Ransomware

BleepingComputer / Maine AG disclosure

πŸ“… 2021-02-19 🦠 DarkSide
Primary Source β†—

Incident Details

DarkSide ransomware attacked fashion retailer Guess (NYSE: GES) in February 2021, exfiltrating data before encryption. DarkSide published a sample of stolen files on their leak site in April 2021. Guess disclosed the breach on June 9 2021 and notified approximately 1,300 affected individuals (per Maine AG filing) whose personal data was exposed, including Social Security numbers, driver’s license numbers, passport numbers, and financial account information. The relatively small notification count suggests the exfiltrated data primarily affected employees or a subset of HR records rather than the full customer base. Guess did not disclose whether a ransom was paid.

Technical Details

Initial Attack Vector
CWE-506: Embedded Malicious Code (DarkSide ransomware)
Malware Family
DarkSide

Timeline

  1. 2021-02-19 Breach occurred
  2. 2021-06-09 Publicly disclosed
  3. 2021-06-09 Customers notified