
The perceived interest in Brazil and Portugal suggests that the ransomware group consists of Portuguese-speaking members.

However, the Brazilian technology website TecMundo reported that Lapsus$ consisted of a Spaniard and several Colombians.Īccording to Portuguese authorities, the ransomware attack on Impresa is the largest in the country’s history. The attack also comes hot on the heels of another suspected ransomware attack on a Norwegian media giant Amedia that manages more than 90 publications.
#JACK CABLE GROUP RANSOMWHERE TV#
#cybersecurity #respectdata Click to Tweet Impresa group suffered a #ransomware attack that shut down the media company’s websites, disrupted Expresso Newspaper, and pulled SIC TV stations offline. “Being able to continuously validate people, processes, and technologies is always going to be a struggle,” Elizabeth Wharton, Vice President, Operations, SCYTHE, said. “Ransomware gangs like Lapsus$ may use the same tactics, techniques, and procedures (TTPs) to carry out their attacks, or they may reorder the TTPs to fly under the radar. Various blockchain analysis groups have the means to compile ransomware statistics, but only for a price.Ĭompanies need to continuously test their controls using threat intelligence, like the news of this attack, to protect their business interests.The FBI notes in its annual IC3 report that ransomware is uniquely underreported, and its statistics can't really be trusted. That is unfortunate, as the information would be invaluable as researchers hope to get a handle on the scope of ransomware and what could be done to prevent further outbreaks. "We don't have at least publicly comprehensive data sets for payments. And without that, it can be hard to gauge the impact of whether what we're doing makes a difference," said Jack Cable, a Krebs Stamos Group researcher. In his spare time Cable's working on Ransomwhere, an open visualization website analyzing Bitcoin wallet transactions.

Cable formally launched the site last week, based on publicly available wallet information, user wallet submissions and bulk information donations from researchers. If the project goes well, Cable sees it as a means to evaluate the success of different ransomware prevention policies. "People have proposed different ways of combating ransomware via economic means, whether that's outright banning payments or other methods, such as Putin to get some of this under control.
