Skip to main content

Garmin reportedly used decryption key, may have paid ransom after cyberattack

GPS technology company Garmin is recovering from a recent ransomware attack and has reportedly received a decryption key to recover its files, suggesting it may have paid a ransom, as uncovered by Bleeping Computer.

The site found that the attackers used the WastedLocker Ransomware and reported that they demanded $10 million as a ransom. Now, it also uncovered that Garmin is using a decryption key to regain access to its files, suggesting that the company may have paid that ransom demand or some other amount. The WastedLocker software uses encryption which has no known weaknesses, so the assumption is that to break it, the company must have paid the attackers for the decryption key.

Garmin was the victim of the ransomware attack at the end of July, when hackers succeeded in shutting down services including Garmin Connect, the network which syncs data for Garmin customers using wearables such as watches. Affected systems came back online within a few days, but services continued to be slow for some users.

As well as the inconvenience for wearables users, the hack had some people worried about more serious consequences as well. Some aviation navigation software like the flyGarmin app was also affected, meaning it could have been in breach of Federal Aviation Authority (FAA) requirements.

The company reassured customers that no customer data was stolen, and that no payment information from the Garmin Pay payment system was accessed or stolen either.

On Twitter, the company announced last week, “We are happy to report that many of the systems and services affected by the recent outage, including Garmin Connect, are returning to operation. Some features still have temporary limitations while all of the data is being processed.”

When asked for comment on these reports, a Garmin representative pointed Digital Trends to a statement the company made about the incident last week and said it had no further comments at this time.

Update August 3, 2020: Added response from Garmin

Editors' Recommendations

Georgina Torbet
Georgina is the Digital Trends space writer, covering human space exploration, planetary science, and cosmology. She…
Hackers are pretending to be cybersecurity firm to lock your entire PC
A hacker typing on an Apple MacBook laptop while holding a phone. Both devices show code on their screens.

As hackers come up with new ways to attack, not even trustworthy names can be taken at face value. This time, a ransom-as-a-service (RaaS) attack is being used to impersonate a cybersecurity vendor called Sophos.

The RaaS, referred to as SophosEncrypt, can take hold of your files -- or even your whole PC -- and requires payment to have them decrypted.

Read more
‘World’s largest sundial’ to double as green energy provider
Houston's Arco del Tiempo (Arch of Time).

Houston’s next piece of public art is being described as "the world's largest sundial" and will also produce solar power for the local community.

The striking Arco del Tiempo (Arch of Time) is the creation of Berlin-based artist and architect Riccardo Mariano and will be installed in the Texan city’s East End district in 2024.

Read more
Nvidia’s peace offering isn’t working
Two MSI RTX 4060 Ti 16GB GPUs over a black background.

Nvidia's RTX 4060 Ti 16GB is here, but you wouldn't know it if you didn't follow GPU news closely. It seems that the GPU might just be so far behind some of the best graphics cards that Nvidia isn't advertising it too much. As a result, early benchmarks are scarce.

MSI has released some benchmarks of its own, comparing the 8GB and the 16GB versions of the RTX 4060 Ti. It turns out that the new GPU might actually be slower. Is this why Nvidia didn't even make its own version of this card?

Read more