The news about Synoptek service disruptions surfaced online after people began discussing it on Reddit. However, the firm only confirmed the security incident in a tweet on December 27, 2019. That time too, they merely called it a “credential compromise” which they contained.
https://twitter.com/Synoptek/status/1210695156669616128
- Synoptek
As revealed, the incident took place on December 23, 2019, two days before Christmas.
In a subsequent update tweet, they merely mentioned contacting the customers affected by the incident. They did not reveal any technical details about what the incident was, how it happened, and the extent of the attack.
https://twitter.com/Synoptek/status/1211426493672259584
- Synoptek
Nonetheless, the government officials more promptly reached the customers in this regard. The State of California and the U.S. Department of Homeland Security alerted the users about the Synoptek cyber attack.
https://www.reddit.com/r/sysadmin/comments/ef2egh/synoptek_issues/fc178wn/
Even on Reddit, various users confirmed the incident as a ransomware attack. Some of them also fell victim to the ransomware.
Krebs also disclosed the payment of ransom. According to the sources, Synoptek paid the asked ransom to receive decryption keys.
Sources also say the company paid their extortionists an unverified sum in exchange for decryption keys.Earlier, Sodinokibi also affected a dental backup firm PerCSoft. Though, it remained unclear whether the company paid the ransom to recover the data or not since they merely mentioned about contacting some software company for data recovery.