UnitedHealth Outage: Blackcat Ransomware Gang Disrupts Pharmacies Across U.S.

According to a report from Reuters, the Blackcat ransomware gang is behind a massive ransomware attack that has impacted prescription deliveries throughout the United States. Last week, bad actors reportedly gained access to systems owned by Change Healthcare, a prescription...
February 26, 2024

Free Ransomware Decryption Tool Released for Rhysida

A group of researchers has released a free recovery tool for data encrypted by Rhysida ransomware.  The Rhysida ransomware variant appeared towards the beginning of 2023 and spread quickly, primarily targeting education, healthcare, manufacturing, government, and information technology (IT) sectors....
February 14, 2024

White Phoenix Ransomware Recovery Tool: What to Know

White Phoenix is an open-source ransomware decryption tool, intended for use with larger files encrypted by the Play ransomware group and other ransomware variants that use intermittent encryption. The tool is available on GitHub here, and it’s both free...
January 31, 2024

Report: 75% of Organizations Hit By Ransomware in 2023

In a report from software company Veeam, 75% of businesses said that they’d dealt with ransomware or malware attacks in 2023. The attacks were cited as the most common cause of technology outages, and many organizations were subjected to multiple...
January 18, 2024

$1.2 Million in Bitcoin Mysteriously Sent to Satoshi’s Wallet

Satoshi Nakamoto — the pseudonym used by the founder of Bitcoin — is a little bit richer this week.  On Friday, January 5, Nakamoto’s first cryptocurrency wallet received a deposit of 26.9 bitcoin (BTC). The transaction was valued at about...
January 8, 2024

Black Basta Ransomware: Free Decryption Tools Released

A team from Security Research Labs (SRL) has released a set of free decryption utilities for victims of specific Black Basta ransomware attacks.  Of course, the tools are not perfect: Data recovery depends on the size of the file and...
January 3, 2024

Justice Department Announces Decryption Tools for ALPHV/Blackcat Ransomware

The Department of Justice (DOJ) has announced a disruption campaign against ALPHV, a ransomware group responsible for hundreds of attacks on businesses and critical U.S. infrastructure. ALPHV, also known as Blackcat or Noberus, is a ransomware-as-a-service (RaaS) gang. RaaS groups...
December 22, 2023

State of Maine Becomes Latest Victim of MOVEit Hack

The state government of Maine has announced a major cybersecurity incident, which may have exposed the personally identifiable information (PII) of nearly all of the state’s residents. “On May 31, 2023, the State of Maine became aware of a software...
November 10, 2023

Data Recovery and Computer Forensics: What’s The Difference?

In our industry, “data recovery” refers to the process of restoring data that has been corrupted, deleted, or made inaccessible for another reason (such as a media failure).  “Computer forensics” is related, but different: Forensics attempts to determine what happened...
November 6, 2023

“WormGPT:” Generative A.I. Could Help Ransomware Spread

Imagine that you’re sitting at your work computer when you receive an email:“Hey, it’s Bill — I’m the new guy in IT. I need your password so that I can set you up on the new sales system.”  You...
October 18, 2023