Canadian vehicle rental service hit by ransomware
One of Canada’s largest car rental companies is trying to recover after being hit by a ransomware attack.
A spokesman for US-based car rental giant Enterprise Holdings announced Saturday that its Canadian division, Discount Car and Truck Rentals, had been hit by a cyber attack. Enterprise’s Canadian division bought Discount last fall. This is the latest Canadian company to fall victim to ransomware on the heels of a British Columbia real estate company that suffered a similar attack in late January.
Enterprise Holding brands include Enterprise Rent-A-Car, National Car Rental and Alamo Rent a Car.
On Sunday morning, the Discount website was still offline due to “technical problems”.
IT World Canada asked the dealership for a comment when the Darkside ransomware group posted a notice on its website a few days ago that it had copied 120 GB of corporate, banking and franchise data from Discount’s.
“Discount Car and Truck Rentals was exposed to a ransomware attack that affected the office of the Discount headquarters,” said a statement sent to the publication. “A dedicated team quickly isolated and contained the attack. The team is working to investigate and restore the service as quickly and safely as possible. “
When asked by email whether personal information from customers or employees was copied and how the attack began, a spokesman said only that the investigation is still ongoing.
The online statement from the Darkside Group states: “We have downloaded a lot of interesting data from your network. If you need proof, we are at your disposal. The data is pre-installed and published automatically if you don’t pay. “
As evidence of the data, there is a screenshot of alleged folders from the file structure of Discount.
According to cybersecurity firm Acronis, Darkside emerged in August 2020 to use encryption and data theft as a printing tactic to get money from corporate victims. Brookside Residential is one of the Canadian victims.
A few months after going live, Darkside announced a partner program (referred to as Ransomware-as-a-Service by Infosec professionals) that would allow paying or authorized cybercriminals to use their code to attack part of the ransom payments.
“We’re a new product on the market, but that doesn’t mean we have no experience and came out of nowhere,” the group said at the time. “We have made millions of dollars in profit by partnering with other well-known cryptolockers. We created Darkside because we couldn’t find the perfect product for us. Now we have it.
“Based on our principles, we will not attack the following goals: medicine, education, nonprofits, government. We only attack targets that can pay the requested amount. We don’t want to kill your company. Before each attack, we analyze your accounting and, based on your net income, determine how much you can pay. You can ask all your questions on the chat before paying and our support team will answer them. ”
Cybersecurity firm Bitdefender released a decryption key in January in hopes that it would thwart the ransomware. However, Darkside released a statement that this has been fixed and that victims cannot rely on this solution.
Follow ReMax Kelowna
Meanwhile, the Conti ransomware group, which hit ReMax Kelowna last month, has released over 10,000 documents that it claims were copied in the attack. The documents contain at least one T4 receipt from an employee or former employee.
The attackers’ move angered ReMax Kelowna owner Jerry Redman, who said in an interview on Friday that he had not received any threat notes or communications from the attacker before the full load of stolen data was released.
Speaking to IT World Canada on February 5, Redman said attackers copied documents but were unable to deploy ransomware. At the time, he said the copied documents were mostly PDFs on a company information server. He emphasized that a server with customer information would not be affected.
“I know ten thousand documents were put online,” Redman said on Friday. “But that’s less than one percent of the data on my server. So they never got mine [the one with customer data] Server.”
“We will inform everyone of everything that is gone. None of our customer information is on it [compromised] Server. If there is a T4 receipt on this server, it would have been one of my employees who worked for us or for the company before I owned it. “
All employees have been told that personal information may have been copied, he said.
When asked how much personally identifiable information about people from the threat group was on hold, Redman said it would take some time to confirm.
“We’re still analyzing the data … everyone we need to help is being looked after,” he said.
Cyber security experts emphasize the importance of using cybersecurity fundamentals to reduce the chance of being hit by ransomware. This includes knowing where sensitive data is and protecting it with access control and encryption. Updating and patching of software systems, including websites, in particular anti-virus and anti-malware software; and training staff to look for suspicious email attachments and links without clicking them.
Would you recommend this article?
Thank you for taking the time to let us know what you think about this item!
We’d love to hear your thoughts on this or any other story you read in our publication. Click this link to send me a note →
Jim Love, Chief Content Officer of IT World Canada
Related download
Sponsor: CanadianCIO
Cybersecurity Conversations With Your Board – A Survival Guide
A SURVIVAL MANUAL BY CLAUDIO SILVESTRI, VICE PRESIDENT AND CIO, NAV CANADA
Download now