Broadway

Complete News World

The attack on Swiss IT service providers affects Pathé cinemas much more

The attack on Swiss IT service providers affects Pathé cinemas much more

A private Swiss cloud provider has been hacked. With dire consequences.Photo: Watson/Midjourney

The ransomware attack against Unico Data AG in Bern has far-reaching consequences. Many customers are affected, including a well-known gadget manufacturer.

02/06/2023, 09:0102/06/2023, 11:59 AM

Daniel Shorter
Daniel Shorter

Follow me

A hacker attack on Bernese IT company Unico Data AG is spreading. Last Wednesday, officials had to present information about the cyber attack at a hastily convened media conference.

Unico Data takes care of more than 100 small and medium-sized clients from Münsingen with about 75 employees, “Thuner Tagblatt” reports. These are found mainly at home in the Bern region.

“Unfortunately, we are currently affected by a cyberattack, which has resulted in a precautionary shutdown of all systems.”

Answering machine for an IT service provider
on Friday morning
Source: Watson

The consequences are dire for many private companies and state institutions, research shows.

Movie tickets are only available on site

Meanwhile, the far-reaching consequences of the ransomware attack are becoming clear. For example, the Pathé cinema chain is required to inform on its website that online ticket sales are not possible until further notice.

“Due to technical issues, the sale of tickets on our website and in the app is currently restricted. However, our cinemas are open for you and tickets can be purchased with cash on site (no credit/twint card). »

A note about ticket purchase on Friday morningSource: pathe.ch

According to a media release from Pathé, the system is being restored “in cooperation with the responsible authorities”. Contact by e-mail is not currently possible. It is not yet possible to say when the systems will be fully available again. We do our best to provide services as quickly as possible.

Pathé Switzerland operates cinemas in Basel, Bern, Dietlikon ZH, Ebikon LU, Geneva, Lausanne and Spreitbach AG.

A well-known gadget manufacturer is struggling with the problems

It appears that Swiss tool manufacturer PB Swiss Tools has also been affected. The traditional company based in Wasen in the Emmental provides information on its website:

“Since the Whitsun weekend, Unico Data AG’s data centers have been subjected to a cyberattack. Since then, PB Swiss Tools, as a customer of Unico Data AG, is no longer able to access hosted services (VDI, mail exchange, data, applications), which restricts direct written communication with our stakeholders and currently allows access to internal data and software impossible. . »

Source: pbswisstools.com

Notice on the PB Swiss Tools website about an IT security incident.  (June 2, 2023).  The Play ransomware gang attacked the IT service provider of the tool manufacturer and its terms…

The company is transparent about the cyber attack. Behind it is the Play Ransomware gang.Screenshot: pbswisstools.com

Despite the restrictions, production can be maintained in shifts, says Managing Director Eva Gesli and asks customers for patience.

Municipal administration is paralyzed

The municipality of Rugsau in Bern has also been in a state of emergency for the past few days. Officials reported on Tuesday that the municipality’s administration’s EDP system is down.

“The IT data center of the municipal administration is currently affected by the business outage. (…) Management services are very limited, in particular, it is not possible to receive, reply to or send emails. »

Source: ruegsau.ch

“Thuner Tagblatt” quoted the managing director of Unico Data as saying that the affected IT systems “will start running again over the next few days and weeks.” So residents will have to be patient for their administration to operate again as normal.

“We can bridge such a failure for a day or two. Then it will be difficult.”

Municipal Clerk Bernhard LiechtiSource: Thuner Tagblatt

Electrical engineering group confirms attack

Boess Group has also been affected, a company representative confirmed to Watson. The group of companies specializing in electrical engineering services, headquartered in Bern 13 locations across Switzerland.

Who are the attackers?

the Hacker and blackmailer gang “play” It posted a message on its data leak page on the dark web on Friday (June 2, 2023), which does not bode well.

A ransomware attack against Berne-based IT service provider UnicoData affects the Pathé cinema chain, among others.

On the dark web data leak page, criminals claim to have stolen 2.8 terabytes of data and threaten to release it.Screenshot: Watson

Cybercriminals mock:

“After introducing Unico, we edited and removed the files of the organizations it serves. Private and personal confidential data, customer and employee documents, passports, contracts and much more. »

Source: darknet / translated from English

Unico Data CEO Vince Lehman had previously confirmed to the media that it was a ransomware attack.

“At the moment we have completely disconnected the data center from the network. We will not connect him to the network again until we are sure he allows us to.”

Source: netzwoche.ch

The file extension “play.” What was discovered in the encrypted data was clear evidence of the involvement of the gang of the same name, whose previous victims included Xplain AG, media companies NZZ and CH Media (to which Watson belonged). .

Typical of cybercriminals: They launched the actual encryption attack outside of business hours, during Pentecost weekend. Unico Data’s IT managers observed the malware attack on the night of Saturday, May 27th to Sunday, May 28th.

Unico Data reported on your website On progress in containing cyber attack. There it says:

“We are working to restore all services as quickly as possible. The hotline is currently down to allow all resources to be allocated to processing.”

also affected?

It is currently difficult to estimate the full extent of the cyber attack against Unico Data AG. watson accepts information about other affected organizations and businesses. Write to digital editor Daniel Schurter via email or via the secure Swiss messaging app Threema. His Threema ID is: ACYMFHZX. All information will be treated strictly confidential.

sources

This is how a ransomware attack works

17/1

This is how a ransomware attack works

16 Things Gen Z (Probably) Don’t Understand Anymore

Video: Watson

This may also interest you: