A ransomware gang asserts they intend to leak employees’ records, autopsy photographs, and confidential personal data which they claim to have obtained from a hospital.
Cobb County
government data breach.
Driving the news:
On Thursday, the hacker collective known as Qilin uploaded a statement onto their data breach website claiming they had amassed 400,000 files amounting to 150 gigabytes of information. They announced their intention to release this data within the next 48 hours.
- The posting from the hacker collective featured raw sample images of what appeared to be autopsy photographs, along with scans of driver’s licenses and documents containing individuals’ Social Security numbers, as per a dark web ad reviewed by Axios.
Caveat:
Axios cannot confirm the authenticity of the images.
Catch up quick:
On April 24, officials from the Cobb government announced that a cyber security breach impacted 10 people, which included three county staff members.
- The county stated that they are offering these people advice on self-protection, and in specific instances, they are also supplying identity theft protection and credit monitoring services when their cases include particular kinds of data.
- Initially, the county didn’t disclose particular information regarding which data had been compromised or the extent of it. It remains uncertain whether the materials Qilin says he possesses originate from that security breach.
What they’re saying:
On Friday, the county stated that they had not verified the authenticity of social media claims regarding a “cybersecurity incident” and declared they would “refrain from speculating on data purportedly discovered in lesser-known sections of the web.”
- The county mentioned that a “third party” reached out to their officials following a recent cyberattack with a ransom demand. However, the county refused.
- The statement reads, ‘We decline to back or facilitate criminal organizations, regardless of challenging decisions. ’ It also notes, ‘Although this might provide little solace to those impacted, maintaining our stance conveys a strong message: Those involved in illegal activities will not benefit from such crimes.’
Zoom in:
According to Comparitech
Qilin operates from Russia and grants permissions for others to use their malware in ransomware attacks. In return, they claim between 15% to 20% of the profits generated.
the Guardian reports
.
Sam Sabin from Axios provided additional reporting.
Receive more local stories in your inbox with Axios Atlanta.