fbi seal

FBI Warns U.S. Companies About Recent Scourge of “Maze” Ransomware Attacks

The advisory warned businesses about cyber attacks featuring cryptocurrency sites and spam campaigns impersonating government agencies.

In a recent advisory to private companies across the U.S., the FBI warned businesses about a series of cyber attacks using “Maze” ransomware, which began hitting American organizations in November.

According to CyberScoop, which obtained a copy of the alert sent to businesses in late December, the FBI described a recent scourge of ransomware attacks in which the hacker, sometimes acting as a government agency, stole data from companies and encrypted it to further extort the business.

“From its initial observation, Maze used multiple methods for intrusion, including the creation of malicious look-a-like cryptocurrency sites and malspam campaigns impersonating government agencies and well-known security vendors,” the advisory reads, according to CyberScoop.

The advisory also cited a late November attack in which hackers using Maze threatened to release confidential and sensitive files from an American victim in a move to extort the company for ransom.

Hackers using Maze software were behind the ransomware attack that targeted the city government of Pensacola, Florida in December shortly after a shooter killed three sailors at the Naval Air Station Pensacola.

The actors behind the attack released 2GB of files that were allegedly stolen from the government in an effort to pressure officials to pay the ransom, according to BleepingComputer. Hackers have demanded a $1 million payment to release the data.

Brett Callow, an analyst at cybersecurity firm Emsisoft, told StateScoop that the group is using the data as additional leverage to extort payment.

“Whether the city pays or doesn’t pay, the end result is the exactly same: their data is in the hands of cybercriminals,” Callow said. “Were the city to pay, it would simply have the criminals’ word that the data wouldn’t be released or that they wouldn’t attempt to extort money for a second time.”

Cybersecurity experts say that the Maze trend is an indication of attacks to come.

“We expect to see an increasing trend of threat actors stealing sensitive data from victim organizations before encrypting the data in the victim environments,” Charles Carmakal, senior vice president at Mandiant, told CyberScoop.

Carmakal added: “Organizations may feel more coerced to pay the threat actors because they may feel it’s the best option to prevent the disclosure of sensitive information."

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • Security Industry Association Announces the 2026 Security Megatrends

    The Security Industry Association (SIA) has identified and forecasted the 2026 Security Megatrends, which form the basis of SIA’s signature annual Security Megatrends report defining the top 10 factors influencing both near- and long-term change in the global security industry. Read Now

  • The Future of Access Control: Cloud-Based Solutions for Safer Workplaces

    Access controls have revolutionized the way we protect our people, assets and operations. Gone are the days of cumbersome keychains and the security liabilities they introduced, but it’s a mistake to think that their evolution has reached its peak. Read Now

  • A Look at AI

    Large language models (LLMs) have taken the world by storm. Within months of OpenAI launching its AI chatbot, ChatGPT, it amassed more than 100 million users, making it the fastest-growing consumer application in history. Read Now

  • First, Do No Harm: Responsibly Applying Artificial Intelligence

    It was 2022 when early LLMs (Large Language Models) brought the term “AI” into mainstream public consciousness and since then, we’ve seen security corporations and integrators attempt to develop their solutions and sales pitches around the biggest tech boom of the 21st century. However, not all “artificial intelligence” is equally suitable for security applications, and it’s essential for end users to remain vigilant in understanding how their solutions are utilizing AI. Read Now

  • Improve Incident Response With Intelligent Cloud Video Surveillance

    Video surveillance is a vital part of business security, helping institutions protect against everyday threats for increased employee, customer, and student safety. However, many outdated surveillance solutions lack the ability to offer immediate insights into critical incidents. This slows down investigations and limits how effectively teams can respond to situations, creating greater risks for the organization. Read Now

New Products

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation.

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.”