Cloud Hosting Provider DataResolution.net Battling Christmas Eve Ransomware Attack
2019-01-02 • Krebsonsecurity •
DataResolution.net, a California cloud hosting and business-continuity provider serving roughly 30,000 businesses, was hit by Ryuk ransomware on Christmas Eve 2018. Customer updates cited by KrebsOnSecurity said attackers used a compromised login account, gained control of the company’s data-center domain, and forced Data Resolution to shut down its network while restoring email, databases, and hosted accounting/payroll services. The article notes Ryuk was the same strain disrupting several U.S. newspapers and had previously been reported as possibly tied to a sophisticated North Korean hacking team, but the DataResolution incident itself is presented primarily as a cloud-provider ransomware compromise rather than a confirmed DPRK operation. The case is useful for tracking Ryuk tradecraft against managed service infrastructure, especially credential abuse, domain takeover, and business-impact recovery pressure.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| DOMAIN | dataresolution.net | 2019-01-02 | 2019-01-08 |