Hackers leak images to taunt Western Digital
The ALPHV ransomware operation, aka BlackCat, has published screenshots of internal emails and video conferences stolen from Western Digital, indicating they likely had continued access to the company's systems even as the company responded to the breach.
The leak comes after the threat actor warned Western Digital on April 17th that they would hurt them until they "cannot stand anymore" if a ransom was not paid. On March 26th, Western Digital suffered a cyberattack where threat actors breached its internal network and stole company data. However, no ransomware was deployed and files were not encrypted.
In response, the company shut down its cloud services for two weeks, including My Cloud, My Cloud Home, My Cloud Home Duo, My Cloud OS 5, SanDisk ibi, and SanDisk Ixpand Wireless Charger, together with linked mobile, desktop, and web apps. TechCrunch first reported that an "unnamed" hacking group breached Western Digital, claiming to have stolen ten terabytes of data. The threat actor reportedly shared with TechCrunch samples of the stolen data, which included files signed with Western Digital's stolen code-signing keys, unlisted corporate phone numbers, and screenshots of other internal data.