News: 1706271910

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Akira ransomware gang says it stole passport scans from Lush in 110 GB data heist

(2024/01/26)


The Akira ransomware gang is claiming responsiblity for the "cybersecurity incident" at British bath bomb merchant.

Akira says it has stolen 110 GB of data from the UK-headquartered global cosmetics giant, which has more than 900 stores worldwide, allegedly including "a lot of personal documents" such as passport scans.

Passport scans are routinely collected to verify identities during the course of the hiring process, which suggests Akira's affiliate likely had access to a system containing staff-related data.

[1]

Company documents relating to accounting, finances, tax, projects, and clients are also said to be included in the archives grabbed by the cybercriminals, who are threatening to make the data public soon. There is still no evidence to suggest customer data was exposed.

[2]

[3]

Akira's retro-vibe website separates victims into different sections: One for companies who didn't pay the ransom and thus had their data published, and another for those whose data is to be published on an undisclosed date.

A likely conclusion to draw, if the incident does indeed involve ransomware as the criminals claim, is that there may have been negotiations which have stalled, with Akira using the threat of data publication as a means to hurry along the talks.

[4]

The Register approached Lush for comment. Its representatives acknowledged the request but did not provide a statement in time for publication.

Lush last communicated about the situation on January 11, saying it was responding to an "incident" and working with outside forensic experts to investigate the issue – often phrasing used in a ransomware attack.

"The investigation is at an early stage but we have taken immediate steps to secure and screen all systems in order to contain the incident and limit the impact on our operations," it [5]said . "We take cybersecurity exceptionally seriously and have informed relevant authorities."

[6]

The statement came a day after a post was made to the unofficial Lush Reddit community. Written by a user who seemingly had inside knowledge of the incident, [7]the post claimed members of staff were instructed to send their laptops to head office for "cleaning" – an assertion that El Reg understands to be true.

Akira is better known for its [8]extortion-only MO, which it adopted more recently in October 2023.

A recent [9]report from researchers at Sophos revealed that they only responded to a single case that actually led to the deployment of a ransomware payload, and that was back in August 2023. That said, this intel is limited only to Sophos's engagements – other incident response companies may have a different story to tell.

Chester Wisniewski, director, global field CTO at Sophos, said today: "It is unclear if this was a ransomware attack or simple extortion as Sophos Incident Response Services has observed this crew to engage in either or both activities with their victims. If it was extortion without an encryption component this could be why there has been no visible external disruption to Lush's operations."

[10]Trickbot malware scumbag gets five years for infecting hospitals, businesses

[11]EquiLend drags systems offline after admitting attacker broke in

[12]Major IT outage at Europe's largest caravan and RV club makes for not-so-happy campers

[13]Using GoAnywhere MFT for file transfers? Patch now – an exploit's out for a critical bug

He added: "Akira is developing into a force to be reckoned with. We first observed them in early 2023 and have seen an increasing number of victims approach our incident response service. They seem to favor attacking vulnerable Cisco VPN products and remote access tools without [14]MFA deployed. While we don't know the cause of Lush's alleged breach this is a great reminder of the importance of expedient patching of all external facing network components and the requirement for multifactor authentication for all remote access technologies."

The group is primarily known for targeting organizations in the UK, Australia, and North America, and also its indiscriminate targeting of industries – anyone is fair game for them.

According to SentinelOne's [15]insights , Akira also demands "outrageous ransom payments" that can regularly reach US dollar sums in the nine-figure range.

Trend Micro's [16]analysis found that the group is run by "highly experienced and skilled operators" and is thought to be one of the many spin-off gangs following the crumbling of Conti in 2022.

Blockchain data and the source code of Akira's ransomware payload both pointed to a relationship with Conti, itself a descendant of Ryuk, both of which were considered the most menacing ransomware operations of their times.

Akira is also believed to be behind the recent attack on Finnish IT service provider Tietoevry, which has affected a number of online services at Swedish government departments and some of the country's universities.

According to a [17]press release , the attack was limited to only to one of Tietoevry's Swedish datacenters, and the incident is contained, but the company isn't sure how long it will take to fully recover. ®

Get our [18]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZbPlPl7pPAZMXQUlFYWVRQAAAcQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbPlPl7pPAZMXQUlFYWVRQAAAcQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZbPlPl7pPAZMXQUlFYWVRQAAAcQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZbPlPl7pPAZMXQUlFYWVRQAAAcQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://weare.lush.com/lush-life/company-statements/lush-cyber-incident/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZbPlPl7pPAZMXQUlFYWVRQAAAcQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.reddit.com/r/LushCosmetics/comments/193g7tv/lush_have_had_a_cyberattack/

[8] https://www.theregister.com/2022/10/09/extortion_ransomware_threats_category/

[9] https://news.sophos.com/en-us/2023/12/21/akira-again-the-ransomware-that-keeps-on-taking/

[10] https://www.theregister.com/2024/01/25/trickbot_malware_dev_sentenced/

[11] https://www.theregister.com/2024/01/25/cybersecurity_incident_forces_equilend_to/

[12] https://www.theregister.com/2024/01/24/major_it_outage_at_caravan/

[13] https://www.theregister.com/2024/01/24/public_exploit_published_within_hours/

[14] https://www.theregister.com/2023/11/07/microsoft_likens_mfa_to_1960s/

[15] https://www.sentinelone.com/anthology/akira/

[16] https://www.trendmicro.com/vinfo/gb/security/news/ransomware-spotlight/ransomware-spotlight-akira

[17] https://www.tietoevry.com/en/newsroom/all-news-and-releases/other-news/2024/01/ransomware-attack-in-sweden-update/

[18] https://whitepapers.theregister.com/



Doctor Syntax

You have to wonder just when it will dawn on HR types that personal data held for a moment longer than needed becomes toxic waste. Perhaps a mandatory fine of 1,000 GBEurollars per retained passport scan discovered on audit* and 10x that for each taken in a heist would have some effect. But probably not.

* It's time for compulsory unannounced audits of organisations licensed** to hold personal data of more than, say 100 people.

** Yes, it's time for such licensing.

Hoarding personal data like a flabby dragon sat on it's treasure

tmTM

Maybe someone needs to walk into HR and stick the boot in, demand to know why they thought it was a good idea to store all this stuff?

Passport scans

that one in the corner

> are routinely collected to verify identities during the course of the hiring process

Collected? Not just "checked and that check signed off by HR"?

Oh no, of course not, that might mean that HR actually has to take responsibility for doing their job and putting their name to it. Far less damaging[1] to demand and keep a scan.

[1] to that HR hack, that is.

Korev

Did they use SOAP webservices at Lush?

There we go again - Passport scans are routinely collected

Joe-Thunks

There should be a time limit on this. After somebody has been "verified", the scan should be deleted permanently. A fine of £10,000 for every scan retained if it is not deleted.

All these companies siphon up data, keep it stored insecurely. Then they get to wash their hands of the problems they cause by having poor security.

Re: There we go again - Passport scans are routinely collected

gryphon

Problem might be that the immigration service no doubt says that records must be kept for XYZ years to verify that proper employment checks were done when hiring.

i.e. HR would have to prove that they were presented with what looked like authentic documents at the time rather than just have their word taken for it.

Even then they could probably just print out the passport scans etc. and stick them in a handy filing cabinet with a reference rather than leaving them on a computer.

They should certainly be deleting / shredding any that relate to past employees one would think since keeping those would surely breach Data Protection laws.

Translating Spokespeak

Doctor Syntax

"we have taken immediate steps to secure and screen all systems in order to contain the incident and limit the impact on our operations,"

Translation: we've sent comeone to the ironmongers for stable door bolts.

"We take cybersecurity exceptionally seriously"

Translation: we/ve just discovered cybersecurity has to be taken exceptionally seriously"

Alternative translation: Cybersecurity is to be taken seriously but we made an exception.

STOP SCRAPING AND KEEPING!

Plest

Tell me, in the name of that's holy and blessed, why the fricking hell a shop that sellls fricking soap, needs to be storing customer's passport scans?! Employees in the HR DB, fair enough but customers?! I hope they had a damn good reason else GDPR will be ragging their arses once the hackers have finished having their fun.

"But I don't like Spam!!!!"