June 17, 2022

Italy's University of Pisa hit by data breach, ransom demanded

The University of Pisa in Italy reportedly is being held to ransom for $4.5 million.

BlackCat, or ALPHV, a Ransomware as a Service (RaaS) group, has claimed responsibility for the cyberattack and issued a ransom note, stating that the University has until June 16th to pay the ransom. The threat actor says the ransom will increase to $5 million if payment is not received.

Cybersecurity experts shared a photo of the ransom note, counting down the minutes until the price increases:

Recent Microsoft research said the threat actor is a prime example of the growing RaaS gig economy and is noteworthy due to its unconventional programming language (Rust). Using a "modern language for its payload," this ransomware attempts to evade detection, especially by conventional security solutions.

While BlackCat's arrival and execution vary based on the actors deploying it, the outcome is the same — target data is encrypted, exfiltrated, and used for 'double extortion,' where attackers threaten to release the stolen data to the public if the ransom isn't paid.