Walmart Denies Yanluowang Ransomware Attack

Share post:

Walmart has denied that it suffered from a ransomware attack launched by the Yanluowang gang. Clarification became necessary after the Yanluowang ransomware gang posted an entry to their data leak website on Monday, claiming that they breached the retailer and encrypted between 40,000 and 50,000 devices.

In a statement, Walmart denied the claims. Walmart stated that their “Information Security team is monitoring our systems 24/7,” and believes the claims are untrue.

“We believe this claim is inaccurate and are not aware of a successful attack in this regard on our devices,” a Walmart spokesperson said.

Yanluowang ransomware gang claimed to have carried out the attack over a month ago and were able to encrypt devices but not steal any data. The gang demanded a $55 million ransom from hackers, but never received a response from Walmart.

The entry on Yanluowang’s data leak website contains various files that allegedly contain information extracted from Walmart’s Windows domain during the attack.

Although the attack has been denied, the files on the data leak site contain information purportedly from Walmart’s internal network, including a security certificate, a list of domain users, and the output of a Kerberoasting attack.

The sources for this piece include an article in BleepingComputer.

SUBSCRIBE NOW

Related articles

CrowdStrike faces backlash over $10 “apology” voucher

CrowdStrike is facing criticism after offering a $10 UberEats voucher to apologize for a global IT outage that...

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

Security company accidentally hires a North Korean state hacker: Cybersecurity Today for Friday, July 26, 2024

A security company accidentally hires a North Korean state actor posing as a software engineer. CrowdStrike issues its...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways