Garmin Paid Millions Of Dollars In Ransom After Attack – Report

The fallout of the Garmin hack continues this week, with allegations that the US fitness and navigation specialist paid a multi-million dollar ransom to cyber criminals.

Garmin was the victim of a ransomware attack on 23 July, when its systems were impacted by what it initially described as an ‘outage’.

Days later, the American firm admitted it had suffered a ransomware attack. But worryingly, media reports at the time revealed that Garmin had somehow obtained the decryption key to recover its computer files, but the firm “did not directly make a payment to the hackers.”

Ransom payout

Now according to Sky News, sources told it that Garmin had paid a multi-million dollar ransom to criminals via a ransomware negotiation business called Arete IR.

Arete IR touts that it has “assembled an elite global team of incident response experts to create unparalleled capability to assist clients in preparing for and defending themselves against a cyber-attack, from incident response readiness assessments to post-incident remediation and ongoing hunt services.

Garmin could have only have obtained a decrypt key if it paid (even indirectly) the hackers (said to be Russia-based Evil Corp), who reportedly used the ransomware malware known as WastedLocker.

Although Garmin may have allegedly made a payment via a third party, it could potentially be at risk of violating US Treasury sanctions against Evil Corp.

However, Garmin could potentially evade investigation here, as the criminals reportedly developed the ransomware after the US sanctions were issued in December, and so it is not mentioned specifically in the US Treasury’s sanction notice.

The US government has not yet made a public attribution linking WastedLocker to the sanctioned individuals.

Indirect payments?

According to people with knowledge of the matter, speaking to Sky News on the condition of anonymity, Garmin had initially sought to pay the ransom using another firm which specialises in responding to these incidents.

However, this unnamed firm told Garmin that it didn’t negotiate ransom payments in WastedLocker cases due to the risk of running foul of US sanctions.

The sources said after being initially rejected by that unnamed firm, Garmin then sought the services of Arete IR.

Sources with knowledge of the incident told Sky News that Garmin did not directly make a payment to the hackers.

Separate sources confirmed to Sky News that Arete IR made the payment as part of its ransomware negotiation services, although Arete argues that WastedLocker is not conclusively the work of Evil Corp.

Neither Garmin nor Arete IR disputed that the payment was made when offered the opportunity to do so, Sky News reported.

A representative for Arete told Sky News they could not comment regarding Garmin, stating: “Arete has contractual confidentiality obligations to all clients and therefore cannot discuss any client identity or interactions.”

Regarding the allegation that the operators of WastedLocker are covered by US sanctions, they added: “Arete follows all recommended and required screenings to insure compliance with US trade sanctions laws.”

Garmin told Sky News it had no additional comment to make.

Security expert always advise ransomware victims not to pay the ransom, as there is no guarantee they will actually receive the decrypt key from the hackers.

Instead firms are advised to regularly backup systems and files and then restore systems after an attack.

Do you know all about security? Try our quiz!

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

UK CMA Seeks Feedback On Microsoft, Amazon AI Partnerships

British regulator invites feedback on major partnerships Microsoft and Amazon have struck with smaller AI…

43 mins ago

Google Fires More Staff Over Israel Protest

Another 20 staff have been fired by Google over Israel protest and their “completely unacceptable…

2 hours ago

Australian PM Hits Out At Elon Musk Over Knife Attack Video

Censorship row brewing down under, after the Australian Prime Minister calls Elon Musk an 'arrogant…

3 hours ago

US SEC Seeks $5.3 Billion Fine From Terra’s Do Kwon

Financial regulator asks New York judge to impose $5.3 billion in fines against Terraform Labs…

4 hours ago

Microsoft Launches Smallest AI Model, Phi-3-mini

Lightweight artificial intelligence model launched this week by Microsoft, offering more cost-effective option for Azure…

7 hours ago

US Senate Passes TikTok Ban Or Divestment Bill

ByteDance protest falls on deaf ears, as Senate passes TikTok ban or divest bill, with…

9 hours ago