By Ray Birch
GREENSBORO, N.C.—Two more credit unions have allegedly been hit with ransomware attacks, a sign the crime continues to spread and target CUs, according to one security expert, who is further warning the attacks are becoming more “extreme.” That even includes blackmail attempts against individuals based on the stolen data.
And size of the institutions attacked does not seem to faze crooks, as one of the CUs alleged to have been hit had less than $10 million in assets.
An expert in cybersecurity who for anonymity told CUToday.info the $305-million Summit CU in North Carolina is among the CUs that have been hit with a ransomware attack at the hands of the criminal group REvil. The former $9.7-million St. James Hospital Employees FCU in Olympia Fields, Ill., was allegedly also compromised by RansomExx, the expert stated. St. James Hospital EFCU merged last year into $277-million Illiana Financial CU, based in Calumet City, Ill. The latter credit union, however, is denying any such breach occurred.
In both instances criminal organizations are posting images of data from the credit unions allegedly attacked. CUToday.info has obtained images of compromised data from both organizations. Typically what the hackers do is steal a company’s data and post a sample of it on the web, warning the company/CU that more will be posted unless a ransom is paid. The source told CUToday.info the attack on Summit CU likely occurred in March of 2021 and the St. James crime was committed during 2020.
The expert said the most likely scenario in both attacks is the criminals stole copies of the credit unions’ sensitive personal data prior to deploying the ransomware, which encrypts and locks down an organization’s data systems. In some cases, companies detect and block the actual ransomware attack before it locks down their internal data, but copies of their data is already in crooks’ hands at that point.
What the Hackers Know
The source said hackers like REvil often first gain access to companies’ networks, and are well aware of their victims’ financial positions and can therefore customize demands. They may even know how much cyber insurance the organization carries.
The expert stated REvil is responsible for the two highest ransomware demands to have become publicly known: $50 million (Acer) and $42 million (Grubman Shire).
The problem the victim faces is not knowing how much information the criminal group was able to steal outside of what has been posted online.
“It’s impossible to say what information they obtained. They may have a considerable amount, or they may be exaggerating in an attempt to pressure the organization into paying,” the expert stated. “It can take weeks for companies to work out exactly what data was exfiltrated, and threat actors may attempt to use that period of uncertainty to their advantage.”
The expert noted groups like REvil attempt to not only steal data and lock down an organization’s data, but will also attempt to delete all backup files. If backups are wiped out, it further limits the compromised organization’s options, the expert pointed out.
Some of the data received by CUToday.info from the alleged St. James Hospital EFCU attack includes copies of members’ drivers licenses.
Summit CU acknowledged it suffered a cybersecurity incident in March.
Law Enforcement Notified
“Earlier this month, Summit Credit Union of North Carolina learned that it had experienced a cybersecurity incident,” explained Summit CEO Sam Whitehurst in an emailed statement to CUToday.info. “We immediately began work to resolve the issue by taking our systems offline and engaging a third-party forensic firm to conduct an in-depth investigation of the incident. We have notified law enforcement and are cooperating with them as they conduct their own investigation into this matter. Our systems are fully operational and our investigation remains ongoing.
“We recently learned that a select few members had their personal information impacted during this incident,” continued Whitehurst. “We have notified affected members, as well as the appropriate regulatory bodies. We understand the concern this may cause and are offering all affected members complimentary credit monitoring and identity protection services out of an abundance of caution. Summit does not take this incident lightly, and the protection of member data is our highest priority. Should our investigation uncover additional relevant information, we will communicate with the appropriate parties directly.”
CU Denies Any Breach Occurred
Illiana Financial CU CEO James Henmueller told CUToday.info that Illiana Financial has not been hit with a ransomware attack, nor was St. James Hospital EFCU compromised before it merged into IFCU.
“Ransomware is more of a threat than ever,” said Brett Callow, threat analyst at security firm Emsisoft. “The criminals continue to get better at targeting larger enterprises, which means they’re able to demand more money, which, in turn, means they have the resources and motivation to ramp up their operations in terms of both scale and sophistication. In other words, it’s a vicious cycle—the more money they get, they better they get.”
Callow said ransomware has fundamentally changed.
“In the past, threat actors simply encrypted their victims’ data but, since the end of 2019, they’ve been stealing it, too, and using it as additional leverage to extort payment,” he said. “Unless the victim pays, the data gets posted online or, in some cases, auctioned. This has happened to more than 1,300 organizations. Companies in this situation have no good option. If they don’t pay, their data will be made public. However, if they do pay, all they’ll get is a pinky-promise that the stolen data will be destroyed. But, unsurprisingly, the criminals don’t always destroy data and some companies that paid have been extorted for a second time.”
Tactics More ‘Extreme’
Callow warned the tactics used by these criminal organizations are becoming more “extreme.”
“They phone and harass employees. They’ll use any incriminating documents they find in the data to further extort companies or to blackmail individuals,” he said. “For example, a company was publicly accused of planning to commit insurance fraud while an executive was blackmailed over potentially embarrassing photos that he kept on his work machine. They’ll contact business partners, send out press releases and threaten to steal customers’ identity. Some groups have even taken out Facebook ads to promote the data breach in order to further pressure the victim. And, of course, the risks extend beyond what the threat actor may do with the stolen data—the data is posted online and can be accessed by any would-be identity thief or fraudster on the planet.”
To emphasize the point, Callow repeated that globally, more than 1,300 companies, many U.S.-based, have lost data including intellectual property and other sensitive information via ransomware attacks, said Callow.
“This is simply the number of companies which had data published on leak sites and takes no account of the companies which paid to prevent publication,” he said. “Multiple companies in the U.S. Defense Industrial Base sector also had data stolen, including a contractor which supports the Minuteman III nuclear missile program.”
What Can Be Done
What should credit unions do to prevent the attacks?
“Not patching promptly, not using multi-factor authentication, not conducting security awareness training…most ransomware attacks happen because of basic security failings such as these,” stated Callow. “While it’s impossible for an organization to ever be completely secure, getting the basics right can significantly reduce the likelihood of an organization becoming the next victim.”
The best advice for organizations that are hit by ransomware is always not to pay, according to Callow.
“Paying doesn’t guarantee that they’ll get their data back, doesn’t guarantee that stolen data will not be misused and, of course, helps make cybercrime profitable, which ensures this will continue,” he said. “The bottom line—the more organizations pay, the better resourced and more motivated cybercriminals will become.”
