{"id":39469,"date":"2022-07-14T10:30:00","date_gmt":"2022-07-14T10:30:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/39469"},"modified":"2022-07-14T10:30:00","modified_gmt":"2022-07-14T10:30:00","slug":"videogame-maker-bandai-namco-confirms-cyber-attack","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=39469","title":{"rendered":"Videogame maker Bandai Namco confirms cyber attack"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/07\/videogame-maker-bandai-namco-confirms-cyber-attack.jpg\" class=\"ff-og-image-inserted\"><\/div>\n<p>After days of fevered speculation, <a href=\"https:\/\/en.bandainamcoent.eu\/\">Bandai Namco<\/a>, the Japan-based developer of videogames including Pac-Man, Dark Souls, Soulcaliber and Tekken, has confirmed a cyber attack against its systems did take place, although it stopped short of describing it as a ransomware attack.<\/p>\n<p>Talk of an incident surfaced on Monday 11 July when <a href=\"https:\/\/www.vx-underground.org\/\">VX Underground<\/a> revealed via Twitter that Bandai Namco\u2019s details had appeared on a <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252521596\/Alphv-ransomware-gang-ups-pressure-with-new-extortion-scheme\">victim leak site<\/a> run by the ALPHV \u2013 also known as <a href=\"https:\/\/www.computerweekly.com\/news\/252513488\/BlackCat-ransomware-gang-claims-responsibility-for-Swissport-attack\">BlackCat<\/a> \u2013 ransomware crew, along with a threat to leak its data.<\/p>\n<blockquote class=\"twitter-tweet\">\n<p dir=\"ltr\" lang=\"en\">ALPHV ransomware group (alternatively referred to as BlackCat ransomware group) claims to have ransomed Bandai Namco.<\/p>\n<p>Bandai Namco is an international video game publisher. Bandai Namco video game franchises include Ace Combat, Dark Souls, Dragon Ball*, Soulcaliber, and more. <a href=\"https:\/\/t.co\/hxZ6N2kSxl\">pic.twitter.com\/hxZ6N2kSxl<\/a><\/p>\n<p> \u2014 vx-underground (@vxunderground) <a href=\"https:\/\/twitter.com\/vxunderground\/status\/1546479433405665280?ref_src=twsrc%5Etfw\">July 11, 2022<\/a>\n<\/p><\/blockquote>\n<p><a href=\"https:\/\/www.videogameschronicle.com\/news\/bandai-namco-has-been-hacked\/\">In a statement provided to multiple outlets<\/a>, the publisher said the internal systems of several group companies in Asia had indeed been accessed by a third party.<\/p>\n<p>\u201cAfter we confirmed the unauthorised access, we have taken measures such as blocking access to the servers to prevent the damage from spreading,\u201d the firm said.<\/p>\n<p>\u201cIn addition, there is a possibility that customer information related to the Toys and Hobby Business in Asian regions (excluding Japan) was included in the servers and&nbsp;PCs, and we are currently identifying the status about existence of leakage, scope of the damage, and investigating the cause.<\/p>\n<p>\u201cWe will continue to investigate the cause of this incident and will disclose the investigation results as appropriate. We will also work with external organisations to strengthen security throughout the group and take measures to prevent recurrence,\u201d the spokesperson added.<\/p>\n<p>\u201cWe offer our sincerest apologies to everyone involved for any complications or concerns caused by this incident.\u201d<\/p>\n<p>Commenting on the incident, <a href=\"https:\/\/www.vectra.ai\/\">Vectra<\/a> EMEA CTO Steve Cottrell said: \u201cBandai Namco appears to be the latest in a growing line of victims of <a href=\"https:\/\/www.techtarget.com\/whatis\/definition\/ransomware-as-a-service-RaaS\">ransomware-as-a-service<\/a> [RaaS] group ALPHV. The group has been upping the stakes recently, hitting businesses of all sizes worldwide and extorting victims for all they\u2019re worth \u2013 <a href=\"https:\/\/resecurity.com\/blog\/article\/blackcat-aka-alphv-ransomware-is-increasing-stakes-up-to-25m-in-demands\">reportedly charging up to $2.5m for ransoms<\/a>, and carrying out \u2018quadruple extortion\u2019 ransomware attacks, hitting victims with data encryption, data theft, denial-of-service attacks and further harassment, all pressuring them to cough up.\u201d<\/p>\n<p>ALPHV\/BlackCat has been operational since late 2021, and <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252516148\/BlackCat-emerges-as-one-of-the-top-ransomware-threats\">likely has links to the BlackMatter group<\/a> and <a href=\"https:\/\/www.computerweekly.com\/news\/252504921\/BlackMatter-goes-on-the-record-about-DarkSide-and-REvil-links\">through them, possibly, Darkside and REvil<\/a>. It has struck a number of high-profile victims, including Germany-based fuel distributor <a href=\"https:\/\/www.computerweekly.com\/news\/252512876\/BlackCat-crew-supposedly-behind-OilTanking-ransomware-heist\">OilTanking<\/a> and aviation services firm <a href=\"https:\/\/www.computerweekly.com\/news\/252513488\/BlackCat-ransomware-gang-claims-responsibility-for-Swissport-attack\">Swissport<\/a> and, more recently, <a href=\"https:\/\/www.techtarget.com\/searchsecurity\/news\/252516676\/April-ransomware-attacks-slam-US-universities\">a number of universities in the US<\/a>.<\/p>\n<p>Jonathan Earley,&nbsp;a cyber threat response analyst at Dublin-based <a href=\"https:\/\/www.integrity360.com\/\">Integrity360<\/a>, has dealt with multiple ALPHV intrusions in recent months.<\/p>\n<p>He said it was becoming clear that as the RaaS economy becomes increasingly specialised \u2013 with some threat actors specialising in initial access, some in post-compromise activity, and some in victim monetisation, security teams\u2019 jobs are becoming harder because it is increasingly unclear who is doing what.<\/p>\n<p>Multiple ALPHV victims, he said, seem to have fallen prey to an identical initial access vector being used by different operations, like the result of <a href=\"https:\/\/www.computerweekly.com\/news\/252521553\/2k-to-access-your-organisation-on-the-dark-web\">active initial access brokers<\/a> (IABs) selling their bridgeheads to others.<\/p>\n<p>However, he told Computer Weekly in emailed comments, there are some commonalities seen across ALPHV intrusions. Most notably, said Earley, the gang often makes an immediate attempt to encrypt <a href=\"https:\/\/www.vmware.com\/uk\/products\/esxi-and-esx.html\">VMware ESXi<\/a> infrastructure.<\/p>\n<p>\u201cIn our experience, this can be devastating for many organisations because much of their estate is virtualised, additionally from the attacker\u2019s perspective, encrypting one server can bring a victim organisation to its knees,\u201d he said.<\/p>\n<p>\u201cWe would recommend the following mitigations for ESXI systems: network segmentation for VMware ESXI and vCenter Server Management; use <a href=\"https:\/\/kb.vmware.com\/s\/article\/1008077\">Lockdown Mode in ESXI<\/a>; robust backups; enable multifactor authentication; and have centralised logging.\u201d<\/p>\n<p>Earley added: \u201cAside from locking down ESXi, it is imperative organisations ensure their endpoint protection capabilities and coverage can detect tools such as BloodHound AD enumeration, Cobalt Strike and lateral movement Powershell scripts such as ADRecon.<\/p>\n<p>\u201cFurthermore, on the network side, correlation rules identifying lateral movement with PsExec and traffic to sites such as MEGAsync would be considered important.\u201d<\/p>\n","protected":false},"excerpt":{"rendered":"<p>After days of fevered speculation, Bandai Namco, the Japan-based developer of videogames including Pac-Man, Dark Souls, Soulcaliber and Tekken, has confirmed a cyber attack against its systems did take place, although it stopped short of describing it as a ransomware attack. Talk of an incident surfaced on Monday 11 July when VX Underground revealed via [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":39470,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-39469","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/39469","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=39469"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/39469\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/39470"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=39469"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=39469"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=39469"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}