I haven’t heard of a ransomware attack in quite a while, to be honest. I’d thought they had perhaps gotten bored over the Covid period and decided to do something else. Turns out they’re still out there.
Ransomed.vc, some new kids on the block that have only just started operating this month, claims to have accessed “all of Sony’s systems” and acquired their data.
Ransomed.vc says that Sony has not paid them for the data yet and has listed a post date of the “28th of September”, possibly when they plan to either leak the data to the public or open it to the wholesale market. Sony only says that they have launched an investigation into the matter.
The evidence that has been provided though seems a little underwhelming. “screenshots of an internal log-in page, an internal PowerPoint presentation outlining test bench details, and a number of Java files.” as well as a file tree that lists around 6,000 html files. I’ve attempted to make a website before, and I had over 6000 files just littered all over my file structure. I’m pretty sure Sony has a lot more than that.
What’s also interesting is that Ransomed.vc is attempting to portray themselves as some sort of white, digital knight. Claiming that being able to access this data is against the GDPR (General Data Protection Regulation) laws and that Sony will be slapped with a much heftier fine if they don’t pay Ransomed.vc who will then show them how the data was accessed.
Whatever way you paint it, though, I guess we’ll only really find out tomorrow when the post deadline occurs and either Ransomed.vc disappears into the dark web, or we start seeing Sony making some sneaky payouts.
