Skip to main content
News

Cyber News Rundown: Royal Ransomware takes down City of Dallas

Cyber News Rundown: Royal Ransomware takes down City of Dallas
Forum|alt.badge.img+7
  • Threat Research Analyst
  • 4 replies

Last week, officials for the City of Dallas were forced to take many of their crucial IT services offline after their security team discovered the beginnings of a ransomware attack. The incident, which has caused the entire Dallas judicial system to delay any proceedings until further notice, has been confirmed as an attack by the Royal Ransomware group after ransom notes started printing from all network-connected printers. Ransomware attacks on local governments have been constantly on the rise in recent years and have targeted over 30 cities in 2023 alone.

San Bernadino County pays $1.1 million ransom

A month after first identifying the ransomware attack on their systems, the San Bernadino County Sheriff’s Office has agreed to pay their portion of the $1.1million ransom to restore their files and resume normal operations. While the incident did not compromise any sensitive information on employees or citizens, the interruptions to the Sheriff Office’s operations have caused significant delays in law enforcement activities for all agencies that they regularly interact with. San Bernadino County was only responsible for $511k of the demanded ransom, as their insurance covered the remainder.

NextGen Healthcare breach impacts over 1 million patients

The healthcare software provider, NextGen Healthcare, has recently announced that they were victims of a data breach, that had illicitly accessed sensitive records for over 1 million patients. The breach occurred in March and the hackers remained connected to the system for several weeks, before NextGen staff secured their network. As this breach contains a significant amount of personally identifiable information, officials for NextGen have begun notifying all affected patients and are warning them to be vigilant of any phishing attempts or unusual activity regarding their credit or identity.

Cactus Ransomware encrypts itself to avoid detection

Researchers have been tracking a new ransomware variant that uses an unusual tactic to avoid detection by any security software: self-encryption. The variant in question, Cactus Ransomware, begins its attack by exploiting a VPN vulnerability to access the network, then runs encryption on each victim file two times before running an encryption sequence on the main ransomware binary. Alongside the encryption process, Cactus also runs a batch script to uninstall any local antivirus programs and uses RClone to exfiltrate all encrypted files for additional victim exploitation.

Smashing Pumpkins pay hackers for stolen songs

Several months prior to the release of the latest Smashing Pumpkins’ album, hackers were able to obtain copies of several unreleased tracks from them and other artists, and threatened to release them if a ransom was not paid. After consulting with the FBI, the lead singer for the Smashing Pumpkins confirmed that he had paid an undisclosed ransom amount to prevent the leaks from occurring and was working to determine how the hackers were able to access the song files in the first place.

Did this help you find an answer to your question?

15 replies

ProTruckDriver
Moderator

Thanks again Connor for the informative article. 


russell.harris
Popular Voice
Forum|alt.badge.img+5

Thanks as always @ConnorM 

The Smashing Pumpkins brings back memories of my youth!


  • Administrator
  • 1 reply
  • May 12, 2023
russell.harris wrote:

Thanks as always @ConnorM 

The Smashing Pumpkins brings back memories of my youth!

Samesies! When I read this, I was like, NOT THE PUMPKINS!!


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

Thank you again Connor.


TripleHelix
Moderator
Forum|alt.badge.img+63
  • Moderator
  • 9015 replies
  • May 12, 2023

Thanks Connor for the great info!


  • New Member
  • 41 replies
  • May 16, 2023

Thanks for the info Connor....it is always good to read similar reports to stay sharp and awake toward similar attacks.


Forum|alt.badge.img+1
  • New Member
  • 56 replies
  • May 16, 2023

Good information cheers Connor 


Martin.1
Popular Voice
Forum|alt.badge.img+4
  • Popular Voice
  • 424 replies
  • May 16, 2023

@ConnorM  thank you for the article. Always good to read these and share as well. Keep people updated on the industry to always stay focus on what we do and why we do it. 


Martin.1
Popular Voice
Forum|alt.badge.img+4
  • Popular Voice
  • 424 replies
  • May 16, 2023
russell.harris wrote:

Thanks as always @ConnorM 

The Smashing Pumpkins brings back memories of my youth!

@russell.harris  what else is next if people can steal songs…… hope the culprits can get caught and a few concrete pumpkins smashed on their heads. 


russell.harris
Popular Voice
Forum|alt.badge.img+5
Martin.1 wrote:
russell.harris wrote:

Thanks as always @ConnorM 

The Smashing Pumpkins brings back memories of my youth!

@russell.harris  what else is next if people can steal songs…… hope the culprits can get caught and a few concrete pumpkins smashed on their heads. 

Oh yes


tasystems
New Voice
Forum|alt.badge.img+8
  • New Voice
  • 156 replies
  • May 16, 2023

Paying for your music to not be released… and honest guv, we will destroy all the stuff we have…. scary!


Robis
New Member
Forum|alt.badge.img+1
  • New Member
  • 74 replies
  • May 16, 2023

Thank You Connor


So I guess now is not the time to be filing for divorce…..

 

“Sorry your request has been denied because Ransomware Group said so”


kleinmat4103
Popular Voice
Forum|alt.badge.img+6
  • Popular Voice
  • 512 replies
  • May 17, 2023

Thanks, Conner!


russell.harris
Popular Voice
Forum|alt.badge.img+5
harminder.chagger wrote:

So I guess now is not the time to be filing for divorce…..

 

“Sorry your request has been denied because Ransomware Group said so”

😄


Reply