Ransomware – CloudNordic / AzeroCloud
Company
CloudNordic / AzeroCloud
Sector
IT / Hosting
##Description
In the early hours of Friday 18 August 2023, attackers shut down all systems at Danish hosting providers CloudNordic and sister company AzeroCloud. The companies believe the compromise happened while servers were being moved between data centres, which brought otherwise separated systems onto the same network — allowing the attackers to reach administrative systems, primary storage and the backup systems together, then encrypt everything.
The result was not a data breach but a data destruction event. Websites, mail systems, customer systems and customer data were unrecoverable. CloudNordic stated that "the majority of our customers have consequently lost all their data with us." Several hundred Danish companies lost everything they had stored — websites, mailboxes, documents.
The companies refused to pay the ransom demand of six bitcoin, engaged external security expertise and reported the incident to police. CEO Martin Haslund Johansson stepped down in September 2023.
The definitive Danish case for why backups must be isolated from the production administrative plane, and for the concentration risk of small hosting providers serving hundreds of SMEs.
##Timeline
- 2023-08-18
Attackers shut down and encrypt all systems, including backups
- 2023-08-21
Customers informed that data recovery is largely impossible
- 2023-08-23
Extent of loss reported publicly; hundreds of Danish companies affected
- 2023-09
CloudNordic CEO steps down
##References
- Version2 — Dansk hostingselskab lagt ned af ransomware: Kunder har mistet al data
- Ingeniøren — Hostingselskab lagt ned af ransomware: Al data mistet
- DR — Al data forsvundet i ransomware-angreb
- TV 2 — Tusindvis af kunder mister data i stort hackerangreb
- Version2 — Topchef i CloudNordic stopper efter omfattende ransomwareangreb
- BleepingComputer — Hosting firm says it lost all customer data after ransomware attack
- Help Net Security — Cloud hosting firms hit by devastating ransomware attack