Failed blackmail attempt prompts hackers to leak ocean of data belonging to major companies

Failed blackmail attempt prompts hackers to leak ocean of data belonging to major companies 1

A hacking group has published a trove of data belonging to Citycomp which appears to have exposed the data of customers, some of which are extremely well-known enterprise companies across the globe.

Citycomp is a German IT company which provides the IT backbone and infrastructure required by enterprise companies. Citycomp says it maintains over 70,000 services and storage systems, as well as providing support and maintenance services for peripherals including cash register systems and printers.

In a statement issued this week, the company said it was the victim of a “targeted” cyberattack in early April this year.

While the company said it was able to “successfully fend off” the “hacker attack” with the help of external cybersecurity experts and the State Criminal Police Office of Baden-Württemberg, it was not entirely successful — as customer data had already been stolen.

The threat actors identities are unknown. However, it appears the attack was simply about the money, as the hackers tried to force Citycomp to pay a blackmail fee on the threat of the data entering the public domain.

Citycomp did not comply and so customer data has been released.

TechRepublic: Why third-party providers pose a security risk to organizations

“Since Citycomp does not comply with blackmail the publication of customer data could not be prevented,” the IT provider says. “The stolen data has now been published by the perpetrators and Citycomp’s customers were informed about it.”

The leaked data has been posted to a .onion domain, which is not accessible in the “public” clear Internet. These domains can only be accessed through the Tor network.

On the website, the threat actor claims that “312,570 files in 51,025 folders and over 516GB of data” was stolen, including “financial and private information on all clients, include VAG, Ericsson, Leica, MAN, Toshiba, UniCredit, and British Telecom (BT).”

See also: DJI employee who leaked source code sent behind bars

Other Citycomp clients named in the data dump include ATOS, Grohe, Hugo Boss, Oracle, SAP, and Porsche, among others.

In the data dump, which was viewed by ZDNet, customer email addresses and telephone numbers, meetings reports, asset lists — such as servers and other equipment connected to a customer account — as well as some payroll records, project sheets, and accountancy statements were all available. 

Some clients were only connected to a handful of leaked documents, whereas other customer records were far more robust and extensive. The authenticity of the leaked data has not been verified at the time of writing.

The ProtonMail email address posted with the information leak is connected to a form of ransomware which encrypts files using the .snatch extension. The ransomware strain in question was discovered in December 2018.

CNET: Cybercriminals ramping up fraud attacks on social media, says report

The — or one — of the alleged hackers behind the campaign spoke to the Register, telling the publication that the data currently available online is only a sample of the whole and was published as Citycomp did not pay a $5,000 ransom demand.

ZDNet has reached out to clients which appear to have been involved in the breach, including BT, Oracle, Ericsson, Hugo Boss, and SAP. At the time of writing, none of the companies have responded to requests for comment. 

Previous and related coverage

Have a tip? Get in touch securely via WhatsApp | Signal at +447713 025 499, or over at Keybase: charlie0

About the author

E-Crypto News was developed to assist all cryptocurrency investors in developing profitable cryptocurrency portfolios through the provision of timely and much-needed information. Investments in cryptocurrency require a level of detail, sensitivity, and accuracy that isn’t required in any other market and as such, we’ve developed our databases to help fill in information gaps.

Related Posts

E-Crypto News Executive Interviews

Automated trading with HaasBot Crypto Trading Bots

Crypto Scams

Millions in Cryptocurrency Stolen by Scammers in the Last Month According to Tenable Research
November 24, 2021
Behind The Scenes: How this Crypto Community Responded to + $50m Hack
October 18, 2021
Crypto Scams
Crypto Scams Still Persistent In 2021, SEC Warns About Red Flags To Watch
September 9, 2021
Poly Network
Here’s How Hackers Stole Over $600 million in the Poly Network Attack
August 12, 2021
The World’s Most Infamous Crypto Hacks and Scams
July 31, 2021

Blockchain/Cryptocurrency Questions and Answers

Crypto casinos
How Does Bitcoin Casino Work + 2021 Beginner’s Guide
November 8, 2021
How to Buy and Sell Cryptocurrency
November 8, 2021
What Are Bitcoin Futures And How Will They Work In 2022?
November 4, 2021
The Unconventional Guide to Ethereum
October 28, 2021
ICo Presale
The Science Behind ICO Presales…
October 14, 2021

CryptoCurrencyUSDChange 1hChange 24hChange 7d
Bitcoin48,429 0.40 % 2.07 % 15.39 %
Ethereum4,078.0 0.30 % 2.92 % 4.94 %
Binance Coin540.62 0.50 % 5.61 % 11.58 %
Tether0.9986 0.03 % 0.08 % 0.23 %
Solana184.62 1.85 % 7.81 % 7.90 %
Cardano1.310 0.43 % 5.68 % 18.03 %
USD Coin1.000 0.14 % 0.20 % 0.17 %
XRP0.7738 0.65 % 7.73 % 19.97 %
Polkadot30.87 2.19 % 17.29 % 10.73 %
Terra63.06 2.47 % 14.68 % 26.19 %

Bitcoin (BTC) $ 48,110.00
Ethereum (ETH) $ 4,061.26
Binance Coin (BNB) $ 538.30
Tether (USDT) $ 0.99827
Solana (SOL) $ 185.07
Cardano (ADA) $ 1.30
USD Coin (USDC) $ 0.998259
XRP (XRP) $ 0.771285
Polkadot (DOT) $ 26.11
Terra (LUNA) $ 61.70