A New Ransomware Gang Claims It Stole Source Code, Passwords And More In Epic Hack
Before diving into the details of the attack, Mogilevich is a relatively new group that little is known about by researchers. The group only has four posts on its website at the time of writing, including Infiniti USA, Bazaar Voice, Ireland's Department of Foreign Affairs, and Epic Games. While it is unclear who is behind this attack, the name itself is potentially a reference to Russian crime boss Semion Mogilevich who the Federal Bureau of Investigation wants for a slew of crimes primarily relating to finances.
Regarding the Epic Games attack, the group claims to have made off with 189GB of data, which includes “email, passwords, full name, payment information, source code, and many other data included.” All of this is available for sale, and the deadline for it is 3/4/24. However, this might be a load of fake data given a deadline to increase demand or importance around it. Bleeping Computer’s Lawrence Abrams reached out to the group to verify the claim but was told that they would not provide proof of breach unless there were “proof of funds,” which would total $15K for the data.
When we saw these allegations, which were a screenshot of a darkweb webpage in a Tweet, we investigated within minutes and reached out to Mogilevich for proof. Mogilevich has not responded.
— Epic Games Newsroom (@EpicNewsroom) February 28, 2024
We’ll keep investigating.