← HTC Global Services

2023 HTC Global Services — ALPHV/BlackCat ransomware; Citrix Bleed exploitation suspected

2023 Unknown records affected Share on X

Data compromised

Passport images, email corpora, and confidential project files previewed on extortion portals per BleepingComputer and Teiss reporting

Technical writeup

IT services and CareTech-parent HTC Global Services acknowledged a December 2023 intrusion after ALPHV/BlackCat leak-site teasers surfaced passports, mail stores, and partner documentation; analysts including Kevin Beaumont linked the breakout to abused Citrix NetScaler session artifacts associated with CVE-2023-4966. The vendor publicly engaged incident-response firms and sought to restore customer-facing services while criminals monetized screenshots of sensitive files.

Root cause

Suspected edge-device session hijacking (Citrix Bleed) enabling follow-on ransomware deployment

References