News: 1708351346

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

ALPHV gang claims it's the attacker that broke into Prudential Financial, LoanDepot

(2024/02/19)


The ALPHV/BlackCat ransomware group is claiming responsibility for attacks on both Prudential Financial and LoanDepot, making a series of follow-on allegations against them.

Both US companies recently confirmed ( [1]here and [2]here ) cybersecurity incidents via Form 8-K filings with the Securities and Exchange Commission (SEC), but neither document mentioned the involvement of ransomware.

Neither company has had any of their stolen data leaked at this stage, although if negotiations continue to stall as ALPHV says they have (presuming its claims are true), then a data dump may not be too far away.

[3]

The [4]advice from both CISA and the FBI is that victims should not pay ransom demands to cybercriminals, and in many cases this is followed.

[5]

[6]

When ransom demands aren't paid, however, victims are often "punished" by having their attacks publicized, before continued non-compliance with the criminals' demands leads to data disclosure. That's the double extortion model.

ALPHV has now made a number of inflammatory allegations against both victims, which of course should be taken with a substantial grain of salt given that they are indeed criminals.

[7]

In the case of [8]Prudential Financial , the gang has alleged that the company fibbed in its regulatory filing, which claimed the attackers broke in on February 4 and systems were contained a day later.

"The claims… are categorically false. We continue to have uninterrupted access to their network and are actively exfiltrating information," ALPHV alleged on its site. "This can be verified as we sent the CEO, CIO, and legal person an email today showing evidence of this [as of] Feb 15."

The gang said it is currently looking for customers who may wish to buy the stolen data, but will consider releasing it for free. This follows Prudential's claim that it had seen no evidence of customer or client data being stolen. It made no such exclusions for other data types.

[9]

If the allegations are true, the company could face a backlash from the SEC and investors. However, it's worth remembering that ALPHV made a name for itself towards the back end of last year for weaponizing regulators against ransomware victims.

For example, in a novel November 2023 case, ALPHV [10]filed an SEC complaint against fintech firm MeridianLink for failing to notify the regulator of a material breach. It was seen as a new way for cybercriminals to hasten the ransom payment negotiations beyond the traditional methods.

So, until we hear Prudential's side it's worth exercising some extreme caution before we buy into these claims.

As regards LoanDepot, the company [11]confirmed a breach in early January with the SEC but didn't confirm ransomware's involvement.

If ALPHV was indeed responsible for the attack here, the group has allowed negotiations to carry on for a month and a half. Many groups lose patience much sooner.

According to the criminals, LoanDepot's negotiators deployed stalling tactics presumably to delay the release of stolen data. An initial ransom payment of $6 million was proposed, but it wanted extra time to secure a bigger sum, at least that's ALPHV's claim. After that, the company stopped replying, apparently.

The Register contacted both Prudential Financial and LoanDepot for comment but neither immediately responded.

Evasive ALPHV

The ALPHV ransomware group continues to frustrate US authorities by terrorizing major organizations under its watch after surviving a takedown attempt in December.

It's not often a cybercrime operation can withstand and overcome attempts to shutter it after international law enforcement sets out to dismantle its infrastructure, but that's what happened in December when ALPHV [12]wrestled the feds for control of its site over the space of a few days.

It seems the BlackCat does indeed have nine lives, as they say.

When the FBI's initial seizure splash page appeared on the outfit's dark web site, followed by press releases lauding the takedown and release of a decryptor, infosec watchers believed one of the world's most notorious ransomware gangs had fallen like so many before it.

Fast-forward two months and it's like nothing happened. The group's website is back up and running and affiliates continue to claim major attacks on Western organizations.

[13]Feds post $15 million bounty for info on ALPHV/Blackcat ransomware crew

[14]ALPHV blackmails Canadian pipeline after 'stealing 190GB of vital info'

[15]New kids on the ransomware block in 2023: Akira and 8Base lead dozens of newbies

[16]Thieves steal 35.5M customers’ data from Vans sneakers maker

Most recently, it allegedly broke into Canada's [17]Trans-Northern Pipelines – an attack on a critical infrastructure organization that naturally brings back memories of DarkSide's [18]Colonial Pipeline incident.

It may also not be a coincidence, given that ALPHV is linked to BlackMatter, which itself was linked to DarkSide.

Towards the end of last week, the US [19]announced that it would offer a maximum total reward of $15 million for information leading to the identification or location of ALPHV leadership members and/or their arrest. ®

Get our [20]Tech Resources



[1] https://www.sec.gov/Archives/edgar/data/1137774/000119312524033753/d770643d8k.htm

[2] https://www.sec.gov/Archives/edgar/data/1831631/000183163124000011/pressrelease.htm

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZdOJN3@9QQDde10zCjzoBgAAAFg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-061a

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZdOJN3@9QQDde10zCjzoBgAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZdOJN3@9QQDde10zCjzoBgAAAFg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZdOJN3@9QQDde10zCjzoBgAAAFg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://www.theregister.com/2024/02/14/prudential_financial_finds_cybercrims_lurking/

[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZdOJN3@9QQDde10zCjzoBgAAAFg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[10] https://www.theregister.com/2023/11/16/clorox_ciso_washes_out/

[11] https://www.theregister.com/2024/01/10/fidelity_data_disclosure/

[12] https://www.theregister.com/2023/12/19/blackcat_domain_seizure/

[13] https://www.theregister.com/2024/02/19/infosec_news_in_brief/

[14] https://www.theregister.com/2024/02/13/alphv_canadian_pipeline/

[15] https://www.theregister.com/2024/02/06/akira_and_8base_new_ransomware_research/

[16] https://www.theregister.com/2024/01/19/vf_corp_ransomware_impact/

[17] https://www.theregister.com/2024/02/13/alphv_canadian_pipeline/

[18] https://www.theregister.com/2022/05/09/in_brief_security/

[19] https://www.theregister.com/2024/02/19/infosec_news_in_brief/

[20] https://whitepapers.theregister.com/



What Did Santa Claus Bring You In 1999? (#1)

LINUS TORVALDS: Santa didn't bring me anything, but Tim O'Reilly just gave
me a large sum of money to publish my new book, "Linus Torvalds' Official
Guide To Receiving Fame, Fortune, and Hot Babes By Producing Your Own
Unix-Like Operating System In Only 10 Years".

ORDINARY LINUX HACKER: I kept hinting to my friends and family that I
wanted to build my own Beowulf Cluster. My grandmother got mixed up and
gave me a copy of "Beowulf's Chocolate Cluster Cookbook". I like
chocolate, but I would've preferred silicon.

LINUX LONGHAIR: My friends sent me a two-year subscription to several
Ziff-Davis publications, much to my dislike. I don't want to read Jesse
Berst's rants against Linux, or John Dvorak's spiels about how great
Windows 2000 is. Still, I suppose this isn't so bad. Ziff-Davis glossy
paper makes an excellent lining for fireplaces.