Teilen:

Payment platform MoneyGram says there is no evidence that ransomware is behind a recent cyberattack that led to a five-day outage in September.

MoneyGram is an American payment and money transfer platform that allows people to send and receive money through an extensive network of 350,000 physical locations in 200 countries or via its mobile app and website.

MoneyGram confirmed they had suffered a cyberattack and took systems offline to contain the breach on September 20, three days after customers started reporting experiencing issues.

The disruption to IT systems prevented customers from being able to access and transfer their money and perform other online activities.

While many suspected it was a ransomware attack, MoneyGram shared no further details, and no ransomware gangs claimed responsibility.

In an email with updated information about the cyberattack sent to stakeholders on September 25 and seen by BleepingComputer, MoneyGram said that customers are finally able to transfer funds again.

MoneyGram confirmed that corporate systems were breached, but after investigating the attack with CrowdStrike, law enforcement, and other cybersecurity professionals said there was no evidence that ransomware was behind the attack.

After working with leading external cybersecurity experts, including CrowdStrike, and coordinating with U.S. law enforcement, the majority of our systems are now operational, and we have resumed money transfer services,” says an email obtained by BleepingComputer.

“We recognize the importance of system security as we take these actions. We restored our systems only after taking extensive precautionary measures. At this time, we have no evidence that this issue involves ransomware nor do we have any reason to believe that this has impacted our agents’ systems.”

A source familiar with the attack shared further information, telling BleepingComputer that MoneyGram was initially breached through a social engineering attack on the company’s internal help desk.

This attack allowed the threat actors to access MoneyGram’s network using an employee’s credentials and target employee information in the company’s Windows Active Directory Services. However, they were detected and blocked before more damage could be done.

BleepingComputer contacted MoneyGram with questions about the breach but did not receive a reply back.

If you have any information regarding this incident or any other undisclosed attacks, you can contact us confidentially via Signal at 646-961-3731 or at [email protected].

While MoneyGram has not publicly attributed the attack to any particular threat actor, the strategies are reminiscent of attacks previously conducted by a loose-knit hacker collective known as Scattered Spider (aka UNC3944, the Com, and 0ktapus).

In September 2023, Scattered Spider was behind a cyberattack on MGM Resorts, which they breached by impersonating an MGM employee while calling the IT help desk to reset the password.

Once they gained access to the network, the threat actors deployed the BlackCat ransomware to encrypt hundreds of VMware ESXi servers.

Due to the sophistication of their social engineering attacks, Microsoft, the FBI/CISA, and Mandiant released advisories on their tactics and how to defend against them.

Lawrence Abrams

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
17:10 Uhr, März 27, 2025
Wetter-Symbol 14°C
L: 14° | H: 14°
klarer Himmel
Luftfeuchtigkeit: 65 %
Druck: 1017 mb
Wind: 10 mph WSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 6%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:46 am
Sonnenuntergang: 6:24 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
10° | 13°°C 0 mm 0% 7 mph 81 % 1017 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
6° | 13°°C 0.38 mm 38% 13 mph 86 % 1016 mb 0 mm/h
Sa. März 29 9:00 pm
Wetter-Symbol
4° | 13°°C 0 mm 0% 9 mph 78 % 1022 mb 0 mm/h
So. März 30 9:00 pm
Wetter-Symbol
8° | 17°°C 0 mm 0% 11 mph 93 % 1025 mb 0 mm/h
Mo. März 31 9:00 pm
Wetter-Symbol
8° | 15°°C 0 mm 0% 9 mph 79 % 1027 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
13° | 13°°C 0 mm 0% 7 mph 66 % 1017 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
10° | 10°°C 0 mm 0% 7 mph 81 % 1017 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
7° | 7°°C 0 mm 0% 7 mph 85 % 1015 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
6° | 6°°C 0 mm 0% 8 mph 84 % 1013 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
9° | 9°°C 0 mm 0% 9 mph 86 % 1012 mb 0 mm/h
Tomorrow 9:00 am
Wetter-Symbol
10° | 10°°C 0.28 mm 28% 9 mph 85 % 1011 mb 0 mm/h
Tomorrow 12:00 pm
Wetter-Symbol
13° | 13°°C 0.38 mm 38% 12 mph 49 % 1012 mb 0 mm/h
Tomorrow 3:00 pm
Wetter-Symbol
12° | 12°°C 0 mm 0% 13 mph 42 % 1012 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€80,644.39
0.23%
Ethereum(ETH)
€1,858.35
-0.70%
Fesseln(USDT)
€0.93
-0.02%
XRP(XRP)
€2.17
-2.73%
Solana(SOL)
€128.16
-1.02%
USDC(USDC)
€0.93
-0.01%
Dogecoin(DOGE)
€0.176980
-2.93%
Shiba Inu(SHIB)
€0.000013
-3.57%
Pepe(PEPE)
€0.000008
-1.94%
Peanut das Eichhörnchen(PNUT)
€0.213778
7.85%
Nach oben scrollen