others , reportedly.
"I would say we were lucky if SpaceX contractors were more talkative. But I think this material will find its buyer as soon as possible," Lockbit posted on its dark-web homepage, according to a screenshot [2]shared on Twitter by security analyst Dominic Alvieri.
[3]
We take that broken English to mean Maximum Industries may not be willing to cough up so far, yet the gang believes it may be paid either way: the ransom demand is provided to ensure any stolen files remain unpublished, or someone else will purchase a copy of the data anyway. What's interesting is that the schematics by themselves may not be that useful: you still have to manufacture the parts, which is non-trivial, and then use them without setting off suspicion.
[4]
[5]
A leak would still be embarrassing, and might attract unwanted attention from the US government – for the crooks and the businesses involved, given the reliance on SpaceX to launch stuff for Uncle Sam.
"Elon Musk, we will help you sell your drawing to other manufacturers — build the ship faster and fly away," the gang continued. It also claimed the 3,000 drawings had been "certified" by SpaceX engineers, but we can't confirm if anyone outside of the ransomware gang has verified the purloined dataset is what it's claimed to be.
[6]
Neither SpaceX nor Maximum Industries responded to The Register 's calls and emails seeking comment on the reported security breach.
These SpaceX claims follow several others by LockBit-affiliated criminals, which aren't always the most honest bunch about what — if anything — they've stolen.
Last month, the same group of miscreants [7]claimed to have infiltrated financial technology firm ION and threatened to publish stolen data on February 4 if the software provider doesn't pay up. LockBit [8]said the ransom was paid, but they didn't provide any proof and ION declined to comment.
[9]LockBit's Royal Mail ransom deadline flies by. No data released
[10]LockBit brags it pumped ION full of ransomware
[11]Pepsi Bottling Ventures says info-stealing malware swiped sensitive data
[12]Intruder alert: WH Smith hit by another cyber attack
Meanwhile, another alleged LockBit victim, Royal Mail in the UK, resumed international shipments in February after [13]confirming a "cyber incident" the month prior. Ultimately, the malware slingers appeared to have [14]given up on getting the ransom they asked from Royal Mail before publishing some files they claimed were from the stolen loot.
The UK mail service [15]told Reuters that its investigation didn't find any financial or sensitive customer information among the data the thieves stole. ®
[16]
Stop press: As we were going live with this article, it's [17]claimed the ALPHV ransomware crew is trying to extort Amazon doorbell-maker Ring. We're investigating.
Get our [18]Tech Resources
[1] https://www.theregister.com/2023/01/31/twitter_market_square_lawsuit/
[2] https://mobile.twitter.com/AlvieriD/status/1635376556003713026
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZA--dbpoQPLPMZ3rA5deEwAAAJA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZA--dbpoQPLPMZ3rA5deEwAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZA--dbpoQPLPMZ3rA5deEwAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZA--dbpoQPLPMZ3rA5deEwAAAJA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.theregister.com/2023/02/03/ion_ransomware_attack/
[8] https://www.reuters.com/technology/hackers-say-ransom-paid-case-derivatives-data-firm-ion-company-declines-comment-2023-02-03/
[9] https://www.theregister.com/2023/02/13/lockbits_royal_mail_ransom_deadline/
[10] https://www.theregister.com/2023/02/03/ion_ransomware_attack/
[11] https://www.theregister.com/2023/02/14/pepsi_bottling_malware/
[12] https://www.theregister.com/2023/03/02/wh_smith_breach/
[13] https://www.theregister.com/2023/01/11/royal_mail_uk_cyber_incident/
[14] https://www.theregister.com/2023/02/13/lockbits_royal_mail_ransom_deadline/
[15] https://www.reuters.com/technology/lockbit-ransomware-group-threatens-publish-stolen-royal-mail-data-techcrunch-2023-02-07/
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZA--dbpoQPLPMZ3rA5deEwAAAJA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[17] https://twitter.com/vxunderground/status/1635427567271329792
[18] https://whitepapers.theregister.com/
Yes, I think this is one situation where the black helicopters in your front yard is not a joke.
MaximumInd.com - no HTTPS
It seems this contractor hasn't even bothered to implement HTTPS on their website. In all fairness, there isn't any authentication on their site, but they do have an RFP form. They probably could care less about Google page rank lowering them down a few notches. However, one could infer that IT modernization is likely a low priority for this metal working company.
From what I can tell they most likely cut thick chunks of metal into flanges, bulkheads and the like. I'm doubtful that someone would be able to do much with these blueprints. If the CCP makes a Phalcon-IX, and it works, I would be astonished.
I have a steel company as a client, and they also don't seem to care much about keeping things updated. They had an XP box in daily use until last year. The most I could do was to convince them to do is to not connect it to the internet.
Generally, there's a rule of thumb when it comes to blackmail / extortion. Never ask for more than it would cost to have you silenced.
I'd rather not think too deeply about exactly how determined or petty Mr Musk might get, but he's not the only one with an interest in technology like this. There are several US government agencies that I assume would rather this technology didn't get into another nation's hands, and I could well believe that they might use fairly severe methods to ensure that.
They are playing a dangerous game, I feel. It's probably safer to stick to stealing customer / patient details - companies would pay to avoid the bad publicity, but if things go south they'll just trot out the "we take our customers' security seriously" line and stay quiet for a year.