Ransomware

Cognizant / BleepingComputer / SC Magazine

πŸ“… 2020-04-18 🦠 Maze
Primary Source β†—

Incident Details

Maze ransomware group attacked Cognizant, a Fortune 500 IT managed services provider with ~300,000 employees, on April 18 2020. The attack disrupted services for clients across multiple industries. Cognizant notified clients on April 20 with indicators of compromise including Maze-associated IPs and malware hashes. The incident caused $50M–$70M in losses in Q2 2020 per Cognizant’s own financial disclosures, primarily from lost revenue and remediation costs. Client data may have been exposed given Maze’s double-extortion model (exfiltrate then encrypt), but Cognizant did not confirm specific data theft. The incident highlighted supply-chain risk from IT service provider compromises.

Technical Details

Initial Attack Vector
CWE-506: Embedded Malicious Code (Maze ransomware; initial access vector not publicly confirmed, likely phishing or exploitation of exposed services)
Malware Family
Maze

Timeline

  1. 2020-04-18 Breach occurred
  2. 2020-04-20 Publicly disclosed
  3. 2020-04-20 Customers notified