DonutLeaks Claims Ransomware Attack on ESET; Company Denies Breach

Incident Date: Jul 20, 2024

Attack Overview
VICTIM
ESET, s.r.o
INDUSTRY
Software
LOCATION
Slovakia
ATTACKER
Donutleaks
FIRST REPORTED
July 20, 2024

Ransomware Group DonutLeaks Claims Attack on ESET, s.r.o.

Overview of ESET, s.r.o.

ESET, s.r.o. is a prominent cybersecurity company based in Bratislava, Slovakia. Founded in 1992, ESET has grown into one of the largest privately held cybersecurity firms in Europe. The company specializes in antivirus solutions, internet security, and endpoint protection across various platforms, including Windows, macOS, Linux, and Android. ESET's flagship product, ESET NOD32 Antivirus, has been a cornerstone of its offerings, evolving to include features like antispam and firewall capabilities. The company operates in over 200 countries and territories, with software localized into more than 30 languages.

Details of the Ransomware Attack

The ransomware group DonutLeaks has claimed responsibility for an attack on ESET, specifically targeting the company's Smart Security Premium product. According to DonutLeaks, they compromised the new version of ESET's Premium Home Security Edition before it underwent penetration testing. The group released a taunting note, suggesting that ESET's security measures were inadequate during their testing phase. Despite these claims, ESET has officially denied any breach, labeling the claims as a "false positive" and maintaining that their systems and security protocols remain uncompromised.

About DonutLeaks

DonutLeaks is a data extortion group first detected in August 2022. The group has been linked to several high-profile cyberattacks, including those on Greek natural gas company DESFA and UK architectural firm Sheppard Robson. DonutLeaks uses customized ransomware for double-extortion attacks, encrypting files and leaking stolen data to extort victims. The group is known for its theatrical ransom notes and data leak site, which contains approximately 2.8 TB of stolen data from various victims.

Potential Vulnerabilities

ESET's extensive product portfolio and global reach make it a high-value target for ransomware groups like DonutLeaks. The company's focus on developing security products in Europe and its involvement in various cybersecurity initiatives, such as Google's App Defense Alliance, highlight its commitment to cybersecurity. However, the claim by DonutLeaks suggests that even leading cybersecurity firms are not immune to sophisticated attacks, particularly during phases like product testing where vulnerabilities may be more exposed.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.