2020 CWT (Carlson Wagonlit Travel) — Ragnar Locker ransomware; ~$4.5M BTC payment reported (Jul)
Data compromised
Corporate operational records described in criminal-victim marketing—no consolidated public victim census
Technical writeup
Corporate travel agency CWT, then commonly referenced as Carlson Wagonlit Travel, sustained a July 2020 Ragnar Locker ransomware intrusion that encrypted systems and prompted highly publicized ransom negotiations. Reuters, The Register, and Dark Reading reported a negotiated payment on the order of US$4.5 million in bitcoin in exchange for decryption tools and suppression of claims about roughly two terabytes of exfiltrated corporate material. CWT characterized recovery progress while limiting public detail on data categories; treat file-tree descriptions as partially actor-sourced.
Root cause
Human-operated ransomware deployment and extortion (Ragnar Locker)