REvil Ransomware Attack: Coop, Other Affected Firms Could Take Weeks to Recover

REvil hackers compromised systems of IT firm Kaseya and malware trickled down to its resellers.

Advertisement
By Reuters | Updated: 6 July 2021 10:38 IST
Highlights
  • The ransomware locked data in encrypted files
  • The REvil actors had claimed that a million machines were compromised
  • Many Coop stores remained closed on Monday

Hundreds of Coop grocery stores were shuttered after ransomware attack compromised its computer systems

Computer systems of several companies across the world, including 800 physical grocery stores of Sweden's Coop, that were shut down after attacked by REvil ransomware could take weeks to recover, cyber security experts said.

Hackers from the REvil cybercrime gang compromised systems of IT firm Kaseya and malware trickled down to its resellers and reached end customers such as Coop who used its software.

The ransomware locked data in encrypted files and late on Sunday hackers demanded $70 million (roughly Rs. 520 crores) to restore the data.

Advertisement

The REvil actors had claimed that a million machines were compromised, said Mark Loman, director of engineering at cybersecurity firm Sophos.

Advertisement

"Depending on how big your business is and if you have backups, it can take weeks before you have restored everything, and as the supermarkets in Sweden have been impacted, they can lose a lot of food and revenue," he said.

Coop's grocery store chain had to close hundreds of stores on Saturday because its cash registers are run by Visma Esscom, which manages servers for a number of Swedish businesses and in turn uses Kaseya.

Advertisement

"We have stopped the attack and we are now restarting our systems," a Coop spokesperson said.

"We are recovering the systems and have now technicians who are visiting all of the affected stores to recover the data systems," they added.

Advertisement

Visma Esscom did not respond to requests for comment.

While many Coop stores remained closed on Monday, some stores have opened their doors and were allowing customers to pay by using an app called "Scan and Pay."

"I don't think we have seen anything this large scale before," said Anders Nilsson, chief technology officer at ESET Nordics. "This is the first time we are seeing a grocery not been able to process payments and this shows how vulnerable we are."

To fix the issues, Coop's payment provider needs to physically go to all stores and restore payment machines manually from backups.

As is routine, the hackers created a channel for negotiating with the victims of the ransomware attack.

Speaking in this online chatroom, which Reuters was able to access, a representative for a REvil affiliate said the hackers had no regrets about forcing Coop to close.

"It's nothing more than a business," the representative told Reuters when asked about the impact of shutting supermarkets in Sweden.

The representative said that while the gang was seeking $70 million (roughly Rs. 520 crores) to restore all the data from all the victims, "we are always ready to negotiate."

ESET's Nilsson said, "It doesn't really matter if they pay or not, they are still going to take time to restore all the machines."

Colonial Pipeline faced an extortion attack earlier this year, causing a shutdown lasting several days. The company paid the hackers nearly $5 million (roughly Rs. 37 crores) to regain access.

"Paying a ransom is just putting the fire out but it will not make your environment more secure," said David Jacoby, deputy director at Kaspersky.

"The companies should not pay the ransom, because we don't want to encourage cyber criminals that this is something that's profitable."

© Thomson Reuters 2021
 


Interested in cryptocurrency? We discuss all things crypto with WazirX CEO Nischal Shetty and WeekendInvesting founder Alok Jain on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's How Much the Oppo Reno 15 Pro Mini Might Cost in India
  2. Vijay Sales Announces Apple Days Sale With Offers on These Apple Products
  3. Rainbow Six Siege Outage: Ubisoft Restores Access After Massive Breach
  4. Why the Samsung Galaxy S26 Series Might Launch at a Higher Price in 2026
  5. OnePlus Teases OnePlus Turbo 6 Series China Launch Date, Key Specs
  6. Mystery Realme Smartphone Surfaces With 10,001mAh Battery
  7. Here's What the Samsung Galaxy A07 5G Might Look Like
  8. Samsung to Showcase New Soundbars, Wireless Speakers at CES 2026
  1. Realme 16 Pro+ 5G Chipset, Display and Other Features Confirmed Ahead of January 6 India Launch
  2. OnePlus Turbo 6, Turbo 6V Price Range Leaked; Company's Website Confirms RAM and Storage Configurations
  3. Oppo Reno 15 Pro Mini Price in India, Retail Box Price Leaked: Expected Specifications, Features
  4. Samsung’s Bixby Assistant Might Be Leveraging Perplexity AI to Answer Complex Questions
  5. Dial 100 Now Available for Streaming Online: Know Everthing About This Malayalam Thriller Drama
  6. Vivo X300 Ultra Spotted on EEC Certification Site Ahead of China Launch: Expected Specifications
  7. 120 Bahadur OTT Release Date Reportedly Revealed: Know When and Where to Watch it Online?
  8. Vivo V70 Elite 5G Listed on BIS Database Alongside Vivo Y51 5G, Hinting at Imminent Launch in India
  9. OpenAI Looking for a Head of Preparedness to Make AI Models Safer, Offers $500K Plus Equity
  10. iQOO Z11 Turbo With Snapdragon 8 Gen 5 Chipset Reportedly Listed on Geekbench
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.