Article Details

Scrape Timestamp (UTC): 2025-03-05 01:17:53.628

Source: https://www.theregister.com/2025/03/05/tata_technologies_hiunters_international/

Original Article Text

Click to Toggle View

Ransomware thugs threaten Tata Technologies with leak if demands not met. Hunters International ready to off-shore 1.4 TB of info allegedly swiped from Indian giant. A subsidiary of Indian multinational Tata has allegedly fallen victim to the notorious ransomware gang Hunters International. The extortionists claim to have pilfered 730,160 files totaling 1.4 TB from the tech giant's Tata Technologies. The gang is threatening to release the information next Monday unless a ransom is paid, though it hasn't publicly specified an amount nor shared any teaser documents to support its claims. Tata Technologies is a product engineering subsidiary of the industry behemoth Tata Motors, which owns Jaguar Land Rover and Daewoo. The company had no comment at time of going to press regarding whether it had been contacted by the crooks nor therefore any comment on the demanded ransom. In a mandatory filing with the Indian stock exchange, Tata in January disclosed [PDF] it had been the subject of a "ransomware incident." Now, it appears, the culprits have surfaced. "As a precautionary measure, some of the IT services were suspended temporarily and have now been restored," the technology titan said. "Our client delivery services have remained fully functional and unaffected throughout. Further detailed investigation is underway in consultation with experts to assess the root cause and to take remedial action as necessary." Hunters International are infamous in the industry for going for large targets – reportedly stealing terabytes of data from the Industrial and Commercial Bank of China in September, for instance. They are also not afraid to go for targets that some other ransomware crews won't touch, such as doctors. There is some evidence Hunters International is a rebooted extortion crew and simply a rebranding of the Hive gang, which operated from 2021 to 2023. After a string of high-profile break-ins, the US government offered a $10 million bounty for information on the gang and shortly afterwards the group's website was seized by the FBI and shuttered. A few months later Hunters International appeared, and a sharp-eyed security researcher spotted that the crew was using exactly the same strain of ransomware as Hive. While not conclusive, it does suggest Hunters could be a rebranded version of Hive. Hive has had prior experience with Tata. In 2022 the criminals raided Tata Power and published some stolen material online when the ransom wasn't paid.

Daily Brief Summary

CYBERCRIME // Tata Technologies Threatened by Ransomware, Hunters International Involved

Tata Technologies, a subsidiary of Tata Motors, has reportedly been targeted by the ransomware gang Hunters International.

The attackers claim to have stolen 730,160 files (1.4 TB of data) and are threatening to publish it unless a ransom is paid.

Tata Technologies has not publicly responded to the ransom demand or confirmed contact with the criminals.

The company had earlier reported a "ransomware incident" in a mandatory filing with the Indian stock exchange.

In response to the incident, Tata temporarily suspended some IT services, which have since been restored, ensuring that client delivery services remained unaffected.

A detailed investigation is ongoing with expert consultation to identify the root cause and implement necessary remedial actions.

Hunters International, possibly a rebranded version of the previously known Hive gang, targets high-profile entities and has been linked to other significant cyberattacks.

Prior interactions include an attack on another Tata subsidiary, Tata Power, where data was published online after ransom demands were unmet.