{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-garmin-outage-from-wastedlocker-ransomware-initial-lure-never-publicly-c"},"incident":{"title":"Garmin outage from WastedLocker ransomware; initial lure never publicly confirmed","date":"2020-07-23","date_precision":"day","victim_org":"Garmin Ltd.","sector":"Technology","country":"United States","primary_vector":"Watering Hole / Malvertising","secondary_vectors":[],"ai_involvement":"No AI reported","ai_notes":"No AI element reported.","outcomes":["Ransomware Deployment","Service Disruption","Extortion"],"loss_usd":null,"loss_note":"Garmin never confirmed a ransom payment or a loss figure; press reporting of a multimillion-dollar payment is unverified.","records_affected":null,"threat_actor":"Evil Corp (WastedLocker operators)","summary":"Garmin suffered a multi-day global outage beginning 23 July 2020 that took down Garmin Connect, flyGarmin and customer support; the company later confirmed it was a ransomware attack, identified by researchers as WastedLocker. Garmin has never disclosed how the attackers got in. WastedLocker campaigns by Evil Corp were documented by multiple vendors as being delivered through the SocGholish fake browser-update framework on compromised websites, which is a deception-based lure, but that vector has not been confirmed for Garmin specifically.","how_it_worked":"In the WastedLocker campaigns of 2020 as documented by researchers, users browsing legitimate but compromised news and business websites were served a fake browser or Flash update overlay. Accepting the prompt downloaded a JavaScript-based loader, after which operators escalated privileges, moved laterally with Cobalt Strike and PowerShell, disabled security tooling and deployed WastedLocker across servers. For Garmin, only the ransomware family and the operational impact were publicly established; the entry point was never disclosed by the company or by law enforcement, so the human-deception element in this specific case is inferred from the campaign pattern rather than confirmed.","lessons":"Blocking user-initiated software updates from browser prompts and enforcing application control on workstations removes the fake-update lure that this ransomware family relied on.","confidence":"Alleged","sources":[{"title":"Garmin outage caused by confirmed WastedLocker ransomware attack","url":"https://www.bleepingcomputer.com/news/security/garmin-outage-caused-by-confirmed-wastedlocker-ransomware-attack/","publisher":"BleepingComputer"},{"title":"WastedLocker explained: How this targeted ransomware extorts millions from victims","url":"https://www.csoonline.com/article/569859/wastedlocker-explained-how-this-targeted-ransomware-extorts-millions-from-victims.html","publisher":"CSO Online"},{"title":"LockerGoga and WastedLocker ransomware insight","url":"https://www.recordedfuture.com/blog/lockergoga-ransomware-insight","publisher":"Recorded Future"}],"entry_type":"incident","slug":"2020-garmin-outage-from-wastedlocker-ransomware-initial-lure-never-publicly-c","year":2020,"loss_kind":null,"url":"https://global-social-engineering-impact-da.vercel.app/incidents/2020-garmin-outage-from-wastedlocker-ransomware-initial-lure-never-publicly-c"}}