Read more about the article Colonial Pipeline Ransomware: One Password, 17 Emergency States
Hmmnm cover v2 — TECHNOLOGY

Colonial Pipeline Ransomware: One Password, 17 Emergency States

DarkSide entered through a no-MFA legacy VPN password, exfiltrated 100 GB, and encrypted Colonial's IT — prompting a precautionary shutdown of 45% of East Coast fuel supply. Anatomy of the most policy-consequential ransomware ever.

Continue ReadingColonial Pipeline Ransomware: One Password, 17 Emergency States
Read more about the article CD Projekt Red Ransomware: The Source-Code Auction That Failed
Hmmnm cover v2 — SECURITY

CD Projekt Red Ransomware: The Source-Code Auction That Failed

HelloKitty ransomware encrypted CDPR's network and stole Cyberpunk 2077 and Witcher 3 source code — then auctioned it on a crime forum after the studio refused to pay. The incident file on IP extortion, auction economics, and the no-ransom playbook.

Continue ReadingCD Projekt Red Ransomware: The Source-Code Auction That Failed
Read more about the article Ransomware at a Gas Compression Facility: CISA’s OT Alert
Hmmnm cover v2 — SECURITY

Ransomware at a Gas Compression Facility: CISA’s OT Alert

On 20 February 2020, CISA published AA20-030A, a joint advisory describing how ransomware had disrupted a natural gas compression facility: a phishing link let commodity ransomware spread from IT into the OT network, encrypting data historians and polling servers, severing HMI visibility, and leaving operators blind to real-time pressure and flow data for two days. The advisory became a reference model for oil and gas asset owners because it mapped, step by step, how a single email chained into loss of operational visibility without directly controlling pipeline equipment. This retrospective walks through the kill chain, the defensive gaps, and the guidance that followed.

Continue ReadingRansomware at a Gas Compression Facility: CISA’s OT Alert
Read more about the article Travelex Ransomware 2020: When Sodinokibi Crippled a Currency Giant
Hmmnm cover v2 — SECURITY

Travelex Ransomware 2020: When Sodinokibi Crippled a Currency Giant

On 31 December 2019, foreign exchange giant Travelex took its UK and international websites and mobile apps offline following a cyberattack, an outage that also knocked out white-label travel money services at ASDA, Tesco and Sainsbury's overnight. When the story became public on 7 January 2020, the criminals behind Sodinokibi (REvil) ransomware were demanding 4.6 million pounds, claiming to have copied more than 5GB of customer data, and the company would spend weeks rebuilding systems by hand. This account reconstructs the verified timeline, the double-extortion playbook, and how the incident contributed to an August 2020 administration that cut more than a thousand UK jobs.

Continue ReadingTravelex Ransomware 2020: When Sodinokibi Crippled a Currency Giant