Refusing To Pay For Ransomware Ransom, Scottish Agency Had Its Files Shared To Public

The Scottish Environment Protection Agency (SEPA) is Scotland’s environmental regulator and national flood forecasting, flood warning and strategic flood risk management authority.

To protect and improve Scotland's environment, SEPA helps business and industries understand their roles in environmental responsibilities. The agency allows customers to comply with legislation, and make them aware of the benefits of having good environmental practices.

Back on Christmas Eve of 2020, SEPA was hit by a ransomware attack. The hackers that were behind the attack, managed to steal some 1.2GB of data in the process.

Just like any other ransomware attack, the hackers asked SEPA to pay ransom.

SEPA however, made it clear that it won't engage with the hackers, and won't pay them anything.

As a result, a month after the attack, the hackers behind the ransomware attack on SEPA, started sharing the files they stole to the public internet for anyone to see.

SEPA, hacked and leaked
Seen on Conti’s data leak portal, the hackers published 7% of the data it stole from SEPA.

According to Terry A'Hearn, Chief Executive of SEPA, as quoted on a SEPA's web page:

"We've been clear that we won't use public finance to pay serious and organized criminals intent on disrupting public services and extorting public funds."

"We have made our legal obligations and duty of care on the sensitive handling of data a high priority and, following Police Scotland advice, are confirming that data stolen has been illegally published online. We're working quickly with multi-agency partners to recover and analyze data then, as identifications are confirmed, contact and support affected organizations and individuals."

At this time, SEPA has yet to confirm the ransomware that crippled its system. But the Conti ransomware gang claimed responsibility for the attack.

Because SEPA refused to comply with the Conti's request, Conti has published all of the stolen data on its website, posting over 4,000 documents and databases related to contracts, commercial services and strategy.

Most of the data includes SEPA letters, contracts, service logs, and forecast details, enforcement notices.

[block:block=87]

Ransomware attacks are malicious campaigns that target companies/organizations, aiming to steal their data and threatening to make them public if ransom is not paid.

The attacks usually involve a type of malware that encrypts targets' data. And the ransom the hackers demand, is for the victims' to get the decryption key to restore their files.

Some ransomware attacks use simple ransomware malware, which may only lock the system. More advanced malware uses a technique called cryptoviral extortion among others, to encrypt victim's files, making them inaccessible.

Ransomware attacks are typically carried out using a Trojan disguised as a legitimate app that victims are tricked to download and open.

Due to their widespread usage, ransomware has become one of the most disruptive and damaging cyberattacks an entity can face.

Following the ransomware attack, SEPA works and investigates the attack with the Scottish Government, Police Scotland and the National Cyber Security Centre (NCSC).

At the same time, the agency is also working to fully restore its system.

Despite the impact of the attack, SEPA said that it can still provide flood forecasting and warning services, as well as regulation and monitoring services.