Garmin Cyber-attack Garners Up To $10 Million Ransom To Hackers

The News: A Garmin cyber-attack made the tech company pay some or all of a $10 million crypto ransom to hackers who managed to encrypt the firm’s internal network and take down several of its services on July 23. According to an August 1 report from Lawrence Abrams at Bleeping Computer, Garmin’s IT department used a decryptor to regain access to workstations affected by the initial WastedLocker ransomware attack. The malware took down the company’s customer support, navigation solutions, and other online services. Garmin’s script contains a timestamp of ’07/25/2020′, which indicates that the ransom was paid either on July 24 or July 25. Read the Bleeping Computer report here.

Analyst Take: As I have written about cyber-attacks before, I noted they are going to be on the rise, particularly during a time of crisis when companies are most vulnerable. In this instance, during a global pandemic, when not all employees are physically in offices and are relying on remote collaboration during an emergency.

So much security discussion is around mitigation, but it in reality, a lot of security is reaction and recovery. As hackers demanded $10 million for the keys to liberate Garmin’s systems, Sky News reported that the company ultimately paid, likely through an intermediary. Garmin has declined to comment much beyond confirming that a cyberattack did occur. The company’s CEO Cliff Pemble released a statement saying, “Most of you are aware of the recent cyberattack that led to a network outage affecting much of our website and consumer-facing applications. We immediately assessed the nature of the attack and started remediation efforts. We have no indication that any customer data was accessed, lost, or stolen.”

Garmin was lucky in that ransomware attacks usually involve the stealing of files and then the threatening to dump them online if a payment does not come through. Another recent and very public attack against nonprofit software company Blackbaud resulted in hackers stealing files from at least 125 of its clients, including Planned Parenthood and the UK’s National Trust.

Garmin was hit by a relatively new strain of ransomware called WastedLocker, which has been tied to the Russia’s Evil Corp malware dynasty. For about ten years, the hackers behind Evil Corp has been using banking-focused malware to steal more than $100 million from financial institutions. In 2017, Evil Corp began incorporating Bitpaymer ransomware into its theft practices.

Unfortunately, Garmin reports that it hasn’t fully recovered and is still having syncing issues and delays of the Garmin Connect platform. As ransomware is growing in popularity and becoming more sophisticated, holding large institutions like banks, hospitals and even whole cities for ransom, it’s only a matter of time before a big ransomware attack happens again. Companies today need to make sure they have the latest tools for mitigation and CISOs must make sure they have a fast-reacting plan for disaster and recovery.

Futurum Research provides industry research and analysis. These columns are for educational purposes only and should not be considered in any way investment advice.

Other insights from the Futurum team:

What the Massive Twitter Hack Means for CISOs and Security Vendors

CISO’s Playbook for Leading Security During COVID-19 – Futurum Tech Podcast Interview Series

Failing IoT Security Means Old Malware Makes IoT Comeback

Image Credit: Cycling Tips

Author Information

Sarah most recently served as the head of industry research for Oracle. Her experience working as a research director and analyst extends across multiple focus areas including AI, big data and analytics, cloud infrastructure and operations, OSS/BSS, customer experience, IoT, SDN/NFV, mobile enterprise, cable/MSO issues, and managed services. Sarah has also conducted primary research of the retail, banking, financial services, healthcare, higher ed, manufacturing, and insurance industries and her research has been cited by media such as Forbes, U.S. News & World Report, VentureBeat, ReCode, and various trade publications, such as eMarketer and The Financial Brand.

Related Insights
CrowdStrike Bets on Its Own Models to Secure the AI Revolution
September 8, 2026

CrowdStrike Bets on Its Own Models to Secure the AI Revolution

Fernando Montenegro, VP at Futurum, analyzes CrowdStrike's Fal.Con 2026: an ambitious, largely defensible push into its own AI models and agent security, anchored to the endpoint and the promise to...
OPSWAT at GISEC 2026: Can You Secure What You Can't Detect?
September 7, 2026

OPSWAT at GISEC 2026: Can You Secure What You Can’t Detect?

OPSWAT debuted its AI Content Inspector at GISEC Global 2026, introducing a new defense layer against semantic fraud and AI-generated content that bypasses traditional malware scans in enterprise environments....
HGC and Macroview Bet on AI SecOps Education to Win Enterprise Trust
September 7, 2026

HGC and Macroview Bet on AI SecOps Education to Win Enterprise Trust

HGC and Macroview Telecom co-launch an AI ASOC Workshop Series in October-November 2026, positioning themselves as trusted advisors helping enterprises modernize network and security operations amid critical SOC capacity gaps....
Forescout Brings National-Scale OT Security to Water Utilities
September 5, 2026

Forescout Brings National-Scale OT Security to Water Utilities

Forescout Technologies joins Project Watershed 250, a White House and Texas-backed initiative delivering continuous monitoring and AI-enabled defense to water and wastewater utilities across the nation....
OpenAI’s GPT-6 Astra: Benchmarks, Cyber Risks, and Market Impact
September 4, 2026

OpenAI’s GPT-6 Astra: Benchmarks, Cyber Risks, and Market Impact

Nick Patience, VP and Practice Lead, AI Platforms at Futurum, shares his insights on GPT-6 Astra and what its cyber threshold and monitorability trade-offs mean for Anthropic and Google....
OPSWAT 5.15.0: Closing the Timeout Gap in Enterprise File Inspection
September 4, 2026

OPSWAT 5.15.0: Closing the Timeout Gap in Enterprise File Inspection

OPSWAT's MetaDefender ICAP Server v5.15.0 introduces Smart Scan Timeout, a 30-day workload heat map, and mTLS support to address enterprise security teams' top blockers in scaling perimeter file inspection....

Book a Demo

Welcome

The vision behind everything in Futurum’s Custom Research practice is this: research should show you what is happening, what comes next, and what to do about it. It should be personal to each audience, easy for people to grasp, and structured so LLMs can reason over it accurately. And it should be fast and turnkey; you want answers now, not another project to carry for quarters.

Whether you are defining business, channel, or go-to-market strategy; evaluating vendors or justifying ROI; or commissioning research to fill an emerging market need, we have your back, with a program that answers your questions with the objectivity and credibility to drive real decisions.

To do it, we bring unmatched data to bear: Futurum research, surveys, and market projections; validated market feeds; ETR’s 15 years of insight from 10,000 technology decision-makers; G2’s buyer and user data; and what our analysts hear every day. Add leading primary collection, from AI-moderated voice interviews to surveys and analyst-led interviews, all turnkey, and every project comes out credible, nuanced, and actionable.

And we don’t just drop the results in your lap. For internal work, we provide analyst-led sessions, interactive dashboards, and a range of formats. For market-facing work, Futurum delivers turnkey activation and amplification that actually gets seen, by people and by LLMs, through our media and share of voice. This is research that moves decisions and markets.

We will meet you wherever you are, from a fast-turn brief to a multi-year program, and shape the work to your goals, timeline, and budget. The right program for your moment.

If any of this is useful, I would love to talk.

Benjamin Brown, VP Custom Research, Futurum Research

Benjamin Brown

VP, Custom Research · The Futurum Group

Newsletter Sign-up Form

Get important insights straight to your inbox, receive first looks at eBooks, exclusive event invitations, custom content, and more. We promise not to spam you or sell your name to anyone. You can always unsubscribe at any time.

All fields are required






Thank you, we received your request, a member of our team will be in contact with you.