Garmin reportedly paid multi-million dollar ransom after suffering cyberattack


Fitness brand Garmin paid millions of dollars in ransom after an attack took many of its products and services offline last month, Sky News reports. The payment was reportedly made through a ransomware negotiation company called Arete IR, in order for Garmin to recover data held hostage as a result of the attack.
BleepingComputer reported last week that Garmin had received a decryption key to access data encrypted by the virus, and that the initial ransom demand was for $10 million.
The attack itself began on July 23rd, and put Garmin’s wearables, apps, website, and even its call centers offline for several days. Garmin confirmed that it had been the victim of a cyberattack on July 27th, as many of its services were starting to come back online. Its statement did not say whether it had paid a ransom in response to the attack, but noted that no customer data was accessed, lost, or stolen.
Early on, reports suggested that the fitness brand had been hit by a strain of ransomware called WastedLocker, which is believed to have been developed by individuals linked to a Russia-based hacking group. The group, known as Evil Corp, was placed under sanctions by the US Treasury last December, and Sky News reports that one ransomware negotiation company declined to work with Garmin to resolve the incident over fears of breaking those sanctions.
Arete IR declined to confirm to Sky News whether it had worked with Garmin to respond to the incident citing “contractual confidentiality obligations to all clients.” The firm said that it “follows all recommended and required screenings to insure compliance with US trade sanctions laws.” On July 24th, Arete IR tweeted a white paper disputing reports of a link between WastedLocker and Evil Corp. A representative from the company did not immediately respond to The Verge’s request for comment.
The US government has not publicly attributed WastedLocker to the individuals it placed under sanction in December, Sky News reports, and since the software was developed after the sanctions were announced it does not appear in the original announcement.
BleepingComputer reports that it believes Garmin must have paid the ransom because of the lack of known weaknesses in the WastedLocker virus. Code from a Garmin-developed executable reviewed by BleepingComputer suggests the company paid the ransom on either July 24th or July 25th, and the publication confirmed that the executable was able to decrypt sample files encrypted by WastedLocker.
Garmin did not immediately respond to The Verge’s request for comment, and told Sky News that it no additional comment to make.
Fitness brand Garmin paid millions of dollars in ransom after an attack took many of its products and services offline last month, Sky News reports. The payment was reportedly made through a ransomware negotiation company called Arete IR, in order for Garmin to recover data held hostage as a result…
Recent Posts
- Reddit is experiencing outages again
- OpenAI confirms 400 million weekly ChatGPT users – here’s 5 great ways to use the world’s most popular AI chatbot
- Elon Musk’s AI said he and Trump deserve the death penalty
- Grok resets the AI race
- The GSA is shutting down its EV chargers, calling them ‘not mission critical’
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010