Indigo admits cyber attack was ransomware, employee data accessed

Share post:

Two weeks after suffering a cyber attack, Indigo Books and Music has acknowledged it was hit by ransomware and employee data was compromised.

“On February 8, 2023, Indigo experienced a ransomware attack,” the company says in an updated FAQ on its website. “Through our investigation we learned there is no reason to believe customer data has been improperly accessed, but that some employee data was.”

“We are notifying all affected employees,” the site says. “We have also notified and are co-operating with law enforcement.

“Since this incident, we have been working with third-party experts to strengthen our cybersecurity practices, enhance data security measures and review our existing controls.”

No ransomware group has taken responsibility for the attack as yet, according to a threat researcher for a cybersecurity company.

Also today, the company said it has been able to restore online sales of books — but not other items it sells.

“Books are back,” Indigo trumpeted on its website, saying thousands of titles are available. However, shoppers can only browse for lifestyle products. These will have to be bought in stores across the country.

Indigo is still in the process of remediation. The website says it is the “temporary online home,” suggesting that a new website is being built.

According to a report released today by Fortinet that looks at cyber incidents in the second half of 2022, ransomware volume around the world increased 16 per cent from the first half of last year.

Out of a total of 99 observed ransomware families, the top five families accounted for roughly 37 per cent of all ransomware activity during the second half of 2022, it said.

GandCrab, a ransomware-as-a-service malware that emerged in 2018, was at the top of the list. Although the criminals behind GandCrab announced that they were retiring after making over $2 billion in profits, the report says, there were many iterations of GandCrab during its active time. “It is possible that the long-tail legacy of this criminal group is still perpetuating, or the code has simply been built upon, changed, and re-released.”

In an IBM report, also released today, that looked at incidents the company was called on for help across all of 2022, researchers said incidents of ransomware dropped last year compared to 2021. However, deploying ransomware was the second most common action after a threat actor was able to breach security controls. Installing a back door was number one. Back doors lead to the distribution of malware, including ransomware, to further everything from credential theft through data theft and data destruction.

Alarmingly, IBM said there was a four per cent reduction in the average time for the deployment of ransomware attacks in 2022 compared to the previous year. To put that in perspective, what took attackers over two months in 2019 took just under four days in 2021.

The post Indigo admits cyber attack was ransomware, employee data accessed first appeared on IT World Canada.

Howard Solomon
Howard Solomonhttps://www.itworldcanada.com
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for several of ITWC's sister publications including ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

SUBSCRIBE NOW

Related articles

Cyber Security Today, May 3, 2024 – North Korea exploits weak email DMARC settings, and the latest Verizon analysis of thousands of data breaches

This episode reports on warnings about threats from China, Russia and North Korea, the hack of Dropbox Sign's infrastructure

Hashtag Trending for World Password Day, Thursday, May 2nd, 2024

Security firm Okta warns of an unprecendented password stuffing attack that is piggybacking on regular user’s mobile and...

Google Chrome’s new post-quantum cryptography causes connection issues

The latest update to Google Chrome, version 124, which integrates a new quantum-resistant encryption mechanism, has led to...

UK legislation bans weak passwords

Starting Monday, the UK will enforce new laws banning the sale of devices with weak default passwords such...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways