Advertisement
Canada markets close in 5 hours 10 minutes
  • S&P/TSX

    21,922.79
    +37.41 (+0.17%)
     
  • S&P 500

    5,098.92
    +50.50 (+1.00%)
     
  • DOW

    38,182.42
    +96.62 (+0.25%)
     
  • CAD/USD

    0.7311
    -0.0012 (-0.16%)
     
  • CRUDE OIL

    83.39
    -0.18 (-0.22%)
     
  • Bitcoin CAD

    87,502.90
    +791.02 (+0.91%)
     
  • CMC Crypto 200

    1,340.49
    -56.04 (-4.01%)
     
  • GOLD FUTURES

    2,345.20
    +2.70 (+0.12%)
     
  • RUSSELL 2000

    2,001.13
    +20.01 (+1.01%)
     
  • 10-Yr Bond

    4.6510
    -0.0550 (-1.17%)
     
  • NASDAQ

    15,918.47
    +306.71 (+1.96%)
     
  • VOLATILITY

    15.26
    -0.11 (-0.72%)
     
  • FTSE

    8,143.90
    +65.04 (+0.81%)
     
  • NIKKEI 225

    37,934.76
    +306.28 (+0.81%)
     
  • CAD/EUR

    0.6840
    +0.0019 (+0.28%)
     

Ransomware gang with ties to Colonial Pipeline hack reportedly recruiting talent under guise of real tech company

A computer hacker.
A computer hacker. THOMAS SAMSON/AFP via Getty Images

A criminal organization believed to have produced the software used in the Colonial Pipeline hack earlier this year has "set up a fake company to recruit potential employees," The Wall Street Journal reports, according to researchers at Microsoft and intelligence firm Recorded Future.

The phony cybersecurity organization is reportedly using the name Bastion Secure, and is thought to be run by "well-known hacking group" Fin7, Recorded Future and Microsoft told the Journal. They're believed to have attacked "hundreds of businesses, stolen more than 20 million customer records and written the software used in a hack that disrupted gasoline delivery in parts of the Southeastern U.S," the Journal explains, per federal prosecutors and researchers.

This latest impersonation attempt "represents a new development by purveyors of ransomware to grow and spread a scourge" that has disrupted hundreds of businesses, across sectors, writes the Journal. Ransomware groups are "increasingly operating like criminal startups," using illegally-earned millions to fund their grift.

ADVERTISEMENT

The professional-looking Bastion Secure website lists routine jobs for any security agency — programmers, administrators, etc. And despite its fraudulence, the company made offers to some prospective recruits, per researchers. One potential new hire spotted red flags in the operation not long after, telling Recorded Future that nobody at Bastion would meet face-to-face or talk via voice call.

In fact, a phone call to a number listed on Bastion Secure's site was answered by a Russian-speaking man with what appeared to be no knowledge of the organization, writes the Journal. "I'm just a person. I have nothing to do with any cybersecurity company," he exclaimed before hanging up. Read more at The Wall Street Journal.

You may also like

NYC to impose vaccine mandate for all city workers, including police

The American 'Great Resignation' by the numbers

Rep. Jeff Fortenberry indicted on charges of lying to federal investigators