Ransomware, Security Operations, Supply chain

Space Bears ransomware claims Comcast data breach via contractor Quasar Inc.

(Adobe Stock)

The ransomware group Space Bears is claiming to have obtained internal Comcast materials by exploiting a breach at Quasar Inc., a telecommunications engineering contractor. These claims were published on the group's dark web leak site, which also lists Quasar as an independent victim, suggesting two connected incidents rather than a single breach, with further coverage provided by HackRead.

Space Bears, which emerged in April 2024 and is linked to the Phobos ransomware-as-a-service program, alleges that Quasar Inc. produced technical documentation for Comcast's Genesis program, creating an entry point. The group claims the compromised files include city design documentation and detailed utility plans for multiple locations. A six-day timer has been set for the potential public release or sale of this data. Separately, Space Bears also claimed to have obtained network project documents, city drawings, and internal materials from Quasar Inc., setting a four-day countdown for that data. Comcast, due to its size, is a frequent target for extortion groups, having faced previous claims from Medusa and data exposures linked to vendor incidents.

This incident highlights the significant risks associated with third-party vendor breaches, where a contractor's security lapse can lead to the compromise of a larger entity's sensitive data. The ongoing targeting of major telecommunications companies like Comcast also points to the increasing value of infrastructure-related data for cybercriminals.

Source: HackRead

An In-Depth Guide to Ransomware

Get essential knowledge and practical strategies to protect your organization from ransomware attacks.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds