The Hive ransomware group has claimed an attack on Tata Power, a leading Indian energy company, and encrypted its systems with ransomware.
Hive claimed to have encrypted the systems of the electric utility subsidiary of Tata Group on 3 October at around 7 pm, disclosing the attack on 24 October in a post on its leak site.
The dumped sample of files includes employment contracts, supplier contracts, 'master' files on various employees, documents detailing senior executives' remuneration packages, and more.
This comes after Tata Power declared on 14 October in a stock exchange filing it had suffered a cyber attack on its IT infrastructure, impacting some of its IT systems. The company said it had taken steps to retrieve and restore the systems, without revealing what kind of attack it was or who it was carried out by.
“All critical operational systems are functioning; however, as a measure of abundant precaution, restricted access and preventive checks have been put in place for employee and customer-facing portals and touch points,” the company said at the time.
A number of Tata Power customers have reported difficulties paying their energy bills on Twitter, with some stating that they have been disconnected from the service for not being able to complete the payment. Some also reported that they made the payment but were still receiving calls that their bill hadn’t been paid.
IT Pro has contacted Tata Power for comment.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Hive is one of the most successful ransomware organisations currently in operation and is run in a similarly 'professional' fashion as other high-profile gangs of past and present, such as REvil and LockBit.
Once infected, victims are taken to a bespoke portal where there are agents working for Hive that guide victims through the ransom payment process via live chat functionality.
Hive is known for its aggressive and unsympathetic approach to negotiating ransom payments and has been observed using tactics such as triple extortion - a method becoming increasingly popular among the most well-resourced groups.
RELATED RESOURCE
Facilitating Fintech
Reducing the risk of potential data interception among fintech solutions
The attack on Tata Power is the latest in a series of attacks carried out by the ransomware organisation. In September, it claimed an attack on the New York Racing Association (NYRA). The NYRA reported the attack on 30 June, after learning that its IT operations, website availability, and member data were compromised.
A few days before this, the group claimed responsibility for a data breach at Bell Canada subsidiary Bell Technical Solutions (BTS). The breach exposed personally identifiable information of its Ontario and Québec-based customers, and compromised and encrypted BTS’s systems.
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
Which form factor? When to choose the Dell Pro 7 in 13in, 14in, or 2-in-1 designSponsored The Dell Pro 7 laptop is available in a range of form factors designed to suit different ways of working. Which should you choose?
-
Delta Airlines flight Wi-Fi tampered with after DEF CON conferenceNews A rogue network named 'Delta WiFi Fast' was created in an apparent in-flight phishing attack
-
Companies are still paying ransoms to cyber criminals despite official adviceNews A Proofpoint survey found evolving ransomware techniques and the use of AI is exacerbating the situation for victims
-
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in JuneNews The Gentlemen, a ransomware a service operator, now accounts for 17% of published attacks
-
Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clientsNews Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals
