AXA suffers major ransomware attack

ID theft
(Image credit: Future)

French multinational insurance firm AXA has been struck by a ransomware attack days after the company announced a change in its policy to stop reimbursing ransom payments for cybercrime victims in its homeland.

The Financial Times pins the attack on the Avaddon ransomware group, which claims to have stolen three terabytes of sensitive customer data, including screenshots of IDs, bank details, and confidential medical records.

AXA has acknowledged the attack, which it says was directed at its Asia Assistance division, as well as affecting IT operations in Thailand, Malaysia, Hong Kong and the Philippines.

TechRadar needs you!

We're looking at how our readers use VPN for a forthcoming in-depth report. We'd love to hear your thoughts in the survey below. It won't take more than 60 seconds of your time.

>> Click here to start the survey in a new window<<

The company told BleepingComputer that it had informed regulators and business partners of the attack and in response has also set up a dedicated task force with external forensic experts to investigate the incident.

Paying ransom debate

The attack on AXA follows a similar ransomware campaign against Colonial Pipelines, which operates one of the largest fuel pipelines in the US. 

Even as Colonial paid the ransom to regain control of its network, it reignited the debate over giving in to the demands of cyber criminals. The US administration and security agencies advise against paying extortion fees, but there is currently no law that prevents victims paying the ransom.

Cyber insurance policies cover the cost of the ransom along with other associated costs incurred due to the downtime. A section of cybersecurity experts feel that this protection makes companies give in to the demands of the attacks, which further emboldens them to launch similar attacks against other similarly protected targets.

In a major announcement last week, AXA said that it would suspend the writing of cyber insurance policies for its French customers that refund the cost of ransom payments. 

While the attack on AXA’s Asian division is seen as a direct result of its newly announced policy, Financial Times leverages on an anonymous individual who it claims is familiar with the matter as saying that the ransomware attack predates the policy change.

AXA hasn’t disclosed the date of the attack, nor the amount of the ransom demanded.

Via BleepingComputer

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
security
Ransomware gangs allegedly hit two major US healthcare firms, 300,000 patients have data stolen
Ransomware
Atos now says its systems weren't hit by a ransomware attack after all
A computer being guarded by cybersecurity.
The impact of the cyber insurance industry in resilience against ransomware
A laptop with a red screen with a white skull on it with the message: &quot;RANSOMWARE. All your files are encrypted.&quot;
Bad news - businesses who pay ransomware attackers aren’t very likely to get their data back
Atos database reportedly breached by hackers
Insurance
Globe Life data breach may have affected 850,000 more patients than previously thought
Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)