Data Breaches

Ransomware Group Takes Credit for LoanDepot, Prudential Financial Attacks

The BlackCat/Alphv ransomware group has taken credit for the LoanDepot and Prudential Financial attacks, threatening to sell or leak data.

BlackCat ransomware

The notorious ransomware group known as BlackCat and Alphv has taken credit for the recently disclosed cyberattacks impacting financial giants LoanDepot and Prudential Financial.

The two companies were named on the BlackCat leak website on Friday, February 16, and, based on the messages published by the hackers, both companies have refused to pay a ransom.

In the case of mortgage and non-mortgage lending firm LoanDepot, it had been known that the company was targeted in a ransomware attack, but insurance, retirement and investment firm Prudential Financial had not shared too much information on the type of cyberattack, except to say that it was conducted by a cybercrime group. 

When it disclosed the incident, Prudential Financial said the attackers accessed administrative and user data, as well as user accounts associated with employees and contractors. It said there had been no evidence of customer or client data theft. 

In a post published on its leak website on Friday, the BlackCat ransomware gang claimed it still had access to Prudential systems. The cybercriminals claimed they had been looking into selling the data, but said they might also release it for free “so journalists can investigate financial wrongdoing”.

As for LoanDepot, the company confirmed in January that a ransomware attack resulted in a data breach impacting 16.6 million people

The cybercrime group said on Friday that it’s in the process of selling the stolen LoanDepot data, which allegedly includes more information than what was mentioned in the company’s breach notification. 

BlackCat was targeted in a law enforcement operation in late 2023 and had its main leak website seized. The US government also released a decryption tool to help some of the impacted organizations recover data without paying a ransom.

Advertisement. Scroll to continue reading.

However, the ransomware group did not appear discouraged, setting up a new leak website and telling affiliates that there would no longer be any limitation on the types of organizations they could target. 

The US last week announced a reward of up to $10 million for information on the BlackCat group’s leaders and up to $5 million for any affiliate. 

It remains to be seen if the cybercriminals keep the BlackCat brand alive or if they migrate to a new operation

Related: Ransomware Attack Knocks 100 Romanian Hospitals Offline

Related: Ransomware Payments Surpassed $1 Billion in 2023: Analysis

Related: The Ransomware Threat in 2024 is Growing: Report

Related Content

Cybercrime

Zscaler says its customer, production and corporate environments are not impacted after a notorious hacker offers to sell access.

Ransomware

Organizations need to look beyond preventive measures when it comes to dealing with today’s ransomware threats and invest in ransomware response.

Ransomware

Philadelphia-based real estate company Brandywine Realty Trust shuts down systems following a ransomware attack.

Data Breaches

University System of Georgia says Social Security numbers and bank account numbers were compromised in the May 2023 MOVEit hack.

Ransomware

Charges and sanctions announced against Dimitry Yuryevich Khoroshev, the alleged developer and operator of LockBit ransomware.

Ransomware

The City of Wichita, Kansas, has shut down its network after falling victim to a file-encrypting ransomware attack.

Cybercrime

Yaroslav Vasinskyi was sentenced to 13 years and seven months in prison for his alleged role in the REvil ransomware operation.

Data Breaches

Dropbox says hackers breached its Sign production environment and accessed customer email addresses and hashed passwords. 

Copyright © 2024 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version