AIRLINK 81.25 Increased By ▲ 1.84 (2.32%)
BOP 5.30 Decreased By ▼ -0.03 (-0.56%)
CNERGY 4.42 Increased By ▲ 0.04 (0.91%)
DFML 35.05 Increased By ▲ 1.86 (5.6%)
DGKC 77.60 Increased By ▲ 0.73 (0.95%)
FCCL 20.75 Increased By ▲ 0.22 (1.07%)
FFBL 33.78 Increased By ▲ 2.38 (7.58%)
FFL 9.80 Decreased By ▼ -0.05 (-0.51%)
GGL 10.20 Decreased By ▼ -0.05 (-0.49%)
HBL 118.50 Increased By ▲ 0.57 (0.48%)
HUBC 136.50 Increased By ▲ 2.40 (1.79%)
HUMNL 7.07 Increased By ▲ 0.07 (1%)
KEL 4.65 Decreased By ▼ -0.02 (-0.43%)
KOSM 4.70 Decreased By ▼ -0.04 (-0.84%)
MLCF 37.55 Increased By ▲ 0.11 (0.29%)
OGDC 137.79 Increased By ▲ 1.09 (0.8%)
PAEL 22.99 Decreased By ▼ -0.16 (-0.69%)
PIAA 27.00 Increased By ▲ 0.45 (1.69%)
PIBTL 6.91 Decreased By ▼ -0.09 (-1.29%)
PPL 114.02 Increased By ▲ 0.27 (0.24%)
PRL 27.55 Increased By ▲ 0.03 (0.11%)
PTC 14.76 Increased By ▲ 0.01 (0.07%)
SEARL 57.19 Decreased By ▼ -0.01 (-0.02%)
SNGP 66.99 Decreased By ▼ -0.51 (-0.76%)
SSGC 11.01 Decreased By ▼ -0.08 (-0.72%)
TELE 9.27 Increased By ▲ 0.04 (0.43%)
TPLP 11.58 Increased By ▲ 0.02 (0.17%)
TRG 72.30 Increased By ▲ 0.20 (0.28%)
UNITY 25.70 Increased By ▲ 0.88 (3.55%)
WTL 1.37 Decreased By ▼ -0.03 (-2.14%)
BR100 7,633 Increased By 107.7 (1.43%)
BR30 24,893 Increased By 243.1 (0.99%)
KSE100 72,814 Increased By 842.4 (1.17%)
KSE30 24,057 Increased By 308.2 (1.3%)

LONDON: US travel management firm CWT paid $4.5 million this week to hackers who stole reams of sensitive corporate files and said they had knocked 30,000 computers offline, according to a record of the ransom negotiations seen by Reuters.

The attackers used a strain of ransomware called Ragnar Locker, which encrypts computer files and renders them unusable until the victim pays for access to be restored. The ensuing negotiations between the hackers and a CWT representative remained publicly accessible in an online chat group, providing a rare insight into the fraught relationship between cyber criminals and their corporate victims.

CWT, which posted revenues of $1.5 billion last year and says it represents more than a third of companies on the S&P 500 US stock index, confirmed the attack but declined to comment on the details of what it said was an ongoing investigation.

"We can confirm that after temporarily shutting down our systems as a precautionary measure, our systems are back online and the incident has now ceased," it said in a statement.

"While the investigation is at an early stage, we have no indication that personally identifiable information/customer and traveller information has been compromised."

Comments

Comments are closed.