The US State Department has offered a $10 million bounty for information linking members of the Kropp affiliate responsible for a recent data extortion campaign to foreign governments.
Using the #StopRansomware hashtag, the ministry announced the announcement as part of its Rewards for Justice initiative. Launched in 1984, the program aims to enhance national security by soliciting information on terrorists, North Korean activities, cyber threat actors, and election interference.
Rewards for Justice: Read more about US Doubles Rewards for North Korean Hacker Information.
“Do you have information linking foreign governments to the CloP ransomware gang and other malicious cyber actors targeting US critical infrastructure?” The post says. “Send me a tip. You might be eligible for a reward too.”
The news follows the successful Clop campaign targeting users of the popular MOVEit managed file transfer service. After exploiting a zero-day vulnerability in software, the group claims to have compromised data belonging to hundreds of organizations.
Several US government agencies are believed to have been caught in the campaign, along with major brands such as British Airways, Boots and the BBC. In the campaign, Kropp’s affiliates are trying to extort money from victims, threatening to leak the stolen data if they don’t comply. don’t pay
Officials told the Federal News Network that the personal information of tens of thousands of US government employees may have been compromised as a result.
However, the identities of most of the affected government agencies have not yet been made public. The only specific name that has been revealed so far is the Department of Energy, and a source told the news site that MOVEit Transfer is used by many government agencies, so more names will follow.
But Cybersecurity and Infrastructure Security Agency (CISA) Director Jen Easterly tried to allay national security concerns late last week.
“Based on our discussions with industry partners in the Joint Cyber Defense Collaborative, these intrusions gain broad access to gain persistence into targeted systems to steal specific high-value information. “It’s not being used for anything,” she was quoted as saying.
“As we understand it, this attack is largely opportunistic.”