ANDOVER, MA — A ransomware group has claimed the Town of Andover as a victim, potentially shedding new light on the cyberattack that disrupted municipal and school computer systems for four days last month.
The group, known as WallStreet, added “Andover” to its dark-web leak site Sunday, Aug. 30, according to RansomLook, a cybersecurity platform that monitors ransomware groups and their victim postings.
The listing identifies the target as the Town of Andover, Massachusetts, and describes the municipal services provided by the Town. It does not publicly identify what information the group claims to possess, how much data may have been taken or whether any files have been released.
The claim has not been independently verified, and the Town has not publicly attributed the August cyberattack to WallStreet.
Andover News has asked Town Manager Andrew Flanagan for additional details about the group’s claim and the Town’s investigation. This story will be updated when he responds.
Ransomware groups use dark-web leak sites to identify organizations they claim to have breached, frequently as part of an effort to pressure victims into paying a ransom. The groups may threaten to publish information allegedly stolen during an attack if their demands are not met.
A listing alone does not prove that an organization’s data was accessed or stolen. Cybersecurity monitoring services caution that such claims can be exaggerated, based on old information or, in some cases, false.
Local news matters.Subscribe to the free Andover News weekday newsletter for trusted coverage of the stories shaping our community.
The timing of the WallStreet posting, however, raises new questions about the Aug. 13 cyberattack on Andover’s municipal and school network.
Flanagan confirmed Aug. 21 that a cyberattack caused the four-day outage, which disrupted Town departments, temporarily disabled external email and delayed the release of teacher assignments to Andover Public Schools families.
At the time, Flanagan did not identify who was responsible, how the attackers gained access or whether ransomware was involved. The Town also did not say whether municipal or school information had been accessed, copied or removed from its systems.
Officials said the Town responded by activating its cyber-incident protocols, taking external email offline and retaining independent cybersecurity professionals to investigate the attack and restore affected systems.
Town buildings remained open, telephone service continued operating and public safety agencies, utilities and other infrastructure were not interrupted. Most affected systems had been restored by Aug. 17, although some residents continued experiencing difficulty using online services such as bill payments.
The newly discovered WallStreet listing does not establish whether the group encrypted the Town’s files, demanded payment or removed information from the network before the attack was discovered.
It also does not identify what types of records might have been exposed. The Town and APS share network resources, potentially making the scope of any unauthorized access an important question for municipal employees, school personnel, students and residents whose information is maintained by either organization.
WallStreet appears to be a relatively new or newly tracked ransomware operation. RansomLook had recorded nine victim postings attributed to the group as of Tuesday, including the Andover listing.
The Town has previously said it is working with cybersecurity and legal professionals and is following applicable legal, technical and notification requirements.
Under Massachusetts law, organizations generally must notify affected individuals and state regulators if an investigation determines that protected personal information was acquired or used by an unauthorized person.
No such notification connected to the August incident has been publicly announced.
Click Here For The Original Source.
