Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Ransomware

Deloitte Responds After Ransomware Group Claims Data Theft

Deloitte has issued a response after the Brain Cipher ransomware group claimed to have stolen over 1 TB of information belonging to the company.

Deloitte hacked

Deloitte has issued a statement in response to a ransomware group’s claims regarding the theft of a significant amount of information belonging to the company. 

The ransomware group calling itself Brain Cipher listed Deloitte UK on its Tor-based website last week, claiming to have obtained over one terabyte of data (they claim this is the volume of the data when compressed).

The hackers are threatening to make the stolen files available in five days from now, unless a ransom is paid. 

“We are aware of the claims by the threat actor,” a Deloitte spokesperson told SecurityWeek. “Our investigation indicates that the allegations relate to a single client’s system which sits outside of the Deloitte network. No Deloitte systems have been impacted.”

Brain Cipher has been around since at least April 2024, but it became known in June, after it targeted an Indonesian data center and caused significant disruption to government and other critical services in the country. 

The threat group has targeted dozens of organizations, including in the healthcare, education and manufacturing sectors. They deliver file-encrypting malware that is based on LockBit, and also steal data from victims. Some ties have been found to the ransomware groups named SenSayQ and EstateRansomware.

Advertisement. Scroll to continue reading.

This is the second time Deloitte has had to respond to hacking claims in recent months. In September, the notorious hacker IntelBroker claimed to have stolen sensitive data, but the audit and consulting giant said at the time that impact was limited.

Related: BT Investigating Hack After Ransomware Group Claims Theft of Sensitive Data

Related: Energy Sector Contractor ENGlobal Targeted in Ransomware Attack

Related: Two UK Hospitals Hit by Cyberattacks, One Postponed Procedures

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Veritas Capital has appointed Joel Fulton as Chief Information Security Officer.

incident.io has appointed Carlos Gonzalez-Cadenas as Chief Operating Officer.

Ruben D. Chacon has joined ADM as Vice President and Global CISO.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.