A group called N4ughtysecTU has claimed responsibility for the ransom demand of R224 million from TransUnion South Africa, after they obtained access to a TransUnion South Africa server through misuse of an authorised client’s credentials.
READ: Hackers want R224 – or will leak Absa, FNB and Standard Bank data
The African division of TransUnion operates in eight African countries offering commercial and consumer insurance and risk information solutions across various industries, reports
MyBroadband reports it spoke to the group itself. “It alleged it gained access to the personal records of 54 million South African customers totalling more than 4TB of data.”
It told MyBroadband it got in via a user and then to all the files on their servers. The users password was apparently “password”. The group had demanded a $15-million (R224.4 million) ransom to return the data, reports MyBroadband.
BleepingComputer reports the hackers are from Brazil. “The threat actors claim to have breached a poorly secured TransUnion SFTP server and stolen data containing roughly 54 million customers, mainly from South Africa. Still, records from other countries are included in the stolen data as well.”
Additionally, the hackers told Bleeping Computer they set the ransom demand to $15,000,000 in Bitcoin and threatened to extort TransUnion’s customers by demanding an “insurance” payment if a ransom was not paid.
The hacking group states that the “insurance” for large TransUnion clients will be $1,000,000, while smaller businesses will have a smaller $100,000 demand.



