Continental 'held to ransom', refuses to confirm if LockBit has stolen data
The ransomware group is threatening to leak the data it has on the German manufacturer tonight if a ransom isn't paid


The LockBit ransomware group has claimed an attack on German manufacturer Continental, which is refusing to confirm whether its data has been stolen.
LockBit claimed the attack on its leak site and is threatening to publish the company’s data by 15:45:36 UTC, according to its deep web blog. At this time, the group hasn’t specified what the data contains or how much it allegedly has, just that it will publish “all available data".
When asked for comment, Continental referred IT Pro to a statement it had published on 24 August 2022 regarding a cyber attack. It declared it had been the victim of an attack which infiltrated parts of its IT systems.
The company claimed to have detected the attack, but then managed to avert it and that its business activities hadn’t been affected. It added that it had full control over its IT systems and that the systems of third-party providers hadn’t been affected either.
The company's August statement made no reference to data, stolen or otherwise. When pressed on whether the company was aware if LockBit was in possession of any of its data, a Continental spokesperson told IT Pro that it is "not commenting on this beyond the statement that has already been published on our website in August".
RELATED RESOURCE
LockBit is one of the leading ransomware organisations currently in operation and operates on a double extortion model which involves stealing data from a victim - which is usually a business or other type of organisation - and threatening to leak it if a ransom isn't paid.
Victims are usually encouraged to pay the ransom demand up front, or in some cases, they are afforded a window in which time they can negotiate the ransom demand down to a lower rate.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
LockBit has a history of claiming attacks on large businesses and those claims were ultimately revealed to be untrue. This week, French multinational Thales confirmed to IT Pro that the claims made by LockBit concerning an attack on its systems were unfounded following an internal investigation.
Similarly, it repeated this behaviour with cyber security firm Mandiant earlier this year, claiming to have taken more than 350,000 files from the company and intended to publish them.
However, the company found no evidence that the attack had been carried out, and the countdown reached zero without data being published. LockBit later admitted the incident was a 'PR stunt'.
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
How to implement a four-day week in tech
In-depth More companies are switching to a four-day week as they look to balance employee well-being with productivity
-
Intelligence sharing: The boost for businesses
In-depth Intelligence sharing with peers is essential if critical sectors are to be protected
-
Hackers breached a 158 year old company by guessing an employee password – experts say it’s a ‘pertinent reminder’ of the devastating impact of cyber crime
News A Panorama documentary exposed hackers' techniques and talked to the teams trying to tackle them
-
The ransomware boom shows no signs of letting up – and these groups are causing the most chaos
News Thousands of ransomware cases have already been posted on the dark web this year
-
Everything we know about the Ingram Micro cyber attack so far
News A cyber attack on Ingram Micro severely disrupted operations and has been claimed by the SafePay ransomware group.
-
A prolific ransomware group says it’s shutting down and giving out free decryption keys to victims – but cyber experts warn it's not exactly a 'gesture of goodwill'
News The Hunters International ransomware group is rebranding and switching tactics
-
Swiss government data published following supply chain attack – here’s what we know about the culprits
News Radix, a non-profit organization in the health promotion sector, supplies a number of federal offices, whose data has apparently been accessed.
-
Ransomware victims are getting better at haggling with hackers
News While nearly half of companies paid a ransom to get their data back last year, victims are taking an increasingly hard line with hackers to strike fair deals.
-
LockBit data dump reveals a treasure trove of intel on the notorious hacker group
News An analysis of May's SQL database dump shows how much LockBit was really making
-
‘I take pleasure in thinking I can rid society of at least some of them’: A cyber vigilante is dumping information on notorious ransomware criminals – and security experts say police will be keeping close tabs
News An anonymous whistleblower has released large amounts of data allegedly linked to the ransomware gangs