NetWalker ransomware attack managed to cripple K-Electric (KE), a private-owned electricity provider in Karachi, Pakistan.
The hack was first reported by researcher Ransom Leaks. He was informed about this hack by a local Pakistani security company that said the attack was impacting K-Electric internal services.
The cyberattack occurred in the morning of September 7th, with NetWalker demanding a $3,850,000 ransom payment. In a Tor payment page, it is said that if a ransom is not paid within the next seven days, the ransom will increase to $7.7 million.
The Tor payment site also includes a "Stolen data" page that states the NetWalker operator stole unencrypted files from K-Electric before performing the attack.
The page however, didn't reveal much about what data was stolen.

In a statement, the company said that:
"All critical customer services including bill payment solutions and 118 call-centre are operational and fully functional, to ensure the integrity of our systems, as a precautionary measure, we have isolated few non-critical services."
It should be noted that KE has access to consumers’ names, addresses, CNIC and NTN numbers.
They are the information that is also published in bills.
Financial data is linked to customers' CNIC (including with bank accounts, credit card), because many KE consumers pay their bills online. What this means, the ransomware attack and the attackers mentioning that they've managed to steal some data, means that customers' privacy is at stake.

When data breach happens, companies are urged to disclose the things that have been leaked, especially when it concerns users' personal data.
However, the draft for Pakistan's data protection bill does not offer adequate protection of citizens in case of data breaches.
This is why KE that issued a following statement telling its customers to expect disruptions to some other online services, didn't mention anything about “cyber-incident”.
K-Electric is Pakistan's largest power supplier, serving 2.5 million customers and employing over 10 thousand people. Understandably, many of its consumers are unable to access most of the company’s online services because of this.
Fortunately, the only thing disrupted, was K-Electric's billing and online services. No supply of power was affected.
To resolve this issue, K-Electric started by re-routing users through a staging site, among others.
This ransomware attack happened a few days after K-Electric was targeted by Argenian border services, which halted its operation for more than 4 hours.























































































































































































































































































































































































