FatFace Pays $2million Ransom To Cyber Criminals

British clothing retailer FatFace paid out a $2m ransom to restore its data following a January 2021 cyber attack by the criminal hacking group called Conti.  

The criminals initially demanded a ransom of 213 Bitcoins, about $8 million/£5.8 million, but agreed to lower the amount to $2 million after FatFace's negotiator explained that the firm's revenues had slumped over the past year due to lockdown restrictions. 

Conti finally agreed to a $2 million payment, saying that it didn't want to bankrupt the retailer.

Conti told FatFace that it had initially breached their network via a phishing attack on 10th January 2021. The gang used this compromise to gain admin rights and expand its reach through the network, as well as identifying the firm's Veeam backup servers and Nimble storage. The final attack occurred on 17th January, when the criminals were able to exfiltrate over 200GB of data from FatFace's systems before encrypting machines.

After receiving the ransom pay-out, Conti offered advice to the company's IT team about how they could strengthen security to prevent cyber attacks in future.

Advice included implementing email filtering, reviewing Active Directory password policy, conducting employee phishing tests, and investing in better endpoint detection and response technology. FatFace disclosed the security breach to customers in an email last week, informing them that some customer details - including names, email and postal and addresses, and limited credit card data - had been compromised in an attack on its systems.

The company asked customers to keep information about the data breach 'strictly private and confidential'. It also told customers that the delay in informing them occurred as they were working to identify the hackers behind the incident and to determine precisely what information was stolen.

Under the terms of the GDPR, companies must tell the ICO of a breach within 72 hours of becoming aware of it. If they decide there is a high risk to individuals' rights and freedoms, they also need to inform affected individuals 'without undue delay'.

FatFace confirmed the ransomware attack and they notified the ICO and law enforcement agencies about the incident. Almost 5,000 ransomware attacks hit British firms in 2019, with criminals collecting payments of nearly £210 million, the US cyber security firm Emsisoft said in a report last year. The company said that organisations are showing 'more willingness' to pay ransoms due to fears of public embarrassment, lost data and potential penalties from regulators (of course, paying a ransom to retrieve stolen data does not avoid fines for losing that data in the first place).

The 2020 CrowdStrike Global Security Attitude Survey revealed that almost 40% of UK organisations had been subject to ransomware attacks in the past 12 months, and 13 per cent of them had chosen to pay the ransom.

Some of the other key findings in the report is a growing fear of nation-state intrusions and ransomware attacks in the wake of COVID-19 outbreaks: 

  • 56% of organisations surveys reported a ransomware attack within the last 12 months.
  • 87% of respondents indicated that nation-state attacks are much more common than commonly supposed.
  • 73% say nation-state attacks are the single biggest threat to their organisations. 
  • 84% say they have accelerated their digital transformation efforts as a result of COVID-19, Potentially compounding their risk.
  • 45% stating that they have increased cloud rollouts to support employees working remotely. 

According to Crowdstrike, UK businesses paid an average ransom of £940,000 ($1.2 million) which is higher than the global average of $1.1 million.

Crowdstrike:     Information Commissoner:        Computer Weekly:         Computing

You Might Also Read: 

Ransomware Victim Travelex Folds:

 

« Twenty Cyber Security Startups To Watch
Half A Billion LinkedIn Members Found For Sale »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

Practice Labs

Practice Labs

Practice Labs is an IT competency hub, where live-lab environments give access to real equipment for hands-on practice of essential cybersecurity skills.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

APWG

APWG

APWG is the international coalition unifying the global response to cybercrime across industry, government, law-enforcement and NGO communities.

Cyber Exec

Cyber Exec

Cyber Exec is an executive search firm dedicated to global talent acquisition in Cyber Security, Information Technology, Defense...

IronScales

IronScales

IronScales combines human intelligence with machine learning to automatically prevent, detect and respond to email phishing attacks.

Wind River

Wind River

Wind River delivers the technology and expertise that enables the deployment of safe, secure, and reliable intelligent connected systems.

SKKU Security Lab (seclab)

SKKU Security Lab (seclab)

SKKU Security Lab supports research and education in information security engineering. The lab is a part of the College of Software, Sungkyunkwan University.

National Forensic Sciences University (NFSU) - India

National Forensic Sciences University (NFSU) - India

National Forensic Sciences University is the world’s first and only University dedicated to Digital Forensic and allied Sciences.

Uleska

Uleska

Uleska is a scalable platform that provides automated and continuous software security testing whilst translating cyber risk.

ITRenew

ITRenew

ITRenew is a leading global IT lifecycle management solutions company, specializing in onsite data center decommissioning and data erasure services.

Zenity

Zenity

Zenity is the first and only security governance platform for low-code/no-code applications.

Primus Institute of Technology

Primus Institute of Technology

At Primus Institute of Technology our mission is to inspire, support, and empower current and aspiring IT professionals through training and career development workshops.

Bores Security Consultancy

Bores Security Consultancy

Bores Security Consultancy are an established family-run business delivering expertise in security and technology.

Cyberlocke

Cyberlocke

Cyberlocke is dedicated to finding inventive solutions to meet the distinct IT obstacles of each organization we support.

KTrust

KTrust

KTrust provides Continuous Threat Exposure Management for Kubernetes environments.

Hudson Rock

Hudson Rock

Hudson Rock’s products — Cavalier & Bayonet — are powered by our cybercrime database, composed of millions of machines compromised by Infostealers in global malware spreading campaigns.

SecureDApp

SecureDApp

SecureDApp is a blockchain security company that specialises in offering comprehensive security solutions to companies operating in the web3 space.

LEPHISH

LEPHISH

LePhish is a French cybersecurity solution specializing in automated phishing campaigns.