OmniVision Says Personal Information Stolen in Ransomware Attack

OmniVision Says Personal Information Stolen in Ransomware Attack

May 21, 2024 at 06:16AM

OmniVision Technologies disclosed a data breach caused by a ransomware attack in September 2023. A notification letter to the California Attorney General’s Office revealed that personal information was stolen and later leaked by the Cactus ransomware group. OmniVision is providing free credit monitoring and identity restoration services to the affected individuals, but the number of individuals impacted was not disclosed.

The meeting notes highlight the disclosure of a data breach by semiconductor manufacturing giant, OmniVision Technologies, following a ransomware attack in September 2023. The breach was discovered on September 30, 2023, after certain systems were encrypted by malware. The company promptly launched a comprehensive investigation with the assistance of third-party cybersecurity experts, notified law enforcement, and took proactive measures to remove the unauthorized party and ensure system security.

The investigation, completed on April 3, 2024, revealed that personal information was stolen from OmniVision systems between September 4 and September 30. The Cactus ransomware group claimed responsibility for the incident, stating that roughly 3.5 terabytes of data were stolen and made available for download in December.

The stolen data, which included confidential documents, non-disclosure agreements, business documents, and passport scans, was leaked by Cactus. OmniVision is offering free credit monitoring and identity restoration services to impacted individuals for 24 months but has not disclosed the number of affected individuals. Additionally, the company operates from Santa Clara and produces semiconductors for various applications, including medical, security, and consumer devices.

The Cactus ransomware gang, active for about a year, is known for encrypting its malware to evade detection and had previously claimed responsibility for an attack on Schneider Electric. These details provide a comprehensive overview of the data breach incident and its impact on OmniVision Technologies.

Full Article