Xerox Subsidiary Pwned… And Xerox May Be Negotiating

Xerox has confirmed a cyber attack on its US subsidiary Xerox Business Solutions. INC Ransom posted Xerox on its leak blog, but recently removed it (including leaked documents), meaning negotiations are likely underway.

Darren Williams, CEO and Founder, BlackFog had this comment:

“While it remains unclear whether Xerox is in negotiations with INC Ransom, the removal of their leaked documents implies ongoing discussion may be taking place. Given that data exfiltration claims were made by the ransomware group, the company is likely scrambling to safeguard not only themselves but their customers. Negotiating with cybercriminals is highly discouraged and should be avoided at all costs. Paying a ransom or even just entering into negotiations builds confidence within the cybercriminal network and provides an incentive for future attacks on the same company, and others alike. Once it becomes known that there is a willingness to cooperate, cybercriminals are likely to persist in their attacks.”

I second the sentiment that nobody should pay a ransom when they are hit with a cyberattack. It emboldens threat actors and it doesn’t guarantee that the threat actors will keep their end of the deal. Thus protection and a plan to deal with an attack that doesn’t involve paying a ransom has to be in every companies cybersecurity playbook.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading