logo

OmniVision disclosed a data breach after the 2023 Cactus ransomware attack

ID: 0057494a-1375-58a8-83c3-338242c13dd7

STIX ID: report--0057494a-1375-58a8-83c3-338242c13dd7

Feed Name: Security Affairs

Threat Score
72/100

Date Published: 2024-05-22

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

OmniVision disclosed a data breach following a September 2023 intrusion by the Cactus ransomware group that encrypted systems and exfiltrated personal and corporate documents (including passport images, NDAs, and contracts); the extortion gang published proof and ultimately released the stolen data. The report details the group's TTPs—use of legitimate remote access tools (Splashtop, AnyDesk, SuperOps RMM), Cobalt Strike, Chisel, PowerShell-based discovery and deployment scripts, antivirus removal via batch scripts, and Rclone for exfiltration—and notes mitigation steps taken by OmniVision (increased monitoring, cloud migrations, policy updates, and credit monitoring for affected individuals).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.