WaterISAC Navigation
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
  • About
  • Report Incident
  • Contact Us
  • Become a Member
  • NRWA Signup
  • WaterISAC Champions
Home Posts Sodinokibi Ransomware Actors Adopt New Tactics
Become a Member

Log in

  • Upcoming Events
  • Resource Center
  • Tools
  • Webcasts
  • Contaminant Databases
  • Community Partners
  • About
  • Log in

  • My Account

  • Logout

  • Report Incident
  • Contact Us
  • NRWA Signup
  • WaterISAC Champions
More Resources

Sodinokibi Ransomware Actors Adopt New Tactics

Author: Charles Egli

Created: Thursday, April 2, 2020 - 15:11

Categories: Cybersecurity

The FBI has published a Private Industry Notification (PIN) advising that Sodinokibi ransomware actors have adopted new tactics with the potential to increase the number of victims. According to the PIN, these new tactics include examining data in compromised accounts for information that could provide leverage for extortion and searching for unpatched vulnerabilities in VPN servers to facilitate deployment of malware. These tactics mimic those of several other ransomware groups, including the one behind Maze. By threatening to pass the information, which could be sensitive or contain embarrassing details, to competitors or sharing it with the general public, the threat actors hope to motivate their victims to pay. The PIN also contains a list of actions to prevent organizations from becoming victims of this activity.

WaterISAC has previously reported on this new tactic and how it has been employed by the threat actors behind the Sodinokibi (aka REvil) and Maze ransomware variants. See its posting “When Ransomware Strikes, Assume Data Breach Too” from the February 11, 2020 Security and Resilience Update for additional background.

Attached Files:

PIN_20200401_001

Related Resources

Tip of the Week – May 14, 2026

May 14, 2026 in Cybersecurity, Security Preparedness
Members Only

(TLP:AMBER+STRICT) Situation Report: Heightened Threat Environment – Potential Retaliation by Iranian Threat Actors Following U.S. Strikes on Iran (Updated May 14, 2026)

May 14, 2026 in Cybersecurity, OT-ICS Security, Physical Security, Security Preparedness

(TLP:CLEAR) Non-Human Identities (NHIs) Are Growing Faster Than Most Security Programs

May 14, 2026 in Cybersecurity, Security Preparedness

Become a Member
FAQs
About
Report Incident

Terms & Conditions
Privacy Policy
AI Policy
Contact Us

LinkedIn

1250 I Street NW, Suite 350
Washington, DC 20005
1-866-H2O-ISAC (1-866-426-4722)
© 2026 WaterISAC. All Rights Reserved.

Toggle the Widgetbar