So, who or what is Ragnar Locker? And what did they want from BEL's data systems? They're a group that uses ransomware by the same name, and they've been active since 2019. A report from 2022 says they have been specifically attacking energy sectors. But did they try to extort BEL? Mencias explained.

John Mencias, CEO, BEL

"They are the group that uses what they called a double extortion technique. So they come in and they snoop around and leak data out and maybe leak about 5% of the data and tell you listen to me, there is more that we can leak, give me something or whatever, otherwise I will go another step and leak more data."

"In this case, it seemed they leaked all. Again, we take nothing for granted. These are cyber criminals. We're not going to believe a word they say and we are not going to trust them."

"But then they go to a second step where the can encrypt your data and so your data is hidden from you and you can't access the data and even parts of your system. Actually, the FBI, I think in 2022 they issued their report and they identified at least 52 entities across 10 critical infrastructure sectors that were affected by Ragnar Locker ransomware. They are entities in financial services, in government information technology, and that's just Ragnar Locker. You all know very well that some of the bigger corporations around the world have been impacted by cyber attacks."

Reporter
"Did they request a ransom of any sort from BEL, because I understand that's part of their MO as well?"

John Mencias, CEO, BEL
"No, they didn't and that is why of course we are saying. We know that the MO is that they would indeed do this and that is why we will have to think that this is not over and we remained on high alert."

Tags John Mencias BEL FBI