Continental 'held to ransom', refuses to confirm if LockBit has stolen data
The ransomware group is threatening to leak the data it has on the German manufacturer tonight if a ransom isn't paid
The LockBit ransomware group has claimed an attack on German manufacturer Continental, which is refusing to confirm whether its data has been stolen.
LockBit claimed the attack on its leak site and is threatening to publish the company’s data by 15:45:36 UTC, according to its deep web blog. At this time, the group hasn’t specified what the data contains or how much it allegedly has, just that it will publish “all available data".
When asked for comment, Continental referred IT Pro to a statement it had published on 24 August 2022 regarding a cyber attack. It declared it had been the victim of an attack which infiltrated parts of its IT systems.
The company claimed to have detected the attack, but then managed to avert it and that its business activities hadn’t been affected. It added that it had full control over its IT systems and that the systems of third-party providers hadn’t been affected either.
The company's August statement made no reference to data, stolen or otherwise. When pressed on whether the company was aware if LockBit was in possession of any of its data, a Continental spokesperson told IT Pro that it is "not commenting on this beyond the statement that has already been published on our website in August".
RELATED RESOURCE
LockBit is one of the leading ransomware organisations currently in operation and operates on a double extortion model which involves stealing data from a victim - which is usually a business or other type of organisation - and threatening to leak it if a ransom isn't paid.
Victims are usually encouraged to pay the ransom demand up front, or in some cases, they are afforded a window in which time they can negotiate the ransom demand down to a lower rate.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
LockBit has a history of claiming attacks on large businesses and those claims were ultimately revealed to be untrue. This week, French multinational Thales confirmed to IT Pro that the claims made by LockBit concerning an attack on its systems were unfounded following an internal investigation.
Similarly, it repeated this behaviour with cyber security firm Mandiant earlier this year, claiming to have taken more than 350,000 files from the company and intended to publish them.
However, the company found no evidence that the attack had been carried out, and the countdown reached zero without data being published. LockBit later admitted the incident was a 'PR stunt'.
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
Post-cloud strategy: Architecting the next enterprise stackAs enterprises rethink their dependence on hyperscale, hybrid architectures are emerging as the new foundation for resilient, AI-ready infrastructure
-
Anthropic just launched Claude Fable 5, its first Mythos-class AI modelNews The launch of Claude Fable 5 marks the first public release of a Mythos-class AI model
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals
-
Ransomware negotiator sentenced for role in major cyber crime groupNews Deniss Zolotarjovs was a key player in a group associated with Conti
-
Threat actors ditch ‘spray and pray’ attacks in shift to targeted exploitationNews A dip in ransomware volumes points to a more targeted approach focused on vulnerability exploitation
-
Security leaders overconfident about ransomware recoveryNews Few manage to recover all their data, and many experience business disruption
-
German authorities want your help finding the hackers behind GandCrab and REvilNews Daniil Maksimovich Shchukin and Anatoly Sergeevitsch Kravchuk are believed to have made millions from ransomware as a service schemes
-
Sectigo taps Clint Maddox to lead global field operationsReviews The appointment follows a year of strong momentum for the security vendor as it expands its global channel footprint
