BlackBasta is probably behind the ransomware attack on Sixt

B2B Cyber ​​Security ShortNews

Share post

As Spiegel.de reports, the new attacker group BlackBasta is probably behind the ransomware attack on the car rental company Sixt. According to research by Heise.de, the new group seems to be a spin-off or an employee takeover of the Conti Group, which has probably dissolved.

The ransomware extortion business remains one of the most lucrative. But at some point the great invention against ransomware attacks will have to come, because they are increasing massively. The media can hardly keep up with the reporting. The car rental company Sixt was already the victim of a ransomware attack in early May 2022.

Sixt: Attack noticed early

In a press release, Sixt announced: “On April 29, 2022, IT security at Sixt SE identified IT irregularities. Response measures were initiated immediately in accordance with the pre-planned security protocols. It was subsequently confirmed that Sixt SE was the subject of a cyber attack, which Sixt was able to contain at an early stage.

As a usual precautionary measure, access to IT systems was immediately restricted and the pre-planned recovery processes were initiated. Many central Sixt systems, especially the website and apps, were kept running. This minimized the impact on the company, its operations and its services in order to provide customers with business continuity. In the short term, however, temporary disruptions are to be expected, particularly in customer centers and selected branches. Nevertheless, Sixt takes this incident seriously and has conducted a thorough investigation with internal and external experts. Sixt will provide further updates as more information becomes available and asks for customers' understanding and patience."

After Conti dissolution: new groups form

As already heise.de has reported for some time, the Conti employees are breaking new ground. They join other hacker groups or form new ransomware attack teams. Suddenly new names like Karakurt, BlackBasta or BlackByte appear in the scene. Other members probably joined ransomware-as-a-service (RaaS) gangs such as BlackCat, Alphv, HIVE, HelloKitty/FiveHands or AvosLocker and used new variants of the well-known Conti encryption software.

According to the (+)Spiegel.de The BlackBasta group is said to be behind the attack on Sixt. What exactly happened, whether data was stolen or encrypted, is not known. However, even after almost a month, Sixt is still struggling with technical problems. Because with 2.000 branches in over 110 countries, Sixt is a heavyweight in its sector and has a strong network.

More at Sixt.com

 

Matching articles on the topic

Report: 40 percent more phishing worldwide

The current spam and phishing report from Kaspersky for 2023 speaks for itself: users in Germany are after ➡ Read more

BSI sets minimum standards for web browsers

The BSI has revised the minimum standard for web browsers for administration and published version 3.0. You can remember that ➡ Read more

Stealth malware targets European companies

Hackers are attacking many companies across Europe with stealth malware. ESET researchers have reported a dramatic increase in so-called AceCryptor attacks via ➡ Read more

IT security: Basis for LockBit 4.0 defused

Trend Micro, working with the UK's National Crime Agency (NCA), analyzed the unpublished version that was in development ➡ Read more

MDR and XDR via Google Workspace

Whether in a cafe, airport terminal or home office – employees work in many places. However, this development also brings challenges ➡ Read more

Test: Security software for endpoints and individual PCs

The latest test results from the AV-TEST laboratory show very good performance of 16 established protection solutions for Windows ➡ Read more

AI on Enterprise Storage fights ransomware in real time

NetApp is one of the first to integrate artificial intelligence (AI) and machine learning (ML) directly into primary storage to combat ransomware ➡ Read more

FBI: Internet Crime Report counts $12,5 billion in damage 

The FBI's Internet Crime Complaint Center (IC3) has released its 2023 Internet Crime Report, which includes information from over 880.000 ➡ Read more