Africa's biggest supermarket hit by ransomware attacks

ransomware avast
(Image credit: Avast)

Africa’s largest supermarket chain, Shoprite Holdings, has suffered a ransomware attack that may have put personal user data at risk.

The company issued a statement in which it notified customers in Eswatini, Namibia, and Zambia, of possible compromise.

"Additional security measures to protect against further data loss were implemented by amending authentication processes and fraud prevention and detection strategies to protect customer data," the statement reads. "Access to affected areas of the network has also been locked down. The data compromise included names and ID numbers, but no financial information or bank account numbers."

Shoprite ransomware

Soon after posting the warning, a threat actor known as RansomHouse took responsibility for the attack, the publication says. Allegedly, the group posted an evidence sample, 600GB in size, claiming to be the data it stole from the supermarket’s endpoints. 

Not only did they post an evidence sample, but they also took to Telegram to explain how Shoprite’s employees’ lack of cybersecurity practices was “outrageous”. “Their staff was keeping enormous amounts of personal data in plain text, completely unprotected”, the group apparently said. There was no talk of any malware, or vulnerabilities, abused in the attack.

The group also said it invited the company to negotiate the returns of the data and the payment for the decryption key, but all they did was change their passwords, “like it solves everything”. 

In case Shoprite decides not to pay the ransom demand, the data will probably be sold to third parties, or leaked publicly, in case there’s no demand for the data. 

Shoprite is the largest supermarket chain on the African continent. It has almost 3,000 stores in a number of countries, including South Africa, Nigeria, Ghana, Madagascar, Mozambique, Namibia, DRC, and Angola, BleepingComputer finds. It has almost 150,000 employees, and revenue of $5.8 billion.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
security
Ransomware gangs allegedly hit two major US healthcare firms, 300,000 patients have data stolen
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Lock on Laptop Screen
Clop ransomware lists Cleo cyberattack victims
An abstract image of padlocks overlaying a digital background.
US healthcare giant Ascension says ransomware attack affected nearly six million customers
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Major ransomware attack sees Tata Technologies hit - 1.4TB dataset with over 730,000 files allegedly stolen
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
UK private health services firm told to pay up $2m for ransomware hit
Latest in Security
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Code Skull
US government warns Medusa ransomware has hit hundreds of critical infrastructure targets
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Microsoft warns about a new phishing campaign impersonating Booking.com
Ransomware
Microsoft uncovers sleuthy new XCSSET MacOS malware campaign
Latest in News
Jason Sudeikis' Ted Lasso pointing at someone in Ted Lasso season 2
Believe it, baby: Ted Lasso season 4 is officially in development for Apple TV+ – and Jason Sudeikis will reprise his role as the titular soccer coach
Quordle on a smartphone held in a hand
Quordle hints and answers for Saturday, March 15 (game #1146)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Saturday, March 15 (game #377)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Saturday, March 15 (game #643)
Rainbow Six Siege X promotional art.
The Tom Clancy's Rainbow Six Siege X 6v6 mode might finally pull me away from Black Ops 6
A close up of the new web version of Apple Music Classical
Apple Music Classical is now available on the web, but its Mac app is still nowhere in sight