Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Constellation Struck By Ransomware Attack, ALPHV Lays Claim
News & Analysis Attacks Data Protection Ransomware Security

Constellation Struck By Ransomware Attack, ALPHV Lays Claim

Olivia WilliamBy Olivia WilliamMay 5, 2023Updated:August 22, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Constellation Struck By A Ransomware Attack, ALPHV Lays Claim
Constellation Struck By A Ransomware Attack, ALPHV Lays Claim
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

On Thursday, Canadian software firm Constellation Software reported that threat actors had broken into some of its networks and stolen personal information and corporate data.

A small number of systems used for internal financial reporting and related data storage by Constellation’s operating groups and companies were affected by “the Incident,” the company said.

“This incident had no effect on the separate IT systems used by Constellation’s operating groups and businesses.” Constellation further noted that the attack had been stopped and that it had fully restored the IT infrastructure systems that had been compromised.

ALPHV gang claims #ransomwareattack on Constellation Software https://t.co/eYhhA9Cjx9

— Lorenzo H. Gomez (@lgomezperu) May 5, 2023

Business associates and people whose data was compromised are also being contacted to provide them with more information.

The Incident affected a small number of people’s private data. The company further said, “A small amount of data belonging to business partners of Constellation businesses was also impacted.”

Constellation Software has six divisions that it uses to buy, manage, and grow software companies; these divisions are Volaris, Harris, Jonas, Vela Software, Perseus Group, and Topicus.

The Canadian firm’s consolidated revenues surpass $4 billion, and its more than 25,000 workers span North America, Europe, Australia, South America, and Africa.

Constellation has bought over 500 software firms since 1995 and now serves over 125,000 customers in over 100 countries. The ALPHV ransomware group has taken credit for the attack. The ALPHV ransomware gang (aka BlackCat) added a new entry to its data leak site, claiming that they breached the company’s network and stole more than 1 TB worth of files.

At the same time, Constellation has yet to provide information on who was behind the attack or how the threat actors gained access to its network. The ransomware group further threatens to release the stolen data if the organization does not comply with the ransom demand.

We’ve spent a lot of time on your network and thinking about your company. We have successfully stolen over one terabyte of your private information. “We will be forced to release all of your data to the public if you ignore or reject the deal,” the group said.

ALPHV has already posted certain documents online containing business information as evidence that they gained access to and exfiltrated files from Constellation’s network.

The DarkSide/BlackMatter cybercrime syndicate is suspected of launching this November 2021 ransomware campaign under a new name. After attacking the Colonial Pipeline as DarkSide, it caught the attention of law police around the world.

when rebranding in July 2021 as BlackMatter, the company was shut down again in November when the servers were seized and Emsisoft developed a decryptor by taking advantage of a vulnerability in the ransomware.

The ALPHV group is currently recognized as one of the major ransomware threats posing a threat to corporations all over the world.

The FBI issued a warning about ALPHV in April, saying that they have “extensive networks and experience with ransomware operations” after the group successfully hacked over 60 companies throughout the world between November 2021 and March 2022.

Conclusion

Canadian software company hacked this week. On Wednesday, Toronto-based Constellation Software Inc. revealed a cyber-security incident affecting a few IT infrastructure systems. It reported a minimal breach of personal data. Constellation business partners’ limited data was affected. Constellation’s operating groups and companies directly engage such persons and business partners.” British Columbia Emsisoft threat analyst Brett Callow tweeted that the AlphV ransomware gang attacked Constellation. The letter says we’ve been on your network for a while and can assess your business. We stole 1TB. We will reveal your data if you reject the arrangement.

Constellation Software buys and builds software firms. It claims over 25,000 employees and US$4 billion in consolidated revenues. Volaris Group, Harris Computer, Jonas Software, Perseus Group, and Topicus Group operate over 170 software companies in 40 vertical markets. Constellation said the intrusion affected a few internal financial reporting and data storage systems for its operating divisions and businesses. Constellation’s independent IT systems were unaffected. Constellation said the event did not affect its commercial operations. Constellation immediately hired cyber-security professionals to control the attack and perform a forensic investigation. “The incident was contained, and impacted systems have been restored,” it reads.

Olivia William
  • Olivia William
    Ciso Playbook: Cyber Resilience Strategy
  • Olivia William
    Apple Responds Swiftly to Active Security Threats with iOS 16.5.1 Update
  • Olivia William
    Zacks Investment Research Faces Larger Data Breach Affecting 8.8 Million Users
  • Olivia William
    British Airways and Boots Battling Data Breaches, Millions of Customers Affected

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Lazarus Group Turns to Medusa Ransomware in Escalating Global Extortion Campaign

February 26, 20263 Mins Read

The Cyberattack That Exposed the Fragility of Digital Heritage

February 11, 20268 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}