Teamsters was hit by ransomware in 2019, but refused to pay up

security
(Image credit: Shutterstock / binarydesign)

When the International Brotherhood of Teamsters, more widely known simply as Teamsters, was targeted by ransomware back in 2019, the US and Candian labor union simply refused to pay, new reports have revealed.

Asked for $2.5 million, Teamsters decided to simply rebuild its entire network instead of caving in to the demands of the attackers, NBC News reported, based on details shared by anonymous sources.

The sources familiar with the previously unreported attack claim that back then even the Federal Bureau of Investigation (FBI) advised the union to just pay the ransom, a far cry from its current stance.

When Teamsters officials alerted the FBI and asked for help in identifying the source of the attack, they were informed that theirs wasn’t an isolated incident and that the bureau had their hands full.

"They said 'this is happening all over D.C. ... and we’re not doing anything about it,'" one of the three anonymous sources told NBC News.

No easy way out

The sources added that Teamsters officials initially bargained with the attackers over the dark web, negotiating the ransom down to $1.1 million.

However, unlike the FBI, the group was advised by its insurance company not to settle with the attackers, which is why they decided to restore their network from backup

An official Teamsters spokesperson told NBC News that the perpetrators only managed to lock one of the union's two email systems along with some other data, though personal information for its millions of active and retired members was never compromised. 

The spokesperson added that while Teamsters was able to restore virtually all of its data from backups, some of it had to be imported from hard copies. 

Tip of the iceberg

Those were simpler times, and ransomware gangs hadn’t learned the art of double extortion. 

No data was exfiltrated and there were no threats of leaks. If a victim refused to pay, the threat actors would chalk it up to experience and simply move on to their next target. 

However, the revelation once again highlights how many organizations simply don’t share details about the attacks. 

If it wasn’t for Avaddon releasing the decryption keys for their victims, we wouldn’t have found out that the group attacked 2934 targets, a staggeringly large number compared to the mere 88 reported victims.

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
A computer being guarded by cybersecurity.
The impact of the cyber insurance industry in resilience against ransomware
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Less than half of ransomware incidents end in payment - but you should still be on your guard
A laptop with a red screen with a white skull on it with the message: "RANSOMWARE. All your files are encrypted."
Bad news - businesses who pay ransomware attackers aren’t very likely to get their data back
sewage water treatment
Southern Water denies claims it offered $750,000 ransom to ransomware hackers
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Interlock ransomware attacks highlight need for greater security standards on critical infrastructure
Image of laptop infected with malware
Ransomware criminals are now sending their demands...by snail mail?
Latest in Security
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
botnet
Another top security camera maker is seeing devices hijacked into botnet
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
Latest in News
Apple's Craig Federighi demonstrates the iPhone Mirroring feature of macOS Sequoia at the Worldwide Developers Conference (WWDC) 2024.
Report: iOS 19 and macOS 16 could mark their biggest design overhaul in years – and we have one request
Google Gemini Calendar
Gemini is coming to Google Calendar, here’s how it will work and how to try it now
Lego Mario Kart – Mario & Standard Kart set on a shelf.
Lego just celebrated Mario Day in the best way possible, with an incredible Mario Kart set that's up for preorder now
TCL QM7K TV on orange background
TCL’s big, bright new mid-range mini-LED TVs have built-in Bang & Olufsen sound
Apple iPhone 16e
Which affordable phone wins the mid-range race: the iPhone 16e, Nothing 3a, or Samsung Galaxy A56? Our latest podcast tells all
An image of a Jackbox Games Party Pack
Jackbox games is coming to smart TVs in mid-2025, and I can’t wait to be reunited with one of my favorite party video games