Ransomware group ALPHV have claimed responsibility for an attack on Ring, the doorbell and security camera company owned by Amazon.
The Victim
Ring is a technology company that specialises in home security products. It was founded in 2013, and its flagship product is the Ring Video Doorbell, which features a built-in camera and microphone, allowing homeowners to see and communicate with visitors at their door from anywhere in the world.
In 2018, Ring was acquired by Amazon, which has helped to fuel the company’s growth and expand its product line, with millions of customers around the world relying on its products to keep their homes and families safe.
The Hacker Group
The ALPHV ransomware gang, also known as BlackCat, operate a Ransomware-as-a-Service (RaaS) business model, using a bespoke malware also named BlackCat.
According to their developers’ claims, it can infect various Windows and Linux operating system versions. Unlike other malware, Blackcat is designed to be human-operated rather than automated, and is used to target specific large organisations.
The ransoms demanded by ALPHV typically range from five to six figures in USD, with their largest demand being three million dollars requested in Bitcoin.
The Ransomware Attack
ALPHV maintains a leak site on the dark web, where they call out their victims for maintaining poor cyber security and “letting” their data become ransomed.
If ALPHV’s victims refuse to pay, the group threatens to publicly release the stolen data. Their threat to Ring Security Systems was the first sign that Ring had suffered a ransomware attack, and can be seen here:

Currently, it is not known what, if any, data has been stolen and encrypted by ALPHV. As a result, no Ring users have been informed of a breach or given advice on how to prevent further cyber attacks.
Ring’s doorbells are equipped to support end-to-end encryption, and if enabled, secures the devices to prevent any organisation, including Amazon or even law enforcement, from accessing any footage recorded by the device. This means that even if an actual ransomware attack has occurred, the hacker group will have only stolen corporate & customer data, rather than video recordings.
A Ring spokesperson has released a short statement regarding their supposed ransomware attack:
“We currently have no indications that Ring has experienced a ransomware event.”
However, Vice has reported that in an internal Amazon slack channel, a Ring manager stated in regard to the attack:
“Do not discuss anything about this. The right security teams are engaged”.
While this does suppose that an incident has occurred, Ring’s Security teams have determined for the time being that ALPHV has not perpetrated a successful ransomware attack.
How does this affect you?
If you are a Ring customer or own a Ring device, it is important to check if you have received any communication regarding this recent suspected attack.
If the Ring ransomware attack is real, you will receive further details stating how Ring is remediating the incident, and offering support for any future security incidents you may encounter as a direct result of this incident.
We all want to feel confident that we have taken appropriate measures to protect our organisation and the sensitive data that it holds, be that internal or third-party data, and this can be done most easily by certifying to the Cyber Essentials standard.
By achieving a strong basic foundation of security, such as Cyber Essentials, you can proudly declare your level of protection to stakeholders and other third parties, demonstrating that you take data compliance seriously. In the event that you can become the victim of an attack, you will be better placed to defend your organisation and show that you have taken steps to protect your data, which will have a direct impact when dealing with the authorities during any subsequent investigation.
Achieving certification for Cyber Essentials is a relatively straightforward process, and as an NCSC-assured service provider, TecSec Services can work with you to both implement the necessary controls and can directly certify your organisation.









