Blog · IT scandals · Ransomware
Ransomware infected about 18,000 Telecom Argentina computers and demanded $7.5 million
In July 2020, the REvil group attacked Telecom Argentina. According to reports, about 18,000 computers were infected, and the ransom was $7.5 million in the Monero cryptocurrency, with a deadline to pay. Attackers don't need to take down customer services to do damage: reaching the computers that run internal operations is enough.

What happened
According to ESET, the attack took place over a weekend in July 2020, and the ransomware arrived as an email attachment that an employee downloaded and opened. From there, the attackers took over an internal domain administrator account and used it to push the malware to more than 18,000 workstations.
The demand was $7.5 million in Monero. According to Infosecurity Magazine, the amount doubled to $15 million if it wasn't paid by the deadline. Internally, the company asked staff to minimize access to the corporate network, including the VPN, and to shut down any compromised computer immediately.
Customer services kept running: internet and landline service stayed up, although remote customer support systems were affected and the website went offline. Telecom said it regained access to its systems and did not give in to the extortion.
Why did it spread so far?
An opened attachment is an incident on one computer. A domain admin account in the attacker's hands is an incident across the whole company. With that credential, the attacker had the same reach as the team that manages the company's computers.
A specialist quoted by Infosecurity Magazine recommended segmenting the network and detecting lateral movement. Those are the two defenses that turn a carelessly opened email into a contained problem.