Categories: SecurityWorkspace

PGA Championship Hit By Targeted Ransomware Attack

The Professional Golfer’s Association (PGA) of America is the latest large organisation to be hit by a targeted ransomware attack, ahead of this week’s PGA Championship in Missouri.

Ransomware typically spreads across organisations’ systems or networks and encrypts sensitive files, demanding a ransom to unlock them.

Many variants are launched randomly via junk email messages, but in this case the attack appears to have been targeted specifically at PGA America and timed with this week’s competition.

Files associated with the PGA Championship and the upcoming Ryder Cup in France were locked, according to officials.

The attack was timed with the PGA Championship this week. Credit: PGA America

Years of work lost

The attack surfaced on Tuesday morning when staff found a message from the attackers displayed on their systems.

The message warned that any attempt to decrypt the files could cause them to be permanently deleted.

“We exclusively have decryption software for your situation,” the message said. “No decryption software is available in the public.”

The attackers offered to decrypt sample files in order to prove their “honest intentions”.

The files involved include graphics and display materials for the PGA Championship and the Ryder Cup, including promotional banners and logos for digital and print communications and for digital displays around the competition grounds.

Disruption

The files also included development work on logos for future championships that would be difficult to replicate, according to Golf Week.

The attackers provided an email address and a Bitcoin wallet number, but didn’t specify a ransom amount.

The PGA declined to comment as the situation was ongoing, but said the PGA Championship would not be affected.

Golf Week cited unnamed sources as saying the PGA did not intend to pay the attackers.

The city of Atlanta was disrupted by ransomware earlier this year in an attack carried out by a gang referred to by the name SamSam.

The SamSam group carries out its attacks exclusively through targeted, manual means, and has raked in nearly $6 million (£4.67m) in ransom payments over the past three years, security experts say.

The SamSam ransomware deliberately seeks out and encrypts backups found on the network in order to maximise its damage, researchers said.

Matthew Broersma

Matt Broersma is a long standing tech freelance, who has worked for Ziff-Davis, ZDnet and other leading publications

Recent Posts

Northvolt Mulls US Bankruptcy Protection – Report

Troubled battery maker Northvolt reportedly considers Chapter 11 bankruptcy protection in the United States as…

12 hours ago

FTC Plans Investigation Into Microsoft Cloud Business – Report

Microsoft's cloud business practices are reportedly facing a potential anti-competitive investigation by the FTC

14 hours ago

Programmer Sentenced To Five Years In Prison For Bitcoin Laundering

Ilya Lichtenstein sentenced to five years in prison for hacking into a virtual currency exchange…

16 hours ago

Hate Speech Watchdog CCDH To Quit Musk’s X

Target for Elon Musk's lawsuit, hate speech watchdog CCDH, announces its decision to quit X…

1 day ago

Meta Fined €798m Over Alleged Facebook Marketplace Violations

Antitrust penalty. European Commission fines Meta a hefty €798m ($843m) for tying Facebook Marketplace to…

1 day ago

Elon Musk Rebuked By Italian President Over Migration Tweets

Elon Musk continues to provoke the ire of various leaders around the world with his…

1 day ago