Rhysida ransomware group published documents stolen from the Chilean Army

Organization
Ejercito de Chile (Chilean Army)
Exploit
Ransomware
Industry
Military

The Chilean Army confirmed on May 29, 2023 that a security incident detected two days earlier had affected systems on its internal network. The institution said it isolated the affected network and began recovery work, and reported the matter to Chile's national computer security incident response team and the Ministry of National Defence.

In mid-June the Rhysida ransomware operation, which had first been observed only weeks earlier, published material it said came from the army's network. BleepingComputer reported that roughly 360,000 documents appeared on the group's dark web leak site, and that Rhysida described the release as about 30 percent of what it had taken.

Chilean investigators moved quickly. Officers from the metropolitan cybercrime brigade of the PDI, the country's investigative police force, arrested an army corporal. On June 5 a court ordered him held in preventive detention on charges under Chile's computer crime law, and investigators seized his electronic devices for forensic examination. The military prosecutor's office opened its own inquiry.

At the time of the arrest the army said its critical information systems had not been affected, while it continued auditing security and restoring network services. Neither the army nor prosecutors publicly explained how Rhysida came to hold the data, and the document count and the claim that the leak represented only part of the haul rested on the group's own statements.

Sources