US networking hardware manufacturer A10 Networks suffered a cyber attack that involved hackers stealing confidential business data from its servers.
Founded in 2004, A10 Networks specialises in the manufacturing of application delivery controllers (software and hardware), bandwidth management appliances, identity management solutions, firewalls, and DDoS threat intelligence and mitigation services. Its clients include Twitter, LinkedIn, Samsung, Uber, Sony Pictures, Windows Azure, Xbox, Yahoo, GE Healthcare, GoDaddy, Huffington Post, and more.
In a recent 8-K filing, the company revealed that threat actors infiltrated its corporate IT infrastructure on January 23 and stayed there for a few hours before their access was identified and terminated. The company said the security incident was not related to any of the products or solutions used by its customers.
“Upon detecting the incident, the company launched an investigation and engaged the services of cybersecurity experts and advisors, incident response professionals and external counsel to support the investigation,” A10 Networks’
8-K filing with the Securities and Exchange Commission read.
The company’s investigation revealed that after they gained unauthorised access to shared drives, threat actors were able to facilitate malware distribution and exfiltrate data related to human resources, legal and finance departments.
According to Bleeping Computer, the infamous Play ransomware gang has
listed A10 Networks as a victim on its data leak site and threatened to publish the stolen data. The gang claims it holds “private and personal confidential data, a lot of technical documentation, agreement, employee and client documents” stolen from the company.
So far, A10 Networks has not commented on how much data was accessed or stolen, how the threat actors infiltrated its network, or whether any ransom has been demanded.
The Play ransomware gang has featured among the most active ransomware groups in recent years. In December, the group claimed responsibility for a cyber attack on British automobile company Arnold Clark and uploaded a 15 GB sample of customer data on the dark web to back its claim. The group also threatened to release the remaining 467 GB of customer data it stole from the company if a multi-million-pound ransom wasn’t paid.