Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Data Stolen in Breach at Security Company Entrust

Entrust suffered a data breach last month and the security company has confirmed that the attackers have stolen some files.

Entrust suffered a data breach last month and the security company has confirmed that the attackers have stolen some files.

The breach was discovered on June 18 and the firm started notifying customers on July 6. However, the intrusion came to light only on July 21 when security researcher Dominic Alvieri came across a copy of the notification sent by Entrust to customers.

Entrust is a Minneapolis, MN-based company that provides security solutions for user and machine identities, payments, and digital infrastructure. The firm’s services are used across 150 countries, including by some of the world’s largest organizations.

In the notification to customers, Entrust CEO Todd Wilkinson said that while the investigation is ongoing, the company determined that some files had been taken from internal systems.

“On June 18, 2022, we determined that an unauthorized party accessed certain of our systems used for internal operations – functions such as HR, finance, and marketing. We promptly began an investigation with the assistance of a leading third-party cybersecurity firm and have informed law enforcement,” Entrust told SecurityWeek in an emailed statement.

“While our investigation is ongoing, we have found no indication to date that the issue has affected the operation or security of our products and services, which are run in separate environments from our internal systems and are fully operational. We take seriously our responsibility to protect our systems and have been engaged with our customers on the issue,” the company added.

Advertisement. Scroll to continue reading.

Vitali Kremez, CEO of threat intelligence firm AdvIntel, told Bleeping Computer that the incident involved ransomware, with a known — but unnamed — threat actor acquiring compromised Entrust credentials and using them to access the company’s network. Kremez said the attackers encrypted files and exfiltrated data.

Entrust has not provided any additional details. SecurityWeek has checked the websites of several major ransomware groups, but it did not find Entrust being mentioned by any of them at the time of writing.

Related: Car Parts Giant Denso Targeted by Ransomware Group

Related: Ransomware Gang Leaks Files Stolen From Industrial Giant Parker Hannifin

Related: Ransomware Gang Threatens to Leak Files Stolen From Tire Giant Bridgestone

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Mark Carter has been appointed Chief Information Security Officer at Socure.

Spektrum Labs has named Mark Cravotta Chief Operating Officer.

Philip Martin has joined Uber as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.