International Cyber Digest Profile picture
Aug 18 10 tweets 2 min read Read on X
🚨 Nova ransomware gang demanded $30M from Clinical Diagnostics/Eurofins to not leak 480k+ people's sensitive medical data. Allegedly received $50k. Unsatisfied, they now demand more. Image
We're unaccustomed to seeing double or triple extortion from ransomware gangs, as it undermines their business model. Moreover, Nova misrepresented their reasons for demanding more, making them (surprise) an unreliable party.
The stolen data can harm many people. We were shocked to learn it includes reports of women's rape, with names, addresses, and numbers attached to documents.
Since Nova appears to be an unreliable ransomware gang, we doubt paying the ransom will secure the data, as there's no guarantee they'll delete it or won't demand more. However, Eurofins must attempt to reach an understanding if possible, given the high stakes.
Leaking this data could even lead to honor killings, causing some women's deaths. Some could face severe consequences for premarital sex.
We don't know how they gained an initial foothold in the Clinical Diagnostics company. However, we learned the breach was caused by one of Nova's partners, who activated Nova's Ransomware-as-a-Service (RaaS).
Nova allegedly infiltrated systems for a month to extract data before deploying ransomware. During this period, they found backup files in production environments and highly sensitive patient files in Excel documents, PDFs, database files, videos, and photos.
Once Eurofins detected the breach, they failed to notify anyone, including the authorities they were required to inform. A month passed before they disclosed it. During this time, some sample breach data was online.
How is this still rising? Image
@threadreaderapp unroll

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with International Cyber Digest

International Cyber Digest Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @IntCyberDigest

Nov 7, 2024
🚨🔓 Ransomware group Hellcat is uploading @SchneiderElec breach data as we post. What happened?

- How did @SchneiderElec get breached for the third time in a year?
- What can we learn from this breach to better protect ourselves?

🧵 A thread... Image
1/ Is this really bad for @SchneiderElec? We don't know yet. We've had contact with Hellcat spokesperson @holypryx, he told us 'Today we are leaking everything so samples won't be important anymore right?'
2/ What we do know is that @SchneiderElec has refused to acknowledge the breach through their official channels and also does not intend to pay Hellcat.
Read 8 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us!

:(