CSIDB logo
Incident

CyGilant

Incident posture

Attack window
Sep 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-29 00:00

Linked entities

Victim
CyGilant
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Sep 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cybersecurity firm specializing in threat detection experienced a ransomware attack impacting part of its technology infrastructure. The company's internal team halted the attack's progression and engaged third-party forensic experts and law enforcement to assess the incident. Evidence suggests involvement by the NetWalker ransomware group, known for data exfiltration alongside file encryption, with stolen information briefly appearing on a dark web leak site before being removed. While the group historically delists victims following ransom payments or negotiation agreements, the targeted firm did not publicly disclose whether it paid or negotiated with the attackers.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Cygilant, a cybersecurity firm specializing in threat detection, experienced a ransomware attack impacting part of its technology environment on or around September 3, 2020. The company’s Cyber Defense and Response Center team intervened immediately to halt the attack’s progression. Christina Lattuca, Cygilant’s chief financial officer, publicly acknowledged the incident, emphasizing collaboration with third-party forensic investigators and law enforcement to assess the attack’s scope and implications. The company reaffirmed its commitment to network security and enhancing its security protocols. Security analyst Brett Callow of Emsisoft attributed the attack to the NetWalker ransomware-as-a-service operation, which provided infrastructure for affiliate threat actors to execute such campaigns. NetWalker’s malware not only encrypted files but also exfiltrated data to attacker-controlled servers, enabling double-extortion tactics where victims faced both operational disruption and threats of data publication.

Evidence emerged when NetWalker operators published screenshots of Cygilant’s internal directories and files on a dark web leak site, signaling potential data exposure. The listing was later removed, though Cygilant did not disclose whether it paid a ransom or engaged in negotiations. Callow noted that NetWalker had previously delisted victims temporarily during negotiations or permanently upon payment. The company’s public statements did not specify which systems or data types were compromised, the operational or financial impacts, or whether customer information was affected. Cygilant’s response remained focused on containment, forensic analysis, and reinforcing security measures without revealing further technical or procedural details about the attack vector or recovery timeline.

Sources

Sources available to members: 1 source.

CSIDB