A Restic clue helped 12 US firms recover INC-encrypted data

THE BRIEF
CSO Online reports that 12 US companies affected by the INC ransomware group recovered encrypted data after Cyber Centaurs identified cloud storage infrastructure allegedly used to hold stolen information. The Florida-based cybersecurity firm said it found artifacts associated with Restic, a legitimate open-source backup utility that the group uses to encrypt and exfiltrate victim data into cloud environments it controls. Researchers reportedly inferred that the gang might reuse Restic-based infrastructure and located an unnamed cloud storage provider where data had been dumped. Andrew von Ramin Mapp, Cyber Centaurs’ managing principal, characterized the result as potentially only an inconvenience for the group because it could rent new cloud infrastructure. The account highlights how operational-security mistakes around attacker tooling and storage can expose recovery opportunities, while also underscoring that such access may be temporary. The supplied report does not identify the companies or explain the recovery process for each firm.
WHY IT MATTERS
The reported recovery illustrates how attacker operational-security mistakes can reveal links between encryption activity and cloud storage used for data exfiltration. It also shows the limits of relying on one exposed infrastructure location: Cyber Centaurs’ managing principal said the ransomware group could easily rent new cloud infrastructure. Security teams can use the case to examine how backup tools, cloud environments, and retained artifacts might expose useful investigative clues without assuming that one discovery will disrupt an operation permanently.
WHO SHOULD CARE
Incident responders, ransomware recovery teams, cloud-security practitioners, backup administrators, and security leaders responsible for investigating encrypted systems or identifying where stolen data may have been stored.
WHAT TO DO NOW
- Review backup and cloud-storage workflows for artifacts that could reveal where data is encrypted, copied, or stored.
- Include legitimate tools such as Restic in incident-response investigations when examining ransomware activity and suspected data exfiltration.
- Document cloud infrastructure associated with an incident and preserve relevant findings for recovery and investigation.
- Treat access to suspected attacker-controlled storage as potentially temporary, since the reported group could rent new infrastructure.