• About
    • About Us
    • Our Expertise
    • Meet The Team
    • Careers
  • Managed Services
    • Overview
    • Monitoring & Detection
    • Protection
    • Response
    • Training
  • Cyber Assessments
  • Consultancy
    • Consulting Services
    • Cyber Executives
  • News & Resources
    • In the News
    • Blog
    • Resources
  • Contact
Can We Help?
  • About
    • About Us
    • Our Expertise
    • Meet The Team
    • Careers
  • Managed Services
    • Overview
    • Monitoring & Detection
    • Protection
    • Response
    • Training
  • Cyber Assessments
  • Consultancy
    • Consultancy Service
    • Cyber Executives
  • News & Resources
    • In the News
    • Blogs
    • Resources
  • Contact
  • Can We Help?

How A Ransomware Gang Caused A National Emergency

Conti are a ransomware group who have been hitting the headlines in recent months, but you might have heard of them before – they’ve been in the public eye since 2020. Their operation is known as Ransomware-as-a-Service (RaaS), and they specialise in double extortion, otherwise known as pay-now-or-get-breached. They’ll hack their victims’ networks and steal data before encrypting it, threatening to make it public unless a ransom is paid. The gang doesn’t work alone - they’re believed to be linked to the Russian-speaking cyber crime organisation known as Wizard Spider.

 What is Conti?

Information on the group is sparse due to their secrecy and the turnover of its members, so it’s unknown how many individuals are in Conti. It’s believed that there’s a hierarchy to the group, with the most senior member, known by the aliases of Stern and Demon, acting as the CEO. Below Stern/Demon is Conti’s General Manager, who goes by Mango, and the two are in constant communication. Working underneath these two are teams of cyber criminals. The number of teams isn’t known, but the largest team is believed to include between 60 and 100 individuals. Conti are always recruiting new members – either from legitimate job recruitment websites or from hacker forums. Programmers who join them can earn $1,500 (£1,222) to $2,000 (£1,630) a month, as well as receive a share of Conti’s ransom profits.

Conti has long been suspected of working for or with the Russian government. This was confirmed during the Russian invasion of Ukraine, which began in February this year, as Conti declared their support of Russia, and threatened to deploy retaliatory measures if any cyber attacks were launched against the country. As a result of Conti’s allegiance with the Russian government, an anonymous insider (who supported Ukraine) leaked approximately 60,000 messages from internal chat logs, source code and other files used by Conti. These have provided almost all of the information currently known about the group and its inner workings.

What have they done?

Some of Conti’s known targets have included international brands and government agencies, such as: the Scottish Environment Protection Agency (SEPA), Fat Face, Ireland’s Health Service Executive, the Waikato District Health Board in New Zealand, Shutterfly, and KP Snacks. Their most recent attack was on the country of Costa Rica – Conti hit multiple government bodies, and on Sunday the 8th of May, the recently-appointed President of Costa Rica, Rodrigo Chaves Robles, was forced to declare a national emergency. The attack began in April, when Conti claimed that they’d stolen 672GB of data from government agencies. On the 8th of May, Conti’s data leak site was updated to state they’d leaked 97% of the stolen data – they’d demanded a $10 million (£8,156,700) ransom, which the Costa Rican government was unwilling to pay.

 It's believed that prior to January 2022, the Conti ransomware group had targeted over a thousand organisations and extorted over $150 million (£122,350,500) in ransom payments from their victims. With this in mind, the U.S. Department of State is now offering a reward for any information that could help identify and locate any members of the group. They’re offering up to $10 million (£8,156,700) for any information on high-ranking members, and an additional $5 million (£4,078,350) for information that leads to the conviction of individuals who have participated in any of Conti’s ransomware attacks. 

What can be done to stop them?

The question that cyber security and law enforcement organisations from around the world - especially from countries that are in the FVEY (Five Eyes) intelligence alliance – should be asking themselves, as they ramp up their efforts to stop or even slow down Conti, is “Will this be enough to stop such an incredible force within the cyber community?”

Cyber criminals will be looking for endpoints to get into your network, and one of the best ways of preventing data breaches is to make sure all of your operating systems, software, and firmware are as up-to-date as possible. In order to do that, you should always download patches and updates as soon as they’re released. Cyber security education is also important, and one of the best strategies you can implement to improve your organisation’s cyber defences. You should take care to ensure your staff know what kinds of links and emails they should be watching out for, and ensure they know what to do in the event of a data breach.

With the right knowledge and security tools, you can protect your information from data breaches, and we can help you take the right steps to secure your networks. At Cyber Security Associates, we offer a wide range of services for businesses looking to strengthen their defences, including training and educational courses – get in touch with us today to find out how we can help.

Related articles

Posted on December 16, 2021

CSA Awards of the Year 2021

As we near the end of year, an incredibly busy year for our teams in terms of growth and innovation, we wanted to take a moment to…

Posted on December 14, 2021

Cyber Essentials Changes: Here's Everything You Need To Know

Rapid digital transformation, mass adoption of cloud-based services and migration to home-working were necessary changes for businesses…

Posted on December 8, 2021

CSA 12 Days of Cyber Christmas

As the end of the year fast approaches, we wanted to share a little refresher on ways to ensure your technology and data remains…

Posted on December 1, 2021

Planning To Shop Online This Holiday Season? Here Are The Cybercrimes You Need To Be Aware Of

Black Friday and Christmas are considered a blessing and a curse within the retail industry. It’s a time where retailers…

Posted on October 20, 2021

This Apple “AirTag” Vulnerability could be harvesting your credentials

During late September, the headlines were hit with the news of a vulnerability within Apple’s AirTag…

Posted on October 13, 2021

September Security Roundup

Currently, the world faces not one pandemic but two: Coronavirus and the rise of ransomware attacks…

Posted on October 10, 2021

Is Data More Valuable Than Jewels? The A-List Cyber Heist That’s Putting Ransomware Attacks On The Map

Cybercriminals don’t discriminate. It doesn’t matter how famous you are, if your information is vulnerable…

Posted on October 6, 2021

CSA adds Lookout Mobile Endpoint Security to growing solutions portfolio

Following the global pandemic, the mass migration to remote working was a necessary move…

Posted on September 15, 2021

​​The Rising Popularity of NFTs and The Rising Security Threat

The art world is known for being ahead of the curve, adopting new and interesting technologies to…

Posted on September 7, 2021

TG1021 (Praying Mantis): The new threat actor group that could be targeting your IIS servers!

Recently, an infamous threat actor group going by the name of TG1021 or Praying Mantis…

Posted on August 19, 2021

Is Cyber Training and Education working?

The report from the ICO on the ‘surprising’ decline in personal data breaches…

Posted on August 13, 2021

How did an unknown hacker steal over $600M in cryptocurrencies in the biggest ever crypto based cyber-attack?

On 10th August 2021, Poly Network announced in a tweet that it had been attacked…

Posted on May 12, 2021

How to Prevent a Ransomware Attack

According to a 2020 survey by Sophos, 51% of organisations were hit by Ransomware in the last year…

Posted on March 23, 2021

Is your Microsoft M365 service secure from attackers? Are you sure?

The mass migration to remote working as a result of the coronavirus pandemic has…

Posted on January 10, 2021

Covid-19: How to prepare your staff
for remote working

Since the initial Covid-19 outbreak, the nation’s workforce had to learn to quickly…

Posted on December 13, 2020

Covid-19: Cyber Criminals Launch
Their Own ‘Virus’

Whilst the world is currently preoccupied with public health, cyber attackers have taken…

Posted on November 20, 2020

The rise of Covid-19 phishing scams

Whilst the rollout of the Covid-19 vaccine across the UK brings with it the good news…

About

  • About Us
  • Our Expertise
  • Meet The Team
  • Careers

Managed Services

  • Overview
  • Monitoring & Detection
  • Protection
  • Response
  • Training

Consultancy

  • Consulting Services
  • Cyber Executives

News & Resources

  • In the News
  • Blog
  • Resources

Cyber Assessments

Can We Help?

Partner Portal

Contact

Head Office Unit 11, Wheatstone Court, Waterwells Business Park, GL2 2AQ
©2022 Cyber Security Associates. All Rights Reserved.
Terms of Use Privacy Policy
Powered by P1C
This website stores cookies on your computer. These cookies are used to collect information about how you interact with our website and allow us to remember you. We use this information in order to improve and customize your browsing experience and for analytics and metrics about our visitors both on this website and other media. To find out more about the cookies we use, see our Privacy Policy.
Cookie settingsAccept
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT

Can We Help?