Security Market Segment LS
Wednesday, 11 November 2020 06:52

Campari ransomware attackers break into Facebook to publicise incident Featured

By
Campari ransomware attackers break into Facebook to publicise incident Image by Gerd Altmann from Pixabay

The cyber criminals behind the ransomware attack on Italian liqueur manufacturer Campari Group have taken their efforts to publicise the intrusion in a different direction, infiltrating the Facebook page of an entertainment event organiser and posting an ad and news about the attack there.

The attackers used the Ragnar Locker ransomware, that runs only on Microsoft's Windows operating system, to hit Campari, a company with annual revenue of €1.816 billion (A$2.97 billion) revenue in 2017.

DJ Chris Hodson, who runs Hodson Event Entertainment, told iTWire that he had noticed the intrusion into his Facebook page early on the morning of 10 November.

He said the first indication he had that something was amiss was when he received an email from PayPal, informing him that he had been charged for an ad.

This puzzled Hodson who then accessed his Facebook page where he advertises his business. He also promotes it on Instagram.

He noticed that whoever had got into his page had posted the ad [below, right] about the Campari attack in his news feed and his story feed as well.

facebook adHodson said the miscreants had also made posts which he was able to delete. However the downside was that Facebook shut down his ad account as a result of the intrusion.

He said the ads had been removed from the page, but were still in his ad manager and he was not able to do anything about it.

Hodson runs his business as a sole trader and earns a relatively small amount each year, roughly US$200,000 (A$274,663). The ads would cost him US$150 in toto, of which US$36 has already been taken from his account.

He said he had no tech support of any kind and had been in a quandary as to what he should do when he first got wind of the incident. But he is hopeful that Facebook will accept responsibility for the intrusion and not allow the incident to put a hole in his pocket. The company was prompt in getting back to him when he first contacted them and he is hopeful that they will be swift to sort out the issue equally quickly.

Hodson provides professional party and wedding DJ service for the Chicago area suburbs and beyond, as per his website.

A statement issued by Campari about the attack on its infrastructure said it had occurred on 2 November and resulted in the encryption of data on some of its servers. In a notice posted on the dark web, the attackers claimed they had stole 2TB of sensitive data.

The media release also claimed that the company could not "completely exclude that some personal and business data has been taken". This claim was pooh-poohed by the attackers, who said, "This is ridiculous and looks like a big fat lie. We can confirm that confidential data was stolen and we are talking about a huge volume of data."

They said they would wait until 10 November for Campari's response before leaking data on the dark web.

Asked for his reaction, seasoned ransomware researcher Brett Callow said: "This development is not at all surprising; in fact, it was predictable. Threat actors already issue press releases and do media outreach, so social media ads are simply another way to publicise incidents."

Callow, who works for the New Zealand-headquartered security shop Emsisoft, added: "Their strategy may not be to pressure Campari, but rather to pressure future victims. They probably believe that the brighter the spotlight gets, the more likely it is that other companies will pay in order to satay out of it. And, unfortunately, they may well be right."


Subscribe to ITWIRE UPDATE Newsletter here

PROMOTE YOUR WEBINAR ON ITWIRE

It's all about Webinars.

Marketing budgets are now focused on Webinars combined with Lead Generation.

If you wish to promote a Webinar we recommend at least a 3 to 4 week campaign prior to your event.

The iTWire campaign will include extensive adverts on our News Site itwire.com and prominent Newsletter promotion https://itwire.com/itwire-update.html and Promotional News & Editorial. Plus a video interview of the key speaker on iTWire TV https://www.youtube.com/c/iTWireTV/videos which will be used in Promotional Posts on the iTWire Home Page.

Now we are coming out of Lockdown iTWire will be focussed to assisting with your webinatrs and campaigns and assassistance via part payments and extended terms, a Webinar Business Booster Pack and other supportive programs. We can also create your adverts and written content plus coordinate your video interview.

We look forward to discussing your campaign goals with you. Please click the button below.

MORE INFO HERE!

INTRODUCING ITWIRE TV

iTWire TV offers a unique value to the Tech Sector by providing a range of video interviews, news, views and reviews, and also provides the opportunity for vendors to promote your company and your marketing messages.

We work with you to develop the message and conduct the interview or product review in a safe and collaborative way. Unlike other Tech YouTube channels, we create a story around your message and post that on the homepage of ITWire, linking to your message.

In addition, your interview post message can be displayed in up to 7 different post displays on our the iTWire.com site to drive traffic and readers to your video content and downloads. This can be a significant Lead Generation opportunity for your business.

We also provide 3 videos in one recording/sitting if you require so that you have a series of videos to promote to your customers. Your sales team can add your emails to sales collateral and to the footer of their sales and marketing emails.

See the latest in Tech News, Views, Interviews, Reviews, Product Promos and Events. Plus funny videos from our readers and customers.

SEE WHAT'S ON ITWIRE TV NOW!

BACK TO HOME PAGE
Sam Varghese

Sam Varghese has been writing for iTWire since 2006, a year after the site came into existence. For nearly a decade thereafter, he wrote mostly about free and open source software, based on his own use of this genre of software. Since May 2016, he has been writing across many areas of technology. He has been a journalist for nearly 40 years in India (Indian Express and Deccan Herald), the UAE (Khaleej Times) and Australia (Daily Commercial News (now defunct) and The Age). His personal blog is titled Irregular Expression.

Share News tips for the iTWire Journalists? Your tip will be anonymous

WEBINARS ONLINE & ON-DEMAND

GUEST ARTICLES

VENDOR NEWS

Guest Opinion

Guest Reviews

Guest Research

Guest Research & Case Studies

Channel News

Comments