blackbyte

NFL's San Francisco 49ers Hit by Blackbyte Ransomware Attack

The NFL's San Francisco 49ers team is recovering from a cyberattack by the BlackByte ransomware gang who claims to have stolen data from the American football organization.

The 49ers confirmed the attack in a statement to BleepingComputer and said it caused a temporary disruption to portions of their IT network.

While the 49ers did not confirm whether hackers successfully deployed the ransomware, they said they are still in the process of recovering systems, indicating that devices were likely encrypted.

"The San Francisco 49ers recently became aware of a network security incident that resulted in temporary disruption to certain systems on our corporate IT network. Upon learning of the incident, we immediately initiated an investigation and took steps to contain the incident.

Third-party cybersecurity firms were engaged to assist, and law enforcement was notified.

While the investigation is ongoing, we believe the incident is limited to our corporate IT network; to date, we have no indication that this incident involves systems outside of our corporate network, such as those connected to Levi’s Stadium operations or ticket holders.

As the investigation continues, we are working diligently to restore involved systems as quickly and as safely as possible."

San Francisco 49ers

To conduct a ransomware attack, threat actors breach a corporate network and silently spread to other devices while stealing data. The hackers ultimately deploy malware that encrypts all of the devices on the network, while leaving ransom notes demanding a cryptocurrency payment to receive a decryptor.

NFL's San Francisco 49ers Hit by Blackbyte Ransomware Attack Click to Tweet

The ransomware gangs then use the stolen files as leverage, threatening to release them if they are not paid a ransom.

The BlackByte ransomware gangs claimed responsibility for the attack yesterday, right as the NFL gets ready for Super Bowl 2022, by beginning to leak files that they claim were stolen during the attack.

blackbyte
BlackByte ransomware leaking the San Francisco 49ers' data

The leaked data is a 292MB archive of files that the threat actors claim are stolen 2020 invoices from the 49ers' network.

BlackByte usually releases its victims' data in increasing amounts to further pressure the victim into paying.

While it is not known how much data has been stolen during the attack on the 49ers, BlackByte has stolen gigabytes of data from previous victims.

Who is BlackByte?

The BlackByte ransomware operation launched in July 2021 when it began targeting corporate victims worldwide.

The ransomware gang is not particularly active compared to other groups, but they have successfully conducted many attacks, meaning the enterprise should not ignore them.

blackbyte
Example BlackByte ransom note

The ransomware gang is known to utilize vulnerabilities to gain initial access to a network, illustrating the need to always have the latest software updates installed.

In October 2021, the BlackByte operation made the significant mistake of reusing the same decryption/encryption key in multiple attacks.

While BlackByte quickly fixed their mistake, it allowed cybersecurity firm Trustwave to create a free decryptor for some of the ransomware gang's victims.


Source: https://www.bleepingcomputer.com/news/security/nfls-san-francisco-49ers-hit-by-blackbyte-ransomware-attack/


If you are interested in this content, you can follow my LinkedIn and Twitter accounts and access more content.


Join our list

Sign up for the e-mail list to be informed about the developments in the cyber world and to be informed about the weekly newsletter.

Haber bültenine kaydolduğunuz için teşekkürler!

Something went wrong.

Leave a Comment

NFL'nin San Francisco 49ers Takımı Blackbyte Fidye Yazılımı Saldırısına Uğradı

3 min