2023 HTC Global Services — ALPHV/BlackCat ransomware; Citrix Bleed exploitation suspected
Data compromised
Passport images, email corpora, and confidential project files previewed on extortion portals per BleepingComputer and Teiss reporting
Technical writeup
IT services and CareTech-parent HTC Global Services acknowledged a December 2023 intrusion after ALPHV/BlackCat leak-site teasers surfaced passports, mail stores, and partner documentation; analysts including Kevin Beaumont linked the breakout to abused Citrix NetScaler session artifacts associated with CVE-2023-4966. The vendor publicly engaged incident-response firms and sought to restore customer-facing services while criminals monetized screenshots of sensitive files.
Root cause
Suspected edge-device session hijacking (Citrix Bleed) enabling follow-on ransomware deployment
References
- https://www.bleepingcomputer.com/news/security/htc-global-services-confirms-cyberattack-after-data-leaked-online/
- https://www.teiss.co.uk/news/htc-global-services-confirms-cyberattack-data-leak-sparks-concern-13223
- https://heimdalsecurity.com/blog/alphv-blackcat-ransomware-group-breach-htc-global-services/