Vice Society leaked CommScope employee data after March ransomware attack
- Organization
- CommScope
- Exploit
- Ransomware
- Industry
- Network Infrastructure Manufacturing
CommScope, the North Carolina based maker of network infrastructure equipment, confirmed that it detected unauthorised access to a portion of its IT infrastructure on 27 March 2023. The Vice Society ransomware group later claimed the intrusion and published stolen files on its dark web leak site.
TechCrunch reported that the leaked material included internal documents, invoices, technical drawings, backups from the company's customer portal and internal intranet data. SecureWorld reported that the personal information of thousands of employees was in the archive, covering names, postal and email addresses, personal phone numbers, Social Security numbers, bank account information and scans of passports and visa documentation.
SecureWorld noted that most of the leaked files were in Spanish, which pointed to CommScope's operations in Mexico. The data appeared on the leak site on 14 April and was offered for sale, which reporters read as an indication that a ransom had not been paid.
CommScope said it immediately launched a forensic investigation with an outside cybersecurity firm and reported the matter to law enforcement. The company said it had seen no evidence that customer information was accessed, but declined to tell TechCrunch whether it held the server logs needed to establish what had been taken.
CommScope employs more than 30,000 people worldwide and counts hospitals, schools and federal agencies among its customers. The company had not published a count of affected employees as of the reporting date.