Rhysida ransomware group put Washington Times data up for auction
- Organization
- The Washington Times
- Exploit
- Ransomware
- Industry
- Media
In mid-August 2024 the Rhysida ransomware group added The Washington Times to the victim list on its dark web leak site and announced an auction for data it said it had taken from the conservative newspaper. The listing gave prospective buyers a seven day window and described the material as exclusive, with the group saying it would go to a single buyer and could not be resold.
The asking price was set at 5 bitcoin, which the Daily Dot valued at roughly $295,200 at the time of the posting. Rhysida said it would publish the data if no buyer came forward within the auction period.
Screenshots posted alongside the listing appeared to show corporate records including invoices and bank statements, along with employee paperwork. Cyber Daily described names, addresses and possible banking information, and both outlets noted scans of a Texas driver's license and a Social Security card. A cybersecurity analyst quoted by the Daily Dot said the sample looked like employee information rather than critical company data.
The Washington Times did not publicly comment on the claim and did not respond to press inquiries in the days after the listing appeared, so the scale and even the fact of an intrusion remained unverified by the paper. Rhysida has been active since May 2023 and was the subject of a joint advisory from the FBI, CISA and the MS-ISAC in November 2023 warning that it targets education, healthcare, manufacturing, IT and government organisations.