There have been more leaks of stolen data by ransomware groups this year than across the entirety of 2022, according to new research from WithSecure. Alongside this growth comes a switch in ransom-leveraging tactics, with ransomware groups no longer simply relying on victims not having suitable data recovery systems in place and coughing up the money.
Weโve seen tactics evolve in recent years to include denial of service attacks after the initial data exfiltration and encrypting exploit, as well as data leaking.
But now the ALPHV/BlackCat group has taken things one step further by reporting a victim to the US Securities and Exchange Commission (SEC).
ALPHV exploits SEC ruling
In a move as bold as it is outrageous, the infamous cybercrime outfit has sought to use a new SEC ruling in order to pile more pressure on the victim, digital lending platform MeridianLink, to pay up.
Item 1.05 of Form 8-K requires public companies such as MeridianLink to disclose material cybersecurity incidents within four business days.
However, this rule isnโt set to take effect until December.
ALPHV said it reported this non-compliance as it was โinvolved in a material breach impacting customer data and operational information, for failure to file the required disclosure with the Securities and Exchange Commissionโ.
As you might have guessed, this follows MeridianLinkโs apparent failure to engage with the criminals over the ransom demand.
What the experts say
“Using the threat of filing a ‘failure to report’ complaint against its own victim to the SEC is a compelling tactic that could weaponise a government regulation for a cybercriminal groupโs benefit,โ says Patrick Tiquet, VP Security & Architecture at Keeper Security.
โWith the new SEC disclosure going into effect in mid-December, we will surely see an increase in hackers leveraging this as an extortion tactic to humiliate their victims and guarantee payment is made,โ Darren Williams, CEO and Founder at BlackFog, warns.
โThe added levels of embarrassment from hackers exposing organisationsโ failure to follow regulations and remain transparent with their customers and partners, should give them all the more reason to avoid delayed reporting and hopefully eliminate this new extortion tactic.โ
He adds: โMisuse of the new SEC rules to put additional pressure on publicly traded companies was foreseeable, moreover, ransomware actors will likely start filing complaints with other US and EU regulatory agencies when the victims fail to disclose a breach within the timeframe provided by law.
โNot all security incidents are data breaches, and not all data breaches are reportable data breaches,โ argues Dr Ilia Kolochenko, Chief Architect at ImmuniWeb and Adjunct Professor of Cybersecurity & Cyber Law at Capitol Technology University.
โTherefore, regulatory agencies and authorities should carefully scrutinise such reports and probably even establish a new rule to ignore reports uncorroborated with trustworthy evidence, otherwise, exaggerated or even completely false complaints will flood their systems with noise and paralyse their work.โ
With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.
To provide the best experiences, we and our partners use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us and our partners to process personal data such as browsing behavior or unique IDs on this site and show (non-) personalized ads. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Click below to consent to the above or make granular choices. Your choices will be applied to this site only. You can change your settings at any time, including withdrawing your consent, by using the toggles on the Cookie Policy, or by clicking on the manage consent button at the bottom of the screen.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.