Ziggy Ransomware Gang Announces Shutdown; Offers to Refund Ransom Payments

Date:

Share post:

Whether it is a discount or inadvertent deduction, getting a refund is always a delight for everyone. But what’s unbelievable is receiving the same refund from the one who robbed you.  In an unusual scenario, ransomware operators announced that they will refund the ransom payments paid by the victims.

Ziggy, an infamous ransomware group stated that it is paying back its victims, after the group announced it would cease operations in February 2021. Usually, victims of ransomware attacks pay ransom to decrypt their critical information or recover stolen data from ransomware operators. The latest announcement from the Ziggy ransomware group is certainly good news for many ransomware victims.

Ziggy’s Shutdown

According to a report, the administrator of the Ziggy ransomware gang felt bad for their cybercriminal actions and decided to publish all the decryption keys to the data they stole. The group released an SQL file with 922 decryption keys that victims could use to decrypt their encrypted data. The group also shared the source code for different decryptor keys that can be used for infected systems which are not connected online.

What do victims need to do for a refund?

The victims of Ziggy ransomware were asked to contact the group admin at [email protected] and send their proof of payment and the computer’s unique ID. The paid ransom will be refunded to the victim’s Bitcoin wallet within two weeks.

Security researcher Shahpasandi said…

Concerns from recent takedowns! 

Several industry experts opine that Ziggy ransomware operators are concerned after the law and federal enforcement authorities disrupted services of multiple ransomware gangs recently. In January 2021, the authorities across Europe and judicial agencies worldwide disrupted the operations of Emotet, an infamous malware strain that affected multiple organizations over the years. Dubbed “Operation Ladybird,” the international coordinated action took control of the Emotet group’s infrastructure.

In a similar move, the infamous Maze ransomware gang that caused chaos and attacked various MNCs, including the IT firm Cognizant, announced its retirement effective November 1, 2020.

Related Story: How Paying Ransom Doubles the Cost of Ransomware Attack

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

Stop Reviewing Faster: A Practical Model for AppSec at AI Speed

By Aparna Ash Himmatramka A developer using an AI assistant can ship a feature in an afternoon. In many...

Why I Go to the Dark Web Every Day

By Alex Holden, Chief Information Security Officer Hold Security For nearly two decades I made the Dark Web a...

The Cyber Security EXPO is the only dedicated recruitment event for Cyber Security Professionals

Located in the heart of London at the QEII Centre, the Cyber Security EXPO London offers a prime...

Atlanta Set to Host Hacker Halted and Global CISO Forum 2026, Uniting Practitioners and C-Suite Leaders

The Westin Peachtree Plaza will anchor a week of hands-on training, offensive security research, and closed-door executive dialogue...