University Of Utah Pays $457,000 To Ransomware Gang

University of Utah
Image via University of Utah; Composition: ZDNet

The University of Utah revealed today that it paid a ransomware gang $457,059 in order to avoid having hackers leak student information online.

The incident is the latest in a long string of ransomware attacks where criminal groups steal sensitive files from the hacked companies before encrypting their files; and in case victims refuse to pay, threaten to release the stolen documents as a second extortion scheme.

Unfortunately, this is exactly what happened in the case of the University of Utah. In a statement posted on its website today, the university said it actually dodged a major ransomware incident and that the hackers managed to encrypt only 0.02% of the data stored on its servers.

The university said its staff restored from backups; however, the ransomware gang threatened to release student-related data online, which, in turn, made university management re-think their approach towards not paying the attackers.

"After careful consideration, the university decided to work with its cyber insurance provider to pay a fee to the ransomware attacker," the university said today.

"This was done as a proactive and preventive step to ensure information was not released on the internet.

"The university's cyber insurance policy paid part of the ransom, and the university covered the remainder. No tuition, grant, donation, state or taxpayer funds were used to pay the ransom," University of Utah officials added.

University officials also provided details about the attack today, such as the date when it took place (July 19, 2020), and what part of the network it impacted (the network of the university's College of Social and Behavioral Science [CSBS]).

However, the university did not reveal which ransomware gang was behind the attack.

All signs point to NetWalker

Brett Callow, a threat analyst at cyber-security firm Emsisoft, told ZDNet today that, although lacking concrete evidence, the NetWalker ransomware gang is most likely behind the attack.

This particular group, which is believed to have made more than $25 million from ransom payments this year, has been behind a recent wave of attacks against university networks, such as the attacks against Michigan State, the University of California at San Francisco (paid $1.14 million), Columbia College Chicago, and the City University of Seattle.

But Callow also took issue with University of Utah officials paying the attackers to stop a data leak; warning against such practice has little benefits.

"Paying ransoms to prevent data being published seems to make little sense," Callow told us.

"All what organizations are paying for in this scenario is a pinky promise from a bad faith actor that the stolen data will be destroyed. Whether the groups do ever destroy data is something only they know, but I suspect they do not. Why would they? They may be able to monetize the information at a later data or use it for spear phishing or identity theft."

RECENT NEWS

Reassessing AI Investments: What The Correction In US Megacap Tech Stocks Signals

The recent correction in US megacap tech stocks, including giants like Nvidia, Tesla, Meta, and Alphabet, has sent rippl... Read more

AI Hype Meets Reality: Assessing The Impact Of Stock Declines On Future Tech Investments

Recent declines in the stock prices of major tech companies such as Nvidia, Tesla, Meta, and Alphabet have highlighted a... Read more

Technology Sector Fuels U.S. Economic Growth In Q2

The technology sector played a pivotal role in accelerating America's economic growth in the second quarter of 2024.The ... Read more

Tech Start-Ups Advised To Guard Against Foreign Investment Risks

The US National Counterintelligence and Security Center (NCSC) has advised American tech start-ups to be wary of foreign... Read more

Global IT Outage Threatens To Cost Insurers Billions

Largest disruption since 2017’s NotPetya malware attack highlights vulnerabilities.A recent global IT outage has cause... Read more

Global IT Outage Disrupts Airlines, Financial Services, And Media Groups

On Friday morning, a major IT outage caused widespread disruption across various sectors, including airlines, financial ... Read more