Security Market Segment LS
Wednesday, 01 July 2020 06:47

Fisher & Paykel attackers release second lot of company documents on dark web Featured

Fisher & Paykel attackers release second lot of company documents on dark web Image by Corrie Miracle from Pixabay

Attackers who used the Nefilim ransomware, that works on Windows systems, to attack appliance maker Fisher & Paykel have posted links to a second lot of documents which were stolen from the company during the attack, security sources have told iTWire.

A first lot of documents was released early in June with links being posted on the dark web.

Links to the new documents have been released as a text file and a zipped archive as the first lot were. They appear to again contain mostly financial documents.

Fisher & Paykel, which is based in New Zealand, operates in 50 countries and does its manufacturing in Thailand, China, Italy and Mexico, according to Wikipedia.

There are no recent revenue figures given by Wikipedia, but the company's 2007 revenue was NZ$1.42 billion (A$1.32 billion).

paykel second lot

A screenshot from the Nefilim site on the dark web. Supplied

In the past, the company has not responded to a request for comment. Last time, iTWire found that Fisher & Paykel had no media contacts or email addresses listed on its Australian website. Its New Zealand site had no contacts either and appeared to be out of date, with the latest press releases posted there being from 2018.

At the time, iTWire wrote to a media contact listed on one of those 2018 releases.

Now Fisher & Paykel has a line saying, "For media enquiries please contact: Andrew Luxmoore, Senior Corporate Communications Specialist", without giving any indication as to how this man can be contacted. An email address for him was obtained by chatting with a bot on the company's website.

Any reaction will be included in this story as soon as it is received.

Nefilim, which recently attacked logistics and transportation firm Toll Holdings, is one of the growing number of ransomware that exfiltrates victims' files before encrypting them on-site.

This, in effect, means that any victim is hit by both a data breach and also loses access to his/her files.

Contacted for comment, Brett Callow, a ransomware threat researcher from the New Zealand-headquartered security shop Emsisoft, said: "Nefilim publishes data in a series of instalments to maintain pressure on the company and, no doubt, to demonstrate to future victims that they can inflict pain well beyond the initial attack.

"Like Lion, F&P is to be commended for its decision to refuse to meet the criminals’ demands, but not for its security. "


Recently iTWire remodelled and relaunched how we approach "Sponsored Content" and this is now referred to as "Promotional News and Content”.

This repositioning of our promotional stories has come about due to customer focus groups and their feedback from PR firms, bloggers and advertising firms.

Your Promotional story will be prominently displayed on the Home Page.

We will also provide you with a second post that will be displayed on every page on the right hand side for at least 6 weeks and also it will appear for 4 weeks in the newsletter every day that goes to 75,000 readers twice daily.


talentCRU FREE WEBINAR INVITE - Cybersecurity in COVID-19 times and beyond

With the mass transition to remote working, our businesses are becoming highly dependent on the Internet.

So, it’s no surprise that we’ve seen an increase in cyberattacks.

However, what’s more concerning is that just 51% of technology professionals are highly confident that their cybersecurity teams are able to detect and respond to these threats.

Join us for this free online roundtable where our experts discuss key cybersecurity issues IT leaders are facing during the pandemic, and the challenges that will likely emerge in the coming years.


Sam Varghese

website statistics

Sam Varghese has been writing for iTWire since 2006, a year after the site came into existence. For nearly a decade thereafter, he wrote mostly about free and open source software, based on his own use of this genre of software. Since May 2016, he has been writing across many areas of technology. He has been a journalist for nearly 40 years in India (Indian Express and Deccan Herald), the UAE (Khaleej Times) and Australia (Daily Commercial News (now defunct) and The Age). His personal blog is titled Irregular Expression.



Recent Comments