Cybercriminals threaten to leak London Drugs data if it doesn't pay $25M ransom
Last month’s cyberattack on pharmacy and retail chain London Drugs that forced the closure of all its stores in Western Canada was orchestrated by a “sophisticated group of global cybercriminals” who are demanding a ransom—and say they’ll leak the company’s data if it doesn’t pay up.
In a statement to CTV News Tuesday, London Drugs said it has learned that it’s been “identified by cybercriminals on the dark web” as the victim of file theft from its corporate head office, and that some of those files may contain employee information.
The company said that to date it doesn’t appear that patient, customer or “primary employee” databases have actually been compromised, but the investigation into the cyberattack is ongoing.
In its statement, London Drugs did not name the criminal group behind the attack, but Brett Callow, a threat analyst at cybersecurity company Emsisoft identified it as LockBit, a prolific ransomware operation.
Callow told CTV News Emsisoft’s trackers found out about the ransom “fairly quickly” by pulling data off the dark web.
In a screenshot shared with CTV News, LockBit says it will release data it claims to have stolen from London Drugs in 48 hours if it does not pay $25 million. The post also claims that London Drugs has offered to pay $8 million.
London Drugs said it is “unwilling and unable to pay ransom to these cybercriminals.”
“We acknowledge these criminals may leak stolen London Drugs corporate files, some of which may contain employee information on the Dark Web. This is deeply distressing, and London Drugs is taking all available steps to mitigate any impacts from these criminal acts,” the statement continues.
London Drugs says it notified all current employees of the potential breach and offered 24 months of free credit monitoring and identity theft services, regardless of whether or not any of their data was ultimately stolen.
Callow said that London Drugs made “absolutely the right decision” by refusing to pay the ransom.
There’s no guarantee LockBit would delete the data if London Drugs capitulates, he explained, adding that law enforcement has previously found LockBit servers containing data from multiple companies that paid to have it erased.
“They are untrustworthy, bad-faith actors,” he said.
LockBit, through affiliates using its ransomware tools, has extorted $120 million from thousands of victims since 2019, which include airplane manufacturer Boeing, Britain’s National Health Service and China’s biggest bank, according to The Associated Press.
Its ransom demands range from the tens of thousands of dollars to tens of millions, Callow said.
He added that all London Drugs can do now is to support employees whose information may be compromised and hope law enforcement agencies take down LockBit.
Overall, cybercriminals collected $1.1 billion in ransom in 2023, according to crypto-tracing firm Chainalysis. “The bulk of that would have been paid by companies in the U.S. and Canada,” Callow said.
“Victims often claim that the attacks were sophisticated, but most ransomware attacks succeed because of fairly basic security failings, so there are absolutely things organizations can do to reduce the likelihood of becoming the next victim,” he said.
London Drugs said it would not give any interviews Tuesday.
CTVNews.ca Top Stories
Labour Minister Steven MacKinnon will not run for Liberal leadership
Federal Labour Minister Steven MacKinnon will not run in the race to replace Prime Minister Justin Trudeau as leader of the Liberal Party of Canada, he announced on social media Sunday morning.
Former PM Chretien says Liberal party must move back to 'radical centre'
As the Liberal party searches for a new leader, former prime minister Jean Chretien says it's time for the party to move back to the "radical centre" to help its electoral fortunes.
Are there U.S. military bases and American troops in Canada?
The U.S. military has more than 165,000 troops deployed in over 170 countries and territories, including Canada.
'Everything is on the table': Joly won't rule out cutting off energy exports to U.S. in face of Trump tariff threat
Foreign Affairs Minister Melanie Joly is not ruling out any countermeasures when it comes to dealing with U.S. president-elect Donald Trump — his threat of significant tariffs on Canadian imports, in particular.
Royal treasures hidden since Second World War recovered from cathedral
Historical treasures hidden for decades have been uncovered in the crypts of a cathedral, with items including burial crowns and insignia belonging to Medieval European rulers.
Toronto still trying to get students ‘back on track’ with vaccinations after COVID-19 pandemic
Toronto Public Health has begun sending out letters to Grade 11 students who are behind on their routine vaccinations, warning that they could face suspension if they do not comply.
'Thankful for the rest of my life': Woman's final goodbye with father captured on video at Winnipeg airport
One woman is expressing her deepest gratitude to the Winnipeg Richardson International Airport after the staff helped her retrieve the security footage of her final moments with her father.
New Canadian joins the navy, fulfilling his father's dream
Onboard a warship with 250 personnel, if you take the time to listen, you’ll discover a sea of inspiring stories.
As Biden joins the former presidents club, here are some ideas for his retirement to-do list
U.S. President Joe Biden is about to have a lot more free time. He need look no further than past presidents for ideas on what to put on his retirement to-do list.