Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Ransomware Gang Leaks Data Allegedly Stolen From Greek Gas Supplier

The cybergang behind the Ragnar Locker ransomware has published more than 360 gigabytes of data allegedly stolen from Greece’s largest natural gas supplier Desfa.

Established in 2007 as a subsidiary of Depa (Public Gas Corporation of Greece), Desfa operates both the country’s natural gas transmission system and its gas distribution networks.

The cybergang behind the Ragnar Locker ransomware has published more than 360 gigabytes of data allegedly stolen from Greece’s largest natural gas supplier Desfa.

Established in 2007 as a subsidiary of Depa (Public Gas Corporation of Greece), Desfa operates both the country’s natural gas transmission system and its gas distribution networks.

On Saturday, the company announced that it fell victim to a cyberattack that impacted the availability of some systems, and which also resulted in the leakage of data.

Desfa says it has proactively deactivated IT services to contain the incident, but that it is gradually restoring them to normal operations.

“We have managed to ensure and continue the operation of the National Natural Gas System (NNGS) in a safe and reliable way. The management of the NNGS continues to operate smoothly and Desfa continues to supply natural gas to all entry and exit points of the country safely and adequately,” the company said.

The day before Desfa’s announcement, Ragnar Locker’s operators boasted on their Tor website about having hacked the company, claiming to have stolen sensitive corporate data.

The cybergang said that they had contacted the company to inform it of a ‘serious vulnerability’ that led to the breach, but that it had not heard back.

“Desfa remains firm in its position not to negotiate with cybercriminals,” the company said on Saturday.

Advertisement. Scroll to continue reading.

After not hearing back from Desfa, Ragnar Locker’s operators on Tuesday decided to publish the data supposedly stolen from the gas system operator on their Tor website, while also attempting to shame the company.

In March, the FBI warned that Ragnar Locker had compromised at least 52 entities across 10 critical infrastructure sectors and that the cybergang was changing obfuscation techniques frequently, to avoid detection and prevention.

While it’s unclear how the cybercriminals managed to compromise Desfa, they were previously observed targeting Remote Desktop Protocol (RDP) connections for intrusion, and then deploying a custom virtual machine to perform malicious activities unhindered.

Related: FBI Warns of RagnarLocker Ransomware Attacks on Critical Infrastructure

Related: Ragnar Locker Ransomware Uses Virtual Machines for Evasion

Related: Hackers Demand $11 Million From Capcom After Ransomware Attack

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

Professional services company Slalom has appointed Christopher Burger as its first CISO.

More People On The Move

Expert Insights

Related Content

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.

Cybercrime

Zendesk is informing customers about a data breach that started with an SMS phishing campaign targeting the company’s employees.

Cybercrime

Patch Tuesday: Microsoft calls attention to a series of zero-day remote code execution attacks hitting its Office productivity suite.

Ransomware

A SaaS ransomware attack against a company’s Sharepoint Online was done without using a compromised endpoint.

Artificial Intelligence

The release of OpenAI’s ChatGPT in late 2022 has demonstrated the potential of AI for both good and bad.