/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

A Garmin employee confirms that the company's servers were hit by WastedLocker, a ransomware variant developed by Russia-based cybercriminal group Evil Corp

07/24/20 Update below.  This article was originally published on July 23rd, 2020.  It has been updated to reflect that BleepingComputer …

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

Garmin's outage arc moved fast: after shutting down its website, Garmin Connect, and some Asian production lines with a multi-day recovery plan, the company now has internal confirmation of the culprit. An employee's admission that WastedLocker — the ransomware strain built by Russia-based Evil Corp — hit Garmin's servers turns a suspected incident into an attributed one, and Garmin's own statement that there's no indication customer data was stolen frames what is at stake: availability, not confidentiality.

Attribution to Evil Corp carries extra weight because the group sits under 2019 US sanctions, and the later Sinclair attack linked to Evil Corp shows the same strain of infrastructure being reused against other US targets after alleged name changes to dodge those sanctions.

First-order effects

  • Garmin's multi-day recovery plan now has a named cause, and its public posture — no indication of customer data theft, service restoration within days — becomes the benchmark it will be held to if WastedLocker's usual double-extortion behavior surfaces later.

Second-order effects

  • Every Garmin Connect-dependent customer — athletes syncing devices, aviation and marine operators pulling data — must ride out the outage, while Garmin's production lines in Asia idle, pushing recovery cost beyond IT into manufacturing and subscription services.

Third-order effects

  • Sanctioned groups like Evil Corp operating through rebrands means victims and insurers face attribution questions that outlast any single incident, and the pattern visible in the later Sinclair attack suggests WastedLocker-class ransomware against US companies is a recurring structural threat rather than a one-off.

The trend: Ransomware crews under US sanctions are sustaining attacks on major US companies by rebranding, making attribution and response a standing cost of doing business for connected-device makers.

Discussion

  • @garmin @garmin on x
    We are currently experiencing an outage that affects Garmin Connect, and as a result, the Garmin Connect website and mobile app are down at this time. (1/2)
  • @zackwhittaker Zack Whittaker on x
    New: An ongoing outage at Garmin was caused by ransomware, according to two sources with direct knowledge of the incident. WastedLocker, a ransomware strain used by a notorious Russian hacking group — sanctioned by the US Treasury — is likely to blame. https://techcrunch.com/...
  • @zackwhittaker Zack Whittaker on x
    WastedLocker is the ransomware of choice used by Evil Corp, a Russian hacking group, sanctioned by the Treasury last year. That's going to make it tough for Garmin if it wants to pay the ransom (if it doesn't have backups) very difficult. More: https://techcrunch.com/... https://…
  • @bikehugger @bikehugger on x
    What Garmin didn't mention it in their outage alert is multiple flyGarmin services used by aircraft pilots are also down. https://www.bleepingcomputer.com/ ...
  • @amirmizroch Amir Mizroch on x
    What a bonkers story. Garmin hacked by Russian cyber mafia, can't even pay the ransom as that would be in violation of US sanctions. https://www.bleepingcomputer.com/ ...
  • @zackwhittaker Zack Whittaker on x
    In a brief update, Garmin said it has “no indication that this outage has affected your data, including activity, payment or other personal information.” Make of that what you will. https://techcrunch.com/...
  • @tomlawrencetech Tom on x
    The Garmin attack was quite extensive and has shut down their cloud operations, call center & email. “This outage also affects our call centers, and we are currently unable to receive any calls, emails or online chats” https://www.bleepingcomputer.com/ ...
  • @benthompson Ben Thompson on x
    (Mostly small) aircraft will potentially be grounded because they can't update location databases (and I wonder how many Garmin devices the military uses) https://www.infosecurity-magazine.com/ ...
  • @benthompson Ben Thompson on x
    This strikes me as a pretty big deal. https://www.bleepingcomputer.com/ ...