ADVERTISEMENT

Harvard Business Publishing licensee hit by ransomware

Threat actors got to a database with over 152,000 customer records before its owner, the Turkish branch of Harvard Business Review, closed it. Crooks left a ransom note, threatening to leak the data and inform authorities of the EU’s General Data Protection Regulation (GDPR) violations.

HBR Turkey

By Shutterstock

Jurgita Lapienytė
Jurgita Lapienytė Chief Editor
October 6, 2022 Updated: October 7, 2022 5 min read
  • On September 16, Cybernews discovered an open database belonging to a Harvard Business Publishing licensee in Turkey called Infomag.
  • Three days later, Cybernews researchers revisited the database to see whether it had been closed, and found it had been hit with ransomware.
  • An attacker asked for a 0.01 BTC (about $200) ransom, threatening to start leaking data and warning about huge fines related to the potential GDPR violations.
  • A Cybernews investigation revealed that at least five victims acceded to the cybercriminals’ demands. However, the last payment to the attackers was made on July 31, so there’s no evidence of Infomag having paid the ransom.

The discovery

  • The 3.9GB-strong database held information from 2017 onwards.
  • The database contained 15 employee emails, names, and poorly protected (SHA1-128bit) passwords.
  • The database index marked “Users” contained over 152,000 entries: names, emails, links to social media profiles, and passwords, some of which were hashed using a very weak MD5 algorithm.
  • The “Orders” index stored names, physical addresses, payment types, and phone numbers of both companies and individuals. It also had organizations’ tax numbers.

Dangerous leak

ADVERTISEMENT

The ransomware

Proper encryption is key

ADVERTISEMENT