Employee arrested for locking Windows admins out of 254 servers in extortion plot
ID: c172f023-89bb-5ac0-9f38-c3f292da4fa7
STIX ID: report--c172f023-89bb-5ac0-9f38-c3f292da4fa7
Feed Name: Bleeping Computer
An alleged insider extortion incident: a former core infrastructure engineer remotely accessed a New Jersey industrial company's systems, changed passwords for domain and local administrator accounts and hundreds of user accounts, scheduled shutdowns that affected 254 servers and thousands of workstations, and sent a ransom demand for €700,000 (20 BTC). Forensic analysis tied web searches and use of a hidden VM to the activity; the suspect was arrested and faces charges including extortion, intentional computer damage, and wire fraud.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
