A Ransomware Victim Refuses to Pay

Stu Sjouwerman | Feb 15, 2021

Ransomware Victim Refuses to PayVideo game studio CD Projekt Red, makers of The Witcher series and Cyberpunk 2077, have disclosed a ransomware attack, WIRED reports.

The attackers claimed to have stolen source code for the company’s games and threatened to release the data if the company didn’t pay the ransom. The company refused to pay, and the attackers have since claimed that they’ve sold the code.

“We will not give in to the demands nor negotiate with the actor, being aware that this may eventually lead to the release of the compromised data,” CD Projekt Red stated. “We are taking necessary steps to mitigate the consequences of such a release, in particular by approaching any parties that may be affected due to the breach. We are still investigating the incident, however at this time we can confirm that – to our best knowledge – the compromised systems did not contain any personal data of our players or users of our services. We have already approached the relevant authorities, including law enforcement and the President of the Personal Data Protection Office, as well as IT forensic specialists, and we will closely cooperate with them in order to fully investigate this incident.”

CD Projekt Red added that it doesn’t know if the attackers stole data belonging to the company’s former employees, but cautions that these individuals should be on the lookout for fraud just in case.

“To our ex employees: As of this moment, we don't possess evidence that any of your personal data was accessed,” the company wrote. “However, we still recommend caution (i.e. enabling fraud alerts). If you have questions, please write to our Privacy Team dpo[at]http://cdprojektred.com.”

CD Projekt Red should be commended for resisting the pressure to pay the ransom, as this disrupts the attackers’ business model. New-school security awareness training can help your employees recognize social engineering attacks to prevent these attacks from occurring in the first place.

WIRED has the story.

Topics: Ransomware

Test Your Network’s Defenses with our Free Ransomware Simulator

When employees bypass guidance and fall for social engineering, your network security is the last line of defense. Run our 100% harmless RanSim tool on Windows 10+ workstations to safely simulate 25 ransomware and cryptomining infection scenarios, pinpoint technical vulnerabilities, and get your results in minutes.

Launch Your Free Ransomware Simulation

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.