Ferrari notifies customers of ransom demand

Share post:

Super sports car manufacturer Ferrari is notifying an unknown number of customers that their contact information is in the hands of crooks, after the Italian company received a ransom threat.

In a news release, Ferrari N.V. said it was recently contacted by a threat actor with a ransom demand “related to certain client contact details.” Upon receipt of the ransom demand, it immediately started an investigation in collaboration with a leading global third-party cybersecurity firm. In addition, it brought in law enforcement authorities.

“As a policy, Ferrari will not be held to ransom as paying such demands funds criminal activity and enables threat actors to perpetuate their attacks,” the statement says.

Security researcher Troy Hunt posted a copy of the letter that was sent to customers on his Twitter feed. “A threat actor was able to access a limited number of systems in our IT environment,” it says in part. Data accessed includes names, addresses, email addresses and phone numbers.

No customer payment information, bank account numbers or other sensitive information was accessed, the letter adds.

A list of Ferrari customers would be prized by crooks for phishing attacks because the car owners would be high net worth individuals. One of the most famous brand names in the world — let alone in sports cars — its limited production cars are prized by driving enthusiasts and collectors. Continental Ferrari, an Illinois Ferrari dealership, says a base Ferrari Roma would start at US$218,000. Limited edition cars would go for three times as much or more.

This is the not the first cyber attack reported on Ferrari. According to a news report, last October the RansomEXX claimed it had stolen 7GB of data. At the time the company said it had no evidence of a breach of its systems or of ransomware.

The post Ferrari notifies customers of ransom demand first appeared on IT World Canada.
Howard Solomon
Howard Solomonhttps://www.itworldcanada.com
Currently a freelance writer, I'm the former editor of ITWorldCanada.com and Computing Canada. An IT journalist since 1997, I've written for ITBusiness.ca and Computer Dealer News. Before that I was a staff reporter at the Calgary Herald and the Brampton (Ont.) Daily Times.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways