Nokia subsidiary reveals data breach following Conti ransomware raid

SAC Wireless notifies current and former employees that their personal information may be at risk

A Chicago-based subsidiary of Nokia has admitted to a data breach after it was the victim of a ransomware attack that left systems encrypted and data stolen.

According to a letter sent out to current and former employees, SAC Wireless disclosed that an unauthorized third party accessed its systems as part of a ransomware attack on June 16. IT said the threat actor was the Conti cyber crime gang and had gained access to the SAC systems, uploaded files to its cloud storage, and then deployed ransomware to encrypt the files on its systems.

Following a forensic investigation with help from external cyber security experts, SAC Wireless found the affected files could contain employees’ details, such as date of birth; contact information. such as home addresses, emails, and phone numbers; government ID numbers, such as driver’s license, passport, or military ID; Social Security numbers; and more. Dependents or beneficiaries of employees may also be affected in the breach.

SAC Wireless said it would continue to work with forensic experts to remedy this incident and to identify potential enhancements to its information security systems.

“In response to this ransomware attack, we have already changed firewall rules, disconnected VPN connections, activated conditional access geo-location policies to limit non-U.S. access, provided additional employee training, deployed additional network and endpoint monitoring tools, expanded multi-factor authentication, and deployed additional threat-hunting and endpoint detection and response tools,” SAC Wireless said in the letter.

Related Resource

The five essentials from your endpoint security partner

Empower your MSP business to operate efficiently

Five essentials from your endpoint security partner - title against a background of blue circles - whitepaper from MalwarebytesDownload now

The company has also brought in Experian to offer employees a free 24-month membership to their identity protection services.

Sam Curry, chief security officer of Cybereason, told ITPro that while SAC may not be a household name, Nokia is, and threat actors follow the money to the biggest bank vaults and companies.

“They have a lot of experience in knowing who pays. While nothing is 100 percent preventable, ransomware attacks can be managed and most often stopped. In the case of data breaches, organizations need deeper insight into potentially malicious activity in their environments and around the closed threat monitoring is most critical,” he said.

Curry added that organizations should have the right practices in place technically, like closing vulnerabilities, identity hygiene, strong general policies, back and recovery practices, and so on. They should also have an EDR, MDR, or XDR strategy.

“Ransomware is spread using the old APT toolkit — the operations that penetrate networks and plant ransomware like explosives can be hamstrung and stopped as they spread,” he added.

Featured Resources

The definitive guide to warehouse efficiency

Get your free guide to creating efficiencies in the warehouse

Free download

The total economic impact™ of Datto

Cost savings and business benefits of using Datto Integrated Solutions

Download now

Three-step guide to modern customer experience

Support the critical role CX plays in your business

Free download

Ransomware report

The global state of the channel

Download now

Recommended

Phishing emails target victims with fake vaccine passport offer
cyber crime

Phishing emails target victims with fake vaccine passport offer

21 Sep 2021
Researchers disclose top flaws abused by ransomware gangs
ransomware

Researchers disclose top flaws abused by ransomware gangs

20 Sep 2021
Best MDM solutions 2020
mobile device management (MDM)

Best MDM solutions 2020

17 Sep 2021
How do hackers choose their targets?
hacking

How do hackers choose their targets?

17 Sep 2021

Most Popular

What are the pros and cons of AI?
machine learning

What are the pros and cons of AI?

8 Sep 2021
The technology powering the future of shopping
Technology

The technology powering the future of shopping

16 Sep 2021
Citrix mulling potential sale after tumultuous 2021
mergers and acquisitions

Citrix mulling potential sale after tumultuous 2021

15 Sep 2021