Hackers asking for 8-figure ransom after stealing 10TB of data from Western Digital

In case you missed it, in the past couple of weeks Western Digital was facing a major cybersecurity issue that brought down its My Cloud service. The hackers behind it have now surfaced, claiming to have 10TB of data stolen from Western Digital which includes customer information. They’re now asking for a ransom of at least 8-figures if Western Digital doesn’t want the stolen data made public.

In a new report by Tech Crunch, the hackers have apparently gotten in touch with the publication to prove that they had the data with them. They shared with Tech Crunch a file that had been digitally signed using a Western Digital code-signing certificate. This seems to imply that the hackers can now impersonate Western Digital by forging their digital signature. Tech Crunch added that they had two security researchers analyse the file, and they found that the signature really is Western Digital’s certificate.

On top of that, the hackers also managed to get the personal phone numbers of several Western Digital executives. Tech Crunch called these numbers up and most of them did ring, with two of them going to voicemail which then mentions the name of the person the hacker said they belonged to. The hackers added that they had stolen data from Western Digital’s back end interface that manages their eCommerce data too, together with internal emails and files stored in a PrivateArk instance.

The hackers claim that their only goal in this data breach was to make money. They say that they’ve been trying to contact Western Digital numerous times since the hack, emailing executives on their personal emails too. They’re demanding a one-time payment, according to Tech Crunch, and state that they’ll leave Western Digital alone after that. Western Digital was apparently chosen randomly by the hackers, who declined to name themselves.

However, they added that if Western Digital won’t respond to their demands they’ll publish stolen data on the website of the Alphv gang, though they aren’t directly affiliated with Alphv. Western Digital spokesperson Charlie Smalling declined to comment on any of the claims made by the hacker, including the amount of data stolen or if customer data is included.

Western Digital’s troubles originally began at the start of the month, with the company revealing that they had suffered a network security incident on 3 April. They found that the hackers had exfiltrated data from their systems, leading to their services being down for nearly two weeks, before finally going back online earlier this week.

Recent Posts

Gentari: Beware of 3rd party EV charging promotions

Gentari has released a statement to address the recent discounted Gentari Go EV charging service…

17 hours ago

Xiaomi TV Stick 4K Second Gen: Google TV on a stick, priced at RM219

Want to convert almost any TV with an HDMI port into a Google TV? Xiaomi…

2 days ago

Sony WF-1000XM6: 25% better noise cancelling and improved Bluetooth connectivity, pre-order now for RM1,249

Sony has introduced the Sony WF-1000XM6 in Malaysia, its latest flagship truly wireless earbuds under…

2 days ago

GWM Wey G9 PHEV: The latest Alphard fighter in Malaysia, locally assembled in Melaka

More than a year after it was first previewed at the KL International Mobility Show…

2 days ago

Google Pixel 10a coming to Malaysia on 5 March: Priced from RM2,299

Google has officially announced its latest smartphone, the Pixel 10a. The new model joined other…

2 days ago

Gentari turns on 200kW DC Charger at Petronas Penchala Link (Damansara Bound)

Ahead of the Chinese New Year holiday, Gentari has upgraded its existing EV charging station…

5 days ago

This website uses cookies.