DonutLeaks Claims Ransomware Attack on ESET; Company Denies Breach

Incident Date:

July 20, 2024

World map

Overview

Title

DonutLeaks Claims Ransomware Attack on ESET; Company Denies Breach

Victim

ESET, s.r.o

Attacker

Donutleaks

Location

Petržalka, Slovakia

, Slovakia

First Reported

July 20, 2024

Ransomware Group DonutLeaks Claims Attack on ESET, s.r.o.

Overview of ESET, s.r.o.

ESET, s.r.o. is a prominent cybersecurity company based in Bratislava, Slovakia. Founded in 1992, ESET has grown into one of the largest privately held cybersecurity firms in Europe. The company specializes in antivirus solutions, internet security, and endpoint protection across various platforms, including Windows, macOS, Linux, and Android. ESET's flagship product, ESET NOD32 Antivirus, has been a cornerstone of its offerings, evolving to include features like antispam and firewall capabilities. The company operates in over 200 countries and territories, with software localized into more than 30 languages.

Details of the Ransomware Attack

The ransomware group DonutLeaks has claimed responsibility for an attack on ESET, specifically targeting the company's Smart Security Premium product. According to DonutLeaks, they compromised the new version of ESET's Premium Home Security Edition before it underwent penetration testing. The group released a taunting note, suggesting that ESET's security measures were inadequate during their testing phase. Despite these claims, ESET has officially denied any breach, labeling the claims as a "false positive" and maintaining that their systems and security protocols remain uncompromised.

About DonutLeaks

DonutLeaks is a data extortion group first detected in August 2022. The group has been linked to several high-profile cyberattacks, including those on Greek natural gas company DESFA and UK architectural firm Sheppard Robson. DonutLeaks uses customized ransomware for double-extortion attacks, encrypting files and leaking stolen data to extort victims. The group is known for its theatrical ransom notes and data leak site, which contains approximately 2.8 TB of stolen data from various victims.

Potential Vulnerabilities

ESET's extensive product portfolio and global reach make it a high-value target for ransomware groups like DonutLeaks. The company's focus on developing security products in Europe and its involvement in various cybersecurity initiatives, such as Google's App Defense Alliance, highlight its commitment to cybersecurity. However, the claim by DonutLeaks suggests that even leading cybersecurity firms are not immune to sophisticated attacks, particularly during phases like product testing where vulnerabilities may be more exposed.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.