Impact on affected companies
Companies whose data was stolen by LockBit and is now publicly accessible face significant risks:
- Increased risk of attack: Cybercriminals could use the published information to carry out targeted phishing attacks. By knowing internal communication channels and sensitive corporate data, deception attacks can be precisely designed. In addition, further extortion could take place by perpetrators threatening those affected with a second publication.
- Reputational damage: The disclosure of business relationships with LockBit or payments made can massively damage public trust. Companies that rely on customer data in particular, such as financial service providers or healthcare companies, risk a significant loss of trust. Even mere mention in connection with criminal activities can result in long-term reputational damage.
- Legal consequences: Data breaches can result in significant fines under the GDPR. The failure to report an incident to the data protection authority is particularly critical and may additionally be subject to criminal penalties. Companies also face the challenge of proving that their internal security measures met the state of the art.
Recommended measures
Affected companies should immediately consider the following steps:
- Data Leak Check: Companies should immediately check whether and what data is included in the leak. The support of IT forensic experts can be useful in this process. We have access to the leaked data and you can assist with the review.
- Communication: Transparent information sharing with customers, partners, and regulatory authorities regarding the incident and the measures taken is crucial. Communication should be proactive and factual to avoid further speculation.
- Legal advice Specialized attorneys in the field of cybercrime can help review legal obligations and avoid potential fines.
- Documentation: If you should have paid ransom to LockBit or have not informed the data protection authority about the incident, ensure that the basis for this decision is well documented. According to the GDPR, you are obligated to document security incidents. Documentation is particularly important if criminally relevant ransom payments were justified by the defense of necessity.
- Prevention: Implementation of improved security protocols and regular employee training to raise awareness of cyber threats.
For more information on similar incidents, please see our Blog post about the Everest ransomware group.
The law firm ATB.LAW offers companies comprehensive support in the area of ransomware and other cyber attacks. We have a dense network of selected IT specialists. Contact lawyer Roman Taudes under taudes@atb.law or by phone at +43 1 3912345.