Accounting software provider Tipalti says it is investigating a claim by ransomware group ALPHV that they have gained access to Tipalti's systems.
Tipalti makes software for accounting and payment automation and has some big names among its customers.
Organizations who share these file lists, samples or notes with Tipalti run the risk of having their data leaked immediately.
The ransomware group claim to have had access since September 8, 2023.
They say they have stolen 265 GB of data, including data for Twitch and Roblox, who they say they will extort separately.
A Roblox spokesperson told BleepingComputer that the company is working with Tipalti to investigate the claims, but is currently unaware of any impact on its systems.
ALPHV is one of the most active ransomware-as-a-service operators and regularly appears in our monthly ransomware reviews as one of the top 5 most active groups.
Create a plan for patching vulnerabilities in internet-facing systems quickly; and disable or harden remote access like RDP and VPNs. Prevent intrusions.
Stop threats early before they can even infiltrate or infect your endpoints.
Use endpoint security software that can prevent exploits and malware used to deliver ransomware.
Make it harder for intruders to operate inside your organization by segmenting networks and assigning access rights prudently.
Use EDR or MDR to detect unusual activity before an attack occurs.
Deploy Endpoint Detection and Response software like ThreatDown EDR that uses multiple different detection techniques to identify ransomware, and ransomware rollback to restore damaged system files.
Keep backups offsite and offline, beyond the reach of attackers.
Test them regularly to make sure you can restore essential business functions swiftly.
Once you've isolated the outbreak and stopped the first attack, you must remove every trace of the attackers, their malware, their tools, and their methods of entry, to avoid being attacked again.
Our business solutions remove all remnants of ransomware and prevent you from getting reinfected.
This Cyber News was published on www.malwarebytes.com. Publication date: Tue, 05 Dec 2023 13:43:04 +0000