Medibank 2022: The Ransom Refusal That Published Patients
Criminals entered Medibank via a contractor's VPN credentials on a gateway without MFA, then dumped 9.7M customers' health data after the ransom refusal.
Criminals entered Medibank via a contractor's VPN credentials on a gateway without MFA, then dumped 9.7M customers' health data after the ransom refusal.
A criminal franchise paid up to $1M for flaws in its own malware, website, and Tor infrastructure — Silicon Valley tactics inside the ransomware economy.
A pro-Russia statement, a furious insider, and the full Jabber archive of history's most damaging ransomware brand — dumped for everyone to read.
UKG's Kronos Private Cloud ransomware outage forced thousands of employers onto paper time cards. The definitive SaaS continuity case.
October 2021's FSB operation ended REvil with arrests, asset seizures, and infrastructure capture. The talent lived on elsewhere.
Three patched-but-unapplied Exchange bugs chained into unauthenticated RCE. Webshells, mailbox theft, and ransomware followed at population scale within two weeks.
REvil turned Kaseya's remote-management platform into a mass-encryption weapon, hitting ~60 MSPs and up to 1,500 downstream businesses days before a patch could land.
REvil halted the world's largest meat processor over a holiday weekend; JBS restored from backups — and still paid $11M for leak suppression and restart insurance. The economics of ransom beyond decryption.
DarkSide entered through a no-MFA legacy VPN password, exfiltrated 100 GB, and encrypted Colonial's IT — prompting a precautionary shutdown of 45% of East Coast fuel supply. Anatomy of the most policy-consequential ransomware ever.
HelloKitty ransomware encrypted CDPR's network and stole Cyberpunk 2077 and Witcher 3 source code — then auctioned it on a crime forum after the studio refused to pay. The incident file on IP extortion, auction economics, and the no-ransom playbook.
On 20 February 2020, CISA published AA20-030A, a joint advisory describing how ransomware had disrupted a natural gas compression facility: a phishing link let commodity ransomware spread from IT into the OT network, encrypting data historians and polling servers, severing HMI visibility, and leaving operators blind to real-time pressure and flow data for two days. The advisory became a reference model for oil and gas asset owners because it mapped, step by step, how a single email chained into loss of operational visibility without directly controlling pipeline equipment. This retrospective walks through the kill chain, the defensive gaps, and the guidance that followed.
On 31 December 2019, foreign exchange giant Travelex took its UK and international websites and mobile apps offline following a cyberattack, an outage that also knocked out white-label travel money services at ASDA, Tesco and Sainsbury's overnight. When the story became public on 7 January 2020, the criminals behind Sodinokibi (REvil) ransomware were demanding 4.6 million pounds, claiming to have copied more than 5GB of customer data, and the company would spend weeks rebuilding systems by hand. This account reconstructs the verified timeline, the double-extortion playbook, and how the incident contributed to an August 2020 administration that cut more than a thousand UK jobs.