What a brilliant day to be hit by a cyber attack..?
February 9th 2021, 8:59 pm | Arran Hodges
In a statement posted- the company said this;
Yesterday we discovered that we have become a victim of a targeted cyber attack, due to which some of our internal systems have been compromised.
An unidentified actor gained unauthorized access to our internal network, collected certain data belonging to CD PROJEKT capital group, and left a ransom note the content of which we release to the public. Although some devices in our network have been encrypted, our backups remain intact. We have already secured our IT infrastructure and begun restoring the data.
This attack- commonly known as a ransomware has previously taken down the UK National Health Service, lots of different councils and individuals. The primary principle of ransomware is that your own data is held for ransom after being encrypted. You then have to pay (typically in bitcoin) to get the access to the decryption key. CD PROJEKT RED continued in their statement;
We will not give in to the demands nor negotiate with the actor, being aware that this may eventually lead to the release of the compromised data. We are taking necessary steps to mitigate the consequences of such a release, in particular by approaching any parties that may be affected due to the breach.
We are still investigating the incident, however at this time we can confirm that- to our best knowledge- the compromised systems did not contain any personal data of our players or users of our services.
We have already approached the relevant authorities, including law enforcement and the President of the Personal Data Protection Office, as well as IT forensic specialists, and we will closely cooperate with them in order to fully investigate this incident.
Here is a copy of their ransom note;
Images by CD PROJEKT RED