TechCrunch News 前天 04:55
网络安全公司员工被控利用职务之便发动勒索软件攻击
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

美国检察官指控一家专门代表客户与黑客谈判赎金的网络安全公司的两名员工,利用其职务之便发动了勒索软件攻击。这三人被控入侵公司、窃取敏感数据并部署了ALPHV/BlackCat组织的勒索软件。该组织以“勒索软件即服务”模式运营,其分支机构负责执行黑客攻击和部署勒索软件,并从中分得利润。其中一名受害者是一家医疗器械制造商,支付了超过120万美元的赎金。

🔒 **内部人员滥用职权进行勒索攻击**:两名在网络安全公司DigitalMint工作的员工被指控利用其在赎金谈判方面的专业知识,转而对客户公司发动勒索软件攻击。他们涉嫌入侵公司系统,窃取敏感数据,并部署了ALPHV/BlackCat组织的勒索软件,意图勒索赎金。这种行为严重违背了其职业道德和公司信任。

💰 **“勒索软件即服务”模式下的共犯**:此次被指控的个人是ALPHV/BlackCat勒索软件团伙的“联盟成员”。该团伙提供勒索软件工具和基础设施,而像这些被指控的员工则负责执行实际的黑客攻击,并与团伙分享勒索所得。这种模式使得勒索软件攻击的门槛降低,并扩大了其影响范围。

💸 **巨额赎金支付与广泛受害者**:根据FBI的宣誓书,其中一名受害者,一家佛罗里达州的医疗器械制造商,已支付了超过120万美元的赎金。调查还显示,他们还针对了其他几家美国公司,包括一家无人机制造商和一家制药公司,显示了此次犯罪活动的广泛性和潜在的巨大经济损失。

🏢 **公司回应与配合调查**:事发后,涉事员工所在的公司DigitalMint和Sygnia均表示正在配合政府的调查。Sygnia确认已解雇涉事员工,而DigitalMint则表示该员工的行为完全超出了其雇佣范围。这表明公司正试图与不当行为划清界限,并协助追究责任。

U.S. prosecutors have charged two rogue employees of a cybersecurity company that specializes in negotiating ransom payments to hackers on behalf of their victims, with carrying out ransomware attacks of their own.

Last month, the Department of Justice indicted Kevin Tyler Martin and another unnamed employee, who both worked as ransomware negotiators at DigitalMint, with three counts of computer hacking and extortion related to a series of attempted ransomware attacks against at least five U.S.-based companies.

Prosecutors also charged a third individual, Ryan Clifford Goldberg, a former incident response manager at cybersecurity giant Sygnia, as part of the scheme.

The three are accused of hacking into companies, stealing their sensitive data, and deploying ransomware developed by the ALPHV/BlackCat group.

The ALPHV/BlackCat gang operates as a ransomware-as-a-service model, in which the gang develops the file-encrypting malware used to steal and scramble the victims’ data, while its affiliates — such as the three individuals indicted — carry out the hacks and deploy the gang’s ransomware. The gang then takes a cut of the profits made from any ransom payments.

According to an FBI affidavit filed in September, the rogue employees received more than $1.2 million in ransom payments from one victim, a medical device maker in Florida. They also targeted several other companies, including a Virginia-based drone maker and a Maryland-headquartered pharmaceutical company. 

The Chicago Sun-Times first reported the indictment on Sunday.

Sygnia chief executive Guy Segal confirmed to TechCrunch that Goldberg was a Sygnia employee and was terminated after Sygnia learned of his alleged involvement with the ransomware attacks. The company declined to comment further citing the FBI’s ongoing investigation.

DigitalMint president Marc Grens told TechCrunch that Martin was an employee at the time of the alleged hacks, but said Martin was “acting completely outside the scope of his employment.” 

Grens also confirmed that the unnamed individual may be a former employee. DigitalMint is also cooperating with the government’s investigation, said Grens. 

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

勒索软件 网络安全 黑客攻击 内部人员 ALPHV/BlackCat Ransomware Cybersecurity Hacking Insider Threat
相关文章