Show vulnerabilities with patch / with exploit
21 July 2020

Argentina's largest ISP hit by 7.5M ransomware attack


Argentina's largest ISP hit by 7.5M ransomware attack

Telecom, Argentina's largest telecommunications company, has suffered a ransomware attack over the weekend with hackers demanding a $7.5 million ransom to be paid in Monero cryptocurrency to unlock the encrypted files.

The incident, which took place on Saturday, July 18, caused an extensive damage to the company’s operations. The ransomware operators have encrypted nearly 18,000 workstations on the network leading to the Telecom’s employees experiencing troubles accessing the company's VPN and some of the databases, according to the sources fr om the ISP.

Currently, there is not much information regarding how exactly the attackers were able to compromise the corporate network, but it appears that they did it via emails with malicious attachments.

The hackers initially gained access to the company network, then they hijacked an internal Domain Admin and used the access to infect thousands of machines with ransomware. The attack did not affect the internet connectivity to the ISP's customers, nor did it impact fixed telephony or cable TV services.

According to several Telecom’s employees, who shared some details about the incident on social media, the company detected the intrusion right away and has warned employees via internal alerts to lim it their interaction with the corporate network, not to connect to its internal VPN network, and not to open emails containing archive files.

While the identity of the hacker group responsible for this attack is not confirmed, speculation is the operators behind it are the ReVil (Sodinokibi) ransomware gang, according to a now-deleted tweet showing the crew’s dark web portal.

The page on the portal shows a ransom demand of 109345.35 Monero coins (approximately $7.53 million), and the ransomware operators are threatening to double the amount if the ISP will not pay the ransom by July 21. It is unknown whether the company plans to pay the ransom.


Back to the list

Latest Posts

Iranian APT Oilrig becomes the first group to weaponize DNS-over-HTTPS

Iranian APT Oilrig becomes the first group to weaponize DNS-over-HTTPS

Oilrig members have added a new DNSExfiltrator utility to their hacking arsenal.
5 August 2020
Hacker published passwords for over 900 corporate VPN servers

Hacker published passwords for over 900 corporate VPN servers

The list was published on a Russian-speaking hacker forum frequented by different ransomware operators.
5 August 2020
Maze operators published dozens of GBs of data from LG and Xerox

Maze operators published dozens of GBs of data from LG and Xerox

Stolen information may include Xerox support records and source code for the firmware of various LG products.
4 August 2020