Cloud Hosting Provider DataResolution.net Battling Christmas Eve Ransomware Attack

2019-01-02 Krebsonsecurity

https://krebsonsecurity.com/2019/01/cloud-hosting-provider-dataresolution-net-battling-christmas-eve-ransomware-attack/

Thumbnail for Cloud Hosting Provider DataResolution.net Battling Christmas Eve Ransomware Attack

DataResolution.net, a California cloud hosting and business-continuity provider serving roughly 30,000 businesses, was hit by Ryuk ransomware on Christmas Eve 2018. Customer updates cited by KrebsOnSecurity said attackers used a compromised login account, gained control of the company’s data-center domain, and forced Data Resolution to shut down its network while restoring email, databases, and hosted accounting/payroll services. The article notes Ryuk was the same strain disrupting several U.S. newspapers and had previously been reported as possibly tied to a sophisticated North Korean hacking team, but the DataResolution incident itself is presented primarily as a cloud-provider ransomware compromise rather than a confirmed DPRK operation. The case is useful for tracking Ryuk tradecraft against managed service infrastructure, especially credential abuse, domain takeover, and business-impact recovery pressure.

Indicators of Compromise

Type Value First Seen Last Seen
DOMAIN dataresolution.net 2019-01-02 2019-01-08

Related Reports

« Back