Puma suffers data breach caused by Kronos ransomware attack

Lock on Laptop Screen
(Image credit: Future)

The impact of last year's Kronos ransomware attack is still being felt, with sports equipment company Puma now confirming it has suffered a related breach.

As reported by Bleeping Computer, Kronos filed a breach notification with several attorney generals’ offices earlier this month, which states that the attackers took data on Puma employees and their dependents from the Kronos Private Cloud (KPC).

"Since the attack was discovered, Kronos has been conducting a comprehensive review of the impacted environment to determine whether any individual’s personal information was subject to unauthorized access or acquisition," said a letter delivered to affected Puma employees last week.

"On January 7, 2022, Kronos confirmed that some of your personal information was among the stolen data. We notified Puma of this incident on January 10, 2022."

Puma employees under attack

In the filing provided to the Office of the Maine Attorney General, Kronos said that a total of 6,632 individuals have had their data stolen, including Social Security numbers. 

To mitigate the effects of the data breach, Kronos has offered the affected individuals a care package that includes two years of free Experian IdentityWorks membership (credit card monitoring, identity restoration, and identity theft insurance).

Commenting on the news, Puma's Senior Head of Communications, Kerstin Neuber, said that no Puma customer data was impacted.

Before encrypting all of the data on the target network, ransomware operators usually download as much of it as possible. That way, they can threaten to release the data online if the victim declines to pay the ransom or attempts to restore its systems from backup.

Not only do data leaks mean competitors might edge ahead, but they also mean data watchdogs and other government organizations may come crashing down, demanding heads roll for the breach of privacy.

Nonetheless, many firms choose not to cave in to ransom demands, with a view to disincentivizing future attacks. There is also no guarantee the threat actor will return the stolen data as promised.

Via BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Mizuno USA says hackers were able to breach networks, steal data for months
Code Skull
Casio confirms data of 8,500 people exposed in recent ransomware attack
Lock on Laptop Screen
Data breach at Pennsylvania education union potentially exposes 500,000 victims
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Ransomware
Atos now says its systems weren't hit by a ransomware attack after all
ransomware avast
The biggest addiction treatment provider in the US says it was hit by data breach
Latest in Security
Code Skull
Interpol operation arrests 300 suspects linked to African cybercrime rings
Insecure network with several red platforms connected through glowing data lines and a black hat hacker symbol
Multiple H3C Magic routers hit by critical severity remote command injection, with no fix in sight
An abstract image of a lock against a digital background, denoting cybersecurity.
Critical security flaw in Next.js could spell big trouble for JavaScript users
Microsoft
"Another pair of eyes" - Microsoft launches all-new Security Copilot Agents to give security teams the upper hand
Lock on Laptop Screen
Medusa ransomware is able to disable anti-malware tools, so be on your guard
An abstract image of digital security.
Fake file converters are stealing info, pushing ransomware, FBI warns
Latest in News
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS
Netflix Ads
Netflix adds HDR10+ support – great news for Samsung TV owners, but don't expect LG and Sony to do the same any time soon
FiiO FX17 IEMs
Our favorite budget audiophile brand unveils wired earbuds with 26(!) drivers, electrostatic units, USB-C ultra-Hi-Res Audio, and a not-so-budget price
Nvidia RTX 5080 against a yellow TechRadar background
RTX 5080 24GB version teased by MSI - is it time to admit that 16GB isn't enough for 4K?
A close up of the PlayStation symbol at the top of a PS5 Slim console with a white brick background
Sony has dropped a new PS5 update, improving activities and adding more emoji support
girl using laptop hoping for good luck with her fingers crossed
Windows 11 24H2 seems to be a massive fail – so Microsoft apparently working on 25H2 fills me with hope... and fear