Security

Ransomware scumbags leak Boeing, Lockheed Martin, SpaceX documents after contractor refuses to pay

Anti-mortar system specs, legal paperwork, payment forms, and more, dumped online from infected PCs

Got Tips? 120
SHARE

Internal confidential documents belonging to some of the largest aerospace companies in the world have been stolen from an industrial contractor and leaked online.

The data was pilfered and dumped on the internet by the criminals behind the DoppelPaymer Windows ransomware, in retaliation for an unpaid extortion demand. The sensitive documents include details of Lockheed-Martin-designed military equipment – such as the specifications for an antenna in an anti-mortar defense system – according to a Register source who alerted us to the blueprints.

Other documents in the cache include billing and payment forms, supplier information, data analysis reports, and legal paperwork. There are also documents outlining SpaceX's manufacturing partner program.

The files were siphoned from Visser Precision by the DoppelPaymer crew, which infected the contractor's PCs and scrambled its files. When the company failed to pay the ransom by their March deadline, the gang – which tends to demand hundreds of thousands to millions of dollars to restore encrypted files – uploaded a selection of the documents to a website that remains online and publicly accessible.

Visser is a manufacturing and design contractor in the US whose clients are said to include aerospace, automotive, and industrial manufacturing outfits – think Lockheed Martin, SpaceX, Tesla, Boeing, Honeywell, Blue Origin, Sikorsky, Joe Gibbs Racing, the University of Colorado, the Cardiff School of Engineering, and others. The leaked files relate to these customers, in particular Tesla, Lockheed Martin, Boeing, and SpaceX.

When asked about the dump, a Lockheed Martin spokesperson told us: "We are aware of the situation with Visser Precision and are following our standard response process for potential cyber incidents related to our supply chain.

"Lockheed Martin has made and continues to make significant investments in cybersecurity, and uses industry-leading information security practices to protect sensitive information. This includes providing guidance to our suppliers, when appropriate, to assist them in enhancing their cybersecurity posture."

Why is ransomware still a thing? One-in-three polled netizens say they would cave to extortion demands

READ MORE

Visser Precision did not respond to a request for comment on the leak. Tesla, SpaceX, and Boeing did not respond either.

This is not the first time the DoppelPaymer crew has publicly shared stolen confidential data after a victim failed to pay the ransom demands. In fact, the crooks have a regularly updated website full of internal documents belonging to organizations that didn't cough up, though admittedly most are significantly less interesting than the Visser Precision cache.

The dumps are intended to scare others who are infected with the ransomware into paying the group's demands. The Register will not be linking to the site.

For what it's worth, the DoppelPaymer gang vowed to lay off attacking hospitals during the coronavirus pandemic. Whether or not this promise was honored is another question.

While law enforcement agencies and security experts uniformly agree that paying a ransom demand is a bad idea and poor substitute for keeping offline backups and properly securing data, some experts have conceded that, when it's your corporate data on the line, caving in and paying up can be an option. ®

Sign up to our NewsletterGet IT in your inbox daily

120 Comments

Keep Reading

SpaceX beats an engine failure to loft another 60 Starlink satellites

Falcon 9? Falcon 8 more like, as booster takes an unplanned bath

NASA's Human Spaceflight boss hits eject a week before SpaceX crew launch

Doug Loverro leaves after less than six months in charge

Turns out Elon can't control the weather – what a scrub: Rain, clouds delay historic manned SpaceX-NASA launch

Lightning strike threat postpones lift-off to Saturday

SpaceX Falcon 9 and Dragon cleared to hoist real live American astronauts into space

Rocket taxi to fly on Wednesday in first all-American launch since 2011

Axiom signs up with SpaceX to fly private astronauts to the International Space Station

Three 'nauts, one commander to ride Musk's missile for an eight-day stay

Bezos to the Moon: Blue Origin joins SpaceX and Dynetics in a three-horse lunar lander race

NASA selects three contenders for flag-in-Moon prize

Big Falcon explosion as SpaceX successfully demos Crew Dragon abort systems

Mere months until 'nauts get a ticket to ride?

SpaceX's Elon Musk high on success after counting '420' Starlinks in orbit and Frosty the Starship survives cryo test

Roundup Also: Russia sends another freighter filled with astro goodies to ISS

Contacts-slurping Android malware sneaked onto Google Play store – twice

Could a simple automated scan have picked up open-source nasty? Hmm

Google's joins Gang of Four to guard Play Store apps from malware, and maybe not fail so much

The App Defense Alliance posse will scrutinize Android app code before release

Tech Resources

Ransomware has gone nuclear

A new generation of attackers are crafting plans to cause the most panic, pain, and operational disruption. They will take the time to maximize your organization’s potential damage and also their payoff -- not just encrypting your data, but stealing it and posting it publicly if you don’t play ball. Join Roger Grimes from KnowBe4 and Tim Phillips from The Reg for a RegCast in which they will be sounding the ransomware emergency klaxon.

Staying Healthy and Secure

Leaders will share how to create a vibrant, secure remote community that promotes safety, productivity, and engagement

2020 SANS Network Visibility and Threat Detection Survey

Read the report to learn how to do more with the network data you already have and what to look for in a network visibility tool.

Reduce costs with cloud-based VMware data protection

Consider a third-party data protection solution that is certified for VMware on-premises and cloud environments.