ransomware
Insurers and vendors alike call for clarity on who would be affected, and what reporting mandates will look like.
In earlier SafePay attacks the group has actively gone after backups and deleted Volume Shadow Copies (VSC) in an effort to inhibit recovery activities.
Full-scale encryption, local exfiltration and self-cleanup into a single Rust binary.
A range of ransomware groups have been seen spoofing IT support numbers or abusing default Teams credentials in social engineering attacks over the past 18 months.
MFA "did not protect against the continued use of WMIC and remote PowerShell activity"
Parcels were moving again in six weeks but the "full recovery" took much longer