The GPS device maker Garmin acknowledged on Monday that it was victimized by a cyberattack last week that encrypted some of its systems, knocking its fitness tracking and pilot navigation services offline. It said systems would be fully restored in the next few days.
In an online statement, the company did not specify that it was the target of a ransomware attack, in which hackers infiltrate a company’s network and use encryption to scramble data until payment is received.
However, a person familiar with the incident response told The Associated Press the attackers had turned over decryption keys that would allow Garmin to unlock the data scrambled in the attack.
Garmin has not revealed whether it paid the $10m ransom demanded by a cybercriminal group headed by 33-year-old Russian playboy hacker, Maksim Yakubets, who drives a customized $250,000 Lamborghini.
In December 2019, the FBI placed a $5 million bounty on Yakubets’ head for information leading to his capture. It is the largest reward being offered for an alleged criminal connected to cybercrime.
The person spoke on condition they not be further identified.
Tens of millions of people around the world found the firm’s GPS and fitness-trackers, including those used by runners, cyclists and pilots, down five straight days.
The attack crippled company services including Garmin Connect, which is popular with runners and cyclists for tracking workouts, and the FlyGarmin navigation service for pilots.
Customers said Monday their services had ‘partially’ returned. One wrote: ‘For the first time in over 4 days, Garmin Connect seems sorta back up. It’s a bit touch and go, but it’s waking up.’ Another added: ‘Took over 5 minutes off my 10k pb this morning. Thank god Garmin is back up and I have proof of it.’
A Garmin spokesperson said the company had no comment beyond its statement.
The online cybersecurity news site BleepingComputer identified the malware as WastedLocker, which various security firms have attributed to the Russian cybercriminal gang Evil Corp.
The U.S. government announced in December that it was freezing the assets of members of the group.
Olathe, Kansas-based Garmin said Monday that, in addition to GPS-based services, customer support and company communications were also interrupted by the July 23 attack.
‘We have no indication that any customer data, including payment information from Garmin Pay, was accessed, lost or stolen,’ Garmin said in its statement. The attack also didn’t affect the functionality of any of its products, which include fitness watches, it added.
Ransomware is a growing threat and experts say it will only get worse if victims keep paying ransoms.
In the U.S. last year, ransomware attacks on state and local governments, healthcare providers and educational institutions alone caused an estimated $7.5 billion in damage, according to the cybersecurity firm Emsisoft.
The ransomware attack has led to a shutdown of many of Garmin’s systems.
Employees working from home connecting by VPN were also cut off from Garmin’s systems in an effort to halt the spread of the ransomware across its network.
Until Monday, Garmin been largely silent on the outage.