LockBit demanded $80 million from CDW after breaching Sirius Federal servers

Organization
CDW
Exploit
Ransomware
Industry
Technology Services

CDW, a large United States technology products and services provider that sells to businesses, schools, hospitals and government agencies, confirmed in October 2023 that it was investigating a security incident after the LockBit ransomware group listed it on the group's extortion site.

The company described the matter as an isolated IT security issue affecting servers dedicated to internal support for Sirius Federal, a small subsidiary of its government arm CDW-G. CDW said those servers were not customer facing and were isolated from the main CDW network, that its security protocols had detected and contained the suspicious activity, and that its systems remained operational. Outside cyber security experts were brought in to assist.

LockBit demanded $80 million. Negotiation messages reported by The Record showed CDW countering with roughly $1 million, a figure Security Affairs put at $1.1 million. The gang publicly complained about the offer and said negotiations were over once its countdown expired.

LockBit then started publishing data. Analyst1 researcher Jon DiMaggio, who reviewed the leaked archives, said they contained employee badges, audit records, commission payout data and other account related information tied to Sirius Federal. Security analysts described the $80 million figure as one of the largest publicly disclosed ransom demands recorded at the time.

Sources