A major attack on Sony? The company finally responded to troubling reports
Representatives from Sony have admitted that they are investigating the matter of the cyber attack, which allegedly took place this week. Subsequent groups of cybercriminals are admitting to carrying it out, which is not surprising according to ESET experts.
The first information about the attack was provided by the hacker group RansomedVC. They announced that they had managed to break into all Sony systems and are ready to sell the illegally obtained materials. On hacker forums, there appeared 3.14 GB of uncompressed data, which allegedly belong to Sony, the well-known manufacturer of televisions, consoles, and games. However, their authenticity could not be confirmed. Instead, there are messages from other criminal groups, which add to the confusion.
Attack on Sony. Who carried it out?
As noted by Bleeping Computer, RansomedVC's position has been undermined by at least one other similar cybercriminal organization, stating that it was the one who initiated the reported attack. According to ESET experts, such a turn of events is not surprising, as hacker groups are looking not only for profit, but also for applause.
- The information about exactly which group is the initiator of an attack often has secondary importance to those attacked. However, it can be important for the cybercriminals themselves, who take pride in their achievements. Cybercriminal criminal groups are often oversensitive about the "authorship" of their attacks, partly because they often seek approval for their actions among their communities and on internet forums. - commented Beniamin Szczepankiewicz, an analyst at the ESET antivirus lab.
Ransomware groups are becoming increasingly dangerous
If the attack is confirmed, it will not be the first event of its kind with a Japanese manufacturer in the background. It was reminded that the loudest cyber attack on Sony to date took place in 2014. North Korean hackers then broke into Sony Pictures' systems with the intention of disrupting the screening of the movie The Interview.
In recent years, ransomware groups have proven to be a problem for many companies. They most often target the largest brands because in such cases they can gain publicity and at the same time extort large sums of money. Blackmail and ransom demands are one of the fundamental operation models of such criminal organizations.
- Ransomware groups over the past few years have transformed into extortion gangs, acting aggressively and leaving victims no chance. Attacking and then blackmailing large organizations and demanding ransom is one of their basic modes of operation. They threaten that if the required fee is not paid, they will disclose the data or put it up for sale. Such a situation can result in not only the paralysis of a company's operations, but also a loss of reputation. This is a very serious threat, especially for organizations that store large volumes of user data - added Benjamin Szczepankiewicz.