Brazil’s Rio Grande Do Sul Court System Hit By REvil Ransomware

Brazil’s Rio Grande Do Sul Court System Hit By REvil Ransomware

Brazil’s Tribunal de Justiça do Estado do Rio Grande do Sul was hit with an REvil ransomware attack yesterday that encrypted employee’s files and forced the courts to shut down their network.

Tribunal de Justiça do Estado do Rio Grande do Sul (TJRS) is the court system for the Brazilian state of Rio Grande do Sul.

The attack started yesterday morning when employees suddenly found that all of their documents and images were no longer accessible and ransom notes had appeared on their Windows desktops.

Soon after the attack started, the official TJRS Twitter account warned employees not to log in to the TJ network’s systems locally or via remote access.

“The TJRS informs that it faces instability in computer systems. The systems security team advises internal users not to access computers remotely, nor to log into computers within the TJ network,” tweeted the TJRS court system.

Tweet from TJRS

Also Read: What You Should Know About The Data Protection Obligation Singapore

REvil ransomware responsible for the cyberattack

A Brazilian security researcher known as Brute Bee shared a screenshot with BleepingComputer of employees sharing the ransom notes and discussing the attack between each other.

Screenshot of ransom notes from the attack

These ransom notes are for the REvil ransomware operation, which BleepingComputer has independently confirmed was responsible for the attack.

BleepingComputer was told that the REVil ransomware operation demanded a $5,000,000 ransom to decrypt files and not leak data.

In a translated audio recording shared with BleepingComputer, a person described the attack as “horrible” and “the worst thing that ever happened there,” with IT staff having a “hysterical stress attack” as they rush to restore thousands of devices.

This cyberattack is not the first ransomware attack on Brazil’s court systems.

This past November, Brazil’s Superior Court of Justice was attacked by the RansomEXX ransomware gang who began encrypting devices in the middle of video conference court sessions.

Also Read: The Difference Between GDPR And PDPA Under 10 Key Issues

At the same time, websites of other Brazilian federal government agencies were offline, but it was not clear if they were shut down to be safe or under attack.

This is a developing story …

H/T  Brute Bee

Privacy Ninja

Recent Posts

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications that every Organisation in…

2 weeks ago

Role of Effective Incident Response Procedures in Strengthening Data Security

Effective Incident Response Procedures in Strengthening Data Security that every Organisation in Singapore should know…

2 weeks ago

Strengthening Your Cyber Defenses: The Crucial Role of Regular Vulnerability Scanning

Crucial Role of Regular Vulnerability Scanning that every Organisation in Singapore should know. Strengthening Your…

2 weeks ago

Enhancing Data Security with Multi-Factor Authentication

Enhancing Data Security with Multi-Factor Authentication that every Organisation in Singapore should know. Enhancing Data…

3 weeks ago

A Strong Password Policy: Your Organization’s First Line of Defense Against Data Breaches

Strong Password Policy as a first line of defense against data breaches for Organisations in…

3 weeks ago

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

4 weeks ago