Louisiana State Servers Disabled, CyrusOne Hit by REvil Ransomware in Latest Wave of Attacks
In a proactive security measure, Louisiana’s Office of Technology Services temporarily disabled state servers, disrupting email, websites, and online applications for multiple agencies. Governor John Bel Edwards confirmed the move was a precaution to prevent the spread of ransomware, following a pattern of attacks targeting government entities and school districts over the summer.
Meanwhile, data center provider CyrusOne confirmed that six of its managed service customers primarily in its New York data center experienced outages after a REvil ransomware attack encrypted devices on their networks. The company clarified that its colocation and network services remained unaffected, though an investigation with third-party experts is ongoing. Attackers left a ransom note, stating they had "the best specialists" to restore files, a tactic consistent with REvil’s operations.
The incidents are part of a broader surge in ransomware activity. Since October 1, at least 15 U.S. organizations including healthcare networks, municipalities, and police departments have been targeted, according to research from Armor. Earlier this year, Texas declared a state of emergency after a coordinated REvil attack crippled local governments, though critical services were later restored.
Security firm McAfee analyzed the malware, noting its sophisticated design, which executes rapidly to encrypt files while obfuscating Windows API calls to evade detection. The REvil strain, active since April, has been linked to multiple high-profile attacks, including those on managed service providers (MSPs). This year alone, 13 MSPs or cloud providers have fallen victim to ransomware, underscoring the growing threat to third-party infrastructure.
Louisiana’s and CyrusOne’s responses highlight the increasing adoption of preemptive shutdowns to contain ransomware, even as attackers refine their tactics to maximize disruption. Law enforcement is assisting in the CyrusOne investigation, though no further details on attribution or ransom demands have been disclosed.
Source: https://www.ciodive.com/news/cyrusone-ransomware-REvil/568549/
Colt Technology Services cybersecurity rating report: https://www.rankiteo.com/company/colt-technology-services
CyrusOne cybersecurity rating report: https://www.rankiteo.com/company/cyrusone
"id": "COLCYR1788296947",
"linkid": "colt-technology-services, cyrusone",
"type": "Ransomware",
"date": "12/2019",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': 'Multiple state agencies and '
'users',
'industry': 'Public Sector',
'location': 'Louisiana, USA',
'name': 'Louisiana Office of Technology Services',
'type': 'Government'},
{'customers_affected': 'Six managed service customers',
'industry': 'Technology/Cloud Services',
'location': 'New York, USA',
'name': 'CyrusOne',
'type': 'Data Center Provider'}],
'attack_vector': 'Unknown (likely phishing, exploit, or third-party '
'compromise)',
'data_breach': {'data_encryption': 'Yes (files encrypted by REvil)',
'data_exfiltration': 'Possible (REvil known for double '
'extortion)',
'type_of_data_compromised': 'Encrypted files (potential data '
'exfiltration)'},
'description': 'Louisiana’s Office of Technology Services temporarily '
'disabled state servers to prevent ransomware spread, '
'disrupting email, websites, and online applications. '
'Meanwhile, CyrusOne confirmed a REvil ransomware attack '
'encrypted devices for six managed service customers in its '
'New York data center, leaving a ransom note. The incidents '
'are part of a broader surge in ransomware activity targeting '
'U.S. organizations.',
'impact': {'brand_reputation_impact': 'Likely negative impact on CyrusOne and '
'Louisiana state agencies',
'data_compromised': 'Files encrypted (data exfiltration possible)',
'downtime': 'Disrupted email, websites, and online applications '
'(Louisiana); outages for CyrusOne customers',
'operational_impact': 'Temporary shutdown of state services '
'(Louisiana); service outages for CyrusOne '
'customers',
'systems_affected': 'State servers (Louisiana), managed service '
'customer devices (CyrusOne)'},
'investigation_status': 'Ongoing',
'motivation': 'Financial gain (ransomware extortion)',
'ransomware': {'data_encryption': 'Yes',
'data_exfiltration': 'Possible',
'ransomware_strain': 'REvil (Sodinokibi)'},
'references': [{'source': 'Armor Research'}, {'source': 'McAfee Analysis'}],
'response': {'containment_measures': 'Temporary server shutdown (Louisiana); '
'isolation of affected systems '
'(CyrusOne)',
'incident_response_plan_activated': 'Yes (proactive server '
'shutdown for Louisiana; '
'third-party investigation '
'for CyrusOne)',
'law_enforcement_notified': 'Yes (assisting in CyrusOne '
'investigation)',
'third_party_assistance': 'Yes (CyrusOne engaged third-party '
'experts)'},
'threat_actor': 'REvil (Sodinokibi)',
'title': 'Louisiana State Servers Disabled and CyrusOne Hit by REvil '
'Ransomware',
'type': 'Ransomware'}