CyrusOne MSP Customers Victims of Ransomware Attack

CyrusOne MSP Customers Victims of Ransomware Attack

By Laura Stotler

Six MSPs in the New York area, including financial and brokerage firm FIA Tech, are the latest ransomware attack victims. The companies, all customers of data center provider CyrusOne, experienced availability issues after last week’s attack, which was traced to a version of the REvil/Sodinokibi ransomware.

The attack encrypted certain devices through the CyrusOne network, directly impacting service levels for the company’s MSP customers. It mainly impacted customers using the company’s Wappinger Falls, NY data center. According to a copy of a ransom note sent to CyrusOne, the company was deliberately targeted in the attack, although the point of entry is still unknown.

The same ransomware was used to attack several MSPs in June, and more than 20 Texas cities and 400 dentists’ offices in August. MSPs have become prime targets for ransomware attacks, and the Homeland Security Department recently issued a warning about an ongoing campaign of attacks linked to the Chinese government.

"Upon discovery of the incident, CyrusOne initiated its response and continuity protocols to determine what occurred, restore systems, and notify the appropriate legal authorities," CyrusOne wrote in a statement acknowledging the attack. "The investigation is ongoing, and CyrusOne is working closely with third-party experts to address this matter."

CyrusOne said the company is working with law enforcement and forensics firms to investigate the attack, while also working with the impacted MSPs to restore their systems. It also said the company’s data center colocation services, which include the IX and IP Network Services, were not impacted by the attack.

FIA Tech was one of the MSPs directly impacted by the attack, and experienced an outage of its cloud services. A statement on the company’s website said the ransomware attack targeted its production and disaster recovery servers. The servers were under fire during a four-hour window, but the company said attackers were not able to access any confidential trade or customer data.

“There is currently no evidence that any data was exfiltrated, instead the attack was focused on disrupting operations in an attempt to obtain a ransom from our data center provider,” wrote FIA Tech in a statement. “The service provider believes the objective of the hack was not to steal data.”

For its part, CyrusOne does not intend to pay the ransom. The company acknowledged that ransomware has become a risk factor for its business in a regulatory filing last year. “We recognize the increasing volume of cyberattacks and employ commercially practical efforts to provide reasonable assurance such attacks are appropriately mitigated,” wrote CyrusOne in the filing. “Each year, we evaluate the threat profile of our industry to stay abreast of trends and to provide reasonable assurance our existing countermeasures will address any new threats identified.”

To provide additional information about ransomware attacks and security measures for MSPs, TMC is hosting its MSP Expo in Fort Lauderdale, FL from February 12-14. The event will offer information about technology, hacking threats and security measures MSPs can take to protect themselves and their customers.




Edited by Maurice Nagle
Get stories like this delivered straight to your inbox. [Free eNews Subscription]

MSPToday Contributing Editor

SHARE THIS ARTICLE
Related Articles

BreachRx Secures $6.5M Seed Funding

By: Stefania Viscusi    4/24/2024

BreachRx closed a $6.5 million seed round, led by SYN Ventures, with additional support from Overline.

Read More

Bigleaf Networks and NHC Partner to Optimize the Edge

By: Greg Tavarez    4/24/2024

New Horizon Communications Corp. (NHC) entered a strategic collaboration with Bigleaf Networks to offer network communications services to organizatio…

Read More

Secure the Everywhere Work Landscape: Ivanti Launches EASM and Platform Upgrades

By: Greg Tavarez    4/24/2024

The recently released Ivanti Neurons for External Attack Surface management, or EASM, helps combat attack surface expansion with full visibility of ex…

Read More

Trellix Teams Up with Google Chrome Enterprise for Protection Against Insider Threats

By: Stefania Viscusi    4/23/2024

Cybersecurity firm Trellix, known for its extended detection and response (XDR) solutions, has partnered with Google Chrome Enterprise.

Read More

VulnCheck Closes Funding Round at $7.95M to Power Up Next-Generation Vulnerability Management

By: Greg Tavarez    4/23/2024

VulnCheck recently closed its seed funding round at a total of $7.95 million, with $4.75 million in new funding.

Read More