Cloud Email Ransomware
A new unnamed ransomware has been observed that targets cloud email platforms.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
A new unnamed ransomware has been observed that targets cloud email platforms.
Threat details
Users receive an email that uses social engineering techniques to encourage them to allow full access to their mailbox for a malicious external application. The user clicks on a link in the email and then approves a prompt from the email platform to grant the requested access.
The malicious application can then encrypt all messages in the user's mailbox. It then displays a message demanding payment for the return of this data.
Remediation advice
To avoid becoming infected with ransomware, ensure that:
Remediation steps
| Type | Step |
|---|---|
To limit the damage of ransomware and enable recovery: All critical data must be backed up, and these backups must be sufficiently protected/kept out of reach of ransomware.
The only guaranteed way to recover from a ransomware infection is to restore all affected files from their most recent backup. |
Last edited: 11 January 2022 11:58 am