Skip to content

Secure IT

Stay Secure. Stay Informed.

Primary Menu
  • Home
  • Sources
    • Krebs On Security
    • Security Week
    • The Hacker News
    • Schneier On Security
  • Home
  • Security Week
  • New Ransomware Group Claims Attack on US Telecom Firm WideOpenWest
  • Security Week

New Ransomware Group Claims Attack on US Telecom Firm WideOpenWest

Ionut Arghire March 26, 2025
0

A new ransomware group claims to have hacked the systems of US telecommunications provider WideOpenWest (WOW!), and to have taken control of critical systems, in addition to stealing customer information.

Calling itself Arkana Security, the threat actor claims to be performing penetration testing, hacking into organizations’ networks by exploiting vulnerabilities in corporate systems. They also steal the victims’ data to coerce them into paying a so-called “fee”.

The same as other ransomware groups, however, Arkana relies on various tactics to extort its victims, listing their names on its Tor-based leak site and threatening to sell the allegedly stolen data on the dark web and to make it public unless a ransom is paid.

In addition to shaming its victims, Arkana appears to engage in doxxing activities, publishing sensitive personal information on the breached organization’s leadership on the leak site.

This week, the group listed on the leak site its first victim, namely WOW!, a US cable, broadband, phone, and internet services provider that serves nearly two million business, residential, and wholesale customers in 19 markets, mainly in Michigan, Alabama, Tennessee, South Carolina, Georgia, and Florida.

Arkana claims to have gained access to critical internal systems within WOW!’s environment, such as AppianCloud, and to have taken full control over the telecom provider’s Symphonica system.

The threat actor alleges the high level of access it has obtained allows it to perform a broad range of malicious activities, such as malware deployment on customer devices, backend code and financial transaction manipulation, and billing information tampering.

Arkana says it stole two databases – one of 403,000 accounts and one of 2.2 million accounts – containing information such as usernames, account IDs, passwords, security information, names, emails, permissions, and Firebase integration details.

Advertisement. Scroll to continue reading.

“For WOW!, this alleged breach can translate into significant reputational damage and potential legal and regulatory repercussions. The exposure of sensitive customer data not only undermines trust but also forces the company to invest heavily in remediation and enhanced cybersecurity measures to prevent future incidents,” cybersecurity firm SOCRadar notes.

WOW! has yet to confirm the alleged hack and data breach. SecurityWeek has emailed the company for a statement and will update this article if a reply arrives.

Related: Ransomware Shifts Tactics as Payouts Drop: Critical Infrastructure in the Crosshairs

Related: Medusa Ransomware Uses Malicious Driver to Disable Security Tools

Related: Albabat Ransomware Expands Targets, Abuses GitHub

Related: Ransomware Group Claims Attack on Virginia Attorney General’s Office

About The Author

Ionut Arghire

See author's posts

Original post here

Continue Reading

Previous: SplxAI Raises $7 Million for AI Security Platform
Next: RedCurl Shifts from Espionage to Ransomware with First-Ever QWCrypt Deployment

Trending Now

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices mm.jpg 1

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices

May 23, 2025
300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide ransomware.jpg 2

300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide

May 23, 2025
SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection safeline.jpg 3

SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection

May 23, 2025
U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation botnet.jpg 4

U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation

May 23, 2025
CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs saas.jpg 5

CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs

May 23, 2025
GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts prompt.jpg 6

GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts

May 23, 2025

Related Stories

Cybersecurity_News-SecurityWeek.jpg
  • Security Week

Insurance Firm Lemonade Says API Glitch Exposed Some Driver’s License Numbers

Ionut Arghire April 15, 2025 0
ransomware.jpeg
  • Security Week

Kidney Dialysis Services Provider DaVita Hit by Ransomware

Ionut Arghire April 15, 2025 0
Cybersecurity_News-SecurityWeek.jpg
  • Security Week

Conduent Says Names, Social Security Numbers Stolen in Cyberattack

Ionut Arghire April 15, 2025 0
Cybersecurity_News-SecurityWeek.jpg
  • Security Week

2.6 Million Impacted by Landmark Admin, Young Consulting Data Breaches

Ionut Arghire April 15, 2025 0
VC-Funding_China-tech.jpg
  • Security Week

China Pursuing 3 Alleged US Operatives Over Cyberattacks During Asian Games

Associated Press April 15, 2025 0
Satellite-Link-Cybersecurity.jpg
  • Security Week

Blockchain, Quantum, and IoT Firms Unite to Secure Satellite Communications Against Quantum Threats

Kevin Townsend April 15, 2025 0

Connect with Us

Social menu is not set. You need to create menu and assign it to Social Menu on Menu Settings.

Trending News

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices mm.jpg 1
  • The Hacker News

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices

May 23, 2025
300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide ransomware.jpg 2
  • The Hacker News

300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide

May 23, 2025
SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection safeline.jpg 3
  • The Hacker News

SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection

May 23, 2025
U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation botnet.jpg 4
  • The Hacker News

U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation

May 23, 2025
CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs saas.jpg 5
  • The Hacker News

CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs

May 23, 2025
GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts prompt.jpg 6
  • The Hacker News

GitLab Duo Vulnerability Enabled Attackers to Hijack AI Responses with Hidden Prompts

May 23, 2025
Oops: DanaBot Malware Devs Infected Their Own PCs Oops: DanaBot Malware Devs Infected Their Own PCs 7
  • Uncategorized

Oops: DanaBot Malware Devs Infected Their Own PCs

May 22, 2025

You may have missed

mm.jpg
  • The Hacker News

ViciousTrap Uses Cisco Flaw to Build Global Honeypot from 5,300 Compromised Devices

[email protected] The Hacker News May 23, 2025 0
ransomware.jpg
  • The Hacker News

300 Servers and €3.5M Seized as Europol Strikes Ransomware Networks Worldwide

[email protected] The Hacker News May 23, 2025 0
safeline.jpg
  • The Hacker News

SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection

[email protected] The Hacker News May 23, 2025 0
botnet.jpg
  • The Hacker News

U.S. Dismantles DanaBot Malware Network, Charges 16 in $50M Global Cybercrime Operation

[email protected] The Hacker News May 23, 2025 0
Copyright © 2025 All rights reserved. | MoreNews by AF themes.