In accordance with Cybernews, Medusa Ransomware posted its calls for on the darkish net final Friday, together with 33 pictures as proof of the 834.4 GB of stolen information. The screenshots allegedly present monetary paperwork and delicate data associated to each staff and clients. Comcast has not confirmed the breach.
“The size of the data leak indicates that it could be a serious breach, strongly suggesting the stolen files include a wide variety of data types far beyond the initially revealed documents,” stated Mantas Sabeckis, Data Safety Researcher at Cybernews. “The data in these documents dates as early as 2020 up to 2025, leading us to believe that they’ve breached the core business system and exfiltrated sensitive files.”
The leaked pictures reportedly embrace a file tree displaying stolen directories from totally different departments. Examples embrace Human Sources (coaching, employment, and compliance data) and Safety (logs and studies).
“The file tree list reveals that attackers have exfiltrated not just regular files but also backups of multiple production databases, human resources data, customer and billing data, insurance operations, and internal IT and security data,” stated Sabeckis.
The hackers additionally connected a countdown timer to their darkish net put up, giving Comcast about 11 days to pay the $1.2 million ransom and delete the info. A possible purchaser may additionally entry the info by paying the requested quantity.
If Medusa’s claims show true, this might not be Comcast’s first cybersecurity incident. Final yr, Comcast and Truist Financial institution introduced a knowledge breach involving their accomplice Monetary Enterprise and Shopper Options (FBCS) in October. Its web firm Xfinity, was additionally breached by the top of final yr, affecting round 32 million clients.