You Searched for: Country = , Industry =
Editorial: Security Remains Everybody’s JobIncident: Cyberattack at Australia’s Origin Energy
Sydney, Australia-based electric and oil and gas provider, Origin Energy Limited is investigating a data security incident it reported on Wednesday involving unauthorized access to some customers’ data where personally identifiable information ended up stolen in the hack.
Origin said it is continuing to work find the amount of its customers that fell victim to the attack. The company also said it is working with external cybersecurity experts to assist with the investigation.
For those affected by the incident the stolen data includes name, address, date of birth, contact phone number and account information, as well as the last four digits of a credit card, or the last three digits of a bank account. The company added incomplete credit card or bank account information cannot end up used to make purchases or access accounts.
Reference: Origin hack investigation points to offshore Accenture employee
Reference: Aussie Energy Provider Hit In Cyberattack
Victim: Origin Energy Limited
Sydney, Australia-based Origin is Australia’s largest energy retailer with more than 4.8 million customers.
Incident: Ransomware Slows Semiconductor Equipment Maker’s Operations
Richardson, Texas-based semiconductor manufacturing equipment provider, Accretech America Inc., one of the group of companies owned by Tokyo Seimitsu Co., Ltd., confirmed the company suffered a ransomware attack affecting its operations in May.
Upon discovering this incident, which occurred May 4, Accretech America took immediate measures. Operations within the U.S. division experienced temporary disruptions. Additionally, the company shut down its network to prevent further damage, and suspended the use of various systems.
The company also made necessary reports to the administrative authorities.
Reference: Notification of Group Company’s Cyber Incident in U.S.
Reference: Ransomware Slows Semiconductor Equipment Maker’s Operations
Malware: AiLock ransomware group
AiLock is a ransomware-as-a-service (RaaS) operation that first came to light in March 2025.
Threat Actor: AiLock ransomware group
AiLock is a ransomware-as-a-service (RaaS) operation that first came to light in March 2025.
Victim: Accretech America Inc.
Accretech America is a provider of semiconductor manufacturing equipment. Its products include high-performance wafer probing machines, dicing saws, precision dicing blades, polish crinders and CMP equipment. Its products allow semiconductor manufacturers to achieve accuracy and efficiency in their production processes.
Incident: Cyberattack at Safetyfirst Systems
Parsippany, New Jersey-based transportation provider, Safetyfirst Systems, LLC experienced a cyberattack in January and they are just now informing victims their personally identifiable data ended up stolen in the incident.
“On January 19, 2026, a log review revealed suspicious activity associated with a portion of our environment,” the company said in a notice to victims. “We secured and remediated the compromise, engaged additional third-party experts, hardened and enhanced our data security, and commenced an investigation.
“Unfortunately, these types of incidents have become commonplace and impact organizations of all sizes,” the company said. “A third-party forensic investigation determined the unauthorized actor had access to a limited portion of our environment between January 16, 2026, and January 19, 2026, and may have accessed some of your Information.”
Reference: Transportation Provider Hit In Cyberattack
Victim: Safetyfirst Systems, LLC
Parsippany, New Jersey-based SafetyFirst is a driver and fleet safety firm. It has over two decades of experience offering a variety of tried and true solutions aimed at helping improve customers’ driver safety cultures. The company also works to improve efficiency of vehicle and equipment fleets.
Incident: LaserShip DBA OnTrac Final Mile Suffers Cyberattack
Chantilly, Virginia-based transportation provider, LaserShip, Inc. doing business as OnTrac Final Mile suffered a cyberattack where personally identifiable information ended up stolen in the hack.
“On March 23, 2026, we learned of potentially suspicious activity on a limited portion our corporate computer network,” the company said in a notice to victims. “In response, we immediately began an investigation with the assistance of third-party specialists.”
In the course of the investigation, the parcel shipping company found certain files may have ended up accessed without authorization between March 20 and March 22.
Reference: Cyberattack At Parcel Shipping Provider
Victim: LaserShip, Inc.
Chantilly, Virginia-based transportation provider, LaserShip, Inc. doing business as OnTrac Final Mile is a major private last-mile e-commerce parcel delivery company formed after LaserShip and OnTrac merged under shared ownership. Additionally, the company operates across 31 states and Washington, D.C., providing regional and transcontinental ground and express shipping services.
Incident: Oil Provider, SM Energy, Hit in Attack
Denver, Colorado-based oil exploration firm, SM Energy Company, suffered a cyberattack in May where personally identifiable information ended up stolen in the hack.
SM Energy ended up hit in the attack May 15, where unauthorized threat actors gained access to certain company systems.
“Based on our investigation, we determined on June 30, 2026, that an unauthorized third party accessed certain SM Energy systems and obtained files containing certain of your personal information,” the company said in a notice mailed out to victims in July.
Reference: Oil Provider Suffers Cyberattack
Victim: SM Energy Company
Denver, Colorado-based SM Energy Company is an independent energy company. It focuses on the exploitation, development, acquisition, and production of natural gas and crude oil in the United States.
Incident: MPS Enterprises Suffers Data Breach
Midland, Texas-based industrial services provider, MPS Enterprises Inc., suffered a cyberattack in May where personally identifiable information ended up stolen in the hack.
MPS Enterprises reported a data security incident resulted in unauthorized access to personal information belonging to 481 Texas residents. Just after becoming aware of the cyberattack, the company launched an investigation to understand its nature and scope of everything that occurred.
The breach ended up discovered May 19 and the company began sending out notices July 31. In Texas, 481 residents ended up affected in the breach, while 675 individuals total fell victim to the attack.
Reference: Breach At TX Industrial Services Provider
Victim: MPS Enterprises Inc.
MPS Enterprises is a Midland, Texas-based industrial supplier and construction service provider. It does business as Milford Pipe & Supply (or Milford Companies). It specializes in polyethylene (HDPE) pipe, fittings, and turnkey oilfield/municipal construction services.
Incident: Cyberattack at Analog Devices
Wilmington, Massachusetts-based semiconductor maker, Analog Devices suffered a cyberattack in June where files ended up stolen in the hack.
“On June 23, 2026, Analog Devices, Inc. identified unauthorized access to certain company systems,” the company said in an 8-K filing with the Securities and Exchange Commission (SEC). “Following detection of the unauthorized access, the company immediately activated its incident response protocols and engaged external cybersecurity experts to assist with containment and investigation activities.”
Additionally, Analog Devices said it is working with law enforcement authorities.
Reference: Analog Devices Suffers Cyberattack
Victim: Analog Devices
Wilmington, Massachusetts-based Analog Devices is a global semiconductor company that designs and builds specialized integrated circuits. Their technology acts like a nervous system for electronics, converting real-world physical signals – such as sound, light, temperature, motion, and pressure – into digital data that computers and digital systems can understand and process.
Incident: Janome America Suffers Cyberattack
Janome America, Inc, the Mahwah, New Jersey-based subsidiary of sewing machine manufacturer Janome Sewing Machine Company of Tokyo, Japan, suffered a cyberattack last October and is now letting victims know about the hack.
“On October 8, 2025, Janome discovered that it had experienced a network disruption and immediately initiated an investigation of the matter, the company said in a notice to victims. “Janome engaged independent cybersecurity experts to assist with the process.’
As a result of the investigation, Janome and affiliated companies determined that certain files ended up accessed or stolen.
Reference: Cyberattack At Subsidiary Of Sewing Machine Maker
Victim: Janome America, Inc,
Janome America is a distributor of household and computerized sewing machines, It is a subsidiary of Janome Sewing Machine Company in Tokyo, which is one of the world’s largest manufacturers of home sewing machines. JAI started up in 1860 as the New Home Sewing Machine Company. In 1960, Janome Tokyo purchased New Home. In 1999, the name of the company was changed from New Home to Janome America, Inc.
Incident: Operations Halted at NC Ports
A cyberattack halted gate operations at all three of North Carolina’s port facilities this past week and the Coast Guard is investigating the incident.
The breach, which occurred Tuesday, August 4, affected the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port, forcing the North Carolina Port Authority to delay gate openings and shifting to manual processing while it worked to contain the intrusion.
The port’s IT team activated the agency’s cybersecurity contingency plan upon discovering the attack, as well as reaching out to state authorities for further support, said an official at the Ports Authority.
The Port of Wilmington, the largest of the three, handles an average of 5,000 container gate moves per week and, together with Morehead City, processes 4.4 million short tons of cargo annually. The attack, detected on August 4, 2026, resulted in a systems-wide IT outage that forced all three facilities to revert to manual gate processing. This manual fallback allowed the IT team to focus on system recovery while maintaining a minimum level of operational continuity.
Reference: NC Ports Suffer Cyberattack
Victim: Ports of North Carolina
Cyberattacks affected the Port of Wilmington, the Port of Morehead City and the Charlotte Inland Port, all in North Carolina.
Incident: Heavy Equipment Maker, Etnyre International Suffers Cyberattack
Oregon, Illinois-based heavy equipment maker, Etnyre International, suffered a cyberattack in February where personally identifiable information ended up stolen in the hack.
“On or about February 19, 2026, Etnyre learned of suspicious activity in its computer environment,” the company said in a notice to victims. “Upon discovery, Etnyre promptly launched an investigation to determine the nature and scope of the activity.”
The investigation, which the company conducted with the assistance of third-party forensic specialists, determined an unauthorized threat actor gained limited access to data on Etnyre’s systems between February 19 and February 20.
Reference: Equipment Maker Suffers Cyberattack
Victim: Etnyre International
Oregon, Illinois-based Etnyre International, is the family-owned parent company of three industrial manufacturing business units: E.D. Etnyre & Co., BearCat Manufacturing, and SMF, Inc. From its global headquarters and manufacturing facilities across the United States, Etnyre International makes equipment that contributes to roads worldwide and fabricate products for other industries.
Incident: Cyberattack at Smith-Midland
Midland, Virginia-based precast concrete maker, Smith-Midland Corporation (SMC) suffered a cyberattack in January last year and is now informing victims of their personally identifiable information ended up stolen in the hack.
“On or around January 15, 2025, SMC became aware of suspicious activity within their network environment,” the company said in a notice to victims. “SMC launched an investigation and determined that between January 9, 2025 and January 15, 2025, an unauthorized actor accessed certain systems within the environment and copied certain files from those systems.”
SMC conducted a review of the copied files. There were then able to confirm the information stolen, and to whom it belonged to for purposes of providing notice.
Reference: Concrete Maker Hit In Cyberattack
Victim: Smith-Midland Corporation
Midlan, VIrgiinia-based SMC started up in 1960 as the Smith Cattleguard Company. From the beginning the company provided precast concrete products. Over the years, the name changed and the products increased. SMC has a full line of products including: Custom precast products, Easi-Set buildings, SlenderWall cladding, architectural precast, sound/retaining wall, barrier control, beach restoration, agricultural, utility and wash racks.
Incident: Polish Power Plant Shut Down
Winds farms were not the only utility attacked this past December as a steam turbine and the process-water treatment system at a Polish combined heat and power (CHP) plant ended up shut down by attackers that gained entry via a private cellular network.
That attack came on the heels of the December Polish wind farm and large CHP plant hack, which destroyed equipment. A small CHP plant also fell victim to an attack and CERT Polska just released that information. The information on the attack became public during DEF CON in Las Vegas last week as Marcin Dudek, head of CERT Polska, presented details on the incident.
The plant in Poland supplies heat to 50,000 residents. The plant’s steam turbine and a water treatment system used to produce process water ended up shut down, interrupting the cogeneration process, in which electricity and heat generate simultaneously. Thanks to the prompt response of the CHP plant’s operators, the December 29 incident resulted only in a short-term outage and did not disrupt heat supplies to consumers.
Reference: APT Group Linked To Poland Grid Attack
Reference: Attackers Shut Down Polish Power Plant
Malware: Sandworm
Sandworm advanced persistent threat attack
Victim: Polish Power Plant
A steam turbine and the process-water treatment system at a Polish combined heat and power (CHP) plant ended up shut down in December 2025 by attackers that gained entry via a private cellular network.
That attack came on the heels of the December Polish wind farm and large CHP plant hack, which destroyed equipment. A small CHP plant also fell victim to an attack and CERT Polska just released that information. The information on the attack became public during DEF CON in Las Vegas as Marcin Dudek, head of CERT Polska, presented details on the incident.
The plant in Poland supplies heat to 50,000 residents. The plant’s steam turbine and a water treatment system used to produce process water ended up shut down, interrupting the cogeneration process, in which electricity and heat generate simultaneously. Thanks to the prompt response of the CHP plant’s operators, the December 29 incident resulted only in a short-term outage and did not disrupt heat supplies to consumers.
Incident: Candy Maker Hit In Ransomware Attack
Los Angeles, California- based candy manufacturer, See’s Candies suffered a ransomware attack in April and stolen personal information ended up on the Dark Web.
See’s Candies ended up notified on April 12 an unauthorized user accessed certain portions of its network and encrypted files on a subset of its servers.
“We immediately launched an investigation and remediation effort with the assistance of outside cybersecurity experts and notified law enforcement,” the company said in a notice to victims of the attack. “Our investigation determined that there was unauthorized access to portions of our network from April 11, 2026 to April 13, 2026.
Reference: Qilin Strikes See’s Candies with Ransomware Attack
Reference: Candy Maker Hit In Ransomware Attack
Malware: Qilin
Qilin Ransomware Gang
Victim: See’s Candies
Los Angeles, California-based See’s Candies is a manufacturer and distributor of chocolates and confections. The company produces millions of pounds of candy a year from its own kitchens and factories in California, which it then sells through its retail shops and online store. The company’s kitchens and factories operate in South San Francisco and Los Angeles, California.
Incident: Trucking Firm, May Trucking, Suffers Cyberattack
Salem, Oregon-based transportation provider, May Trucking Company suffered a cyberattack in June where personally identifiable information ended up stolen in the hack.
“On June 21, 2026, we detected suspicious activity within our network and immediately initiated an investigation,” the company said in a notice to victims of the attack. “We also engaged independent cybersecurity specialists to assist with the process.”
As a result of the investigation, the company found certain files ended up acquired without authorization at the time we detected the incident.
Reference: Trucking Firm Suffers Cyberattack
Victim: May Trucking Company
Salem, Oregon-based May Trucking Company, founded in 1945, has locations throughout the United States to service the dry and temperature controlled freight needs.
Incident: Universal Plant Services Suffers Cyberattack
Industrial services provider, Deer Park, Texas-based Universal Plant Services, LLC suffered a cyberattack in June where personally identifiable information ended up stolen in the hack.
“On June 12, 2026, we became aware of unauthorized activity on our computer network and immediately engaged third-party forensic specialists to determine the full nature and scope of the event,” the company said in a notice to victims. Furthermore, “this investigation confirmed an unauthorized individual accessed data within the Universal Plant Services network from June 8, 2026, through June 12, 2026.”
The company conducted an investigation, and determined the types of information contained and to whom the information belonged. Furthermore, the company completed this review July 14 and proceed to provide notification of this event.
Reference: Cyberattack At Industrial Service Provider
Victim: Universal Plant Services, LLC
Founded in 1986, Deer Park, Texas-based Universal Plant Services (UPS) is a North American provider specializing in installation, maintenance, and repair. The company services critical rotating, reciprocating, and fixed industrial machinery for the energy, refining, and power generation sectors.
Incident: Cyberattack at USA DeBusk
USA DeBusk LLC suffered a cyberattack in September last year and is now informing victims their personally identifiable information ended up stolen in the hack.
“USA DeBusk LLC experienced a cybersecurity incident on or around September 5, 2025, involving unauthorized access to certain of our systems,” the company said in a notice to victims. “Based on our investigation, we determined on July 6, 2026, that, in connection with this issue, an unauthorized third party obtained certain of your personal information.”
The types of impacted information varied by affected individual, but stolen information included name, contact information like postal and email address and telephone number.
Reference: Industrial Services Provider Suffers Cyberattack
Victim: USA DeBusk LLC
USA DeBusk is an industrial service provider that specializes in cleaning, maintenance, and specialty technological solutions for refineries, chemical plants, power generators, and midstream operators. Headquartered in Deer Park, Texas, the company helps industrial facilities safely reduce downtime during major maintenance outages.
Incident: Skin Care Manufacturer, Malin + Goetz, Hit in Cyberattack
New York, New York-based personal care product manufacturer Malin + Goetz suffered a cyberattack in May where personally identifiable information ended up stolen in the hack.
“On June 15, 2026, we received confirmation from a third-party service provider relating to a potential compromise on our website which we were investigating,” the company said in a notice to victims. “The investigation into the activity identified unauthorized code on our site that may have captured certain information entered on the checkout/payment page, at times between May 22, 2026 and June 10, 2026.”
As a result of the investigation, the company took immediate action to analyze the transactions identified as at risk and determine which customers’ information the threat actor could have taken. Once the company determined that, they would notify them.
Reference: Cyberattack At Skin Care Manufacturer
Victim: Malin + Goetz
New York, New York-based Malin + Goetz Inc. operates as a personal care product manufacturing and retail company. They formulate, produce, and sell their own line of skincare, fragrances, and home goods.
Incident: Biotech Giant Amgen Hit In Cyberattack
Thousand Oaks, California biotechnology producer, Amgen Inc. suffered a cybersecurity incident in July where personally identifiable information ended up stolen in the hack.
“On or about July 2, 2026, Amgen became aware of an unauthorized third party access to certain Amgen systems and data stored in cloud environments hosted by third party cloud service providers,” the company said in a notice to victims. “Upon discovering the incident, Amgen promptly commenced an investigation and engaged independent cybersecurity forensic experts.
In the investigation, on July 18, 2026, Amgen identified the unauthorized third party had obtained access to and acquired certain files containing patient personal information and health information.
Reference: Biotech Giant Hit In Cyberattack
Victim: Amgen Inc.
Thousand Oaks, California-based Amgen is a major biotechnology company that discovers, develops, manufactures, and delivers innovative human medicines using advanced cellular and molecular biology. The company creates complex biologic therapies to treat serious illnesses with limited treatment options.
Malware: Ransomware
Barracuda
Malware: Ransomware
Aurora Ransomware Group
Malware: Ransomware
Very
Malware: Ransomware
Storm
Malware: Ransomware
Unknown attacker
Malware: Ransomware
Barracuda
Incident: Ransomware Attack at Advanced Power Services
Boston, Massachusetts-based power generation infrastructure provider, Advanced Power Services (NA) LLC, suffered a cyberattack in August last year and is now informing victims their personally identifiable information ended up stolen in the hack.
Advanced Power Services just notified victims an unauthorized third party accessed a portion of its computer network between August and November 2025, exposing some of their personal information.
As it turns out, the company detected suspicious activity within a portion of its computer network on November 12, 2025.
Malware: Ransomware
Akira ransomware group
Victim: Advanced Power Services (NA) LLC
Advanced Power Services is a privately owned energy company that specializes in the development, financial structuring, and asset management of modern, low-carbon, and renewable power generation and infrastructure projects.
Incident: Cyberattack Shuts Down UK Power Plant
As suspected Iranian-based hackers hit water facilities in 12 states in the United States, the same country also ended up linked shutting down a UK power plant for four days, government officials said.
The incident involved a small-scale energy generator, according to the UK government, which said that at no point was there a risk to the wider energy system. However, it marks an apparent escalation in the threat posed by Iran after the UK said it had given permission for the U.S. to launch “defensive” operations against Tehran from British bases.
The incident took place at the same time as a series of attacks on U.S. water infrastructure last month, which affected 12 states.
Iran’s Islamic Revolutionary Guard Corps (IRGC) is suspected in the attack
Reference: Cyberattack Shuts Down UK Power Plant
Victim: UK Power Plant
The unnamed power plant ended up involved in the incident. It is a small-scale energy generator, according to the UK government, which said that at no point was there a risk to the wider energy system.
Incident: TX Conduit Maker, Cantex, Hit in Attack
Fort Worth, Texas-based Cantex, Inc., a maker of nonmetallic electrical conduit, suffered a cyberattack where personally identifiable information ended up stolen in the hack.
The breach ended up reported to the Texas Attorney General on Aug. 21, with 1,568 Texas residents identified as affected. Because Cantex’s headquarters is in Texas and this figure represents only the state-mandated Texas-resident count, the true nationwide scope of the incident could be higher if the exposed systems also stored information belonging to employees, vendors, or customers located outside the state.
Stolen in the hack were individuals’ names, home addresses, Social Security numbers, financial account information, and health insurance information. Not only were customers hit in the attack, so too were employees.
Reference: Cyberattack At TX Conduit Maker
Victim: Cantex, Inc.
Cantex is a national manufacturer of American-made nonmetallic electrical conduit, fittings, accessories, utility and communications duct, directional boring conduit and residential switch and outlet boxes.
Incident: Cyberattack at Jasper-Newton Electric Cooperative
Kirbyville, Texas-based Jasper-Newton Electric Cooperative, Inc. suffered a cyberattack where 257 people fell victim to the attack when personally identifiable information ended up stolen in the hack.
The cooperative reported the incident to the Texas Attorney General on August 18. Stolen in the attack were victims’ names, Social Security number information and driver’s license number.
When the incident occurred was not immediately available. Jasper-Newton Electric Cooperative is a non-profit electric utility provider headquartered in Kirbyville, TX.
Reference: Small TX Utility Hit In Cyberattack
Victim: Jasper-Newton Electric Cooperative, Inc.
Kirbyville, Texas-based Jasper-Newton Electric Cooperative, Inc. is an electric utility provider dedicated to serving rural communities of Jasper and Newton Counties. The cooperative focuses on community support and offers various member services, including energy solutions, safety tips, and educational resources to help members make informed energy choices. With a commitment to safety and preparedness, JNEC provides resources for natural disaster readiness and electrical safety.
Incident: Cyberattack at Toy Maker Hasbro
Multinational toy manufacturing and media company, Hasbro, Inc. suffered a cyberattack where personally identifiable information ended up stolen in the hack.
Pawtucket, RI-based Hasbro said it implemented containment and remediation measures, including disabling the compromised employee account, terminating unauthorized access, and deploying additional safeguards designed to help prevent a similar incident from occurring in the future. The company disclosed attackers accessed the personal and financial information of an undisclosed number of employees.
Information stolen in the attack involved name and one or more additional personal information elements such as email, address, phone number, national ID number, or financial information, credit or debit card, social security and driver’s license numbers.
Hasbro told Massachusetts regulators the attack traced back to vishing and social engineering, the practice of tricking an employee or help-desk worker into handing over access rather than breaking through a technical defense.
Reference: Hasbro Cyberattack: Vishing Blamed, 6 Months Later
Reference: Toy Maker Hasbro Suffers Cyberattack
Victim: Hasbro
Hasbro, Inc. is a major American multinational toy manufacturing and media company. With 165 years of expertise, Hasbro delivers play experiences and reaches more than 1 billion customers around the world.
Incident: Spectrum Laboratory Products Suffers Cyberattack
New Brunswick, New Jersey-based supplier of laboratory equipment and supplies, Spectrum Laboratory Products, Inc., suffered a cyberattack where personally identifiable information ended up stolen in the hack.
In August, the company began notifying individuals their personal information may have been affected by a data security incident.
According to a notification letter filed with the Massachusetts Attorney General’s office and dated August 26, Spectrum Laboratory Products, informed affected individuals of the data security incident affecting their personal information. The letter does not specify the cause of the incident, when the company discovered it , or the type of the data involved.
Reference: Cyberattack At NJ Lab Equipment Supplier
Victim: Spectrum Laboratory Products, Inc.
Spectrum Laboratory Products serves a range of industries such as pharmaceuticals, dietary supplements, cosmetics, electronics, aerospace and laboratory research. The company provides a wide variety of chemicals, laboratory reagents, solvents, active pharmaceutical ingredients, excipients and lab supplies.
Reference: Cyberattack At Box Manufacturer
Victim: Northwest Paper Box Manufacturers
Camas, Washington-based Northwest Paper Box is a family-owned custom packaging manufacturer based in the Pacific Northwest. It produces set-up boxes, corrugated containers, and full-service packaging solutions.
Incident: Ransomware Attack at South Korean Auto Parts Supplier, Namyang Industrial
South Korean manufacturer Namyang Industrial Co., Ltd., also known as NAMYANG NEXMO, suffered a ransomware attack in August.
Barracuda ransomware group claimed credit for the August 6 attack at the South Korean auto parts supplier, according to a report in Undercode News.
Namyang Industrial is a supplier within the automotive manufacturing environment. NAMYANG NEXMO is an automotive-parts manufacturer producing steering and braking components, with manufacturing operations in Korea and overseas facilities.
Reference: South Korean Auto Parts Supplier Hit By Ransomware
Victim: Namyang Industrial
Namyang Industrial Co., Ltd. (rebranded as NAMYANG NEXMO in 2019) is a specialized South Korean manufacturing company that primarily makes automotive steering and braking system components.
Incident: Logistics Provider, Gallagher Transport International, Hit in Cyberattack
Global logistics provider, Denver, Colorado-based Gallagher Transport International Inc. (GTI) suffered a cyberattack in January and is just now informing victims their personally identifiable information ended up stolen in the hack.
“On January 11, 2026, GTI became aware of suspicious activity in its network in which an unauthorized third party gained access to certain systems within its network,” the company said in a notice to victims. “Upon becoming aware of this event, GTI promptly launched an investigation, with the assistance of third-party cybersecurity specialists, to determine the nature and scope of the event. GTI also took steps to secure its environment.”
Through its investigation, the company discovered an unauthorized third party copied certain files from the computer network on January 11.
Reference: Logistics Provider Suffers Cyberattack
Victim: Gallagher Transport International Inc.
Gallagher Transport International is a global logistics provider that helps businesses move goods internationally and clear shipments through U.S. ports.
Incident: Structural and Steel Products Suffers Cyberattack
Structural and Steel Products, a Fort Worth, Texas-based manufacturer and distributor of steel products for highway construction and other infrastructure projects suffered a cyberattack in January and is just now informing victims of the hack their personally identifiable information ended up stolen in the hack.
The incident occurred January 24 and the company disclosed the information September 25. That is when Structural and Steel Products notified the Texas Attorney General’s Office of a data security incident affecting 896 Texas residents. It also said 1,143 records ended up stolen in the hack.
Information stolen in the hack include: Name of individual, Social Security Number, driver’s license number, government-issued ID number (e.g. passport, state ID card), and financial information (e.g. account number, credit or debit card number).
Reference: Steel Products Maker Hit In Cyberattack
Victim: Structural and Steel Products
Structural and Steel Products manufactures and distributes structural steel products used primarily in highway construction, including overhead sign structures and related infrastructure components, operating out of Fort Worth.
Incident: Cyberattack at Heat Containment Materials Maker, HarbisonWalker International
Pittsburgh, Pennsylvania-based refractory products maker, HarbisonWalker International (HWI), suffered a cyberattack where personally identifiable information ended up stolen in the hack.
Forensic disclosures confirmed on September 22–23, 2026, reveal an extortion-driven threat syndicate infiltrated HWI’s corporate enterprise network, traversed IT/OT boundaries, and exfiltrated over 450 gigabytes of sensitive corporate data, according to a report with Sh3llc0d3, an advanced offensive security research lab, threat intelligence platform, and cybersecurity blog focused on ethical hacking, vulnerability analysis, and APT (Advanced Persistent Threat) tracking.
Beyond proprietary refractory material formulas and industrial manufacturing schedules, the actors accessed and extracted executive treasury files, corporate banking ledgers, and wire transfer authorization manifests before deploying secondary extortion demands.
Reference: Heat Containment Materials Maker Hit In Attack
Victim: HarbisonWalker International
HarbisonWalker International (HWI) is a manufacturer and the largest producer of refractory products (heat-resistant ceramic materials used in high-temperature industrial environments) in the United States.
Incident: Ransomware Attack at German Utility, Stadtwerke Landsberg
German utility, Stadtwerke Landsberg KU, suffered a cyberattack September 1, resulting in the encryption of key IT systems.
Stadtwerke Landsberg KU is a public municipal utility company owned by the city of Landsberg am Lech, Germany, that provides essential local services like power, water, and public infrastructure.
“First and foremost: operations regarding the electricity grid, water supply, wastewater treatment plant, district heating, fiber-optic network, charging infrastructure, the “Inselbad” pool complex, and parking garages have not been affected by the attack,” the company said in an advisory. “However, the utility’s staff are currently available by phone and email only to a limited extent.”
Reference: German Utility’s IT Systems ‘Encrypted’
Threat Actor: Unknown
Threat actor not identified.
Victim: Stadtwerke Landsberg KU
Stadtwerke Landsberg KU is a public municipal utility company owned by the city of Landsberg am Lech, Germany, that provides essential local services like power, water, and public infrastructure.
Incident: Boston Scientific Operations Hit in Attack
Most of manufacturing is back up and running after a cyberattack against Marlbourgh, Massachusetts-based medical device maker Boston Scientific Corporation that is “likely to have a material impact on the company’s results of operations for the third quarter and full year 2026.”
In a new 8-K report filed September 7 with the Securities and Exchange Commission (SEC), the beleaguered company said it identified a cybersecurity incident that affected certain of its information technology systems and resulted in a global disruption to the company’s operations.
Upon detection, the company activated its incident response protocols, and since then has been working, with the assistance of third-party cybersecurity experts, to investigate, assess and contain the impact of the incident and to restore operations.
Reference: Boston Scientific Cyberattack Will Have ‘Material Impact’ On Results
Victim: Boston Scientific
Marlborough, Massachusetts-based Boston Scientific is a global medical technology company that develops, manufactures, and sells less-invasive medical devices used in a wide range of interventional medical specialties.
Incident: Attack at Aerospace Alloys
Bloomfield, Connecticut-based Aerospace Alloys Inc. (AAI) suffered a cyberattack in June where personally identifiable information ended up stolen in the hack.
“On or about July 9, 2026, AAI identified unauthorized activity within its network,” said a noticed to victims of the attack. “Once identified, they quickly took steps to isolate and secure the network and engaged third-party specialists to assist with containing and investigating the activity.”
The investigation found the breach started June 26 and ended up discovered July 9. Additionally, certain data within the network ended up potentially copied without authorization. As a result, AAI subsequently began reviewing the data to determine the contents of the data and to whom it related.
Reference: Specialty Metal Provider Hit In Cyberattack
Victim: Aerospace Alloys Inc.
Bloomfield, Connecticut-based Aerospace Alloys started up in 1980 and is a specialty metal service center and machine shop in Bloomfield, CT, that supplies high-performance metal alloys and manufactures custom precision components.
Incident: Cyberattack at Cognizant Technology Solutions
Teaneck, New Jersey-based Cognizant Technology Solutions US Corporation suffered a cyberattack in April and is now informing victims their personally identifiable information ended up stolen in the hack.
“We are writing to notify you that a breach of security of your personal information occurred on or around April 21, 2026, at Cognizant Technology Solutions US Corporation,” said a letter to the victims of the attack. The breach started April 15 and the company discovered it by April 21.
The company said it has no reason to believe any information ended up misused at this point. However, they wanted to make sure victims of the attack were aware of the incident.
Reference: Cyberattack At AI Service Provider
Victim: Cognizant Technology Solutions
Teaneck, New Jersey-based Cognizant Technology Solutions is a multinational information technology services and consulting company that helps global businesses modernize technology and implement artificial intelligence (AI) solutions. The company works with manufacturing and industrial companies to help them digitize factories, implement supply chain software, and build smart, connected products.
Incident: Talen Energy Hit in Cyberattack
Houston, Texas-based Talen Energy Corporation suffered a cyberattack in January and is now informing victims their personally identifiable information ended up stolen in the hack.
“On January 27, 2026, we experienced a cybersecurity incident,” the company said in a notice to victims of the attack. “Upon discovering unauthorized activity on certain of our systems, we initiated an investigation with the assistance of leading cybersecurity experts.”
As a result of the investigation, the company determined an unauthorized actor obtained a copy of certain files containing people’s personal information.
Reference: TX Energy Provider Suffers Cyberattack
Victim: Talen Energy Corporation
Houston-based Talen Energy is an independent power producer and energy infrastructure company. The company owns and operates 15.6 gigawatts of power infrastructure in the United States, including 2.2 gigawatts of nuclear power and a significant dispatchable fossil fleet. The company produces and sells electricity, capacity, and ancillary services into wholesale U.S. power markets, with its generation fleet located in the Mid-Atlantic, Ohio, Indiana, and Montana.
Incident: NewCorr Packaging Suffers Cyberattack
Northborough, Massachusetts-based NewCorr Packaging, LP suffered a cyberattack in February and they are now informing victims their personally identifiable information ended up stolen in the hack.
“On February 17, 2026, NewCorr became aware of suspicious activity on certain computer systems in its network,” said a letter to the victims of the attack. “In response, NewCorr promptly took steps to secure its network and initiated a comprehensive investigation to determine the full nature and scope of the activity with the assistance of third-party forensic specialists.”
As a result of its investigation, the company found between February 13, and February 18 certain files within NewCorr’s network ended up viewed and/or copied without authorization. NewCorr identified the affected files and hired a data review vendor to conduct a thorough review of the files. They were able to identify sensitive information contained therein and to whom that information related.
Reference: Cyberattack Hits Packaging Maker
Victim: NewCorr Packaging LP
NewCorr Packaging is a manufacturing company based in Northborough, MA, that produces corrugated sheets for box makers and packaging producers.
Incident: Star Aviation Suffers Ransomware Attack
Goshen, Kentucky aviation supplier, Star Aviation, Inc. suffered a ransomware attack by the Storm ransomware group after the threat actors released some information earlier this month.
Star Aviation operates from Goshen, KY, and provides wire harness inspection and repair services for Boeing and Airbus aircraft, according to the company’s website.
Star Aviation is a small U.S. aerospace company whose business centers on repairing and testing engine wire harnesses and electronic wire interconnect systems used in commercial aircraft.
Reference: Storm claims ransomware attack on Star Aviation
Reference: Ransomware Attack At Aviation Supplier
Threat Actor: Storm
Storm’s operational methodology commonly involves acquiring infostealer-sourced credentials from underground marketplaces, validating them, and then using them for authentication before deploying ransomware.
Victim: Star Aviation
Goshen, Kentucky-based Star Aviation is a small U.S. aerospace company whose business centers on repairing and testing engine wire harnesses and electronic wire interconnect systems used in commercial aircraft.
Incident: Brazilian Adhesive Product Maker, Engefitas Hit in Ransomware Attack
Brazilian manufacturer specializing in adhesive tapes and adhesive products, Engefitas, suffered a ransomware attack by the Vexy Ransomware group which reported the incident on their dark web site earlier this month.
Engefitas makes the specialized adhesive products for the packaging, automotive, construction, electronics, and manufacturing sectors,.
The Vexy Ransomware group is a new group, according to a report with SOCRadar’s Dark Web Monitoring service. It appears Engefitas as one of the initial victims of this new attack group. Vexy Ransomware claims to have stolen internal data when the group released some information September 3..
Reference: Ransomware Attack At Adhesive Product Maker
Threat Actor: Vexy
Vexy is a newly observed ransomware and cyber extortion operation first publicly tracked in September 2026. Current public reporting remains limited, but available tracking identifies the group as active and indicates an extortion model centered on public victim listings and threats tied to data exposure.
Victim: Engefitas
Brazil-based makes the specialized adhesive products for the packaging, automotive, construction, electronics, and manufacturing sectors.
Incident: Cyberattack at CenterPoint Energy
Customer data ended up stolen from Houston, Texas-based energy provider, CenterPoint Energy, Inc., when the company became aware of a cyberattack earlier this month when it saw an online post, according to an advisory.
“In September 2026, CenterPoint Energy, Inc. became aware of an online post by a third party claiming to have obtained a data set containing certain of the company’s customer information,” according to an 8-K report filed with the Securities and Exchange Commission (SEC) on Monday, September 14. “Upon becoming aware of the post, the company promptly took action and activated its cybersecurity incident response protocols, initiated an investigation with the assistance of third-party cybersecurity experts, and took steps to further protect the company’s systems.”
Even with an attack on CenterPoint, the company wanted to ensure everyone there was no impact on the delivery of electric and gas services, which remain operational and undisrupted.
Reference: CenterPoint Energy Hit In Cyberattack
Victim: CenterPoint Energy
Houston, Texas-based energy provider.
Incident: Cyberattack at Oil Equipment Provider, Cardinal Services
New Iberia, Louisiana-based oil and gas equipment and services provider, Cardinal Services LLC, suffered a cyberattack in July where personally identifiable information ended up stolen in the hack.
The July 28 data breach affected Cardinal Services and compromised the personal and medical information of 2,241 individuals, according to a report with the Texas Attorney General’s office.
Founded in 2012, the company provides slickline operations, coiled tubing, nitrogen and fluid pumping, pressure control rentals, and over-the-road crane rentals. It provides services in shallow and deep waters of the Gulf of Mexico, plus U.S. land markets.
Reference: Oil Equipment Provider Suffers Cyberattack
Victim: Cardinal Services LLC
Cardinal Services provides slickline operations, coiled tubing, nitrogen and fluid pumping, pressure control rentals, and over-the-road crane rentals. It provides services in shallow and deep waters of the Gulf of Mexico, plus U.S. land markets.
Incident: Ransomware Attack at Costa Solutions, Supply Chain, Freight Handler
San Antonio, Texas-based supply chain and freight handling provider, Costa Solutions, LLC suffered a ransomware attack in April and is now letting victims know about the attack.
The April 29 Costa Solutions breach affected 19,758 Texas residents, with additional individuals potentially affected nationwide, according to a report with the Texas Attorney General’s office.
The information potentially affected includes names, addresses, Social Security numbers, driver’s license numbers, government-issued identification numbers, medical information, health insurance information, dates of birth, and other information.
Reference: Ransomware Attack At Supply Chain, Freight Handler
Threat Actor: Aurora
The Aurora Ransomware Group is an active, Russian-speaking cybercrime operation that gained widespread attention in mid-2026 for pioneering the operational use of AI coding tools during live network intrusions.
Victim: Costa Solutions LLC
Costa Solutions is a provider of supply chain and managed labor solutions, specializing in 24/7 freight handling and logistics support for the warehouse and food service industries.
Incident: PLC Maker Micro-Comm Suffers Ransomware Attack
Olathe, Kansas-based maker of programmable logic controllers (PLCs), Micro-Comm, suffered a ransomware attack in late July where the attacker claimed to steal 644 GB of data.
Micro-Comm supplies control technology to water and wastewater utilities and the ransomware group Barracuda said it stole 644 GB of data from 850,000 files. To that end, Micro-Comm said sensitive user credentials and remote-access information did not end up compromised.
In this attack, the FBI said it is investigating the ransomware attack of the supplier of PLCs and related technology used by public water and wastewater facilities. The exposed material reportedly includes government customer names and system diagrams, information that could assist later attacks even where operating credentials did not end up compromised.
Reference: PLC Maker Hit In Ransomware Attack
Threat Actor: Barracuda
Barracuda, a relatively new ransomware group that describes itself as financially motivated rather than government sponsored.
Victim: Micro-Comm
Olathe, Kansas-based maker of programmable logic controllers (PLCs), Micro-Comm, supplies control technology to water and wastewater utilities.
Incident: Cyberattacks at Water Systems in Colorado
Two small water utility systems in Colorado suffered a cyberattack late last month and it appears foreign threat actors conducted the hack, state officials said.
This attack occurred after hackers hit water facilities in other states like in Minnesota where over 30 small water systems ended up hit. Federal officials associated those attacks with threat actors affiliated with Iran.
It remains uncertain as to who the threat actors were or if the attempted interference was related to the July hacking attempts that affected 12 states
Reference: Colorado Water Systems Hit In Cyberattack
Victim: Colorado Water Systems
Two small water utility systems in Colorado suffered a cyberattack. Computer systems for two Colorado utilities – both of which are private and serve fewer than 200 people – were targeted in late August,
Incident: Safety Contractor Alliance Environmental Group Hit In Cyberattack
Environmental remediation and safety contractors, Azusa, California-based Alliance Environmental Group, LLC suffered a cyberattack where personally identifiable information ended up stolen in the hack.
“On May 7, 2026, Alliance became aware of suspicious activity in our network,” the company said in a notice to victims. “We promptly took steps to secure our systems and initiated an investigation into the nature and scope of the event.”
The investigation found certain files on Alliance systems ended up accessed or acquired without authorization from April 24 to May 7.
Reference: Safety Contractor Hit In Cyberattack
Victim: Alliance Environmental Group
Azusa, California-based Alliance Environmental Group is an environmental remediation, indoor air quality, and safety contractor operating across the West Coast.
Incident: IDScan Hit in Cyberattack
New Orleans, Louisiana-based ID verification service IDScan discovered in early September they suffered a cyberattack and the FBI is investigating the hack where at least 170 million U.S. and Canadian driver’s license information ended up stolen.
IDScan is an identity verification technology company that provides hardware and software solutions for businesses to scan, authenticate, and extract information from government-issued identity documents.
The company said in an advisory on its website “On or around September 1, 2026, IDScan.net received information indicating that certain data may have been accessed without authorization. Upon this discovery, we took immediate steps to secure our systems and engaged a team of third-party specialists to help determine the full nature and scope of the incident. This investigation is currently ongoing.”
Reference: FBI Investigating IDScan Cyberattack
Victim: IDScan
New Orleans, Louisiana-based IDScan is an identity verification technology company that provides hardware and software solutions for businesses to scan, authenticate, and extract information from government-issued identity documents.
Incident: Scientific Equipment Maker, Kurt J. Lesker Company Suffers Cyberattack
Jefferson Hills, Pennsylvania-based scientific equipment maker, Kurt J. Lesker Company (KJLC ), suffered a cyberattack last November and is now informing victims their personally identifiable information ended up stolen in the hack.
“On or about August 4, 2026, KJLC confirmed that certain personal information may have been accessed or taken from KJLC systems between November 12, 2025, to November 13, 2025”, the company said in a notice to victims. “As part of its response to this activity, KJLC took steps to secure its systems and investigate this matter with the assistance of third-party investigators.”
The information that could have been subject to unauthorized access includes name and Social Security number.
Reference: Cyberattack At Scientific Equipment Maker
Victim: Kurt J. Lesker Company
Jefferson Hills, Pennsylvania-basedKurt J. Lesker Company manufactures and distributes scientific vacuum equipment, components, and thin-film deposition systems used in research and high-technology industries.
Incident: Port Operations Down after Ransomware Attack
A major transhipment hub in Malaysia, Port of Tanjung Pelepas (PTP), is returning to normal operations following a ransomware attack that temporarily suspended container terminal operations.
PTP said it detected the incident at 23:34 hours local time on September 9. The operator immediately isolated the affected systems as a precaution, which temporarily suspended container terminal operations while recovery efforts began.
The terminal began a phased restart the following day, including manual processing for some export container gate-ins.
Reference: Cyber attack disrupts operations at Malaysia’s Port of Tanjung Pelepas
Reference: Ransomware Attack Shuts Down Port Operations
Threat Actor: Direwolf
Dire Wolf is an emerging, financially motivated human-operated ransomware group and malware strain first identified in May 2025. It primarily focuses on high-impact industries like manufacturing, technology, finance, construction, and healthcare across global regions including the U.S., Asia, and Europe.
Malware: Direwolf
Dire Wolf is an emerging, financially motivated human-operated ransomware group and malware strain first identified in May 2025. It primarily focuses on high-impact industries like manufacturing, technology, finance, construction, and healthcare across global regions including the U.S., Asia, and Europe.
Victim: Port of Tanjung Pelepas (PTP)
PTP is a major transshipment hub in Malaysia. A transhipment hub is where it is possible to move goods or containers to an intermediate destination or hub, where they end up unloaded and transferred to another carrier, vehicle, or vessel to complete their journey to the final location.
Incident: Northwest Paper Box Manufacturers Hit in Cyberattack
Camas, WA-based Northwest Paper Box Manufacturers suffered a cyberattack in June where personally identifiable information ended up stolen in the hack.
“On June 27, 2026, NW Paper became aware of unusual activity on their network and immediately launched an investigation which included working with third-party specialists,” the company said in a notice. “The investigation determined there was unauthorized access to a portion of NW Paper’s network between June 24, 2026 and June 28, 2026.”
As a result of the investigation, NW Paper conducted a comprehensive review of the relevant files and folders. They then determined the type of information the files contained and to whom it belonged.
Reference: Cyberattack At Box Manufacturer
Victim: Northwest Paper Box Manufacturers
Camas, Washington-based Northwest Paper Box is a family-owned custom packaging manufacturer based in the Pacific Northwest. It produces set-up boxes, corrugated containers, and full-service packaging solutions.
Incident: Cyberattack at Ecopetrol, Colombia Energy Provider
Colombia’s energy giant, Ecopetrol S.A., suffered a cyberattack as threat actors gained unauthorized access to certain digital resources as well as an attempted ransomware attack that ended up blocked by the controls implemented across the company and its subsidiaries, the company said Friday.
The unauthorized access affected cloud-based file storage environments of approximately 15 subsidiaries (including the company), resulting in the download of data associated with approximately 3,300 user accounts.
As a result of the attack, reported Friday, July 17, the unidentified threat actor communicated extortion demands, threatening to publicly disclose the stolen information.
Reference: Colombia’s Energy Giant, Ecopetrol, Suffers Cyberattack
Threat Actor: The Gentlemen
The Gentlemen (tracked by Microsoft as Storm-2697) is a financially motivated Ransomware-as-a-Service (RaaS) cybercriminal group that emerged in mid-2025. Known for utilizing a double-extortion tactic—encrypting enterprise files while exfiltrating sensitive data to threaten public leaks—the group has quickly grown into one of the most active threat operations globally.
Malware: Ransomware attempt
The Gentlemen claimed responsibility.
Victim: Ecopetrol S.A.
Ecopetrol is the largest company in Colombia and a major integrated energy company with more than 19,000 employees. In Colombia, it is responsible for more than 60 percent of the hydrocarbon production of most transportation, logistics, and hydrocarbon refining systems, and it holds leading positions in the petrochemicals and gas distribution segments. With the acquisition of 51.4 percent of ISA’s shares, the company participates in energy transmission, the management of real-time systems (XM), and the Barranquilla – Cartagena coastal highway concession.
Ecopetrol has a stake in strategic basins in the American continent, with drilling and exploration operations in the United States (Permian basin and the Gulf of Mexico), Brazil, and Mexico, and, through ISA and its subsidiaries, Ecopetrol holds leading positions in the power transmission business in Brazil, Chile, Peru, and Bolivia, road concessions in Chile, and the telecommunications sector.
Incident: Cosmetics Giant, Estee Lauder, Hit in Third-Party Attack
As a result of a third-party issue, New York, New York-based cosmetics giant, Estee Lauder Companies, suffered a cyberattack in August of last year and is now letting victims know their personally identifiable information ended up stolen in the hack.
“We became aware of a cybersecurity issue involving a vulnerability in the Oracle E-Business Suite system which is used by the Estee Lauder Companies for HR management purposes,” the company said in a letter to victims. “On June 19, 2026, we determined through our investigation that, on or around August 9, 2025, an unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals.”
The affected information included names, postal and email addresses, dates of birth, Social Security numbers, passport numbers, financial account information (bank account numbers), health information, and employment-related information (such as performance evaluation and payroll information). The impacted data varied for each affected individual.
Reference: Cosmetics Giant Suffers From Third-Party Attack
Malware: Third-party attack
Unauthorized third party gained access to the Oracle E-Business Suite system and obtained personal information of certain individuals.
Victim: Estee Lauder Companies
The Estée Lauder Companies Inc. is an American multinational cosmetics company, a manufacturer and marketer of makeup, skincare, perfume, and hair care products, based in midtown Manhattan, New York City. It is the second largest cosmetics company in the world.
Incident: Cyberattack at Grape Producer, HMC Fresh Foods
Kingsburg, California-based grape producer, HMC Fresh Foods LLC, suffered a cyberattack in June where personally identifiable information ended up stolen in the hack.
“We recently determined that some of your personal information was involved in a data security incident,” the company said in a notice to victims. “We experienced unusual activity involving our computer networks on June 5, 2026, and immediately started an investigation using outside experts to assist.”
As a result of the investigation, HMC Fresh found some employee personal information ended up accessed or downloaded during the incident.
Reference: Grape Producer Hit in Cyberattack
Victim: HMC Fresh Foods LLC
HMC Fresh Foods operates as a manufacturer and processor. Additionally, it functions as a division of HMC Farms, focusing on manufacturing and processing value-added, ready-to-eat grape products. Furthermore, they wash, process, and package fresh fruit in a cold-storage production facility located in Kingsburg, CA.
HMC Fresh Foods is a part of the HMC Group. Companies within the organization suffered cyberattacks on the same day. One of the other companies was Cabot Packing LLC (doing business as HMC Reedley).
Incident: Cyberattack At CA Agricultural Processor, HMC Reedley
Reedley, California-based agricultural processor, Cabot Packing LLC (doing business as HMC Reedley), suffered a cyberattack in June where personally identifiable information ended up stolen in the hack.
“We recently determined that some of your personal information was involved in a data security incident.,” the company said in a notice to victims “We experienced unusual activity involving our computer networks on June 5, 2026, and immediately started an investigation using outside experts to assist.”
The investigation revealed threat actors were able to steal some employee personal information during the incident.
Reference: Cyberattack At CA Agricultural Processor
Victim: Cabot Packing LLC (doing business as HMC Reedley)
Cabot Packing LLC (doing business as HMC Reedley) is a manufacturer and agricultural processor. Located in Reedley, CA, the facility specializes in sorting, packing, repacking, and cold storage of fresh produce. The produce includes stone fruit, table grapes, nectarines, peaches, and plums.
HMC Reedley is a part of the HMC Group. Companies within the organization suffered cyberattacks on the same day. One of the other companies was HMC Fresh Foods LLC.
Incident: Ransomware Shuts Down Coca-Cola Subsidiary, fairlife
Coca-Cola Company ‘s subsidiary, fairlife LLC, suffered a ransomware attack that shut down production-related systems, company officials said Thursday, July 1.
After detecting the unauthorized access by a third party to a portion of its systems, Coke promptly activated its incident response and business continuity protocols, according to an 8-K report the company issued to the Securities and Exchange Commission (SEC).
The company’s investigation and assessment of the impact of the incident is ongoing, with the assistance of outside advisors and cybersecurity experts. Coke also notified law enforcement. Product quality and safety have not suffered an impact, according to the report.
However, as a result of the incident, production operations at fairlife in the United States are temporarily suspended. Having said that, fairlife’s Canada production operations are not suffering from the attack.
Reference: Attack Group Claims Coke Subsidiary Hack
Reference: Coke Subsidiary Shutdown By Ransomware Attack
Malware: Ransomware
Anubis attack group claimed responsibility.
Victim: fairlife LLC
Fairlife is a Chicago-based, wholly owned dairy subsidiary of The Coca-Cola Company known for its ultra-filtered, lactose-free milk.
Incident: Cyberattack at Software Developer Advantive
Tampa, Florida-based software developer for manufacturers, Advantive LLC, suffered a data breach in April where personally identifiable information ended up stolen in the hack.
The data breach occurred between April 10 and April 11, affecting 4,977 people. During this period, attackers gained unauthorized access to sensitive information, including the names of individuals and their financial information, such as account numbers and credit or debit card details.
Advantive disclosed a data security incident involving unauthorized access to certain business files.
Reference: Software Developer Hit In Cyberattack
Victim: Advantive LLC
Advantive is a software development company that provides AI-enabled operational and intelligence software for specialty manufacturers and wholesale distributors.
Incident: Roland Machinery Hit in Ransomware Attack
Springfield, Illinois-based heavy equipment distributor, Roland Machinery Co., suffered a ransomware attack in Australia where personally identifiable information ended up stolen in the hack.
Founded in 1958 and owned by the Roland family, the company is one of the biggest heavy equipment dealers in the Midwest and is a major Komatsu dealership.
The attack ended up discovered June 8 and attackers made off with Social Security Numbers, financial account codes, credit and debit account info, and government identification numbers, according to a July 7 notice with the Vermont Attorney General.
Reference: Ransomware Attack At Heavy Equipment Distributor
Threat Actor: Termite
Termite is a cyber extortion threat group that surfaced in late 2024. It is known for using modified Babuk ransomware source code, executing double-extortion attacks, and targeting major global supply chain and corporate networks.
Malware: Ransomware
Termite ransomware group claimed credit for the attack.
Victim: Roland Machinery Co.
ounded in 1958 and owned by the Roland family, the company is one of the biggest heavy equipment dealers in the Midwest and is a major Komatsu dealership.
Incident: King Ocean Services Hit in Cyberattack
Miami, Florida-based logistics company King Ocean Services Limited suffered a cyberattack in July where personally identifiable information ended up stolen in the hack.
King Ocean specializes in providing ocean transportation, trucking, and warehousing services across the Caribbean, Central America, and South America.
On July 11, 2026, King Ocean Services Limited provided notice regarding a data security incident that resulted in the exposure of personal information. This breach included sensitive information such as government ID numbers.
Reference: Cyberattack At Maritime Shipping Firm
Victim: King Ocean Services Limited
King Ocean Services is a private ocean freight transportation and cargo shipping company specializing in maritime shipping throughout the Western Hemisphere, operating out of Florida ports with over 40 years of industry experience. Its core business focuses on containerized shipping, refrigerated cargo (reefers), heavy machinery, project cargo, vehicles, and less-than-containerload (LCL) consolidation.
Incident: India Nuclear Plant Suffers Ransomware Attack
India’s largest nuclear plant, Kudankulam, suffered a ransomware attack where blueprints of parts of its facilities and supplier details ended up stolen in the hack.
The Kudankulam nuclear power plant, located in Tamil Nadu, is the largest of India’s seven nuclear plants and central to Prime Minister Narendra Modi’s ambitious plans to expand the country’s atomic energy capacity.
Businessman Anil Ambani’s Reliance Group, one of the plant’s contractors, told Reuters in a statement there was a “partial breach” of its data on a server hosted by third-party Indian data center service provider Yotta, and they informed the government about the incident.
Reference: Ransomware Attack At India Nuclear Plant
Malware: Ransomware
World Leaks claimed credit for the attack
Victim: Kudankulam nuclear plant
Kudankulam nuclear power plant, located in Tamil Nadu, is the largest of India’s seven nuclear plants.
Malware: Ransomware
ShinyHunters ransomware group
Incident: Cyberattack at Lawn Tractor Maker Kubota North America
Grapevine, Texas-based lawn tractor maker Kubota North America Corporation suffered a cyberattack in March where threat actors obtained personally identifiable information about employees during the hack.
“We recently identified and addressed an incident involving unauthorized access to certain network systems between March 16, 2026, and April 20, 2026,” said a notice that went out to victims. “When we learned of the incident, we immediately took steps to secure our network.”
On April 30, Kubota found files maintained by its human resources team ended up accessed as part of this incident. The company then went throught the fines and by June 16, it determined that one or more file(s) contained information from employees.
Reference: Lawn Tractor Maker Suffers Cyberattack
Victim: Kubota North America Corporation
Kubota North America Corporation acts as the central business hub and North American production base for its parent company, Kubota Corporation. While the Grapevine, Texas office manages regional strategy, distribution, and business operations, the actual machinery production happens at massive manufacturing plants across the U.S.. The largest of these is Kubota Manufacturing of America Corporation (KMA) in Gainesville, Georgia. This facility serves as the primary U.S. production hub, manufacturing and assembling: Lawn tractors, zero-turn mowers, sub-compact tractors, utility vehicles, and performance-matched implements and tractor-mounted equipment.
Incident: Medical Device Maker Medtronic Hit with Ransomware
Dublin, Ireland-based medical device maker, Medtronic Inc. was the victim of a cybersecurity incident where personal health information for 3.8 million people ended up stolen by a ransomware group.
Medtronic confirmed the cybersecurity breach impacting corporate IT systems attributed to the ShinyHunters extortion group.
“On April 15, 2026, Medtronic became aware of unusual activity on certain corporate IT systems,” the company said in a notice to victims. “Medtronic launched an investigation with the assistance of leading third-party cybersecurity experts to determine the impact and scope of the incident.”
Reference: Ransomware Attack At Medical Device Maker
Victim: Medtronic Inc.
Medtronic is the world’s largest medical device company by revenue. Headquartered in Dublin, Ireland, with operational centers in Minneapolis, Minnesota, the company employs over 90,000 people and serves millions of patients globally. Medtronic develops therapies and technologies across four core portfolios: Cardiovascular, neuroscience, medical surgical, and diabetes.
Incident: Ransomware Attack at Bajaj Auto
Indian automotive giant Bajaj Auto detected an active ransomware attack in late June where it and its wholly owned technology subsidiary, Bajaj Auto Technology Limited (BATL), which handles engineering, R&D, and technology development suffered from the hack.
Bajaj Auto said it acted immediately after the Tuesday, June 23 attack at 8 a.m., and engaged internal and external experts, activated incident response protocols, and notified the Indian Computer Emergency Response Team (CERT-In). Additionally, Bajaj Auto said it did not have any halt in production.
“Immediately upon becoming aware of the incident, the technical team of the company along with cybersecurity experts and the management responded promptly and initiated necessary precautionary actions and protocols to mitigate the impact of this incident and this has been successful based on the available information at this time,” the company said in a notice to regulators.
Reference: Bajaj Auto Hit In Ransomware Attack
Victim: Bajaj Auto
Bajaj Auto is one of India’s largest vehicle manufacturers, producing motorcycles, scooters and commercial vehicles. The company is also the world’s largest manufacturer of three-wheelers, commonly known as auto-rickshaws.
Incident: Third-Party Attack Hits Nissan
There was another incident related to the Oracle PeopleSoft software where attackers were able to steal the personnel records of hundreds of companies of which Nissan was the latest to report former and current employees ended up victimized.
“We have since learned that Nissan was specifically targeted in this attack,” according to an advisory dated Friday, June 26. “Upon learning about this issue, we quickly activated incident response protocols. We have been in communication with authorities throughout our response to this attack. Our technical teams, along with external experts, have secured our systems and will continue to work with Oracle to address this issue.”
Oracle’s PeopleSoft program manages employee records, payroll, and other personal data and in this case attackers were able to exfiltrate data accessed on Nissan’s systems.
Reference: Nissan Falls Victim To Third-Party Attack
Incident: Supply Chain Attack at Application Security Testing Platform Provider Checkmarx
Application security testing (AppSec) platform provider Checkmarx experienced a cybersecurity supply chain incident in March affecting certain developer artifacts distributed through third-party channels and it is continuing supplying updates to the incident.
Checkmarx is an enterprise-grade AppSec platform designed to help developers and security teams identify and remediate vulnerabilities in their code. It seamlessly integrates into developer workflows and CI/CD pipelines to secure software from early coding stages through to production.
The attack all unfolded on March 23 when Checkmarx discovered attackers gained unauthorized access to its GitHub repositories. This access occurred on March 19 due to the Trivy Supply Chain Attack.
Reference: Checkmarx Update On Supply Chain Attack
Victim: Checkmarx
Paramus, New Jersey-based Checkmarx is an enterprise-grade AppSec platform designed to help developers and security teams identify and remediate vulnerabilities in their code. It seamlessly integrates into developer workflows and CI/CD pipelines to secure software from early coding stages through to production.
Incident: Tata Electronics Suffered ‘Cybersecurity Incident’
Operations remain unaffected after Tata Electronics suffered “cybersecurity incident,” as researchers said World Leaks posted component design and specification papers of Apple and Tesla, customers of the technology giant.
The ransomware group posted more than 200,000 files on the dark web, security researchers said in a Reuters report.
“A few weeks ago, Tata Electronics identified a cybersecurity incident on some of our systems. Our response protocols deployed immediately, and the incident has had no impact on our operations across businesses, which remain unaffected,” Tata Electronics told Reuters.
Reference: Tata Electronics Hit In Cyberattack
Reference: Apple iPhone 18 Pro secrets leaked in Tata Electronics hack: What we know
Victim: Tata Electronics
Bengaluru, Karnataka, India-based Tata Electronics is a major global electronics manufacturing company for companies such as Apple and Tesla.
Reference: Tata Electronics Hit In Cyberattack
Reference: Apple iPhone 18 Pro secrets leaked in Tata Electronics hack: What we know
Malware: Ransomware
Ransomware group World Leaks is behind the attack.
Victim: Tata Electronics
Tata Electronics is a major global electronics manufacturing company for companies such as Apple and Tesla.
Incident: Cyberattack at Computer Gaming Maker, American Future Technology
City of Industry, California-based computer gaming maker, American Future Technology Corporation, doing business as iBUYPOWER, suffered a cyberattack in June last year and is now informing victims of the hack.
“On June 21, 2025, we discovered unauthorized activity within our IT network,” the company said in a notice to victims. “We took immediate steps to stop the unauthorized activity, investigate the data security incident, and restore our regular business operations.”
Additionally, the company quickly retained experienced cybersecurity specialists to assist in evaluating the situation and returning to normal.
Reference: Gaming Computer Maker Suffers Cyberattack
Victim: American Future Technology Corporation
City of Industry, California-based computer gaming maker, American Future Technology, doing business as iBUYPOWER, is a manufacturer of custom-built and prebuilt gaming computers, laptops, and peripherals. The company primarily targets gamers, esports organizations, and content creators.
Incident: Energy Exploration Firm Beusa Energy Hit in Cyberattack
The Woodlands, Texas-based private energy exploration company Beusa Energy, LLC, discovered a cyberattack this past May that occurred in July last year where personally identifiable information ended up stolen.
On May 20, 2026, Beusa Energy, LLC, a privately held oil and gas exploration and production company discovered an unauthorized party had accessed its computer network.
The company hired an outside cybersecurity provider to help conduct a forensic investigation and they found between July 24 and July 30, 2025, files containing personal information may have been accessed or copied.
Reference: Oil Exploration Provider Hit In Cyberattack
Victim: Beusa Energy, LLC
The Woodlands, Texas-based private energy exploration company Beusa Energy is a private, independent oil and gas company that focuses on the exploration, development, and production of unconventional oil and natural gas resources in the United States.
Incident: Cal Water Hit in Cyberattack
Iran-linked attack group, Handala, said it compromised California Water Service (Cal Water) in retaliation for recent U.S. actions in Iran.
In an effort to show proof, the attack group published 5GB proof-of-concept data that appears to contain customer billing personally identifiable information (PII) and administrative credentials for an internal RTKBase NTRIP GPS correction network covering seven Cal Water service districts.
In a post on their blog, the hacking group said the intrusion was in retaliation for recent U.S. actions in Iran and claimed they had the ability to disrupt water access but chose not to.
On Thursday, June 11, threat intelligence provider, Dataminr issued a Flash alert detecting a Handala claim of compromise against Cal Water. The organization is one of the largest investor-owned water utilities in the United States, serving two million customers across 100 California communities.
Reference: Iran-Linked Attack Group Claims CA Water Utility Breach
Victim: California Water Service (Cal Water)
California Water Service (Cal Water) is the largest regulated American water utility west of the Mississippi River and the third-largest in the United States. Founded in 1926 and based in San Jose, it provides drinking water and wastewater services to roughly 2 million people across more than 100 California communities.
Incident: Novo Nordisk Suffers Second Ransomware Attack
Danish pharmaceutical giant Novo Nordisk, the maker of popular weight loss drug Wegovy, disclosed two ransomware incidents where the threat actors were seeking $25 million in one attack, and $50 million in the other.
In the second attack “TheUSERS007,” said they were going to leak stolen data after ransom negotiations with Novo Nordisk failed.
Those threat actors claim to have acquired between June 5-7 some different data than what FulcrumSec shared in the first attack. Both threat groups appeared to have been negotiating with Novo Nordisk at the same time.
Data incident site, DataBreaches, asked TheUSERS007 how they gained access to Novo Nordisk and the answer is frightening. In a chat on Tox, a spokesperson for TheUSERS007 told DataBreaches they used venomware.
Venomware is an emerging, highly advanced class of digital attack tool classified as a self-learning, adaptive AI engine used to surgically extract intellectual property. Unlike traditional malware, it does not typically break into systems using forced exploits or encryption; rather, it uses artificial intelligence to identify misconfigurations and navigate networks. which they describe as a self-learning, adaptive AI engine designed for the surgical extraction of intellectual property.
Reference: 2 Ransomware Attacks On Novo Nordisk Go Unpaid
Threat Actor: TheUSERS007
TheUSERS007 is an emerging cyberextortion group. TheUSERS007 claimed to use a self-learning, adaptive artificial intelligence engine dubbed "Venomware." This tool was used to surgically analyze network structures, bypass defensive controls, and extract valuable data rapidly.
Malware: Ransomware
Attack group, named “TheUSERS007" conducted the second attack,
Incident: Pharmaceutical Maker Novo Nordisk Suffers Ransomware Attack
Despite a cyberattack at Novo Nordisk A/S that forced the company to shut down some systems, its core business operations remain up and running.
To that end, Novo Nordisk, the maker of weight-loss drug Wegovy, said Thursday, June 11, it identified an IT security incident involving unauthorized access to a limited number of internal IT systems.
“Upon learning of the incident, we launched an investigation with the assistance of external cybersecurity experts, and we are in contact with the relevant authorities,” the company said in an advisory.
Reference: 2 Ransomware Attacks On Novo Nordisk Go Unpaid
Threat Actor: FulcrumSec
FulcrumSec is a financially motivated cloud extortion group—also known as The Threat Thespians—that has been active since late 2025. Operating primarily via a "steal and squeeze" model, they gain entry into enterprise environments and steal sensitive corporate and user data to demand multi-million-dollar ransoms.
Malware: Ransomware
FulcrumSec claimed responsibility for the incident.
Reference: Weight Loss Drug Maker Suffers Cyberattack
Victim: Novo Nordisk A/S
is a global healthcare company founded in 1923 and headquartered in Denmark. The company develops treatments for diabetes and weight management, including widely popular drugs such as Ozempic, Wegovy, Rybelsus, Victoza, and Saxenda, along with a broad lineup of insulin products. Novo Nordisk employs 67,900 people in 80 countries and markets its products in around 170 countries.
Incident: 2 Mackay Sugar Sugar Mills Shut Down after Attack
A sugar miller in north Queensland, Australia, shut down by a cyberattack last week is undergoing system testing and looking to restart production next week.
Mackay Sugar shut down two of its three mills at Farleigh and Racecourse Wednesday, June 10, after finding operating systems suffered compromise. The company said Monday, Jun 15, it is continuing to respond to a cyberattack affecting some operations.
“We have completed a successful limited manual crushing operation at Farleigh Mill, processing cane harvested prior to the incident,” the company said in an advisory. “This was a step forward in our recovery efforts, giving us confidence that critical operational functions can continue to be restored safely.”
Reference: Sugar Mills Shut Down By Cyberattack
Victim: Mackay Sugar
North Queensland, Australia-based Mackay Suga is Australia’s second largest sugar manufacturer, located in the heart of Australia’s sugar cane belt in tropical North Queensland.
Incident: Chemical Company, Pride Solvent & Chemical, Hit in Cyberattack
Avanel, New Jersey-based Pride Solvent & Chemical Co., Inc., Pride Solvent & Chemical Co. of NY, Inc., and Pride Solvent and Chemical Co. of New Jersey, Inc. suffered a cyberattack in March where personally identifiable information from its workers ended up stolen in the hack.
“On or about March 17, 2026, the company discovered it suffered a cybersecurity attack on its on-premises servers,” according to a notice to victims of the attack. “The company believes the cybersecurity attack occurred on or about March 13, 2026 through March 17, 2026.”
Upon discovery of the breach, the company retained outside counsel and engaged an independent forensic expert to begin an investigation.
Reference: Chemical Firm Hit In Cyberattack
Victim: Pride Solvent & Chemical Co., Inc.
Avanel, New Jersey-based Pride Solvent & Chemical is an independent chemical distributor, serving industries including pharmaceutical, personal care, household, industrial and institutional (HI&I), flavor-fragrance-food, and paints and coatings. The company’s facilities include 175,000 sq. ft. of warehouse space, 15,000 sq. ft. of cGMP compliant white room for specialized packaging, and a full analytical laboratory ensuring product quality and compliance.
Incident: Concrete Maker Rockville Fuel & Feed Suffers Cyberattack
Rockville, Maryland-based concrete maker Rockville Fuel & Feed Co. suffered a cyberattack in February where personally identifiable information ended up stolen in the hack
“On April 1, 2026, we became aware of suspicious activity within our network,” the company said in a notice to victims. “Once identified, we took immediate steps to secure our network and engaged third-party specialists to assist in the containment of the activity and investigate the nature and scope of the activity.”
As a result of the investigation, Rockville learned threat actors accessed certain files on its network.
Reference: MD Concrete Maker Suffers Cyberattack
Victim: Rockville Fuel & Feed Co.
Rockville, Maryland-based concrete maker Rockville Fuel & Feed Co. operates as a manufacturer and supplier of ready-mix concrete for the Maryland suburbs of Washington D.C. While the company originally started in 1926 as a supplier of wood, coal, and farm feed, it evolved into a concrete producer.
Incident: Cyberattack at Engineering Company Othon
Houston, Texas-based engineering company, Othon, Inc., suffered a cyberattack in March where personally identifiable information ended up stolen in the hack.
“On March 12, 2026, Othon became aware of suspicious activity on certain computer systems in its network,” the company said in a notice to victims of the attack. “Othon acted promptly to secure its systems and launched a comprehensive investigation, with the assistance of third-party forensic specialists, to confirm the full nature and scope of the event.”
As a result of the investigation, the company found between March 11 and March 12 certain files within its network ended up accessed and/or downloaded without authorization.
Reference: Cyberattack At TX Engineering Firm
Victim: Othon, Inc.,
Houston, Texas-based engineering company, Othon is a multi-discipline civil engineering firm. The firm’s engineers and designers provided a full range of design services in roads and highways, bridges and structural engineering, high speed rail systems, pumping and drainage networks, airports, municipal infrastructure, intelligent transportation systems, construction management, and program management services for all levels of government agencies as well as private developers.
Incident: Engineering Firm, Asplundh Engineering Services Hit in Attack
Ambler, Pennsylvania-based Engineering company, Asplundh Engineering Services, LLC, suffered a cyberattack in January where personally identifiable information ended up stolen in the hack.
“On or around January 18, 2026, Asplundh Engineering identified suspicious activity on their computer network,” the company said in a notice to victims. “Upon becoming aware of this activity, Asplundh Engineering quickly took steps to secure the environment, with the assistance of third-party specialists, and launched an investigation into the nature and scope of the activity.”
The investigation found an unauthorized actor accessed their network at various times between January 11, 2026 and January 17, 2026 and, during that period, accessed and copied certain files and information from the network.
Reference: PA Engineering Firm Suffers Cyberattack
Victim: Asplundh Engineering Services, LLC,
Ambler, Pennsylvania-based Engineering company, Asplundh Engineering Services provides a engineering, design and testing services to transmission, distribution, substation and renewable infrastructure markets across the United States.
Incident: Engineering Firm MasTec Suffers Cyberattack
Coral Gables, Florida-based engineering firm, MasTec, Inc., suffered a cyberattack last August and is now letting victims know their personally identifiable information ended up stolen in the attack..
“In early October 2025, we received reports of suspicious activity in a small portion of our computer network,” the company said in a notice to its victims. “We promptly began working with third-party cybersecurity experts to investigate and remediate that activity.”
Later on that month, the company said the investigation found an unauthorized third party gained access to a small portion of our computer network for a few days in August 2025.
Reference: FL Engineering Firm Suffers Cyberattack
Victim: MasTec, Inc.
Coral Gables, Florida-based engineering firm, MasTec is a Fortune 500 infrastructure engineering and construction company. As the second-largest Hispanic-owned company in the United States, it employs over 20,000 workers across North America and specializes in building, installing, and maintaining complex energy, utility, and communications infrastructure.
Incident: Industrial Electrical Contractor, Johnson-Peltier Electric Attacked
Santa Fe Springs, California-based industrial electrical contracting provider, Johnson-Peltier Electric, Inc. suffered a cyberattack in March 2025 and it discovered one year later that personally identifiable information ended up stolen in the hack.
“On March 10, 2025, Johnson-Peltier detected suspicious activity related to certain systems within its environment,” the company said in a notice to victims. “We took steps to secure our environment and launched an investigation to determine the nature and scope of the incident.
Through its investigation ending on March 10, 2026, Johnson-Peltier determined an unauthorized actor gained access to its computer network and potentially copied a limited number of files.
Reference: Cyberattack At Industrial Electrical Contractor
Victim: Johnson-Peltier Electric, Inc.
Santa Fe Springs, California-based industrial electrical contracting provider, Johnson-Peltier Electric is a certified Indian Economic Enterprise (IEE), Minority Business Enterprise (MBE) and Small Business Enterprise for Public Works (SB-PW), specializing in full-service industrial electrical contracting, including services such as: Power distribution, medium and low voltage line work, critical power infrastructure, power controls, programable logic controls, instrumentation, communication integration, alternative energies and energy storage installations.
Incident: Equipment Provider, C.N. Wood Suffers Cyberattack
Woburn, Massachusetts-based equipment provider, C.N. Wood Co. Inc., suffered a cyberattack in August last year and is now letting victims know their personally identifiable information ended up stolen in the hack.
“C.N. Wood recently experienced unauthorized access to its network environment,” then a company said in a notice to victims. “Upon learning of this issue, we contained the threat and immediately commenced a prompt and thorough investigation.
As part of its investigation, the company began working very closely with external cybersecurity professionals experienced in handling these types of incidents.
“Following a thorough forensic investigation and extensive manual document review, we discovered on May 6, 2026, that the files that were potentially accessed or acquired by an unauthorized third-party actor on August 16, 2025, contained some of your personal information,” the company said.
Reference: Cyberattack At MA Equipment Provider
Victim: C.N. Wood Co. Inc.
Woburn, Massachusetts-based equipment provider, C.N. Wood has nine locations throughout Massachusetts, Connecticut, Rhode Island New York and Maine. Established by Bob Benard 60 years ago, C.N. Wood sells, rents and supports construction and environmental equipment.
Incident: Cyberattack at Seafood Processor, Lusamerica Foods
Morgan Hill, California-based seafood processor, Lusamerica Foods, suffered a cyberattack in February where personally identifiable information ended up stolen during the hack.
“Upon learning of this issue, Lusamerca Foods immediately commenced a thorough investigation,” the company said in a notice to victims of the attack. “As part of its investigation, Lusamerica Foods has been working very closely with external cybersecurity professionals experienced in handling these types of incidents.”
After the company conducted an extensive forensic investigation and comprehensive data review, on April 22, Lusamerica Foods discovered certain files containing personal information may have been subject to unauthorized access or acquisition.
Reference: Seafood Processor Suffers Cyberattack
Victim: Lusamerica Foods
Morgan Hill, California-based seafood processor, Lusamerica Foods is a manufacturer, specifically operating as a primary and secondary seafood processor, wholesaler, and distributor. Founded in 1975, the company processes over 100 species of domestic and imported seafood for grocery retailers, restaurants, and foodservice operators across the U.S. West Coast. The company provides product packaging solutions among other services.
Incident: Furniture Maker Nickey Kehoe Hit in Cyberattack
Los Angeles, California-based furniture manufacturer Nickey Kehoe suffered a cyberattack in March where personally identifiable information ended up stolen in the hack.
“On March 29, 2026, we identified an unauthorized email sent through our email service provider, Klaviyo, as well as an export event that included receipt of the customer information stored in Klaviyo’s system,” the company said in a notice to victims. “Within 24 hours of the event, we had removed the compromised access credentials, and improved the security protocols and processes associated with accessing the system.”
Following these updates, the company said it did not identify any further attempts to access the information stored by Klaviyo, nor any unauthorized access with any other Nickey Kehoe systems.
Reference: Furniture Maker Suffers Cyberattack
Victim: Nickey Kehoe
Los Angeles, California-based furniture manufacturer Nickey Kehoe is a Los Angeles-based interior design studio, retail brand, and bespoke furniture manufacturer. Founded in 2004 by Todd Nickey and Amy Kehoe, the company designs and produces a signature line of custom furniture, lighting, and home accessories.
Incident: Textile Maker Texollini Suffers Cyberattack
Long Beach, California-based textile manufacturer, Texollini, suffered a cyberattack in February where personally identifiable information ended up stolen in the hack.
“Texollini recently learned of anomalous activity within our environment,” the company said in a notice to victims. “We immediately launched an investigation, with the assistance of third-party forensic specialists, to determine the nature and scope of the activity.”
The company’s investigation determined its environment was subject to unauthorized access from February 16 to February 18, and certain files ended up accessed by the unauthorized actor.
Reference: Textile Manufacturer Hit In Cyberattack
Victim: Texollini
Long Beach, California-based textile manufacturer, Texollini is Long Beach, CA-based textile manufacturer and has one of the largest circular knitting mills in America. Founded in 1989, the company specializes in producing innovative, stretch-and-performance fabrics.
Incident: Cyberattack at Specialty Building Materials Maker Perma-Chink Systems
Redmond, Washington-based specialty building materials company Perma-Chink Systems, Inc. suffered a cyberattack in April where personally identifiable information ended up stolen in the hack.
“On or about May 7, 2026, we identified unauthorized activity on our network,” the company said in a notice to victims of the attack. “Once identified, we quickly engaged third-party specialists to assist us with determining the nature and scope of the activity and conducting an investigation.
During the investigation, the company found certain files ended up potentially copied from its internal network.
Reference: Coatings Provider Hit In Cyberattack
Victim: Perma-Chink Systems, Inc.
Redmond, Washington-based specialty building materials company Perma-Chink Systems is a specialty building materials company. Furthermore, it is also a supplier of coatings and sealants to the log and timber frame home industry.
Incident: Cyberattack at Food Maker Rich Products
Buffalo, New York-based food manufacturer, Rich Products Corporation, suffered a cyberattack via a phishing email last November where personally identifiable information ended up stolen in the hack.
“On November 17, 2025, First Advantage became aware that an unauthorized third party obtained access through sophisticated phishing to a single First Advantage Drug & Occupational Health Screening Unit employee’s account, according to a notice from Rich Products. “First Advantage promptly launched an investigation and determined that the unauthorized third party gained access on or about November 13, 2025.”
The cybersecurity incident originated at First Advantage Corporation, a background screening and identity verification provider that conducts over 200 million screens annually. Rich Products works with First Advantage.
Reference: Phishing Attack Affects Food Manufacturer
Victim: Rich Products Corporation
Buffalo, New York-based food manufacturer, Rich Products is a global, family-owned food manufacturer. Best known for inventing the world’s first non-dairy whipped topping in 1945, it produces over 2,000 items for the foodservice, in-store bakery, deli, and retail sectors.
Incident: Transportation Provider Barnhart Crane & Rigging Hit in Cyberattack
Memphis, Tennessee-based lifting, rigging, and transportation provider Barnhart Crane & Rigging Company, Inc. suffered a cyberattack last April and is now informing victims of the attack.
“On or about April 23, 2025, Barnhart detected unauthorized access to its network occurring between on or about April 23, 2025, and April 24, 2025,” according to a notice sent to victims of the attack. “Upon learning of this issue, Barnhart immediately commenced a prompt and thorough investigation.”
As part of its investigation, the company started working with external cybersecurity professionals experienced in handling these types of incidents.
Reference: Cyberattack At Industrial Transportation Provider
Victim: Barnhart Crane & Rigging Company, Inc.
Memphis, Tennessee-based lifting, rigging, and transportation provider Barnhart Crane & Rigging is a provider of lifting, rigging, and transportation solutions.
Incident: Cyberattack at Wellness Product Maker, Perrigo
Allegan, Michigan-based health and wellness product provider, Perrigo Company, suffered a cyberattack in March where personally identifiable information ended up stolen in the hack.
“On March 4, 2026, Perrigo detected a cybersecurity incident targeting two employee email accounts,” the company said in a notice to victims. “Upon learning of the incident, we immediately contained and remediated the unauthorized access that same day.”
As a result of the attack, the company launched an investigation with the assistance of third-party forensic specialists to determine the nature and scope of the unauthorized access. It also notified law enforcement.
Reference: Wellness Product Maker Suffers Cyberattack
Victim: Perrigo Company
Allegan, Michigan-based health and wellness product provider, Perrigo Company is a global consumer self-care company that manufactures and sells over-the-counter (OTC) health and wellness products, infant formulas, and generic pharmaceuticals. The company produces “store brand” items for major retailers, alongside their own branded products like Opill, Compeed, and Nytol.
Incident: Cyberattack at Precision Metal Parts Maker, Bomco
Gloucester, Massachusetts-based precision metal component provider, Bomco, Inc. suffered a cyberattack in June last year and is now informing victims their personally identifiable information ended up stolen in the hack.
“On June 17, 2025, Bomco became aware that certain files in its network ended up accessed by an unauthorized actor,” the company said in a notice to victims. “Bomco promptly launched an investigation to determine the nature and scope of this incident.”
As a result of the investigation, the company determined an unauthorized actor gained access to certain files within Bomco’s network from June 14, 2025 to June 16, 2025, and may have copied those files.
Reference: Cyberattack At Precision Metal Parts Maker
Victim: Bomco, Inc.
Gloucester, Massachusetts-based precision metal component provider, Bomco produces precision formed metal components for jet engines, industrial gas turbines and land and marine turbines.
Incident: Energy Supplier, Eversource Energy Suffered Phishing Attack
Westwood, Massachusetts-based energy supplier, Eversource Energy suffered a phishing cyberattack in April where personally identifiable information ended up stolen in the hack.
“In April of 2026, Eversource was a victim of a cybercriminal phishing campaign that resulted in unauthorized use of the credentials of two employees to access a limited number of files, some of which contained customer information,” said a notice sent to victims of the attack. “Eversource immediately blocked activities by this hacker group and implemented additional security measures in response to this incident to further strengthen our cybersecurity systems.”
Eversource said it quickly started up an investigation with the assistance of external experts to review the data contained in the files accessed.
Reference: Energy Provider Hit In Phishing Attack
Incident: Chain Manufacturer, pewag Suffers Cyberattack
Bolingbrook, Illinois-based U.S. headquarters for chain manufacturer, pewag, Inc., suffered a cyberattack in March, where personally identifiable information ended up stolen in the hack.
“On or about April 8, 2026, we became aware of unusual activity in our digital environment,” the company said in a letter to victims. “Upon becoming aware, we promptly began an investigation into the scope and nature of the suspicious activity and retained experts to investigate the unusual activity.”
As a result of the investigation into the hack that occurred March 30, the company found certain information ended up copied by an unauthorized individual.
Reference: Cyberattack At Chain Manufacturer
Victim: pewag, Inc.
Bolingbrook, Illinois-based U.S. headquarters for chain manufacturer, pewag was founded in Brückl, Austria in 1479. Pewag is manufacturer of high-performance chains and components. The company makes industrial chains, traction chains, lifting solutions, and tire protection chains. Since 1975, pewag has served the U.S. and Canadian markets from its North American headquarters.
Incident: Fluke Suffered Third-Party Cyberattack
Everett, Washington-based test, measurement, and diagnostic equipment maker Fluke Corporation suffered a cyberattack as a result of a vulnerability in a third-party application.
“We are writing to inform you that a criminal actor detected and exploited a vulnerability within an established third-party business application, which resulted in a data security incident at Fluke Corporation,” the company said in a notice to victims. “The incident involved your personal information, and this letter provides details about what happened, what information of yours may have been involved, what we are doing in response, and what resources are available to you.”
“On September 29, 2025, we learned that a criminal actor exploited a vulnerability in a third-party application used by us and was able to access a limited segment of our network,” the company said in a notice to the 18,517 victims of the attack. “This vulnerability also impacted various other companies that use the same software across different industries.”
Reference: Third-Party Hole Leads To Fluke Attack
Victim: Fluke Corporation
Fluke is an American manufacturer of industrial test, measurement, and diagnostic equipment, including electronic test tools and software. Headquartered in Everett, WA, the company ended up acquired by Danaher Corporation in 1998, then spun off to Fortive, Inc. in 2016.
Incident: Safety Provider, Carlysle Engineering Hit in Ransomware Attack
Norwood, Massachusetts-based fire protection safety provider, Carlysle Engineering, Inc., suffered a ransomware attack in March where personally identifiable information from employees ended up exfiltrated.
“We have discovered that Carlysle Engineering, Inc. was the victim of a ransomware attack,” the company said in a notice to victims. “The attack affected our human resources data, and some of that data may have included some of the personal information we maintain about you as a current or former Carlysle employee or named beneficiary of a current or former Carlysle employee.”
On March 23, 2026, Carlysle discovered a threat actor launched an attack on Carlysle’s primary file server, which encrypted the files on the server. Upon discovery of the attack, Carlysle’s information technology administrator immediately engaged OCD Tech, LLC, a well-known cybersecurity recovery and investigation firm, and cybersecurity legal counsel to investigate the incident and coordinate efforts with our IT administrator.
Threat Actor: Payload
Payload ransomware group is a highly active, financially motivated threat actor that first emerged in February 2026. Operating primarily on a double-extortion model, they encrypt enterprise data and exfiltrate sensitive files, threatening to publish them on their dedicated Tor leak sites if the ransom is not paid.
Malware: Ransomware
Ransomware attack by the Payload ransomware group.
Reference: Fire Protection Provider Hit By Ransomware
Victim: Carlysle Engineering
Norwood, Massachusetts-based fire protection safety provider, Carlysle Engineering is a fire protection contractor that specializes in the design, fabrication, and installation of fire suppression systems. The company provides comprehensive fire safety services to commercial, industrial, and residential sectors throughout New England.
Incident: Ransomware Attack at Aerospace Manufacturer, Extant Aerospace
Melbourne, Florida-based aerospace manufacturer, Extant Aerospace, suffered a ransomware attack in August last year and is now informing victims of the attack.
“On or around August 23, 2025, Extant detected ransomware activity affecting a portion of its network environment,” the company said in a notice to victims. “Upon discovery, Extant promptly took containment steps and notified federal law enforcement.”
Following its investigation, Extant (Symetrics Industries, LLC is the parent company) determined an unauthorized actor accessed certain systems and stole personal information of some current and former employees and other individuals.
Reference: Government Aerospace Manufacturer Hit By Ransomware
Victim: Extant Aerospace
Melbourne, Florida-based aerospace manufacturer, Extant Aerospace manufactures and supplies complex electronic assemblies to the Department of Defense and international customers for military and commercial applications. The company offers digital communications solutions including a full line of Improved Data Modems (IDM) in various hardware form factors with optional imagery transmission capabilities, or as software-only versions; imagery solutions with a TVDS/DVR (Tactical Video Data Server/Digital Video Recorder); and an Electronic Warfare (EW) product line highlighted by the AN/ALE-47(V) Countermeasures Dispenser System (CMDS).
Incident: Cyberattack at Engineering Firm Lamb-Star Engineering
Frisco, Texas-based engineering firm Lamb-Star Engineering, LLC, suffered a cyberattack in January and is now letting victim know their personally identifiable information ended up stolen in the hack.
“On or about January 20, 2026, Lamb-Star detected suspicious activity on its system,” the company said in a notice to victims. “Upon discovery of this incident, Lamb-Star immediately disconnected the affected systems and remote access to the network.”
The company then hired a specialized third-party cybersecurity firm and IT personnel to assist with securing the environment, as well as to conduct a comprehensive forensic investigation to determine the nature and scope of the incident.
Reference: Engineering Firm Suffers Cyberattack
Victim: Lamb-Star Engineering
Frisco, Texas-based engineering firm Lamb-Star Engineering is a Native American-owned civil engineering firm. Furthermore, Lamb-Star serves numerous state departments of transportation, regional toll authorities, municipal governments, and contractors and developers.
Incident: Taiwan’s High-Speed Railway, THSR, Shut Down
Four trains in Taiwan ended up stopped for 48 minutes last month by an attacker using software-defined radio (SDR) communications and handheld radios to transmit a high-priority “General Alarm” signal. That signal triggered emergency braking procedures.
As a result of that incident, a 23-year-old university student in Taiwan is now under arrest suspected of interfering with the TETRA communication system April 5 used by the country’s high-speed railway network (THSR).
THSR is a high-speed railway network in Taiwan that runs a single 350 km (217 miles) two-way line along the western coast of the country, with trains reaching speeds of up to 186 mph (300 km/h).
Reference: Student Busted For Taiwan High-Speed Rail Hack
Victim: TETRA communication system
TETRA communication system used by Taiwan's high-speed railway network (THSR).
Incident: Flooring Manufacturer, New Congoleum Attacked
Mercerville, New Jersey-based flooring manufacturer, New Congol LLC dba New Congoleum, suffered a cyberattack in March where personally identifiable information ended up stolen in the hack.
“On March 24, 2026, we discovered unusual activity in our network and immediately began investigating the matter,” New Congoleum said in a notice to victims. “We also engaged independent cybersecurity experts to assist with the process of ensuring our network was secure and identifying whether any personal information was involved.”
New Congoleum’s investigation determined attackers stole personal information involved in the incident.
Reference: NJ Flooring Maker Hit In Cyberattack
Victim: New Congoleum
Mercerville, New Jersey-based flooring manufacturer, New Congol LLC dba New Congoleum is a subsidiary of Beaulieu International Group. Following its acquisition of Congoleum Acquisition LLC assets in November 2025, it operates as a U.S.-based producer of resilient flooring, continuing the brand’s manufacturing legacy in Pennsylvania and Maryland.
Incident: Transportation Provider, Hogan Transports Suffers Cyberattack
St. Louis, Missouri-based transportation provider, Blue Enterprises, Inc. dba Hogan Transports, Inc., suffered a cyberattack in October where personally identifiable information ended up stolen in the hack.
“On or around November 29, 2025, Hogan became aware of unusual activity on certain systems in its network and promptly took steps to contain the activity and launched an investigation, with the support of third-party cybersecurity specialists,” the company said in a notice to victims. “The investigation determined that the network was accessed without authorization at various periods of time between October 25, 2025, and November 29, 2025, and certain files ended up accessed or copied.”
Following the investigation, Hogan conducted a comprehensive review of the data stored on the affected systems to determine what data the attacker stole and to whom the information belongs. This review concluded March 31.
Reference: Cyberattack At Transportation Provider
Victim: Hogan Transports, Inc.
St. Louis, Missouri-based transportation provider, Blue Enterprises, Inc. dba Hogan Transports is a comprehensive transportation and logistics company. It offers truckload services, full-service leasing, commercial truck rentals, and fleet maintenance. It has a fleet exceeding 10,000 pieces of equipment.
Incident: Polish Water Treatment Plants Breached
While it happened last year and it is now coming to light, attackers breached water treatment facilities in five towns in Poland over a period of time where the threat actors were able to gain access to industrial control systems in some cases.
In a public report, Poland’s Internal Security Agency (ABW) said water treatment stations in Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko and Sierakowo ended up targeted in the attacks.
“Attackers, gaining access in some cases to industrial control systems, had the ability to alter technical parameters of devices,” the report said after translation into English. While it didn’t, and not to over hype the issue, the threat actors had the opportunity to establish a risk to the water supply operations.
ABW did not publicly attribute the incidents to a specific group or country, according to the report. It did say, however, Poland faced intensified cyber activity in 2024 and 2025, “with particular emphasis on the special services of the Russian Federation,” according to a report in The Record.
Reference: Polish intelligence warns hackers attacked water treatment control systems
Reference: Attacks On Water Plants In Poland
Victim: 5 Water Plants in Poland
Water treatment facilities in five towns in Poland suffered attacks over a period of time where the threat actors were able to gain access to industrial control systems in some cases. In a public report, Poland’s Internal Security Agency (ABW) said water treatment stations in Jabłonna Lacka, Szczytno, Małdyty, Tolkmicko and Sierakowo ended up targeted in the attacks.
Incident: Ransomware Attack at Electronics Manufacturer Foxconn
North American factories at electronics manufacturer Foxconn are now resuming normal operations after a reported ransomware attack earlier this week.
In a statement sent to media outlets, a Foxconn spokesperson said the cyberattack affected facilities in North America and “the affected factories are currently resuming normal production.”
The Nitrogen ransomware operation earlier this week said it stole 8 TB of data and more than 11 million documents. On its dark web leak site, Nitrogen said the stolen files contain “confidential instructions, projects and drawings” from Apple, Intel, Google, Nvidia, AMD, and other Foxconn customers.
The breach primarily impacted Foxconn's plants in Mount Pleasant, Wisconsin, and Houston, Texas, resulting in widespread IT outages, a temporary shift to paper-based workflows, and a pause in production. Foxconn responded by isolating the affected systems and shifting to manual operational measures to restore production. The incident has sparked significant supply-chain concerns due to the volume of intellectual property exposed.
Reference: Foxconn Resuming Operations After Ransomware Attack
Threat Actor: Nitrogen
Nitrogen is a highly capable double-extortion ransomware and initial-access group active since late 2024. Operating primarily in the USA, Canada, and UK, they target high-value targets across manufacturing, technology, and finance. Their malware uses advanced evasion and carries a bug that renders decryption mathematically impossible.
Incident: ACME Truck Line Hit in Cyberattack
Gretna, Louisiana-based transportation provider, ACME Truck Line, Inc. suffered a cyberattack in February and is letting victims know their personally identifiable information ended up stolen in the hack.
“On February 19, 2026, ACME discovered that an unauthorized third party gained access to certain computer systems maintained by ACME,” the company said in a notice to victims. “The cyberattack ended up carried out by an unauthorized person who exploited vulnerabilities in third-party security services and software used to protect ACME’s network.”
The third-party vendor retained to monitor ACME’s network for threats of this kind did not identify or escalate indicators of the attack before it ended up executed, the company said.
Reference: Oilfield Carrier Suffers Cyberattack
Victim: ACME Truck Line, Inc.
Gretna, Louisiana-based transportation provider, ACME Truck Line transports equipment, materials, and supplies throughout the United States. Additionally, ACME is the largest oilfield carrier in America. This is a 100 percent owner/operator fleet comprised of over 2,000 trucks.
Incident: Transportation Provider, Empire Express, Suffers Cyberattack
Memphis, Tennessee-based transportation provider, Empire Express, suffered a cyberattack June last year and is now informing victims of the attack their personally identifiable information ended up stolen in the hack.
“On or about October 23, 2025, we learned that an unauthorized individual may have gained access to our network,” the company said in an advisory to victims. “Upon learning of this issue, we immediately commenced a prompt and thorough investigation.”
As part of its investigation, Empire Express has been working very closely with external cybersecurity professionals experienced in handling these types of incidents.
The company conducted an extensive forensic investigation and comprehensive document review. As a result, Empire Express said it found on April 13 this year threat actors were able to steal certain files containing personal information between June 27, 2025, and October 23, 2025.
Reference: Transportation Provider Hit In Cyberattack
Victim: Empire Express
Memphis, Tennessee-based transportation provider, Empire Express is a carrier in the trucking industry. Additionally, the company serves 48 states and handles cargos that require time or safety-sensitive handling. At least 35 percent of the loads end up being packaged chemicals and related products (agricultural chemicals and poisons, paint-related materials and styrene’s, polymers and other chemicals used by the chemical process industry). Other products hauled are clothing and apperal, air cargo, home and office products, packaging and containers, paper products, retail, electronics, cotton and general commodities.
Incident: Cyberattack at TX Product Provider, NCH Corp.
Irving, Texas-based maintenance, repair, and overhaul (MRO) product provider, NCH Corporation, suffered a cyberattack in January where its employees fell victim to a hack involving their personally identifiable information.
“On March 9, 2026, NCH Corporation became aware that an unauthorized actor may have taken files from its network,” the company said in a notice to victims. “NCH immediately implemented its response procedures, took containment measures, and launched an investigation with the support of third-party cybersecurity professionals.”
Additionally, NCH also notified law enforcement and is supporting its investigation.
As a result of its investigation, the evidence showed there was unauthorized activity in NCH’s network between January 21 and February 25. During that time, an unauthorized actor obtained copies of certain files from NCH’s network.
Reference: Cyberattack At Chemical Product Maker
Victim: NCH Corporation
Irving, Texas-based maintenance, repair, and overhaul (MRO) product provider, NCH Corporation is a manufacturer and global provider of industrial maintenance, repair, and overhaul (MRO) products. Founded in 1919, the company produces their own chemical, lubricant, and water treatment solutions in-house, operating 24 manufacturing plants worldwide.
Incident: Chemical Provider, Diamond Chemical Hit in Cyberattack
East Rutherford, New Jersey-based chemical provider, Diamond Chemical Co, LLC suffered a cyberattack last July and is now informing victims their personally identifiable information ended up stolen in the hack.
“On or about September 2, 2025, Diamond Chemical discovered suspicious activity on certain systems in our environment that led to a temporary network disruption,” the company said in a notice to victims. “In response, Diamond Chemical promptly began an investigation with the assistance of third-party specialists to determine what occurred.
In the ensuing investigation, the company found an unauthorized actor accessed certain systems between July 26, 2025, and September 2, 2025, and copied files without permission.
Reference: Cyberattack At NJ Chemical Maker
Victim: Diamond Chemical Co, LLC
East Rutherford, New Jersey-based chemical provider, Diamond Chemical is a national manufacturer of laundry, warewash, housekeeping, sanitizing, and other institutional and industrial products. Through its line of products, programs and services, Diamond Chemical serves and supports most industries that requires cleaning and/or sanitizing including: Laundry, foodservice, janitorial, sanitary maintenance, and healthcare sectors, among others.
Incident: Universal Pure Hit in Cyberattack
Lincoln, Nebraska-based service provider, Universal Pure, LLC, suffered a cyberattack in July of 2024, discovered it in August of 2025, and is now letting victims know their personally identifiable information ended up stolen in the hack.
“On August 20, 2024, Universal Pure identified suspicious activity within certain computer systems,” the company said in a notice to victims. “Universal Pure quickly took steps to secure its network and launched an investigation into the nature and scope of the activity.”
Through this investigation, Universal Pure determined that certain computer systems were subject to unauthorized access and files ended up taken from the Universal Pure network on separate occasions between July 10, 2024 and August 20, 2024.
Reference: 2 Years After Attack, Firm Informs Victims
Victim: Universal Pure, LLC,
Lincoln, Nebraska-based service provider, Universal Pure is a service provider specializing in High-Pressure Processing (HPP) and related food safety services. They act as a partner to food and beverage manufacturers, offering HPP, cold storage, labeling, and packaging.
Incident: Cyberattack at Cheese Processor, Murray’s Cheese
New York, New York-based cheese processor, Murray’s Cheese LLC, suffered a ransomware attack in February where devices became unavailable.
“On February 21, 2026, Murray’s Cheese LLC detected unusual activity within its network that caused certain devices to become unavailable,” the company said in a notice to victims. “Murray’s immediately implemented its response protocols, took measures to contain the activity, and launched an investigation.”
Additionally, a cybersecurity firm that has assisted other companies in similar situations also ended up hired. The evidence showed there was unauthorized activity within the Murray’s network between February 15 and February 21.
Malware: Ransomware
Suffered a ransomware and data breach attack linked to the Akira ransomware group.
Reference: Cheese Maker’s Worker Health Plan Info Stolen
Victim: Murray’s Cheese LLC
New York, New York-based cheese processor, Murray’s Cheese, which is a subsidiary of Kroger, is a manufacturer, specifically through its specialized aging and affinage process in Long Island City, where it transforms raw cheeses into finished products. Also, a retailer, wholesaler, and premier importer, Murray’s also cures and ages cheese in their own caves, acting as a producer rather than just a reseller.
Incident: Sagent Pharmaceuticals Suffers Cyberattack
Schaumburg, Illinois-based Sagent Pharmaceuticals suffered a cyberattack in February where personally identifiable information ended up stolen in the hack.
“We recently discovered unauthorized access to our network occurred on or around February 11, 2026,” the company said in a notice to victims. “We immediately launched an investigation in consultation with outside cybersecurity professionals who regularly investigate and analyze these types of situations to analyze the extent of any compromise of the information on our network.”
Sagent Pharmaceuticals’ investigation and document review concluded on March 23. They discovered attackers were able to steal victims’ full name, Social Security number, driver’s license number or state identification number. Additionally, they took bank account information, and/or health insurance policy information.
Reference: Pharmaceutical Firm Suffers Cyberattack
Victim: Sagent Pharmaceuticals
Schaumburg, Illinois-based Sagent Pharmaceuticals is a provider of pharmaceuticals. Sagent’s extensive product portfolio covers a diverse therapeutic categories and packaging configurations including eye drops, vials, syringes, and premix bags.
Incident: Cyberattack at Utility Technology Provider, Itron
Liberty Lake, Washington-based utility technology provider, Itron Inc., suffered a cyberattack earlier this month and is continuing its investigation into the hack.
“On April 13, 2026, Itron, Inc. ended up notified that an unauthorized third party had gained access to certain of its systems,” the company said in an 8-K report to the Securities and Exchange Commission (SEC). “The company activated its cybersecurity response plan and launched an investigation with the support of external advisors to assess, mitigate, remediate, and contain the unauthorized activity.”
Additionally, the company’s response efforts included proactively notifying law enforcement.
Reference: Utility Technology Provider Hit In Cyberattack
Victim: Itron Inc.
Liberty Lake, Washington-based utility technology provider, Itron is a public technology company that provides smart, industrial IoT (IIoT) solutions, software, and advanced metering infrastructure for electricity, gas, and water utilities. Itron enables utilities to manage energy/water, improve efficiency, and enhance grid reliability via smart meters and data analytics.
Incident: Cloud App Host Vercel Suffers Cyberattack
Cloud app host Vercel Inc. suffered a cyberattack in April involving unauthorized access to its systems, affecting “a limited subset of customers.”
“We’ve identified a security incident that involved unauthorized access to certain internal Vercel systems,” the company said in an advisory. “We are actively investigating, and we have engaged incident response experts to help investigate and remediate. We have notified law enforcement and will update this page as the investigation progresses.
Vercel is a cloud application company. It created and maintains the Next.js web development framework. Vercel provides developer tools, frameworks, and cloud infrastructure to build and maintain websites.
Reference: Cyberattack At Cloud App Host
Victim: Vercel Inc.
San Francisco, California-based Vercel is a cloud application company. It created and maintains the Next.js web development framework. Vercel provides developer tools, frameworks, and cloud infrastructure to build and maintain websites.
Incident: Cyberattack at Clothing Maker Revolution Dancewear
Niles, Illinois-based clothing manufacturer and retailer Up Brands, LLC doing business as Revolution Dancewear suffered a cyberattack in March last year where personally identifiable information ended up stolen in the hack and they are just now informing victims of the attack.
“Revolution Dancewear learned that an unauthorized party gained access to a limited number of Revolution Dancewear internal systems from on or about March 16, 2025, to on or about April 3, 2025.”
Upon learning of this attack, Revolution Dancewear immediately launched an investigation and contained and secured the Revolution Dancewear network environment.
Reference: Clothing Maker Suffers Cyberattack
Victim: Up Brands, LLC doing business as Revolution Dancewear
Niles, Illinois-based clothing manufacturer and retailer Up Brands, LLC doing business as Revolution Dancewear is a manufacturer and retailer of dancewear. It specializes in costumes, footwear, and apparel. The company designs, produces, and sells these products directly to dance studios and educators, focusing on studio-exclusive partnerships.
Incident: Coal Mining Processor, Drummond Company Suffers Cyberattack
Birmingham, Alabama-based coal mining processor, Drummond Company, Inc., suffered a cyberattack in February where personally identifiable information ended up stolen in a business email compromise.
“On February 23, 2026, we determined an unauthorized third party had gained access to the email account of a Drummond employee,” the company said in a notice to victims. “We immediately engaged outside cybersecurity experts to investigate.”
As part of its investigation, Drummond determined files within the employee’s email account may have ended up stolen by the unauthorized access. The company conducted an in-depth review of the email account to understand what information the threat actors may have stolen. Drummond just learned that some of these files include personal identifying information.
Reference: Coal Processor Hit In Cyberattack
Victim: Drummond Company, Inc.
Birmingham, Alabama-based coal mining processor, Drummond Company is a privately-owned company involved in the mining and processing of coal and coal products as well as oil and real estate.
Incident: Manufacturing Designer David Evans Enterprises Hit in Cyberattack
Portland, Oregon-based manufacturing design and management provider David Evans Enterprises, Inc. suffered a cyberattack in February where personally identifiable information ended up stolen in the hack.
“On February 26, 2026, we detected potentially suspicious activity on a limited portion of our computer network,” the company said in a notice to victims. “In response, we immediately began an investigation with the assistance of third-party specialists.”
During the e investigation, David Evans found threat actors gained access to certain files without authorization between February 26 and February 27.
Reference: Cyberattack At Industry Designer
Victim: David Evans Enterprises, Inc.
Portland, Oregon-based manufacturing design and management provider David Evans Enterprises started up in 1976 and is a provider of progressive and sustainable design and management solutions for complex transportation, land development, energy, and water projects nationwide.
Reference: Metal Maker, Distributor Hit In Cyberattack
Incident: Cyberattack at Metal Maker, Distributor, Kloeckner Metals
Alpharetta, Georgia-based metal maker and distributor, Kloeckner Metals Corporation, suffered a cyberattack in February where personally identifiable information ended up stolen in the hack.
“On February 23, 2026, Kloeckner identified unusual activity within their network,” the company said in a notice to victims. “Upon identifying the activity, steps were immediately taken to secure the network and an investigation commenced.”
Kloeckner hired a cybersecurity firm that has assisted other companies in addressing similar situations. To that end, the investigation determined there was unauthorized access to the network between February 17 and February 23. That is when attackers took copies of certain files.
Victim: Kloeckner Metals Corporation
Alpharetta, Georgia-based metal maker and distributor, Kloeckner Metals Corporation is primarily steel service center and metal distributor that also performs extensive manufacturing services and fabrication. The company functions as a metal processor and manufacturer by offering services like laser cutting, stamping, and welding to create finished parts.
Incident: Drilling Provider SDI Management Cyberattack
Mt Morris, Pennsylvania-based gas facility and drilling provider SDI Management LLC (SDIM) suffered a cyberattack in February where personally identifiable information ended up stolen in the hack.
“SDI Management detected a network compromise that could have impacted your personal information,” the company said in a notice to victims. “We have no indication that your information has been or will be misused.”
“SDIM identified and responded to unauthorized network activity on February 25, 2026,” the company said. “We immediately secured and remediated the compromise, engaged additional third-party experts, and commenced an investigation.”
Reference: Cyberattack At Gas Facility, Drilling Provider
Victim: SDI Management LLC
Mt Morris, Pennsylvania-based SDI Management builds gas transmission facilities as well as operates a fleet of horizontal directional drilling rigs.
Incident: Manufacturing Distributor, Shingle & Gibb Automation Hit in Cyberattack
Moorestown, New Jersey-based manufacturing industry distributor, Shingle & Gibb Automation, LLC suffered a cyberattack in November and is now letting victims know their personally identifiable information ended up stolen in the hack.
“On November 12, 2025, we detected suspicious activity within Shingle’s computer network,” the company said in a notice to victims of the attack. “Upon discovering the incident, we promptly began an internal investigation and worked to secure our network.”
Additionally, Shingle also hired a forensic security firm to assist with its investigation and ensure the security of its network. As a result of the forensic investigation, Shingle determined an unauthorized third party accessed our network, and may have acquired certain files from those systems on November 12.
Reference: Industrial Distributor Suffers Cyberattack
Victim: Shingle & Gibb Automation, LLC
Moorestown, New Jersey-based Shingle & Gibb Automation provides industrial automation and networking, motion control, machine safety and power transmission products from manufacturers, including Banner Engineering, Turck and Siemens. The company provides additional services with locations in NJ, NY, VA and FL.
Incident: Cyberattack at Metal Roll Forming Maker, Hygrade Metal Moulding Manufacturing
Bethlehem, Pennsylvania-based metal roll forming maker Hygrade Metal Moulding Manufacturing Corp. suffered a cyberattack in July last year where personally identifiable information ended up stolen from victims in the hack.
“Hygrade observed unauthorized access to our network,” the company said in a notice to victims. “Upon learning of the issue, we immediately secured our network and commenced a prompt and thorough investigation.”
As part of its investigation, Hygrade said it worked closely with external cybersecurity professionals experienced in handling these types of incidents.
Additionally, following the completion of its investigation, on March 13, the company learned between July 25 and July 27 certain files containing a limited amount of your personal information may have been subject to unauthorized access and/or acquisition.
Reference: Cyberattack At PA Metal Rolling Maker
Victim: Hygrade Metal Moulding Manufacturing Corp.
Hygrade Metal Moulding Manufacturing Corp., Hygrade Components, ended up founded in 1939 and has a long history of supporting needs for aluminum and steel roll-formed products throughout the U.S. Hygrade has three manufacturing facilities located across the country and an expansive on-site inventory of tooling coupled with the ability to design and create additional tooling.
Incident: Millwork Manufacturer, Master Millwork Hit in Cyberattack
West Wareham, Massachusetts-based millwork manufacturer, Master Millwork, LLC suffered a cyberattack in February affecting victims’ personally identifiable information.
“On February 4, 2026, Master Millwork discovered suspicious activity on its network and immediately began an investigation,” said a notice the company sent out to victims. “The investigation determined there was unauthorized access to certain information between February 1, 2026 and February 5, 2026.”
To that end, Master Millwork conducted a review to determine the types of information potentially affected and to whom it belonged. Just over one month later, on March 13, Master Millwork completed its review.
Reference: Millwork Manufacturer Hit In Cyberattack
Victim: Master Millwork, LLC
West Wareham, Massachusetts-based Master Millwork is a manufacturer specializing in custom architectural millwork, high-end case goods, and cabinetry. Additionally, the company operates a solar-powered manufacturing facility, offering services from design and engineering to production and installation, primarily for commercial projects throughout New England.
Incident: Cyberattack at Estes Forwarding Worldwide
Richmond, Virginia-based transportation provider, Estes Forwarding Worldwide (EFW), suffered a cyberattack last May and is now letting victims know their personally identifiable information ended up stolen in the hack.
EFW said it ended up alerted to unauthorized access to its network.
“Upon learning of this issue, we contained the threat and immediately commenced a prompt and thorough investigation,” the company said in a notice to victims. “As part of our investigation, we have been working very closely with external cybersecurity professionals experienced in handling these types of incidents.”
Reference: Transportation Provider Suffers Cyberattack
Victim: Estes Forwarding Worldwide
EFW is a domestic and international freight forwarder, providing customized logistics solutions for clients around the world and across all industries including retail, government, automotive, health services, technology, and exhibit services via air, ground, and ocean freight.
Incident: Cyberattack at Chemical & Industrial Engineering
Louisville, Kentucky-based engineering firm, Chemical & Industrial Engineering Inc. (C&I) , suffered a cyberattack last June and is now letting victims know their personally identifiable information ended up stolen in the hack.
“In early August 2025, we detected suspicious activity in a portion of our computer network,” the company said in a letter to victims. “We promptly began working with third-party cybersecurity experts to investigate and remediate that activity.”
The investigation found an unauthorized third party gained access to some of the company’s computer network from June to August 2025.
Reference: Cyberattack At Engineering Firm
Threat Actor: Cicada3301 ransomware group
Cicada3301 is a sophisticated, highly active Ransomware-as-a-Service (RaaS) operation that emerged in mid-2024.
Malware: Ransomware
Cicada3301 ransomware group conducted the attack.
Victim: Chemical & Industrial Engineering Inc.
C&I is a full-service engineering, design & procurement firm, providing hands-on design expertise for increasing capacity, improving efficiency, meeting environmental regulations, and prioritizing safety. For the past 40 years, C&I has become an engineering firm serving refineries, chemical plants, utility facilities, distilleries, and more.
Incident: Service Provider, TIMEC Oil & Gas Suffers Cyberattack
Pasadena, Texas-based heavy industry maintenance and service provider, TIMEC Oil & Gas, Inc., suffered a cyberattack last April and is now letting victims know their personally identifiable information ended up stolen in the hack.
“On or around April 8, 2025, TIMEC became aware of unauthorized activity relating to an employee’s email account,” the company said in a letter to victims of the attack. “Upon becoming aware of this activity, TIMEC promptly launched an investigation to understand the nature and scope of this event.”
As a result of the investigation, the company learned an unknown actor gained access to a TIMEC email account and may have accessed or copied certain emails or attachments within the account between April 7, 2025, and April 10, 2025.
Reference: Cyberattack At Critical Infrastructure Service Provider
Victim: TIMEC Oil & Gas, Inc.
TIMEC, founded in 1971, has over 50 years of experience delivering safety, quality, and efficiency. It is a provider of maintenance and mechanical construction services to heavy industrial industries, including chemical processing and manufacturing, petroleum refining, and oil & gas production and transmission.
Incident: Refrigeration Contractor Alliance Industrial Refrigeration Services Suffers Cyberattack
Walnut, California-based industrial refrigeration contractor Alliance Industrial Refrigeration Services, Inc. suffered a cyberattack in December and is now letting victims know their personally identifiable information ended up stolen by threat actors.
“On December 25, 2025, we discovered suspicious activity within our network environment,” the company said in a notice to the victims of the attack. “Upon discovery, we took immediate action to secure our network environment and engaged cybersecurity specialists to investigate.’
During the investigation, the company discovered some data from its network ended up accessed and acquired by an unauthorized actor between December 25 and December 26.
Reference: Cyberattack At CA Refrigeration Contractor
Victim: Alliance Industrial Refrigeration Services, Inc.
Alliance Industrial Refrigeration Services, Inc. is an industrial refrigeration contractor, specializing in the design, engineering, installation, and maintenance of refrigeration systems and HVAC. Based in Walnut, California, they focus on custom solutions for food processing, cold storage, and pharmaceutical facilities.
Incident: Cyberattack at Eurail
Eurail B.V., the Utrecht, Netherlands-based company that manages and markets the Eurail and Interrail passes, suffered a cyberattack in December where personally identifiable information ended up stolen in the hack.
“We recently identified unusual activity within a segment of our network,” the company said in a letter to victims. “We immediately implemented our incident response procedures, took steps to terminate the activity, and commenced an investigation with the support of third-party cybersecurity professionals.”
Eurail said it also notified law enforcement and are supporting its investigation.
Reference: Eurail Informs U.S. Victims Of Cyberattack
Victim: Eurail B.V.
Utrecht, Netherlands-based company that manages and markets the Eurail and Interrail passes
Incident: Cyberattack at Critical Infrastructure Services Provider, Palacios Marine & Industrial Coatings
Port Lavaca, Texas-based critical infrastructure services provider, Palacios Marine & Industrial Coatings, Inc. (PMI), suffered a cyberattack last September and is now letting victims know their personally identifiable information ended up stolen in the hack.
“On September 30, 2025, PMI detected irregular activity within its computer network,” the company said in a notice to victims. “In response, PMI immediately took steps to secure its network and launched an investigation to determine the nature and scope of the activity.”
Upon discovering the event, PMI moved quickly to investigate and respond to the incident, assess the security of PMI systems, and identify potentially affected individuals.
Reference: Critical Infrastructure Service Provider Suffers Cyberattack
Victim: Palacios Marine & Industrial Coatings, Inc.
Founded in 2003, the Port Lavaca, Texas-based company provides mechanical and field services for nuclear power plants, petrochemical sites and refineries, as well as offshore marine operations.
Incident: Cyberattack at Intoxalock
Vehicle breathalyzer company, Intoxalock, is now back up and running after a cyberattack left drivers across the United States unable to start their vehicles.
Intoxalock said in an advisory on its website Sunday, March 22 “We’re pleased to share that our systems have resumed. Installations, calibrations, and service center support are now available.”
The cyberattack occurred Saturday, March 14. Intoxalock sells breathalyzer devices that fit into vehicle ignition switches, and is used by people who are required to provide a negative alcohol breath sample to start their car.
Reference: Cyberattack Halts Vehicle Breathalyzer Firm
Victim: Intoxalock
Vehicle breathalyzer company,Urbandale, Iowa-based Intoxalock's technology sees action in all 50 states, according to its website. It said it provides services to 150,000 drivers a year.
Incident: Ransomware Attack at Spain’s Port of Vigo
Spain’s Port of Vigo in Galicia suffered a ransomware attack last week that forced officials to disconnect parts of its network and switch cargo handling to manual processes which meant physical ship movement could continue without digital communication.
The attack occurred Tuesday March 25 at 5:45 a.m. when port authority staff at the Port of Vigo discovered ransomware had encrypted servers managing cargo traffic and digital services. Equipment ended up locked and a ransom demand followed. So far, no cybercrime group claimed responsibility.
As a result of the attack, the port’s technology team isolated all affected systems from external networks. Port President Carlos Botana said connections would not be restored until there were absolute guarantees of safety, with no estimated timeline for recovery.
Reference: Port In Spain Hit In Ransomware Attack
Malware: Ransomware
The port did not pay the ransom. No threat group took responsibility.
Victim: Port of Vigo
Spain’s Port of Vigo in Galicia is the operational base for major fishing companies with fleets operating across the globe, from South Africa and Namibia to Argentina, Chile, and Australia. Fish processed through Vigo distributes across Spain and exported to Portugal, Italy, France, and markets throughout Asia.
Reference: Cyberattack At Animal Product Maker
Incident: Animal Health Product Maker, Durvet, Hit in Cyberattack
Blue Springs, Missouri-based animal health product manufacturer, Durvet, Inc. suffered a cyberattack in October and is now letting victims know their personally identifiable information ended up stolen in the attack.
“On October 17, 2025, Durvet learned of suspicious activity on certain systems in its environment,” the company said in a letter to victims. “In response, Durvet immediately took steps to secure the network and initiated an investigation into the nature and scope of the event with the assistance of third-party computer forensic specialists.”
As a result of that investigation, Durvet determined its environment was subject to unauthorized access between October 17, 2025 to October 18, 2025. At that time the attackers stole or copied information.
Victim: Durvet, Inc.
Blue Springs, Missouri-based animal health product manufacturer, Durvet, is an animal health product manufacturer and distributor. Founded in 1970, the company creates private-label, generic animal health products for livestock, equine, and pets, and it was a pioneer in combining manufacturing with distribution in the OTC animal health market.
Incident: Security Firm Victim Of Attack On Benefits Provider
San Francisco, California-based cybersecurity provider HackerOne Inc. fell victim to an attack on one of its benefits administrators where the company suffered from a hack where a threat actor stole personally identifiable information from HackerOne’s employees.
HackerOne said it received notification via mail its benefits administrators, Navia, suffered an attack in December where the personal information ended up stolen. HackerOne met with Navia on March 13 to understand what data ended up impacted and the nature of the security incident.
“A Broken Object Level Authorization (BOLA) vulnerability led to an unknown actor accessing Navia data between December 22, 2025 and January 15, 2026,” HackerOne said in a notice to victims. “On January 23, 2026, Navia became aware of suspicious activity in their environment. Navia sent letters dated February 20, 2026 to impacted companies.”
Reference: Security Firm Victim Of Attack On Benefits Provider
Victim: HackerOne Inc.
San Francisco, California-based cybersecurity provider HackerOne is a provider of Continuous Threat Exposure Management (CTEM). HackerOne unites AI solutions with researchers to discover, validate, prioritize, and remediate exposures across code, cloud, and AI systems.
Incident: Cyberattack at Contract Electronics Manufacturer, Segue Manufacturing Services
North Billerica, Massachusetts-based contract electronics manufacturer, Segue Manufacturing Services LLC suffered a cyberattack where personally identifiable information ended up stolen by a threat actor.
“On January 22, 2026, Segue became aware of a cybersecurity incident that impacted certain systems in its environment,” the company said in a notice to victims. “Segue promptly launched an investigation and engaged a leading cyber firm to assist with assessing the nature and scope of the incident.”
As a result of the investigation, the company discovered certain personal information may ended up stolen in the attack.
The investigation determined attackers stole the following types of personal information: Name, address, and Social Security number.
Reference: Cyberattack At MA Contract Manufacturer
Victim: Segue Manufacturing Services LLC
Segue Manufacturing Services, a Lisconn company, is a global contract electronics manufacturer specializing in complex electro-mechanical integration, cable and harness assembly and engineering services. Segue provides low-to-medium volume solutions, and seamless transitions to low-to-higher volumes at facilities in Mexico or China. Specializing in high-reliability and rugged environments, Segue partners with OEMs, device manufacturers and Tier I EMS providers in medical, instrumentation, industrial, capital equipment and semiconductor.
Incident: Oil Producer, Capital Star Oil & Gas, Suffers Cyberattack
Houston, Texas-based upstream oil producer, Capital Star Oil & Gas, Inc. suffered a cyberattack in November and is now letting victims know their personally identifiable information ended up stolen in the hack.
Capital Star Oil & Gas, Inc. takes the privacy and security of the data under our care very seriously and we regret any concern or inconvenience this may cause.
“On November 3, 2025, we detected suspicious activity within our network, the company said in a notice to victims of the attack. “We promptly initiated an investigation of the matter and engaged cybersecurity specialists to assist with the incident response.”
Reference: Oil & Gas Producer Hit In Cyberattack
Victim: Capital Star Oil & Gas, Inc.
Capital Star Oil & Gas is an independent upstream oil and gas company based in Houston. The company conducts exploration and production efforts in South Texas, and along the Texas Gulf Coast.
Incident: Chip Maker, Trio-Tech International, Hit In Ransomware Attack
Chip maker Van Nuys, California-based Trio-Tech International identified and responded to a ransomware incident in one of its subsidiaries in Singapore.
Trio-Tech International designs, manufactures and markets front and back-end equipment and systems used in the testing and production of semiconductors.
The subsidiary experienced a ransomware incident starting on March 11 that resulted in encryption of certain files within the company’s network, Trio-Tech International said in an 8-K advisory to the Securities and Exchange Commission (SEC).
Reference: Chip Maker Hit In Ransomware Attack
Threat Actor: Gunra
Gunra is a financially motivated, double-extortion ransomware group that emerged in 2025. Operating primarily as a Ransomware-as-a-Service (RaaS), the group actively attacks Windows and Linux systems across global sectors like manufacturing, healthcare, and IT, while deliberately avoiding targets in the United States.
Malware: Ransomware
Gunra ransomware group claimed responsibility
Victim: Trio-Tech International
Van Nuys, California-based Trio-Tech International designs, manufactures and markets front and back-end equipment and systems used in the testing and production of semiconductors.
Incident: AstraZeneca Data For Sale after Attack
An AstraZeneca data breach linked to the LAPSUS$ threat group just appeared on a Dark Web post and it is showing a new type of ransomware attack, a threat research group said.
Based on the materials reviewed, the claim goes beyond a routine leak post and suggests possible exposure of internal code repositories, access-related data, cloud and infrastructure references, and employee-linked records, according to a report with cybersecurity threat intelligence provider, SOCRadar.
A breach involving AstraZeneca ended up advertised on a Dark Web forum and also appeared on a data leak site associated with LAPSUS$. The listing claims the attackers obtained a large archive containing internal data, including source code, infrastructure-related material, and access-linked information.
Reference: AstraZeneca Data For Sale
Malware: Ransomware
Linked to the LAPSUS$ threat group
Victim: AstraZeneca
AstraZeneca is a global, science-led biopharmaceutical and biotechnology company. Headquartered in Cambridge, UK, the company focuses on the discovery, development, and commercialization of prescription medicines for major diseases.
Editorial: OT Threat Report: Physical Impacts Down, Nation-State Attacks on Rise
Incident: NJ Metal Stamping Firm Suffers Cyberattack
Glassboro, New Jersey-based metal stamping manufacturer, Elray Manufacturing Company suffered a cyberattack in November and is now letting victims know their personally identifiable information ended up stolen in the hack.
“On November 19, 2025, Elray became aware of unusual activity within our computer network and immediately took steps to secure our systems, engaging external cybersecurity experts in the process,” the company said in a letter to victims.. “As a result of that investigation, we learned that an unknown actor gained access to our network and may have acquired certain files.”
Based on Elray’s review, the company said victims’ personal information was on the network and involved in this incident.
Reference: NJ Metal Stamping Firm Suffers Cyberattack
Victim: Elray Manufacturing Company
Elray Manufacturing offers design engineering, process engineering, and metal stamping. Their metal stamping machines include production stamping presses, multiple-spindle lead screw tapping machines, milling, drilling, grinding, sanding equipment, vibratory deburring, cleaning, degreasing equipment, and unitek resistance spot welding equipment.
Incident: Plasma Cutting Company, Hypertherm, Victim of Oracle Issue
Hanover, New Hampshire-based plasma cutting provider, Hypertherm, Inc. suffered a cyberattack in August as a result of a vulnerability in its version of Oracle’s E-Business Suite (EBS) software which helps manage operations.
An unauthorized actor leveraged a previously unknown vulnerability in Oracle EBS to take information from numerous organizations’ Oracle EBS applications. Hypertherm was one of those organizations.
Upon becoming aware of the incident, Hypertherm immediately implemented its response procedures, took measures to secure its implementation of Oracle EBS, and launched an investigation with the support of third-party cybersecurity professionals, the company said in a notice to victims.
Reference: Plasma Cutting Company Hit In Oracle Vulnerability
Victim: Hypertherm, Inc.
Hanover, New Hampshire-based Hypertherm Inc. (now known as Hypertherm Associates) is a company specializing in industrial cutting technologies. They design and build plasma, laser, and waterjet cutting systems, alongside associated software and consumables.
Incident: Electronic Systems Maker, OSI Systems, Suffers Cyberattack
Hawthorne, California-based specialized electronic systems manufacturer, OSI Systems, Inc. suffered a cyberattack last December and is now notifying victims of the hack their personally identifiable information ended up stolen.
“On December 25, 2025, OSI became aware of suspicious activity on certain systems in its network,” the company said in a notice to victims of the attack. “In response, OSI promptly took steps to secure its network and initiated an investigation into the nature and scope of the activity with the assistance of third-party forensic specialists.”
As a result of its investigation, the company found certain files within OSI’s network ended up accessed without authorization.
Reference: Electronic Systems Maker Hit In Cyberattack
Victim: OSI Systems, Inc.
OSI Systems, Inc. is a vertically integrated designer and manufacturer of specialized electronic systems and components for critical applications in homeland security, healthcare, defense and aerospace.
Incident: Cyberattack at Fluid Manufacturer, QualiChem
Salem, Virginia-based metalworking fluid manufacturer QualiChem, Inc. suffered a cyberattack in October and is now informing victims of the attack.
The attack occurred between October 23, 2025, and December 16, 2025, when an external hacking incident compromised the security of QualiChem, Inc.’s systems, according to a notice by the company.
The company discovered the attack February 25 this year, according to a notice the company released.
Reference: Fluid Manufacturer, QualiChem, Suffers Cyberattack
Victim: QualiChem, Inc.
QualiChem manufactures some of the most advanced metalworking fluids available in the world. As a global supplier, the company said its fluids meet all of the relevant health and safety regulations, including GHS and REACH. The product line includes water-dilutable coolants, straight oils, metal forming fluids, cleaners, and rust and corrosion inhibitors.
Incident: Safety Provider, Ansell Healthcare, Suffers Cyberattack
Iselin, New Jersey-based safety solution provider and personal protective equipment (PPE) manufacturer Ansell Healthcare Products LLC USA suffered a cyberattack in August and is now notifying victims of the hack where personally identifiable information ended up stolen.
“On or about September 30, 2025, Ansell became aware of claims relating to unauthorized access to certain sets of company data,” the company said in a notice to victims. “Immediately following first awareness and containment, with assistance from experts across the cyber industry, Ansell took steps to investigate in line with its obligations to assess suspected data breaches.”
Following an extensive investigation, Ansell was able to validate the claims made. Through its investigation, Ansell determined the unknown actor gained access to its systems on or around August 9, 2025.
Reference: Safety Provider Suffers Cyberattack
Victim: Ansell Healthcare Products LLC USA
Ansell is a provider of safety solutions and an integrated manufacturer of personal protective equipment (PPE). The company designs, manufactures, and markets brands such as HyFlex, AlphaTec, BioClean, GAMMEX, MICROFLEX, AnsellGUARDIAN, Kimtech, KleenGuard, and The RightCycle Program. These brands help over 10 million workers and professionals in the healthcare and industrial sectors.
Incident: Operations Affected at Aussie Chicken Processor, Hazeldenes
An apparent ransomware attack at major chicken meat processor Hazeldenes in central Victoria, Australia forced the company to curtail operations leading to a shortage of chicken at various businesses across the state.
Victorian poultry processor Hazeldenes confirmed February 26 it had been responding to a cybersecurity incident since February 19, which forced it to halt production across its facilities. The company processes 900,000 birds each week and produces more than 85 million kilograms of chicken annually across more than 50 sites including farms, hatcheries and processing facilities throughout Victoria.
Retail and industry officials said the chicken meat processor has been unable to fill some orders because it cannot package the product, according to a Australian Broadcasting Corporation (ABC) report.
Reference: Attack Shuts Down Aussie Chicken Processor
Threat Actor: Dragonforce
DragonForce is a Ransomware-as-a-Service (RaaS) and ransomware cartel that emerged in late 2023, primarily focused on financial extortion through double-extortion tactics.
Victim: Hazeldenes
Victoria, Australia-based poultry processor Hazeldenes processes 900,000 birds each week and produces more than 85 million kilograms of chicken annually across more than 50 sites including farms, hatcheries and processing facilities throughout Victoria.
Incident: Attack on Service Provider Affects Ericsson
A service provider for Ericsson Inc. suffered a cyberattack last April where personally identifiable information from Ericsson fell into the hands of the threat actor.
Ericsson said it holds personal data for employees and customers and, from time to time, shares this information with the company’s service providers. Ericsson sent a letter out to victims notifying them of data security incident that occurred at one of its services providers, which ma involved personal information.
“On April 28, 2025, our service provider became aware of a suspicious event that may have involved potential unauthorized access to certain data on their system,” the company said in a letter to victims. “It promptly initiated an investigation with the assistance of external cybersecurity specialists. It also notified the Federal Bureau of Investigation and implemented measures to enhance security and minimize the risk of a similar incident occurring in the future.”
Reference: Ericsson Suffers From Attack On Service Provider
Victim: Ericsson
Ericsson is a Swedish multinational networking and telecommunications company headquartered in Stockholm. Additionally, Ericsson has been a major contributor to the development of the telecommunications industry and is one of the leaders in 5G. Additonally, the is a major manufacturer of telecommunications equipment, specifically specializing in 5G infrastructure, radios, and RAN (Radio Access Network) compute systems. They operate a highly automated 5G Smart Factory in Lewisville, Texas, which produces equipment for U.S. networks.
Incident: Pro-Iranian Attack on MI-Based Medical Device Maker, Stryker
Major medical device maker, Stryker, suffered a cyberattack claimed by pro-Iranian threat actors that caused a “global network disruption,” company officials said. That disruption affected manufacturing operations.
“Stryker is experiencing a global network disruption to our Microsoft environment as a result of a cyberattack,” the Portage, Michigan-based company said in an advisory on its website. “We have no indication of ransomware or malware and believe the incident is contained.
“Our teams are working rapidly to understand the impact of the attack on our systems.
Reference: Stryker’s Manufacturing Operations Hit In Cyberattack
Reference: MI-Based Medical Device Maker Hit By Pro-Iranian Attacker
Threat Actor: Handala
Handala is an Iran-affiliated cyber threat group that presents itself as a pro-Palestinian "hacktivist" collective. Emerging in December 2023, the group has become known for disruptive, destructive cyber operations primarily targeting Israeli and Western organizations, often acting as a front for Iran's Ministry of Intelligence and Security (MOIS).
Victim: Stryker
Stryker makes a range of hospital equipment, from defibrillators to ambulance cots. Stryker said it serves more than 150 million patients through its health equipment and services.
Incident: Cyberattack at Software Developer Flash Charm
Austin, Texas-based B2B software developer, Flash Charm, Inc., which does business as Idera, suffered a cyberattack in August and is now letting victims know their personally identifiable information ended up stolen in the hack.
“On October 31, 2025, we detected that an unauthorized party gained access to a third-party file-hosting system,” the company said in a letter to victims. “The access ended up confined to this third-party file-hosting system and did not extend to any of our products or other systems.”
As a result of the August 23 attack, the company took immediate containment steps, notified federal law enforcement, and worked with leading forensics teams to investigate the matter.
Reference: Software Developer Suffers Cyberattack
Victim: Flash Charm, Inc.
Austin, Texas-based Austin, Texas-based B2B software developer, Flash Charm, Inc., does business as Idera.
Idera is the parent company of a portfolio of brands that offer B2B software including database tools, application development tools, test management tools, and DevOps tools. It has offices in Australia, Austria, and the United Kingdom.
Incident: Compliance, Training Provider, MEC, Hit In Cyberattack
Mortgage Educators and Compliance (MEC), a website owned and operated by Austin, Texas-based training provider, 360training.com, Inc. suffered a cyberattack in November where personally identifiable information ended up stolen in the hack.
“On or around November 25, 2025, MEC discovered suspicious activity related to our website,” the company said in a letter to victims. “Upon discovery, we took immediate action to secure our website and started the investigation.”
On November 26, the company’s investigation found an unauthorized party added a script on our site, sending credit card data to a Google Analytics account controlled by an unauthorized party.
Reference: Compliance, Training Provider Hit In Cyberattack
Victim: Mortgage Educators and Compliance
Mortgage Educators and Compliance (MEC) is a website owned and operated by Austin, Texas-based training provider, 360training.com.
Founded in 1997 by Albert Lilly, 360training.com is an Austin, Texas-based online provider of regulatory compliance and continuing education training. The company offers accredited online courses and certification programs across industries such as real estate, food safety, and OSHA.
Incident: Sexual Wellness Manufacturer, Tenga, Suffers BEC
Japan-based sexual wellness maker, Tenga Co., Ltd., suffered a business email compromise last week after officials discovered that an unauthorized party gained access to the professional email account of an employee.
“We immediately took steps to secure the account and began an investigation,” the company said in an advisory. “We have determined that on February 13, 2026, between 12 a.m. and 1 a.m. PT the unauthorized party used this account to send unsolicited “spam” emails to contacts found within the account’s history, which may have included you.” Tenga has a U.S. office in Torrance, California.
The attacker had access to the contents of the email inbox. This means the attacker had access to name, email address, and historical email correspondence (which may include order details or customer service inquiries) ended up potentially viewed or acquired.
Reference: Sexual Wellness Manufacturer Suffers BEC
Victim: Tenga Co., Ltd.
Japan-based Tenga Co., Ltd. specializes in the design, manufacture and sales of functional, hygienic sexual wellness items. With products sold in over 60 countries, Tenga’s headquarters is in Tokyo, Japan. Tenga USA’s headquarters is in Torrance, CA.
Incident: Ransomware Attack at Semiconductor Maker Advantest
Tokyo, Japan- based semiconductor test equipment manufacturer Advantest Corporation suffered a ransomware attack last week impacting certain systems within its network, the company said in an advisory.
“On February 15, the company detected unusual activity within its IT environment,” the company said. “Upon detection, Advantest immediately activated its incident response protocols, isolated affected systems, and engaged leading third-party cybersecurity experts to assist in the investigation and containment of the incident.”
Preliminary findings appear to indicate an unauthorized third party may have gained access to portions of the company’s network and deployed ransomware.
The company said it believes its containment actions and activation of business continuity plans minimized operational disruption and enabled it to continue serving customers.
Reference: Semiconductor Maker Hit By Ransomware
Victim: Advantest Corporation
Tokyo-Japan-based Advantest is a manufacturer of automatic test and measurement equipment used in the design and production of semiconductors for applications including 5G communications, the Internet of Things (IoT), autonomous vehicles, high-performance computing (HPC), including artificial intelligence (AI) and machine learning.
Incident: Security Provider, Data Systems Analysts, Suffers Cyberattack
Trevose, Pennsylvania-based government solution and security provider, Data Systems Analysts (DSA) Inc. suffered a cyberattack in September where personally identifiable information ended up stolen in the hack.
“DSA detected a compromise of its network environment by an unauthorized third party on or about September 11, 2025,” the company said in a letter to victims. “As soon as we became aware of the activity, we took immediate steps to secure the environment and engaged third-party forensic experts to assist in investigating what happened and what information may have been impacted.”
The outside investigators confirmed the environment was secure and hardened. They were also able to enhanced network security, and they conducted a digital forensic investigation to determine the extent of unauthorized activity.
Reference: Security Provider Hit In Cyberattack
Victim: Data Systems Analysts Inc.
Trevose, Pennsylvania-based Data Systems Analysts (DSA) started up in 1963 and provides mission essential solutions for defense, federal government, academia, and commercial customers. The company expanded its customer base to include universities and private industry partners as it provides critical infrastructure support and monitoring. DSA’s service offerings include systems engineering and integration, software development, data analytics, cyber operations and security, systems modernization, cloud solutions, enterprise collaboration and knowledge management, and critical infrastructure intelligence systems.
Incident: Cyberattack at Tecan Technology Development Boston
Woburn, Massachusetts-based medical instrumentation maker Tecan Technology Development Boston, Inc. (T-TDB) suffered a cyberattack in December where threat actors made off with victims’ personally identifiable information.
“On December 2, T-TDB detected a cybersecurity incident impacting its systems at that location,” the company said in a letter to victims. “Upon learning of the incident, we took immediate action to secure the environment and launched an investigation with the assistance of third-party forensic specialists to determine the nature and scope of the unauthorized access.”
The company also notified the FBI office that is investigating the actor responsible for this incident.
Reference: MA Medical Instrument Maker Suffers Cyberattack
Victim: Tecan Technology Development Boston, Inc.
Tecan is a manufacturer and developer of laboratory instruments, automation solutions, and specialized components for life sciences and clinical diagnostics. Operating globally with U.S. manufacturing sites, they provide original equipment manufacturers instruments, consumables, and contract development/manufacturing services.
Incident: Catalyst RCM Attack Leads to Ransomware Hacks
Katy, Texas-based Catalyst RCM fell victim to a cyberattack resulting in its clients losing their customers’ information in a multi-organization ransomware hack.
Catalyst lost information in connection with the medical coding and billing services provided to Charleston, South Carolina-based molecular diagnostics laboratory, Vikor Scientific, Charleston-based Korgene, and Tampa, Florida-based KorPath diagnostic laboratories.
All three companies, Vikor, Korgene and KorPath fell victim to a ransomware attack from the Everest Group, according to a report from Ransomware Live. Everest ransom group collects and analyzes information about their victims. They specialize in customer privacy data, financial information, databases, credit card information, and more. The Everest ransom group leaks the victim’s data to the darknet and they announce any victim that will not contact them will suffer from a data leak.
Reference: Medical Test Kit Makers Victimized By Ransomware
Victim: Catalyst RCM
Catalyst RCM is a data-centric Revenue Cycle Management (RCM) Company offering healthcare providers specialized medical billing, coding, and business analytics.
In this case, one of the victims was Vikor Scientific, a manufacturer in addition to being a molecular diagnostics laboratory. The company expanded its operations to include the assembly and production of molecular diagnostic testing kits, such as for COVID-19, in addition to providing clinical testing services. They manufacture, assemble, and distribute comprehensive molecular pathogen and resistance panel test kits.
Incident: Ransomware Attack at Under Armour
Clothing retailer Under Armour is in the process of investigating a data breach where attackers stole customers’ email addresses and other personal information.
While there are no signs yet attackers stole any passwords or financial information nor have they abused the personal information from the November attack.
The breach occurred late last year, and affected 72 million email addresses, according to The Associated Press report citing information by the cybersecurity website Have I Been Pwned.
Reference: Under Armour Hit In Data Breach
Victim: Under Armour
Baltimore, Maryland-based Under Armour is a global clothing retailer.
Incident: Cyberattack at Security Services Provider, Rockport Technology Group
Salem, New Hampshire-based services provider, Rockport Technology Group, Inc. suffered cyberattack where personally identifiable information from current of former employees ended up stolen in the hack.
“On or about December 18, 2025, we detected that we were the target of a data security incident,” the company said in a notice to victims of the attack. “An unauthorized third party attempted to infiltrate our computer network. Upon detecting the incident, we moved quickly to secure our network environment and engaged a specialized third party forensic incident response firm to assist with securing the network environment and determine the scope and extent of any potential unauthorized access of our systems.”
After an extensive investigation, which concluded on January 6, Rockport said it found some personal information may have ended up compromised in the attack. The attackers made off with the victims’ name and Social Security number.
Victim: Rockport Technology Group, Inc.
Salem, New Hampshire-based Rockport Technology Group provides comprehensive IT solutions, including managed IT services, cybersecurity, cloud services, and professional services such as network design and unified communications. The company also offers specialized building services, including structured cabling, physical security, and server relocation.
Incident: Cyberattack at Transportation Provider, Venezia Bulk Transport
Pottstown, Pennsylvania-based transportation provider, Venezia Bulk Transport, Inc., suffered a cyberattack in August and is now letting victims know about the hack where personally identifiable information ended up stolen.
“On or about August 5, 2025, Venezia Transport experienced unauthorized access to our network,” the company said in a letter to victims. “Upon learning of this issue, we commenced a prompt and thorough investigation and secured the network.”
As part of its investigation, Venezia Transport worked with external cybersecurity professionals experienced in handling these types of incidents.
Reference: Cyberattack At PA Transportation Provider
Victim: Venezia Bulk Transport, Inc.
Family owned and operated truckload company based in Pottstown, Pennsylvania-based Venezia Transport specializes in bulk tank and other bulk transportation. Dry bulk cement , dry food, fly ash, liquid asphalt, propane, motor oils, lubricants are some of the company’s dedicated divisions. Terminals are in Pottstown, Fleetwood, Nazareth, York, and Mount Pocono, PA. Other terminals are in New Middletown OH, Swedesboro NJ, South Plainfield NJ, Triadelphia WV, Culpeper VA, and Indianapolis IN .
Incident: Industrial Textile Maker Hit In Cyberattack
Medina, New York-based industrial textile manufacturer BMP America, Inc. suffered a cyberattack in October and is now letting victims know about the attack where personally identifiable information ended up stolen in the hack.
“On October 3, 2025, we discovered unusual activity on our network and immediately began an investigation,” the company said in a letter to victims. “The investigation determined that a limited amount of information was subject to unauthorized access between October 2, 2025 and October 3, 2025.”
BMP America conducted a review of the stolen information to determine the types of information ended up affected and to whom that information belonged.
Reference: Industrial Textile Maker Hit In Cyberattack
Victim: BMP America, Inc.
BMP America is a manufacturing company headquartered in Medina and has a subsidiary plant in Juarez, Mexico. BMP specializes in converting engineered nonwovens, needlefelts, flat and pleated medias for fluid and air filters, home appliance sewn felt seals, and assemblies for business machines like copiers and printers, the automotive filter industry, and home appliance manufacturers. The company started up in 1982.
Incident: Nova Biomedical Suffers ‘Sophisticated’ Attack
Waltham, Massachusetts-based Nova Biomedical Corp. suffered a “sophisticated cybersecurity attack” where the threat actor “deployed malware” in July and is now informing victims their personally identifiable information ended up stolen in the attack.
“On July 22, 2025, Nova experienced a sophisticated cybersecurity attack that disrupted Nova’s operations,” the company said in a letter to victims. “Nova immediately launched an investigation with the assistance of leading cybersecurity experts. Through Nova’s investigation, Nova determined that an unauthorized actor accessed Nova’s electronic infrastructure and deployed malware. Nova also coordinated with law enforcement.”
Nova’s investigation included a review and analysis of impacted data on its systems.
Reference: Medical Instrument Maker Hit In ‘Sophisticated’ Attack
Victim: Nova Biomedical Corp.
Waltham, Massachusetts-based Nova Biomedical is a manufacturer of advanced technology blood testing analyzers, in-vitro diagnostic devices, and clinical laboratory instruments. It is one of the 25 largest in vitro diagnostic companies globally. Additionally, it is the largest privately owned in vitro diagnostic company in the U.S.
Incident: Oil & Gas Producer, Murex Petroleum, Suffers Cyberattack
Spring, Texas-based Murex Petroleum Corporation suffered a cyberattack in May and is now letting victims know their personally identifiable information ended up stolen in the hack.
“On or about May 27, 2025, we detected unauthorized access to our network,” the company said in a letter to victims. “Upon learning of the issue, we secured our network and commenced a prompt and thorough investigation.”
Murex said as a part of its investigation, it worked very closely with external cybersecurity professionals experienced in handling these types of incidents.
Reference: Oil & Gas Producer Hit In Cyberattack
Victim: Murex Petroleum Corporation
Murex Petroleum focuses on the acquisition, development and operation of oil and gas properties in North America. Since incorporating in 1996, Murex has become the 23rd largest operator in North Dakota. It is also the 37th largest operator in the Rocky Mountain Region. Murex has also been ranked the 38th largest privately held oil and gas company by the Oil & Gas Financial Journal. The company employs 65 workers in its Houston corporate and North Dakota offices.
Incident: EMC Water Suffers from Oracle Vulnerability
Milwaukee, Wisconsin-based EMC Water LLC fell victim to an attack emanating from a vulnerability in the Oracle’s E-Business Suite (“EBS”) software where the threat actor made off with files containing personally identifiable information.
EMC Water, like multiple other organizations use Oracle’s E-Business Suite software to help manage their operations. An unauthorized actor leveraged a previously unknown vulnerability in Oracle EBS to take information from numerous organizations’ Oracle EBS applications.
That is what happened in late November when EMC Water discovered it was one of those organizations.
Reference: Water Firm Suffers From Oracle Vulnerability
Victim: EMC Water LLC
EMC Water System started up in 1973. When the water system was established, there were 190 customers, however, today they have 865 customers.
Incident: Michigan Sugar Co. Hit in Cyberattack
Bay City, Michigan-based Michigan Sugar Company (MSC) suffered a cyberattack in August and is now letting victims know their personally identifiable information ended up stolen in the hack.
“On August 14, 2025, MSC became aware of suspicious activity in its network in which an unauthorized third party gained access to certain systems in its network,” the company said in an advisory. “Upon becoming aware of this event, MSC promptly launched an investigation, with the assistance of third-party cybersecurity specialists, to determine the nature and scope of the event.”
MSC’s investigation found unauthorized access to certain company systems on August 14 and that may have resulted in the unauthorized access and acquisition of certain data.
Reference: Sugar Beet Processor Suffers Cyberattack
Victim: Michigan Sugar Company
Bay City, Michigan-based Michigan Sugar Company has sugar beet processing facilities in Bay City, Caro, Croswell and Sebewaing, Michigan. Nearly 900 grower-owners plant and harvest up to 160,000 acres of sugar beets each year in 20 Michigan counties. They also pull in sugar beets from Ontario, Canada. Those beets are sliced at factories and turned into about 1.3 billion pounds of sugar annually. The company’s sugar ends up sold to industrial, commercial and retail customers under the Pioneer and Big Chief brands. The company also packages sugar for more than 20 private labels, including for Walmart, Meijer and Kroger.
Incident: Haley’s Metal Shop Hit in BEC Attack
Biddeford, Maine-based Haley’s Metal Shop, Inc. suffered a business email compromise cyberattack in December where personally identifiable information ended up stolen in the hack.
“On December 1, 2025, Haley’s Metal Shop, Inc. identified and addressed an email phishing incident associated with one employee’s email account,” the company said in a notice to victims. “Upon identifying the activity, Haley’s Metal Shop promptly took steps to secure the account and began an investigation.”
As a result, the investigation determined an unauthorized actor accessed the employee’s email account only on December 1. Haley’s Metal Shop reviewed the emails and attachments in the email account. On January 23, the company found they contained the name, Social Security number, driver’s license number, and/or financial account information.
Reference: ME Metal Shop Hit In BEC Attack
Victim: Haley’s Metal Shop, Inc.
Biddeford, Maine-based Haley’s Metal Shop is a sheet metal contractor serving Maine, New Hampshire, and Massachusetts. Its service division, Total Comfort Services, installs and maintains heating and air conditioning equipment for homes and businesses.
Incident: DDoS Cyberattack Disrupts La Poste and La Banque Postale Online Services During Peak Christmas
In December 2025, La Poste Groupe suffered a DDoS cyberattack . The attack targeted its online services, parcel tracking (Colissimo), Digiposte, and La Banque Postale digital banking. The attack caused temporary service outages for several days during the Christmas peak, though physical deliveries and in‑person banking continued. The incident was claimed by pro‑Russian hacktivists NoName057(16). No customer data was compromised, and services were gradually restored by late December. La Poste strengthened monitoring and mitigation measures to prevent future disruptions.
Pro-Russian group Noname057 claimed credit for a DDOS attack that affected deliveries. Deliveries were slowed because of an impaired parcel tracking capability.
Victim: La Poste
France’s national postal service and logistics provider La Poste offers postal, parcel delivery, logistics, and financial services.
Reference: Cyberattack on 22 December : what you need to know
Reference: DDoS incident disrupts France’s postal and banking services ahead of Christmas
Incident: Cyber‑Related Disruption Forces Temporary Suspension of PDVSA Oil Cargo Deliveries
Petróleos de Venezuela, S.A. (PDVSA) — the Venezuelan state‑owned oil company — experienced a cyberattack in mid‑December 2025 that disrupted its central administrative and operational systems, including systems used for coordinating oil cargo deliveries. The attack forced PDVSA to isolate its oilfields, refineries, ports and other facilities from its compromised central network to contain the incident. As a result, scheduled oil cargo deliveries and exports were suspended for several days, as terminal workers resorted to manual record‑keeping and contingency measures to avoid further operational stoppages.
By 17 December 2025, PDVSA reported that it had resumed loading and delivering crude and fuel cargoes at its terminals after the cyber‑related suspension and operational isolation. PDVSA said the company could restart operations by manually recording deliveries while maintaining isolation from compromised systems, and exports resumed despite ongoing geopolitical and logistical pressures.
Victim: Petróleos de Venezuela, S.A. (PDVSA)
Venezuela's state-run oil company Petróleos de Venezuela, S.A. (PDVSA)
Reference: Shipbuilding Offshore Coastal/Inland Government Equipment Training Law & Regulations PDVSA Resumes Oil Cargo Deliveries After Cyberattack
Incident: Attempted Cyberattack Triggers Short Service Delays at Aras Kargo, Systems Restored
Aras Kargo — one of Turkey’s largest parcel delivery and logistics companies — detected an attempted cyberattack on its information systems. Security teams identified the intrusion quickly and intervened using the company’s defensive infrastructure. The attack led to short‑term delays and service interruptions. Some branches temporarily paused services during recovery before resuming deliveries and parcel acceptance. Systems were brought back online rapidly, with cargo operations and delivery functions continuing normally following mitigation.
Victim: Aras Kargo
Aras Kargo — one of Turkey’s largest parcel delivery and logistics companies
Reference: Regarding Public Information
Incident: Cyberattack Disrupts Bär Cargolift Production and IT Systems in Germany
A cyberattack struck Bär Cargolift (Gerd Bär GmbH) on Friday, 28 November 2025, affecting its IT systems. The company publicly acknowledged the attack on its website. Normal operations were disrupted while containment and remediation took place. Production resumed during the week after the attack according to company updates. Orders for cargolifts and spare parts could still be placed once the company restored email and web shop functionality. Email systems were taken offline during the incident. By the first week of December, email services and production were reported as restored or resuming. Investigation is ongoing.
Victim: Bär Cargolift (Gerd Bär GmbH)
Bär Cargolift (Gerd Bär GmbH) is a German manufacturing company based in Heilbronn, Germany, specializing in hydraulic tail lifts and loading platform systems for commercial vehicles and logistics operations
Reference: Gerd Bär GmbH is back after cyber attack!
Incident: Canadian Cyber Centre Warns of Hacktivists Abusing Internet‑Accessible Industrial Control Systems
Multiple incidents have been reported in Canada where internet‑accessible industrial control systems (ICS) have been manipulated by opportunistic actors (hacktivists). Attackers altered water pressure values at a water treatment facility, resulting in degraded service for the community. An Automated Tank Gauge (ATG) was manipulated at an oil and gas company, triggering false alarms. Temperature and humidity values were manipulated at a farm grain silo, potentially leading to unsafe conditions if not discovered in time.
Reference: Alert – AL25-016 Internet-accessible industrial control systems (ICS) abused by hacktivists
Incident: Unauthorized Messages Broadcast After Airport Display and PA System Breach at Multiple North American Airports
A cybersecurity breach affecting airport terminal systems occurred at multiple airports in Canada and the United States. The unauthorized actors gained access to public information display screens and public address (PA) systems, broadcasting pro‑Hamas and anti‑Trump/anti‑Israeli messages. Some flights at Kelowna were delayed as a result of the incident. Other airports reported little to no impact on scheduled flights or passenger safety. Normal operations resumed swiftly after systems were restored.
A group calling itself “Siberislam” claimed responsibility for the hacks in the onscreen messages, while social media accounts under that name shared videos of the incidents.
Victim: Windsor International Airport
Windsor International Airport in Ontario
Reference: Apparent hackers take over PA systems at 4 North American airports
Victim: Harrisburg International Airport
Harrisburg International Airport in Pennsylvania, USA
Reference: Three airports in Canada hacked with pro-Hamas messages
Victim: Victoria International Airport
Victoria International Airport, Canada
Victim: Kelowna International Airport
Kelowna International Airport, Canada
Reference: Canadian airport screens, PA systems hacked with pro-Hamas, anti-Trump messages
Reference: Cyberattack by pro-Hamas activists hits multiple Canadian airports By
Reference: Japanese brewer Asahi reports data leak affecting 1.9 million people
Victim: Asahi Group Holdings, Ltd.
Asahi Group Holdings, Ltd. is a global beverage production and distribution company (beer, soft drinks, juices, coffee, alcohol).
Incident: Cyberattack Disrupts Refresco Production Systems in Germany
Refresco, a global beverage manufacturer, suffered a cyberattack. The incident affected production systems and the inflow and outflow of goods in Germany. Some manufacturing lines and logistics workflows were halted or slowed while systems were investigated and restored. Refresco responded by accepting customer orders via email while recovery of core systems was underway, indicating that automated order processing and production planning were affected. At time of reporting systems recovery is in progress, operational mitigation in place.
Refresco has a large global footprint (over 75 manufacturing sites and thousands of employees), making even localized production disruptions potentially significant for supply chains.
Reference: Refresco publishes Annual Report 2024
Victim: Refresco
Refresco is a major food and beverage contract bottler and manufacturer, producing soft drinks, juices and bottled water for global and national brands across Europe, North America and Australia from dozens of plants.
Reference: Refresco is ramping up deliveries again
Reference: ENISA confirms ransomware behind airport disruptions; delays at Heathrow, Brussels, Berlin continue
Reference: European airports continue to crawl after a cyberattack on Collins’ MUSE systems
Reference: European airports recover after cyberattack on Collins Aerospace check-in software
Reference: Flight delays continue across Europe after weekend cyber-attack
Reference: Cyber Incidents Take Off: Europe’s Airports Join a Growing List
Reference: European airports struggle to fix check-in glitch after cyberattack
Reference: Data I/O Issues Update on Cybersecurity Incident
Reference: Data I/O Issues Update on Cybersecurity Incident
Reference: FORM 8-K
Incident: Evergreen Printing Cyber Incident Causing Operational and Fulfillment Disruption
Evergreen Printing suffered a ransomware attack that disrupted its operations. In particular newspaper printing, subscriber fulfillment systems, and mailing operations were impacted. Affected customers were forced to rebuild mailing lists and deal with delays in press operations. The company activated its incident response plan and engaged outside experts to investigate and remediate the attack. Besides The Retrospect, no other Evergreen Printing customers have been publicly named.
Victim: The Retrospect
The Retrospect, local UK newspaper
Victim: Evergreen Printing Co.
Evergreen Printing Co., a printing and publication services company based in Bellmawr, New Jersey, USA,
Reference: The Retrospect’s Printer a Victim of a Ransomware Grinch
Reference: Ransomware at New Jersey printer disrupts newspaper mailings
Incident: Cyberattack at Engineering Services Firm, KMS Solutions
Alexandria, Virginia-based systems engineering provider, KMS Solutions, LLC, suffered a cyberattack in late November where personally identifiable information ended up stolen in the hack.
“KMS Solutions recently identified suspicious system activity and promptly initiated an investigation,” the company said in a letter to victims. “As part of our investigation, we learned that certain information within our systems was subject to unauthorized access or acquisition between November 27, 2025 and December 7, 2025.”
Upon discovery of the incident, KMS hired a third-party specialists to assist with understanding the nature and scope of the activity.
Reference: Engineering Services Firm Suffers Cyberattack
Victim: KMS Solutions, LLC
Alexandria, Virginia-based KMS Solutions is systems engineering, technical services, and consulting firm for the U.S. Navy. Furthermore, the company does perform some system integration, prototyping, and specialized equipment support related to defense systems, sometimes involving hardware and software development for defense applications. Additionally, they offer services like engineering, program management, logistics, testing, and cybersecurity, focusing on naval systems and components.
Incident: Cyberattack Disrupts Nigeria Customs Service Cargo Clearance Operations
The Nigeria Customs Service (NCS) suffered a cyberattack on its ICT platform, known locally as the “B’Odogwu” system. This platform is used to process cargo clearance and trade facilitation across Nigeria’s ports. The attack disrupted cargo clearance operations nationwide, effectively paralyzing the export/import workflow at major ports. It disabled the IT system that links customs data, port terminals, and clearance certifications.
The outage forced licensed customs agents, importers and freight forwarders to incur significant costs in the form of demurrage (storage) fees on containers that were delayed because they could not be cleared on time.
Victim: Nigeria Customs Service (NCS)
Nigeria Customs Service (NCS)
Reference: Cyber attack hits Customs, disrupts cargo clearance
Reference: Hacking of the ICT platform of the Nigeria Customs Service.
Reference: Bridgestone Confirms Cyberattack Disrupts Manufacturing Operations
Reference: Bridgestone Americas restores facilities’ network connections following cyberattack
Reference: Bridgestone Americas resumes operations after cyberattack; damage and supply chain impact remain unclear
Incident: ICS/OT Cyberattack Disrupts Operations at Tczew Hydropower Plant, Poland
A small hydropower plant near Tczew (in northern Poland, close to Gdańsk) was successfully breached in a cyberattack that disrupted its industrial control systems (ICS/OT).The attack disrupted the hydropower plant’s control systems, causing erratic turbine behavior, sudden stoppages, and periods of zero power output as attackers manipulated operational parameters. Unlike an earlier attempted breach in May 2025 (when the plant was offline and unaffected), the August incident was significant because it interfered with a functioning energy facility. There were no reported widespread blackouts in Poland due to this attack.
Incident: Cyberattacks on Poland’s Energy Infrastructure Successfully Prevented
On 29–30 December 2025, Poland’s energy sector came under a coordinated cyberattack targeting critical infrastructure, including combined‑heat‑and‑power (CHP) plants and systems controlling renewable energy generation such as wind and solar farms. The attackers sought to disrupt operational control systems, potentially affecting energy distribution, grid stability, and heating supply in key regions during winter.
Polish cybersecurity teams, energy operators, and government incident response units successfully repelled the attacks, preventing any blackouts or significant service interruptions. The incident required rapid isolation of affected control systems, verification of operational integrity, and enhanced monitoring of the national energy grid. Authorities noted that if the attack had been successful, it could have impacted hundreds of thousands of households and industrial facilities, demonstrating the high risk posed by cyber intrusions against energy ICS/OT systems.
Officials and cybersecurity analysts highlighted that the attack pattern and infrastructure targets suggest Russian‑linked actors, consistent with a series of hybrid warfare campaigns aimed at destabilizing critical infrastructure in Poland and Eastern Europe. The December attack underscored the vulnerability of energy networks to coordinated cyber operations, the importance of robust ICS/OT security, and the need for real-time threat detection and rapid incident response.
Reference: Russian Hackers Breach Polish Hydropower Plant in Major Cyberattack
Reference: Poland Stops Cyberattacks on Energy Infrastructure
Reference: Russian cyberattack disrupts Polish hydropower plant anew
Victim: Tczew Hydropower Plant
Tczew Hydropower Plant (small hydroelectric power station near Gdańsk, Poland)
Reference: Russian hackers target Polish hydropower plant again
Reference: COLABOR GROUP INC. PROVIDES AN UPDATE ON THE CYBERSECURITY INCIDENT
Reference: A damaging security breach for Colabor
Incident: Ransomware Attack Disrupts Operations at Canadian Food Distributor, Colabor Group
A cyberattack disrupted Colabor Group’s internal IT systems, halting automated order processing, warehouse and logistics operations, and delivery scheduling for several days. Manual workarounds allowed partial continuity, with full operational restoration by early August 2025. Employee data exposure prompted precautionary compliance measures.
Akira ransomware group is reported by some news outlets to have claimed the attack, unconfirmed by Colabor.
Reference: Colabor Group Inc. Provides an Update on the Cybersecurity Incident
Victim: Colabor Group Inc
Colabor Group Inc., a Canadian food distributor and wholesaler serving the hotel, restaurant and institutional (“HRI”) markets in Quebec and the Atlantic provinces, as well as retail customers.
Reference: A cyberattack paralyzes this large company in Maine-et-Loire: the factory is at a standstill.
Reference: A cyberattack has completely paralyzed a factory with 600 employees in France, who have been on temporary layoff since Thursday
Incident: Cyberattack Forces Production Halt at Wibaie Manufacturing in France
A cyberattack struck Wibaie, French manufacturer of windows and entrance doors, — in the night of 9–10 July 2025. The attack paralyzed the company’s IT systems and forced a complete halt of production at its Cholet plant. Machines, manufacturing lines and normal operations could not run due to lack of access to critical IT systems. The company isolated all network devices. All 600 employees were sent home while cybersecurity specialists and investigators worked to contain the breach.
No verified date for when full production resumed has been published at this time.
Victim: Wibaie
Wibaie is a French industrial manufacturer of fenestration products (windows, doors, shutters) based in Cholet, Maine-et-Loire, with about 600 employees — a key part of the local economy.
Reference: Cyberattack at Wibaie in Cholet: a look back at ten days of forced shutdown in the middle of summer
Reference: A cyberattack paralyzes this large company in Maine-et-Loire: the factory is at a standstill.
Reference: Inside the Ingram Micro Ransomware Attack: Lessons in Zero Trust
Reference: The Ingram Micro Ransomware Attack: Lessons Learned
Incident: Cyberattack Forces Temporary Production Disruption at Heim & Haus
Heim & Haus, one of Germany’s largest producers and direct sellers of building components, suffered a ransomware attack. The attackers gained unauthorized access to IT systems and encrypted data. The encrypted IT systems were taken offline immediately. Corporate networks, email, customer portals, and internal services were inaccessible for days. Production systems were restored and returned to full operational capacity by early July 2025, with communications channels (phone, email) reactivated soon after. A July 10 update stated core systems (customer portal, direct sales, assembly scheduling) were back online, though processing delays or restricted access could still occur for some services.
Reports indicate about 48 GB of internal information was exfiltrated and posted as proof by the ransomware group Kawa4096.
Threat Actor: Kawa4096
Kawa4096 is an organized ransomware threat actor that emerged in mid-2025, notable for double extortion tactics, data leak sites on Tor, partial encryption methods to maximize impact, and psychological coercion via branding mimicry, and it has already been linked to multiple international incidents.
Victim: Heim & Haus
Heim & Haus, one of Germany’s largest producers and direct sellers of building components such as windows, roofs, roller shutters, and awnings.
Reference: Cyberattack hits major manufacturer of components
Reference: Heim & Haus: Cyberattack on major manufacturer of building components
Reference: Current information on the IT security incident at HEIM & HAUS
Reference: Security incident at HEIM & HAUS (June 2025)
Incident: Cyberattack Temporarily Halts Production at Hero España Plant in Alcantarilla
Hero España — the Spanish subsidiary of the multinational food company Hero Group — reported that its computer systems were hit by an external cyberattack. The incident temporarily disrupted operations at its large production and logistics facility in Alcantarilla, Murcia, Spain. The company shut down compromised systems in a controlled manner to prevent further spread and protect data. Production at the Alcantarilla plant was completely stopped for a few days.
The company emphasized that the incident only affected its operations in Spain, not other divisions of Hero Group globally.
Reference: Hero suffers a cyberattack on its computer systems that affects its plant in Alcantarilla (Murcia)
Victim: Hero España [Hero Group]
Hero España is a Spanish food manufacturer, the parent Hero Group is multinational, Swiss‑based. Hero España is its Spanish subsidiary, which operates the Alcantarilla, Murcia plant and handles local production, distribution, and sales in Spain.
Hero Group is a global food company headquartered in Switzerland with operations in multiple countries. It produces jam, baby food, cereals, snacks, and other packaged foods and owns subsidiaries in Europe, North America, and other markets.
Reference: Cyberattack impacts Hero’s plant in Alcantarilla, Murcia
Reference: Multiple DFA Manufacturing Plants Experienced Ransomware Attack
Reference: U.S. ag hit by cyberattack
Incident: Siloking Manufacturing Stopped by Ransomware
Siloking Mayer Maschinenbau GmbH, a German agricultural machinery manufacturer, was hit by a cyberattack. The attack involved ransomware that encrypted IT systems and caused operational disruption across the company’s network. Production continued only in emergency mode after 5 days while systems were restored.
Victim: Siloking Mayer Maschinenbau GmbH
Siloking Mayer Maschinenbau GmbH, a German agricultural machinery manufacturer best known for feed mixers and livestock feeding technology headquartered in Tittmoning, Bavaria. A family-owned manufacturer with >500 employees and annual revenues in the tens to low hundreds of millions of euros
Reference: Production halted: Hackers attack Siloking
Reference: Siloking affected by ransomware attack
Incident: Cyberattack Forces Temporary Printing Halt at Roularta Media
Belgian Roularta Media Group was hit by a DDoS attack. The attack locked critical IT systems that controlled scheduling, workflow, and production management. Presses could not operate normally until the systems were restored. The disruption affected the timely processing of newspapers and magazines such as Knack and Libelle. The impact is limited however, some Knack readers will receive their magazine a day later.
Reference: Limited disruption after DDoS attack on Roularta
Victim: Roularta Media Group i
Roularta Media Group is a major Belgian media company,
Reference: DDoS Disrupts Roularta Media In Belgium
Reference: Amazon’s Whole Foods Distributor United Natural Foods Hit by a Cyber Attack that Disrupted Operations
Reference: Cyberattack Alters Food Distributor’s Operations
Incident: Dragonforce Ransomware Locks Local Norwegian Newspaper Servers, Printing Halted
Norwegian regional newspaper Altaposten and its sister publication Ávvir were hit by a ransomware attack. The ransomware locked key IT resources, including the server shared by both newspapers, and prevented staff from accessing content and publishing normally. The media outlet’s owners refused to pay the ransom. Management stated it was more cost‑effective to discard the affected server and rebuild rather than follow the attackers’ instructions to retrieve decryption keys. The printed edition of Altaposten was canceled — the first time since the paper’s launch in 1969.
Victim: Ávvir
Ávvir is a Sami-language newspaper serving the indigenous Sami community in Norway, focusing on culture, language, and local news relevant to Sami readers.
Victim: Altaposten
Altaposten: A regional Norwegian newspaper based in Alta, covering local news, events, and regional developments in Finnmark county.
Reference: Altaposten Hit by Dragonforce Ransomware
Malware: Dragonforce
Dragonforce is a malware/ransomware variant that encrypts files on targeted systems and demands payment for a decryption key.
Incident: Wellteam Packaging Production Stops After Cyber Incident
Wellteam, a German packaging manufacturing company, was hit by a significant cyberattack. The attack affected internal communications, halted machinery and transport systems, and forced the company to send employees home due to the inability to continue production. Production was brought to a standstill at all three Wellteam locations.
Victim: Wellteam
Wellteam is a German packaging manufacturing company,
Reference: Hacker attack on German cardboard specialist Wellteam
Reference: Cyberattack temporarily paralyzes production at Wellteam
Reference: A ransomware attack pushed the German napkin firm Fasana into insolvency
Reference: Arla cyber-hit plant nears “normal” operations
Reference: Arla factory in Germany hit by cyber incident
Incident: GPS Spoofing Forces MSC Antonia Aground in Red Sea
On 10 May 2025, Liberian‑flagged container ship MSC Antonia ran aground in the Red Sea. The ship was en route from Marsa Bashayer, Sudan, to Jeddah, Saudi Arabia. Multiple maritime intelligence analyses have determined that the grounding was caused by deliberate GPS/GNSS interference — including spoofed and jammed signals. The interference misled the vessel’s navigation and AIS positioning systems. The Antonia remains aground as of mid‑May 2025, with efforts underway to refloat the vessel. All crew members were reported safe, with no injuries from the accident.
Victim: Mediterranean Shipping Company (MSC)
Mediterranean Shipping Company (MSC)
Reference: Cyber-physical risk in the marine sector: a wake-up call from the MSC Antonia
Reference: Pole Star Confirms GPS Interference Caused MSC ANTONIA Grounding
Incident: Ransomware Strikes Peter Green Chilled, Threatening Supply Chain
Peter Green Chilled, a UK food logistics and cold‑chain distributor, was hit by a ransomware cyberattack. The incident disrupted the company’s ability to process new orders and forced it to warn customers of the breach. The company acknowledged that order processing had been paused, though it maintained that transport operations continued during the disruption. The attack had immediate supply‑chain consequences: suppliers reported stock sitting idle in warehouses and at ports, risking spoilage and financial loss if products could not be delivered to retailers in time.
No ransomware group has publicly claimed responsibility.
Victim: Peter Green Chilled
Peter Green Chilled is a Somerset‑based food logistics and cold‑chain distributor supplying chilled and fresh products to major UK supermarkets such as Tesco, Sainsbury’s and Aldi.
Reference: Ransomware attack on food distributor spells more pain for UK supermarkets
Reference: Ransomware attack hits supplier of refrigerated groceries to British supermarkets
Reference: Everything we know about the Peter Green Chilled cyber attack
Reference: Retail cyber attacks hit food distributor Peter Green Chilled
Reference: Hacking US crosswalks to talk like Zuck is as easy as 1234
Reference: Hacked crosswalk buttons play spoofed voices of tech billionaires
Reference: Silicon Valley crosswalk buttons hacked to imitate Musk, Zuckerberg’s voices
Incident: Crosswalk Audio Hijacked Across US, Spoof Messages Spread on Social Media
Audio‑enabled crosswalk buttons in several U.S. cities were reprogrammed to play AI‑generated voices impersonating tech billionaires (e.g., Jeff Bezos, Elon Musk, Mark Zuckerberg) instead of the normal “walk”/“wait” prompts. The issue stemmed from poorly secured devices and a publicly available configuration app, making it easy for pranksters to connect via Bluetooth and inject custom audio.
Incident: Cybersecurity Breach Temporarily Halts IPEN Radioisotope Production
The Brazilian research Instituto de Pesquisas Energéticas e Nucleares (IPEN) in São Paulo suffered a cyberattack. IPEN/CNEN temporarily halted the production and supply of critical radioisotopes and radiofármacos, substances used across Brazil for medical diagnostics and cancer treatments. Production resumed in early April. Officials emphasized that the physical, radiological, and nuclear safety of the institute’s facilities was not compromised at any point.
Reference: CLARIFICATION NOTE TO THE PUBLIC – CYBER INCIDENT AT IPEN/CNEN
Reference: IPEN/CNEN announces the temporary suspension of the production and supply of radiopharmaceuticals.
Victim: Instituto de Pesquisas Energéticas e Nucleares (IPEN/CNEN)
Instituto de Pesquisas Energéticas e Nucleares (IPEN/CNEN) in Brasil
Victim: Kuala Lumpur International Airport (KLIA)
Kuala Lumpur International Airport (KLIA)
Incident: Crystal D Hit by Cyberattack, Orders Delayed
In early March 2025, Crystal D, a U.S. supplier of crystal awards and gifts, experienced a cyberattack that disrupted its operations, knocking out communications and internal systems. The attack caused phone and email systems to go offline and interrupted order processing and scheduled shipments for a number of days. Approximately 3% of orders were delayed during multi-day production shutdown.
Victim: Crystal D
Crystal D is a U.S. supplier of crystal awards and gifts based in St. Paul, Minnesota
Reference: After Cyberattack, Crystal D Fully Operational Again
Reference: Adval Tech Cyberattack Disrupts Operations
Incident: 800 GB Databreach at German Manufacturer Stürmer Maschinen
The wholesaler Stürmer Maschinen became the target of a ransomware attack. The ransomware gang Lynx claim to have subtracted a data set of 800 gigabytes. It is unclear exactly which data it is. There is no information on the ransom claim and deadline. Stürmer Maschinen has not yet officially commented on the incident.
Victim: Stürmer Maschinen
Stürmer Maschinen currently employs around 280 people at the Hallstadt and Pettstadt locations. The group of companies supplies machines from the fields of metalwork and woodworking, compressed air and welding technology as well as cleaning and workshop technology. Customers include dealers throughout Germany as well as in over 20 European and more than 40 non-European countries.
Reference: Stürmer Maschinen hit by ransomware attack
Reference: Ganong Bros. says it’s investigating cybersecurity incident
Incident: Italian Furniture Company Alf DaFrè Shuts down Factories After Cyberattack
Italian furniture company Alf DaFrè was hit by a ransomware attack. The hackers encrypted company data and disabled computers and machinery, affecting the production chain. An estimated 15 per cent of the company’s IT infrastructure was compromised. The company decided not to pay the ransom. It shut down the entire IT system to avoid further damage.
Production was shut down and employees were laid off for 8 days.
Reference: Treviso, hacker attack on Alf DaFrè furniture company: 350 workers end up on lay-off
Victim: Alf DaFrè
Italian furniture company Alf DaFrè, a historic manufacturer of modular and customisable furniture.with offices in Cordignano and Francenigo di Gaiarine.
Reference: Treviso, hacker attack on Alf DaFrè furniture company: 350 workers end up on lay-off
Incident: Sault Tribe Cyberattack Forces System Shutdowns
In February 2025, the Sault Ste. Marie Tribe of Chippewa Indians in Michigan was hit by a major ransomware cyberattack that forced the shutdown of computer and phone systems across tribal government offices, health centers, businesses and all five of its Kewadin Casinos beginning February 9, 2025. Tribal leaders immediately took systems offline, engaged cybersecurity experts, and refused to pay the hackers’ ransom demand, opting instead to restore operations and strengthen IT defenses. The phased reopening of the casinos began on February 26, 2025, and most services were restored in the following weeks, though some health and administrative functions continued under limited capacity during forensic review.
Victim: Sault Ste. Marie Tribe of Chippewa Indians
Sault Ste. Marie Tribe of Chippewa Indians in Michigan
Reference: Ransomware attack disrupting Michigan’s Sault Tribe operations
Reference: After cyberattack, Sault tribe tells members, employees to secure personal data
Reference: Sault Tribe leaders say they won’t pay ransom after cyber attack, casinos reopen in stages
Reference: Sault Tribe Gives Update On February Ransomware Attack
Incident: Ransomware Attack at London Literary Agency
The Agency, a London-based literary and talent agency, disclosed a ransomware attack. The incident caused significant disruption to its IT systems. The Agency informed clients that personal and internal data may have been accessed or copied during the breach, reported the incident to the UK Information Commissioner’s Office. No public confirmation that any stolen data was released by the hackers responsible for the attack.
Reference: Security Provider, CPI, Suffers Cyberattack
Reference: Lee Enterprises Reports Second Quarter Results May 8, 2025
Reference: More than 75 Lee Enterprises newspapers affected by cyberattack
Reference: Lee Enterprises spent $2M for ransomware recovery
Incident: Teen Hacker Accused of Breaking Into Education and Maritime Systems
A 15-year-old logged into a portal that controls the routes of oil tankers and transport ships in the Mediterranean Sea, changing some routes. The teenager was referred to youth justice in Italy.
Reference: Cesena, 15-year-old hacker discovered: he diverted ships in the Mediterranean and altered his grades on the ministry’s website. But Rome denies the allegations
Incident: Cyberattack on Russia’s Mercury System Halts Food Shipments, Disrupts Supply Chain
Rosselkhoznadzor’s digital systems (including VetIS and its Mercury platform) were targeted by a large‑scale DDoS attack beginning on October 22, 2025, which disrupted food shipments and the issuance of electronic veterinary certificates for meat, dairy and baby food products. The production movement was paralyzed for half of the day, one company manager said, adding that the lack of an emergency procedure allowing shipments without digital paperwork led to financial losses. Rosselkhoznadzor denied reports of prolonged disruptions, saying that the Mercury system was operating “as usual.”
In June 2025, a similar incident forced dairy producers to revert to paper-based certification, creating logistical chaos.
Reference: Russian Rosselkhoznadzor hit by DDoS attack, food shipments across Russia delayed
Reference: Cyberattack on Russia’s food safety agency reportedly disrupts product shipments
Reference: Ransomware Attack At IT Distributor
Victim: Russia’s Federal State Information System for Veterinary Surveillance (VetIS)
Russia’s Federal State Information System for Veterinary Surveillance (VetIS) is part of Rosselkhoznadzor, the Federal Service for Veterinary and Phytosanitary Surveillance in Russia.
Incident: Cyberattack Grounds Aeroflot Flights, Russia’s Largest Airline.
Russian airline Aeroflot was forced to cancel more than 50 round-trip flights, disrupting travel across the country. Two pro-Ukraine hacking groups claimed to have inflicted a crippling cyberattack.
A statement purporting to be from a hacking group called Silent Crow said it had carried out the operation together with Belarusian Cyberpartisans. The hackers claim to have erased 7,000 IT servers and gained control over the personal computers of employees, including senior managers.
Reference: Russian airline Aeroflot grounds dozens of flights after cyberattack
Threat Actor: Silent Crow
Silent Crow is a pro‑Ukraine hacktivist group that became publicly active in late 2024 and has conducted multiple politically motivated cyberattacks against Russian state and corporate infrastructure. Operating in the context of the Russia–Ukraine conflict, the group’s actions are primarily intended to apply political pressure and disrupt adversary capabilities rather than for financial gain.
Threat Actor: Belarusian Cyberpartisans
Belarusian Cyberpartisans is a self-styled hacktivist group that opposes president Alexander Lukashenko and says it wants to liberate Belarus from dictatorship.
Victim: Aeroflot
Aeroflot, Russian Airline
Reference: Pro-Ukrainian hackers claim massive cyberattack on Russia’s Aeroflot
Reference: Ransomware Incident Disrupts Russian Vodka Maker
Incident: Cyberattack Slows Russia’s Drone Weaponization Effort
In July 2025, a cyberattack halted Russia’s drone weaponization network, disrupting the distribution of custom firmware that converts commercial drones into weapons and forcing hundreds of modification centers to pause operations. The attack marked a rare publicly reported cyber disruption of a militarily significant network.”
The attack impacted the volunteer group Russian Hackers for the Front, hundreds of drone modification centers, and Russian military operators reliant on the disrupted weaponized drone network
Victim: Russian Hackers for the Front
Russian Hackers for the Front
Reference: Hackers Disrupt Russia’s Drone Weaponization Network
Incident: Russia’s Food Logistics Paralyzed by Cyberattack
A cyberattack disrupted Russia’s dairy supply by taking offline the Mercury veterinary certification system, a government platform required to authorize the movement of animal-based products. The outage prevented producers from issuing mandatory electronic certificates, forcing a temporary switch to paper documentation. The workaround led to delays as many warehouses and retailers refused shipments without digital verification, causing logistical bottlenecks and supply interruptions.
The broader food supply chain was affected by the attack: dairy producers, livestock product suppliers, logistics operators and major retailers such as Lenta, Miratorg and Yandex Lavka, which were unable to issue mandatory electronic veterinary certificates and thus saw deliveries delayed or halted.
Victim: Rosselkhoznadzor, (food safety agency)
Rosselkhoznadzor is Russian government’s food safety agency
Reference: About the emergency operation mode of the Mercury system
Reference: Hackers Disrupt Russia’s Food System and Officials Pretend Nothing Happened
Reference: Russian dairy supply disrupted by cyberattack on animal certification system
Incident: Cyberattack hits Operator of Russia’s Platon Toll-collection System.
Russia reported a major cyberattack on the truck driver service "Platon." Its website is down throughout the country, route maps aren't being generated and trucks are parked.
Platon is operated by RT-Invest Transport Systems LLC under concession from the Russian federal government.
Victim: RT-Invest Transport Systems LLC
RT-Invest Transport Systems LLC (Russian: ООО «РТ-Инвест Транспортные Системы» / RTITS) is a private company that holds the concession to run the Platon toll collection system under a 13-year agreement with the Russian Federal Road Agency.
Victim: Platon
"Platon" is a Russian state-run toll collection system for trucks with a permitted maximum weight of over 12 tonnes. The system's revenues are used to maintain federal roads and road infrastructure.
Reference: A large-scale cyberattack on the truck driver service “Platon” in Russia: details revealed
Incident: Russian Alcohol Industry Disrupted by Cyberattack on Government-run Tracking System
A volunteer hacker group coordinated by Ukraine successfully disrupted aspects of the Russian alcohol industry by targeting EGAIS, a government-run digital accounting system for tracking alcohol production and sales in Russia. Several private companies reported operational disruptions because EGAIS was unavailable.
-The glitch resulted in the suspension of operations at the Moscow Brewing Company. The MPC plant, with a capacity of 80 million decaliters per year and bottling approximately 90,000 cans per hour, suspended production on May 5.
-Fort (a wine trading company) — reportedly failed to upload about 70% of its transaction invoices during the outage, causing shipment delays.
-Ladoga — another wine producer/distributor, also experienced significant backlogs in processing documents.
-Other market participants have anonymously reported production shutdowns.
Victim: Ladoga
Ladoga , Russian wine producer/distributor,
Victim: Fort
Fort is a Russian wine trading company.
Victim: EGAIS
EGAIS, a government-run digital accounting system for tracking alcohol production and sales in Russia.
Reference: DDoS Attacks by Hacktivists Disrupted Russian Alcohol Supply Chain
Reference: EGAIS has experienced a series of failures.
Victim: Moscow Brewing Company
Moscow Brewing Company plant has a capacity of 80 million decaliters per year and bottles approximately 90,000 cans per hour.
Reference: Pro-Ukrainian hackers boast success in disrupting Russian alcohol industry with DDoS attacks
Incident: Cyberattack Shutdown Russian Oil Giant Lukoil
Cyberattack hit Russian oil giant Lukoil resulting in a complete shutdown of internal systems and caused disruptions across several regions, including corporate offices and gas stations. Lukoil’s management instructed employees via SMS to shut down all work computers after an unusual error message showed on many computers. The attack resulted in partial halt in fuel distribution to gas stations & other consumers for several days.
Reference: Russian Lukoil Hit by Major Cyberattack, Disrupting Operations Nationwide
Reference: Russian Lukoil hit by large-scale cyberattack
Incident: Marine Electronics Manufacturer, Furuno, Hit in Ransomware Attack
Camas, Washington-based marine electronics manufacturer, Furuno U.S.A., Inc. suffered a ransomware attack in September where threat actors made off with personally identifiable information during the hack.
“On September 15, 2025, Furuno U.S.A., Inc. identified unauthorized access to certain of its computer systems,” Furuno said in an advisory. “Upon identifying the incident, Furuno immediately took steps to secure its environment and launched an investigation. A third-party cybersecurity firm was engaged to assist.”
Through the investigation, Furuno found an unauthorized actor viewed and/or obtained certain files stored on its computer servers between September 12 and September 15.
Reference: Ransomware Attack At Marine Electronics Manufacturer
Victim: Furuno USA
Furuno USA, Inc. is a subsidiary of Furuno Electric Co., Ltd. Since its inception in 1948, when the world’s first fish finder ended up commercialized, Furuno developed various types of marine electronics. Today, Furuno is a marine electronics manufacturer operating on a global scale.
Incident: Audio Product Maker Suffers Cyberattack
High-end audio equipment maker, McIntosh Laboratory, Inc. suffered a cyberattack in October which disrupted access to various systems within the network.
“On October 21, 2025, McIntosh detected suspicious activity and experienced a disruption of access to certain of our digital systems,” the company said in a notice to victims. “In response, we took immediate steps to secure our network and engaged forensic experts to investigate.”
Based on the investigation, McIntosh found the attacker accessed and acquired certain data between October 17 and 19.
Reference: Audio Product Maker Suffers Cyberattack
Victim: McIntosh Laboratory, Inc.
Binghamton, New York-based McIntosh Laboratory is a manufacturer of handcrafted high-end audio equipment. It is a subsidiary of the McIntosh Group, which the audio equipment giant, Bose Corporation, acquired in November 2024.
Incident: Cyberattack Hits Fluid Handling Provider, HydroServe
Chelmsford, Massachusetts-based HydroServe LLC, doing business as Gustavo Preston Company, suffered a cyberattack in October where personally identifiable information ended up stolen in the hack.
“On October 14, 2025, Gustavo Preston identified suspicious activity on certain computer systems,” according to a letter to victims of the attack. “Gustavo Preston immediately took steps to secure its systems and launched an investigation into the nature and scope of the activity.”
As a result of its investigation, Gustavo Preston found an unknown actor gained access to certain computer systems between October 6, 2025 and October 14, 2025 and was able to view or download certain data.
Reference: Fluid Handling Provider Hit In Cyberattack
Victim: HydroServe LLC, doing business as Gustavo Preston Company
Chelmsford, Massachusetts-based HydroServe LLC, doing business as Gustavo Preston Company, s a manufacturer by designing, engineering, and assembling custom fluid handling systems (like packaged booster & fire pumps), while also distributing major brands and providing extensive service/repair for building trades, essentially being a hybrid solution provider, systems integrator, and distributor.
Incident: Cyberattack at Pharma Product Maker, Researcher, Chiesi USA
Cary, North Carolina-based Chiesi USA, Inc., a pharmaceutical manufacturing and researcher, suffered a cyberattack in August where personally identifiable information ended up stolen in the hack.
“On August 28, 2025, we learned of potential unauthorized access to our U.S.-based systems,” the company said in a letter to victims of the attack. “We launched our investigation in partnership with third-party cybersecurity specialists to determine the nature and scope of the incident and activated our remediation and recovery efforts.”
After the investigation wrapped up, Chiesi determined an unauthorized third party accessed certain information maintained on its U.S.-based systems. Additionally, the company said this access was the result of an IT security issue that impacted part of its internal IT infrastructure.
Reference: Pharma Product Maker, Researcher Suffers Cyberattack
Victim: Chiesi USA, Inc.
Cary, North Carolina-based Chiesi USA, Inc., as part of the global Chiesi Group, takes part in pharmaceutical manufacturing, developing, marketing, and distributing therapies. Furthermore it has a focus on areas like respiratory health, rare diseases, neonatology, and special care, leveraging R&D and production investments. To that end, while they focus heavily on R&D and commercialization, the larger group engages in significant manufacturing activities.
Incident: Cyberattack at Medical Instrumentation Maker, Cytek Biosciences
Fremont, California-based medical instrumentation maker, Cytek Biosciences, Inc., suffered a cyberattack in November which resulted in threat actors stealing personally identifiable information in the hack.
“Cytek Biosciences experienced a data security incident involving unauthorized access to certain of our systems that occurred on or around November 1, 2025,” the company said in a letter to victims. “Based on our investigation, we learned on or around November 28, 2025, that, in connection with this issue, an unauthorized party obtained certain of your personal information.”
The information varied by affected individual and may have included, to the extent provided to Cytek, name, contact information (e.g., postal address, email address, and phone number), date of birth, Social Security number, driver’s license number, government-issued ID number, citizenship status, signature, health and medical information, financial account and compensation information, as well as Cytek employee account username and password.
Reference: Medical Instrumentation Maker Suffers Cyberattack
Victim: Cytek Biosciences, Inc.
Cytek Biosciences Inc. is a manufacturer and supplier of flow cytometry products and services. Furthermore, Cytek’s instruments and support offerings end up used by researchers and clinicians all over the world. Flow cytometry is an analytical tool used for identifying and quantifying cellular characteristics on a cell-by-cell basis up to tens of thousands of cells per second. This technology sees use in research and clinical studies with various biomedical and therapeutic applications such as investigating the role of the body’s immune system in fighting cancer, diagnosing leukemia and lymphoma, and detecting minimal residual disease in organ transplant patients.
Incident: Medical Researcher, Manufacturer Hit In Cyberattack
West Lafayette, Indiana-based Inotiv, Inc., a medical researcher and maker of products, suffered a cyberattack in August and is now letting victims know their personally identifiable information ended up stolen.
Inotiv, Inc. is a contract research organization that provides nonclinical and analytical drug discovery and development services and research models and related products and services.
“On August 5, 2025, we detected unusual activity on certain Inotiv systems and promptly initiated an investigation,” the company said in a notice to victims of the attack. “On August 8, 2025, we determined that this unusual activity was due to unauthorized actions by a threat actor.”
Reference: Medical Researcher, Manufacturer Hit In Cyberattack
Victim: Inotiv, Inc.
West Lafayette, Indiana-based Inotiv is a manufacturer primarily of research-related products like lab animal diets, bedding, and supplies. Furthermore, it is also a major contract research organization (CRO) providing drug development services, including manufacturing and testing services for preclinical phases. Additionally, they manufacture essential items like custom diets and bedding and also produce biological products from their own research models for drug research.
Incident: Engineering Firm, Pickett and Associates, Attacked, Stolen Info For Sale
A Tampa, Florida-based civil engineering, surveying, and geospatial services firm for utilities and mining operations, suffered a cyberattack and had sensitive client data stolen.
Threat actors posted a new thread on a dark web forum Monday claiming to have stolen more than 800 files from the engineering firm, Pickett and Associates, according to a report from Tech Radar. The data is “real, operational engineering data from active projects of major utilities and is suitable for infrastructure analysis and risk assessment,” the attackers said on their site.
The attacker in this case is Zestix, which also has links to the online persona Sentap, according to Hudson Rock, which specializes in cybercrime intelligence, safeguarding against infostealer-based cyberattacks. The threat actor is an initial access broker (IAB) which also exfiltrates victim data and sells it on hacker forums.
Reference: Engineering Firm Attacked, Stolen Info For Sale
Threat Actor: Zestix
Zestix emerged as a distinct entity in late 2024-early 2025, but its activities link to Sentap operations that have been ongoing since 2021.
Victim: Pickett and Associates
Pickett and Associates is a Tampa, Florida-based civil engineering, surveying, and geospatial services firm for utilities and mining operations.
Incident: BTU International Suffers Ransomware Attack
Westford, Massachusetts-based BTU International, a thermal processing equipment provider, suffered a ransomware attack on April 11, 2021. DarkSide ransomware group took credit for the attack.
Reference: Ransomware Attack At Thermal Processing Equipment Maker
Victim: BTU International
Westford, Massachusetts-based BTU International BTU International is a wholly-owned subsidiary of Amtech Group. It is a global supplier of advanced thermal processing equipment solutions in the electronics manufacturing market. To that end, BTU’s convection reflow ovens end up used in the production of SMT printed circuit board assemblies and in semiconductor packaging processes.
BTU also specializes in precision controlled, high-temperature belt furnaces for a wide range of custom applications. Moreover, those applications include, brazing, direct bond copper (DBC), diffusion, aluminum sintering and advanced solar cell processing. Furthermore, BTU has operations in Westford, and Shanghai, China.
Incident: Ransomware Attack at Cabinets 2000
Norwalk, California-based cabinet maker, Cabinets 2000, suffered a ransomware attack in October.
In the Cabinets 2000 hack, the ransomware group called blackshrantac took credit for the attack.
“On October 15, 2025, we learned that certain files on the computer network were locked by a computer virus,” the company said in a letter to victims. “In response, we took our systems offline and securely restored them, and we reviewed this matter further to determine what occurred.”
The company learned some files on the computer network ended up copied without permission between October 2 and 3.
Reference: CA Cabinet Maker Suffers Ransomware Attack
Threat Actor: BlackShrantac
BlackShrantac ransomware group is a new and sparsely documented threat actor, believed to have emerged in 2025. Indicators suggest it is part of the ongoing wave of short-lived or rebranded ransomware operations that often appear as law-enforcement pressure disrupts established groups.
BlackShrantac follows the now-standard double extortion model, encrypting victim systems while threatening to leak stolen data if the victim does not meet ransom demands. To that end, targets appear to be small to mid-sized organizations. Attacks focus on maximizing operational disruption rather than long-term persistence.
Victim: Cabinets 2000
Norwalk, California-based cabinet maker, Cabinets 2000 produces a range of cabinet and kitchen décor products, including cabinet doors, various finish options, cabinet pulls and knobs, decorative accent elements, and more. Cabinets 2000 operates a 100,000+ square foot facility. The company started up in Founded in 1989.
Incident: Ransomware Attack at Medical Device Maker, Designs for Vision
Bohemia, New York-based custom medical manufacturer, Designs For Vision Inc., suffered a ransomware attack in October and discovered it in December.
On November 3, the ransomware group Akira claimed responsibility for the attack on Designs for Vision, Inc., a leading optical solutions provider based in the United States.
As a result of the hack, the attackers threatened to release 50GB of sensitive data unless their demands end up met. “We will upload about 50gb of corporate documents soon,” Akria attack group said on a web page regarding the Designs for Vision attack. “Lots of project information, a bit of personal information, credit cards de tails and other financial and accounting information, contracts and agreements, NDA, etc.”
Designs For Vision experienced the attack between October 11, 2025, and October 13.
Reference: Medical Device Maker Hit By Ransomware
Victim: Designs for Vision Inc.
Bohemia, New York-based custom medical manufacturer, Designs For Vision Inc. is a custom manufacturer of surgical telescopes, dental telescopes, surgical headlights and dental headlights. Designs for Vision also manufactures optical devices for the partially sighted.
Incident: BK Technologies Hit in Ransomware Attack
Communications equipment maker, Melbourne, Florida-based BK Technologies suffered a cyberattack in September and it appears a ransomware attack group is taking credit for the hack.
“On or about September 20, 2025, BK Technologies Corporation detected potentially suspicious activity involving its information technology (“IT”) systems,” according to the 8-K report with the Securities and Exchange Commission (SEC). “Upon detecting the issue, the company began taking steps to assess, contain, and remediate the potentially unauthorized activity, including isolating the affected systems and launching an investigation with the assistance of external cybersecurity advisors.”
As a result of the incident, a limited number of non-critical systems experienced minor disruption.
Reference: Ransomware Group Takes Credit For BK Technologies Attack
Victim: BK Technologies
BK Technologies specializes in critical communications equipment, primarily two-way radios and software for military, public safety, and government agencies. The company manufactures and distributes its products globally under the BK Radio brand and offers a range of portable and mobile radios, repeaters, base stations, and accessories. In addition to hardware, they provide cloud-based software solutions like InteropONE, a push-to-talk-over-cellular (PTToC) service for smartphones.
Incident: Cyberattack At Organic Personal Care Products Maker
Johnston, Rhode Island-based organic personal care products maker, Pure Haven, LLC, suffered a cyberattack last month where personally identifiable information ended up stolen by threat actors.
The company identified potentially suspicious activity related to an internal account on September 2.
“Upon discovery we took immediate action to address and investigate the activity, including performing a password reset and engaging third-party specialists to assist in conducting a full investigation,” the company said in a letter to victims of the attack. “Through our investigation, on or around September 5, 2025, we determined that an unauthorized individual may have accessed or acquired certain information on September 2, 2025.”
Reference: Cyberattack At Organic Personal Care Products Maker
Victim: Pure Haven, LLC
Johnston, Rhode Island-based organic personal care products maker, Pure Haven, LLC is a private company founded in 2009, manufactures and sells non-toxic personal care, cleaning, and baby products. The company, acquired by Global Ventures Partners in 2016, produces products at its USDA-certified organic facility, emphasizing safety and effectiveness. Products include shampoos, skincare, cleaning supplies, and essential oils, formulated to avoid harmful chemicals and use plant-based ingredients.
Incident: Cyberattack at MA Security Provider, LAN-TEL Communications
Norwood, Massachusetts-based communications and security provider, LAN-TEL Communications, Inc. suffered a cyberattack this past July and notice is now going out to victims of the hack.
The breach occurred July 11, when an external system suffered compromise through a hack attack. As it turns out, the situation ended up discovered over two months later on September 23.
The company sent out written notifications to victims of the attack on October 9, informing them of the breach and the potential risks associated with it.
Reference: MA Security Provider Hit In Cyberattack
Victim: LAN-TEL Communications, Inc.
Norwood, Massachusetts-based communications and security provider, LAN-TEL Communications, Inc. provides state-of-the-art communications and security solutions for private and public sector customers across all market segments in the New England area. The company configures, installs, and provides ongoing service and maintenance for the following solutions: Structured cabling for voice, data and video services; integrated security systems – video surveillance, access control and intrusion; fiber optics; air blown fiber; audio visual systems; paging and clock systems; wireless LAN/distributed antenna systems; Speech Privacy, and IT infrastructure.
Incident: Cyberattack at Security Provider F5
Cybersecurity provider, F5 Inc. suffered a nation-state cyberattack where source code ended up exfiltrated from its networking product suite, BIG-IP, this past August and per Department of Justice approval, delayed notification of the hack until Wednesday.
“On August 9, 2025, F5, Inc. learned that a highly sophisticated nation-state threat actor had gained unauthorized access to certain company systems,” the company said in 8-K report to the Securities and Exchange Commission (SEC) filed Wednesday, October 15. “The company promptly activated its incident response processes, and has taken extensive actions to contain the threat actor. To support these activities, the company engaged leading external cybersecurity experts.”
In the SEC report, F5 said, “during the course of its investigation, the company determined that the threat actor maintained long-term, persistent access to certain F5 systems, including the BIG-IP product development environment and engineering knowledge management platform,” the company said. “Through this access, certain files were exfiltrated, some of which contained certain portions of the Company’s BIG-IP source code and information about undisclosed vulnerabilities that it was working on in BIG-IP.”
Reference: CISA Directs Fed Agencies To Mitigate F5 Issues
Reference: Security Provider F5 Hit In Cyberattack
Victim: F5 Inc.
Seattle, Washington-based F5 specializes in application security, multi-cloud management, online fraud prevention, application delivery networking, application availability and performance, and network security, access, and authorization. Meanwhile, the company had over $2.8 billion in revenues for its last fiscal year.
Reference: Jaguar Begins Phased Restart After Cyberattack Shuts Operations
Incident: Road Products Maker, All States Materials Group, Hit in Cyberattack
West Springfield, Massachusetts-based road materials maker, All States Materials Group, Inc., suffered a cyberattack where threat actors made off with personally identifiable information from victims.
“During the early morning of August 25, 2025, All States Materials Group (ASMG) identified suspicious behavior indicating unauthorized activity was occurring on our network,” the company said in a letter to victims. “All States Materials Group immediately contacted Blue Mantis, ASMG’s independent cybersecurity investigation and recovery vendor, to provide assistance.”
Blue Mantis was able to quickly secure servers from further unauthorized activity and then began an independent cybersecurity analysis.
Reference: Cyberattack At Road Products Maker
Victim: All States Materials Group, Inc.
West Springfield, Massachusetts-based road materials maker, All States Materials Group, Inc. provides a diverse range of products and solutions for the liquid asphalt, paving and road construction industries. The company’s construction materials supply capabilities include liquid asphalt (standard grades, polymer modified, asphalt rubber, and specialty grades), asphalt emulsion, specialty additives and performance products, construction aggregates, hot mix asphalt, and redi-mix concrete.
Incident: Medical Device Maker, Tekni-Plex, Hit in Cyberattack
Wayne, Pennsylvania-based medical device maker, Tekni-Plex, Inc. suffered a cyberattack in August 2024 and is now informing victims of the attack.
“On November 18, 2024, TekniPlex identified suspicious activity on its computer network,” the company said in a letter to victims. “TekniPlex then determined that an unauthorized actor accessed their network at various times between October 25, 2024, and December 7, 2024, and that certain files ended up accessed and/or copied by the actor without authorization.
Upon determining this information, TekniPlex started up a comprehensive and time-intensive review of the involved data, with the assistance of third-party subject matter specialists, to assess the types of data that ended up impacted. They also sought out who the information belonged to.
Reference: Cyberattack At Medical Device Maker
Victim: Tekni-Plex, Inc.
Wayne, Pennsylvania-based medical device maker, Tekni-Plex, Inc. is a globally integrated company that provides solutions through materials science and manufacturing technologies. The company operates in the healthcare and consumer product markets. TekniPlex provides medical device components and a multitude of materials science solutions. The company operates in the healthcare, pharmaceutical, beauty and personal care, household, and food and beverage markets. It has 9,000 employees globally throughout its operations in Belgium, Brazil, Canada, China, Colombia, Costa Rica, Germany, India, Italy, Mexico, Northern Ireland, and the United States.
Incident: Cyberattack at Cybersecurity, IT Provider, Business Integra Technology Solutions
Bethesda, Maryland-based IT and cybersecurity solution provider, Business Integra Technology Solutions, Inc., suffered a data breach where attackers made off with personally identifiable information.
Business Integra Technology Solutions, Inc. suffered a cyberattack in August, the company said in a notice to victims.
“On August 23, 2025, Business Integra experienced a network disruption and immediately began investigating with the assistance of independent cybersecurity experts,” the company said. “As a result of the investigation, we determined that certain files ended up potentially acquired without authorization.”
Reference: Cybersecurity, IT Provider Hit In Attack
Victim: Business Integra Technology Solutions, Inc.
Bethesda, Maryland-based IT and cybersecurity solution provider, Business Integra Technology Solutions, Inc.'s core IT competency areas include program and project management, agile software development, cybersecurity, ICAM, cloud computing, and IT operations and maintenance. The company has a special scientific and aeronautic engineering division. Moreover, that division supports NASA – including the Hubble Telescope and the International Space Station. Additionally, it lso has a special mission support division that services clients including the Department of State and NATO.
Incident: Georgetown Brewing Suffers Cyberattack
Seattle, Washington-based Georgetown Brewing Company suffered a cyberattack where attackers were able to steal personally identifiable information.
Georgetown Brewing discovered a data security event may have resulted in limited unauthorized access to or disclosure of certain personal identifying information in our possession.
“On August 22, 2025, we discovered that a threat actor had gained unauthorized access to our servers,” the company said in a letter to victims. “We immediately launched an investigation, and on or around August 26, 2025, we determined that certain personal identifying information had been exfiltrated from our servers.”
Reference: WA Brewer Suffers Cyberattack
Victim: Georgetown Brewing Company
Georgetown Brewing is an independently owned Seattle craft brewery and maker of Manny’s Pale Ale and Bodhizafa IPA. In May of 2017, after 14 years selling beer, the company went from a draft-only production facility to canning select full-time beers.
Incident: Ransomware Attack At Cabinet Maker, T.R.A. Industries
Liberty Lake, Washington-based wood cabinet maker T.R.A. Industries, Inc. suffered a ransomware attack where personally identifiable information ended up stolen during the hack.
“On August 5, 2025, our Information Services team detected unusual traffic on our network,” the company said in a letter to victims. “On August 9, 2025, an unauthorized intruder activated ransomware on our computer systems. We were able to quickly respond and terminate the intruder’s access to our systems.”
T.R.A. Industries then began the process of restoring its systems using backup data and determining what information could have ended up accessed by the unauthorized intruder. On August 29, 2025, the company finished its review of unencrypted data on our computer systems that may have contained personal information.
Reference: Ransomware Attack At Cabinet Maker
Victim: T.R.A. Industries, Inc.
T.R.A. Industries, Inc., which also operates as Huntwood Industries, started up in 1988 and is a manufacturer of wood kitchen cabinets. The company has over 700 employees. The company produces its own line of custom and ready-to-assemble cabinets from its large, state-of-the-art facility.
Reference: Airport Check-In Systems Hit In Cyberattack
Incident: Monterey Mushrooms Hit in Cyberattack
Watsonville, California-based Monterey Mushrooms, LLC suffered a cyberattack in August where attackers made off with personally identifiable information.
Upon initially discovering this August 2 incident, Monterey Mushrooms took measures to secure its IT network, launched an investigation, and contacted law enforcement.
The investigation determined an unauthorized actor accessed files on the Monterey Mushrooms’ computer servers between August 2 and August 7. Monterey Mushrooms reviewed the files involved in this incident and, on August 30, determined they may have contained the name, Social Security number, and in certain limited circumstances, driver’s license number and/or passport number.
Reference: Mushroom Maker Suffers Cyberattack
Victim: Monterey Mushrooms, LLC
Watsonville, California-based Monterey Mushrooms has 7 farms strategically located across North America. Additionally, the company provides all major U.S. cities with fresh, locally-grown mushrooms year round. In 1971, Monterey Mushrooms started as a single mushroom farm in Watsonville, CA. The company has since expanded to seven locations in the United States and Mexico. Moreover, the company’s farming and packing operations have strategic locations across the country.
Incident: Cyberattack at Wood Flooring Maker, Havco
Scott City, Missouri-based wood flooring maker, Havco Wood Products LLC, suffered a cyberattack in March and it is now letting victims know about the hack.
“On March 31, 2025, we detected suspicious activity within Havco’s computer network,” the company said in a letter to victims. “Upon discovering the incident, we promptly began an internal investigation and worked to secure our systems.”
The company also said it hired a forensic security firm to assist with its investigation and ensure the security of its computer network.
As a result of that investigation, the forensic team determined an unauthorized third party accessed Havco’s computer network for less than 24 hours from Sunday, March 30 until Monday, March 31.
Reference: Wood Flooring Maker Suffers Cyberattack
Victim: Havco Wood Products LLC
Scott City, Missouri-based wood flooring maker, Havco Wood Products LLC is a manufacturer of wood and composite flooring for trailers, truck bodies, and intermodal containers. Founded in 1978, they specialize in producing durable, long-lasting, and decay-resistant oak and composite flooring for the trucking industry.
Incident: Chemical Maker Hit In Cyberattack
Peru, Illinois-based chemical manufacturer Carus, LLC, suffered a cyberattack in August where attackers were able to steal personally identifiable information from victims.
"Carus, LLC writes to notify you of an incident that may have impacted some of your personal information described below. We take the privacy and security of information in our care very seriously."
The company said at this time, there is no evidence to suggest that any information was subject to actual or attempted misuse as a result of this incident.
On August 7, Carus experienced a network disruption. Upon discovery, Carus immediately took steps to secure the network and engaged a third-party forensic firm to investigate the nature and scope of the incident.
Reference: Chemical Maker Hit In Cyberattack
Victim: Carus, LLC
Peru, Illinois-based chemical manufacturer Carus, LLC is a chemical manufacturing company founded in 1915 that specializes in producing chemical products used for water treatment, air purification, and soil remediation. The company manufactures specialty chemistries like potassium permanganate and phosphates.
Incident: Ransomware Attack at Utility Solution Provider, Minsait ACS
Sandy Springs, Georgia-based IT-OT utility solution provider, Minsait ACS, Inc., suffered a ransomware in March and is now informing employee victims of the attack.
“On May 5, 2025, we discovered we were victimized by a sophisticated ransomware attack,” the company said in a letter to victims. “Upon discovery, we immediately began working with our IT team to secure the network, restore our systems to operability, and investigate the full nature and scope of the incident.
“Through the investigation, it was determined that certain Minsait data, kept in the normal course of business, may have been subject to unauthorized access during the attack,” the company said. The attack occurred March 26.
Reference: Utility Solution Provider Hit In Ransomware Attack
Victim: Minsait ACS, Inc.
Minsait ACS is a provider of power grid control software solutions and advanced automation technology that enhances operational performance of the electric power industry. For over 40years, Minsait ACS worked on power grid control. As part of Indra, Minsait ACS mainly offers OT/IT solutions for utilities.
Incident: Third-Party Attack at Auto Giant Stellantis
Global automaker, Stellantis, which owns Chrysler, Dodge, Jeep, Ram and Fiat, discovered unauthorized access to a third-party platform that houses North American customer data.
“We recently detected unauthorized access to a third-party service provider’s platform that supports our North American customer service operations,” the company said Sunday in an advisory.
“Upon discovery, we immediately activated our incident response protocols, initiated a comprehensive investigation, and took prompt action to contain and mitigate the situation,” the company said. “We are also notifying the appropriate authorities and directly informing affected customers.“
Reference: Auto Giant Stellantis Suffers Cyberattack
Victim: Stellantis
Global automaker, Stellantis, owns Chrysler, Dodge, Jeep, Ram and Fiat. Stellantis' official global headquarters is in Hoofddorp, Netherlands, but its North American operations are run from the former Chrysler World Headquarters and Technology Center in Auburn Hills, Michigan.
Incident: Personal Protection Device Maker, Sellmark, Hit in Cyberattack
Personal protection device manufacturer, Mansfield, Texas-based Sellmark Corporation suffered a cyberattack this past March and is now letting victims know about the hack.
“Sellmark Corporation identified and addressed a cybersecurity incident involving unauthorized access to its computer network,” the company said in a notice to victims. “When Sellmark first identified this activity, it immediately took measures to secure its systems and launched an investigation with the help of a cybersecurity firm.”
Sellmark also reported the incident that occurred March 10 to law enforcement, including the FBI. Through the investigation, Sellmark learned an unauthorized actor accessed its network and obtained copies of certain documents from its servers.
Reference: Cyberattack At Personal Protection Device Maker
Victim: Sellmark Corporation
Mansfield, Texas-based Sellmark Corporation makes products under the brands like Sightmark, Firefield, Pulsar, BulletSafe, Inforce, and Kopfjager. Its products include advanced night vision, precision laser sights, tactical scopes, flashlights, and personal protective equipment.
Incident: Cyberattack at Coffee Roaster, Farmers Brothers
Fort Worth, Texas-based coffee roaster, Farmer Brothers Company, suffered a cyberattack this past March and after an investigation, it is now informing victims of the hack.
“On or about March 14, 2025, Farmer Brothers identified indications of potential unauthorized access to its systems,” the company said in a notice to victims. “Farmer Brothers promptly launched an extensive investigation to determine the nature and scope of the event. It worked quickly to secure the systems and investigate to determine whether this event resulted in any impact to information housed on the systems by the unknown actor.“
Farmer Brothers also reported this event to federal law enforcement and supported their investigation.
Through the investigation, Farmer Brothers discovered the unknown actor gained access to certain archived files and folders between March 6 and March 14.
Reference: Coffee Roaster Suffers Cyberattack
Victim: Farmer Brothers Company
Fort Worth, Texas-based coffee roaster, Farmer Brothers Company is a national coffee roaster, wholesaler and servicer of equipment, delivering coffee, tea and culinary products to U.S.-based customers. Its brands include Farmer Brothers, Boyd’s, Cain’s, West Cost Coffee and China Mist.
Incident: Cyberattack Hits Oilfield Services Provider, NPK
Oilfield site access solution provider, The Woodlands, Texas-based NPK International Inc. suffered a cyberattack in October last year and is now letting victims know the details of the attack.
NPK completed an investigation involving suspicious activity within its network that occurred on October 28, 2024.
“When NPK first learned of this activity, it immediately took steps to secure its network, notified law enforcement, and engaged third-party forensic firms with experience helping other companies in similar situations,” the company said in a notice to victims.
Through the investigation, NPK learned an unauthorized actor accessed its network between October 28, 2024, and October 29, 2024. The threat actor copied certain files from its servers. NPK conducted a thorough review of the relevant files, and on August 12, 2025, the review determined that one or more files contained the personal information of victims, including the name, Social Security number, and financial account number.
Reference: Oilfield Services Provider Hit In Cyberattack
Victim: NPK International Inc.
The Woodlands, Texas-based NPK International Inc. has been designing and manufacturing construction equipment attachments since the late 1950s. The company said it provides safe and efficient access for all your project sites. NPK is a utilities, oil and gas, pipelines, or construction site access solutions provider, offering everything from its DURA-BASE composite matting and specialty rental options to site planning, logistics, and remediation.
Incident: Cyberattack at LoveSac Furniture Maker
Stamford, Connecticut-based The LoveSac Company suffered a cyberattack in February and is now letting victims know their personally identifiable information ended up stolen.
On February 28, LoveSac became aware of suspicious activity within its network environment. LoveSac launched an investigation and determined between February 12 and March 3 an unauthorized actor accessed certain systems within the environment and copied certain files from those systems.
“Although we have no evidence of any identity theft or fraud occurring in connection with this incident, LoveSac conducted a review of the copied files to confirm the information contained therein, and to whom it relates for purposes of providing notice,” the company said in a letter to victims.
Reference: CT Furniture Maker Suffers Cyberattack
Victim: The LoveSac Company
Stanford, Connecticut-based The Lovesac Company designs and manufactures its own furniture. It makes “Sactionals” (modular couches) and Sacs (beanbag chairs), through a network of third-party manufacturing partners in North America, Mexico, and Asia. Additionally, while they use external partners, they oversee the design and manufacturing process.
Incident: Cyberattack at CA Prune Growers
Yuba City, California-based Sunsweet Growers Inc. suffered a cyberattack this past December and is now letting current and former employees know they fell victim to threat actors making off with personally identifiable information.
“On December 11, 2024, Sunsweet became aware that certain computer network systems were inaccessible,” the company said in a notice. “We quickly took steps to secure our systems and launched an investigation with the assistance of third-party computer specialists to confirm the full nature and scope of the activity and to restore functionality to the affected systems.
The investigation found an unauthorized actor gained access to certain Sunsweet systems.
Reference: Prune Growers Hit In Cyberattack
Victim: Sunsweet Growers Inc.
Yuba City, California-based Sunsweet Growers operates the largest dried fruit plant in the world. The grower-owned marketing cooperative represents more than one-third of the prune market worldwide, Sunsweet processes more than 50,000 tons of prunes a year. Additionally, Sunsweet manufactures a variety of dried fruit and juice products.
Incident: Cyberattack Disrupts North and Latin American Operations at Bridgestone Americas
Bridgestone Americas experienced a cyberattack in early September 2025 that disrupted operations at several of its manufacturing and retreading facilities. The attack halted or disrupted production at multiple facilities. At least two plants were identified; in Aiken County, South Carolina (U.S.) and a major Bridgestone facility in Joliette, Quebec (Canada). These sites paused normal operations while the incident was contained and IT systems were isolated. Employees at affected plants were either sent home or given optional work on preventive maintenance with pay during the outage. Overall multiple sites across North America and Latin America were affected, causing temporary operational suspension in several plants until systems were isolated and restored by mid‑September 2025.
No ransomware group has publicly claimed responsibility.
Reference: Bridgestone Americas Suffers Cyberattack, Again
Incident: Ransomware Attack at Cornwell Tools
Cornwell Quality Tools suffered a ransomware attack this past December and is now informing its 103,782 victims details of the hack.
The December 2024 data breach compromised Social Security numbers, medical info, and financial account numbers.
Ransomware group Cactus took credit for the attack in February 2025 and said it stole 4.6 TB of data. To prove its claim, Cactus posted sample images of what it said are documents from Cornwell. They include driver’s license scans, tax documents, and credit applications.
“On December 20, 2024, Cornwell became aware of unusual activity within its computer network and immediately took steps to secure its systems, engaging cybersecurity experts in the process,” said a letter to victims of the incident. According to its investigation, an unknown actor gained access to Cornwell’s network and potentially acquired certain files on or around December 12, 2024. Following a comprehensive review of the affected files, Cornwell determined that certain individuals’ personal information may have been involved in this incident. Cornwell then began working diligently to collect up-to-date mailing addresses in order to provide notification of the incident, which was completed on August 4, 2025.”
Reference: Cornwell Tools Hit in Ransomware Attack
Victim: Cornwall Tools
Wadsworth, Ohio-based Cornwell is a mobile tool maker with two factories in Van Wert and Mogadore, Ohio.
Incident: Cyberattack at Corrugated Box Solution Provider, Amtech Software
Fort Washington, Pennsylvania-based Amtech Software, Inc. suffered a cyberattack in March where threat actors were able to make off with personally identifiable information.
“On or about April 7, 2025, Amtech identified suspicious activity on its computer network,” the company said in a letter to victims. “In response, Amtech took steps to secure the network and began a comprehensive investigation to determine what occurred.”
As it turned out, the investigation found attackers go on to the network between March 11 and April 7 and certain files ended up copied from the network as part of the hack.
Reference: Corrugated Box Solution Provider Hit In Cyberattack
Victim: Amtech Software, Inc.
Fort Washington, Pennsylvania-based Amtech Software started uo in 1981, and worked in the corrugated, folding carton, and label packaging industries. Furthermore, it has a family of software, solutions, and technology that ensures customers achieve operational and bottom-line excellence throughout their entire business. Additionally, Amtech is in more than 1,250 manufacturing plants in North America, Latin America, and Europe. Amtech works with corrugated, folding carton, and label manufacturers.
Incident: Cyberattack at Baked Goods Maker, NHB
Norwalk, Ohio- based NHB Holdings, LLC and its subsidiaries suffered a cyberattack where threat actors made off with personally identifiable information.
NHB’s subsidiaries are New Horizons Baking Company, LLC; Genesis Baking Company, LLC; Metraco Transportation Company, LLC, and New Horizons Food Solutions, LLC.
“On January 11, 2025, New Horizons discovered suspicious activity in their environment,” the company said in a notice to the victims of the attack. “New Horizons promptly responded and launched an investigation to confirm the nature and scope of the incident.”
Reference: Baked Goods Maker Suffers Cyberattack
Victim: NHB Holdings, LLC
New Horizons Baking Company is a baked goods production company. Founded in 1967 as the West Baking Company, New Horizons Baking Company is a hamburger bun and English muffin producer. It serves over 5,000 restaurants, food service facilities, and wholesale establishments.
Incident: Bar Code Provider, Southern Graphics Hit in Attack
Louisville, Kentucky-based bar code provider Southern Graphics Inc. suffered a cyberattack in November last year and is now just letting victims know about the attack.
Southern Graphics learned on December 2, 2024, of a cybersecurity incident involving unauthorized access to certain of its IT systems the company believe occurred on November 18.
“Upon detecting the issue, we promptly launched an investigation to determine its nature and scope. In the course of investigating the issue, we took steps to review the impacted information and identify the individuals whose personal information may have been affected,” the company said in a notice to victims.
Reference: Cyberattack At Bar Code Provider
Victim: Southern Graphics Inc.
Southern Graphics is a single source bar code product supplier. That includes everything from RF data collection equipment to business forms, labels, and commercial printing.
Incident: Utility Productivity Provider Hit in Attack
Philadelphia, Pennsylvania-based Util-Assist Inc. suffered a cyberattack in July that had an “operational impact on a limited number of personnel and systems.”
“Util-Assist Inc. discovered the incident involving unauthorized access to its IT system.,” the company said in a notice to victims. “In response, Util-Assist immediately took measures to secure the IT system and launched an investigation.”
The investigation revealed an unauthorized actor accessed the system on July 11 where the attackers made off with personally identifiable information such as the victims’ name, Social Security number and bank account number used for direct deposit.
Reference: Cyberattack At Utility Productivity Provider
Victim: Util-Assist Inc.
Philadelphia, Pennsylvainia-based Util-Assist’s solutions merge technology and strategy to streamline processes, boost productivity, enable data-driven business decisions. The company is looking to transform how utilities operate and deliver value to their customers. It offers professional and managed services for electric, water and gas utilities.
Incident: ‘Malicious Encryption’ at Fire Protection Provider, Hiller
Mobile, Alabama-based fire protection products provider, the Hiller Companies LLC suffered what could be a ransomware attack it discovered this past June.
“On June 13, 2025, Hiller learned that some of your personal information may have ended up involved in a data security incident,” the company said in a notice to victims. “The incident related to a malicious encryption perpetrated by unknown actors, which resulted in certain files being copied from our network without authorization on or about December 18, 2024.
As a result of the attack, Hiller hired a team of outside cybersecurity experts to investigate the matter and help determine whether any sensitive data ended up included exfiltrated in the attack.
Reference: Fire Protection Provider Suffers ‘Malicious Encryption’
Victim: Hiller Companies LLC
The Hiller Companies offers fire protection products and services. Headquartered in Mobile, Alabama, Hiller has offices in Alabama, Arizona, California, Colorado, Florida, Louisiana, Massachusetts, Nevada, South Carolina, Texas, Utah and Virginia. Moreover, the company safeguards organizations from small businesses to nuclear testing facilities, yachts to aircraft carriers, and gas stations to offshore platforms.
Incident: Tungsten Automation Hit In Cyberattack
Irvine, California-based Tungsten Automation Corporation, formerly known as Kofax Inc. before its name change, suffered a cyberattack where personally identifiable information ended up stolen from victims.
“On May 27, 2025, Tungsten Automation discovered suspicious activity occurring on its internal IT networks,” the company said in a letter to victims. “Tungsten Automation immediately began an investigation, engaged third-party cybersecurity experts, and notified law enforcement.”
The company said its investigation found an unauthorized party accessed Tungsten’s internal IT network and obtained certain files in May.
Victim: Tungsten Automation Corporation
Irvine, California-based Tungsten Automation Corporation, formerly known as Kofax Inc. is a automation and document management provider. The company specializes in providing solutions that streamline business processes and enhance operational efficiency.
Incident: Louis Vuitton Hit in Cyberattack
Fashion industry giant and New York, New York-based Louis Vuitton North America Inc. suffered a cyberattack earlier this summer where an attacker was able to gain access to the network and make off with personally identifiable information.
“On July 2, 2025, Louis Vuitton became aware of a cybersecurity incident,” the company said in a letter to its victims. “Louis Vuitton promptly engaged leading third-party cybersecurity experts and took steps to investigate the incident. The investigation determined that an unauthorized party gained access to a database containing client data on June 7, 2025.”
Louis Vuitton said in the letter they were able to contain the incident.
Reference: Fashion Firm, Louis Vuitton, Suffers Cyberattack
Victim: Louis Vuitton North America Inc.
Louis Vuitton North America produced some of their luxury handbags and small leather goods, such as the Neverfull and Keepall, for the North American market. Moreover, the company officially opened a 100,000-square-foot factory in rural Texas in 2019. This was the third manufacturing facility in the United States. There are two other facilities in San Dimas, TZX and Irwin, California.
Incident: Cyberattack at CA Rice Co-Op
Sacramento, California-based Farmer’s Rice Cooperative suffered a cyberattack one year ago and it is now informing victims of the hack.
“On or about August 31, 2024, Farmer’s discovered that it had experienced a cyber security incident,” the co-op said in a letter to victims. “We promptly launched an investigation, engaged a national cybersecurity firm to assist in assessing the scope of the incident and took steps to mitigate the potential impact to our community.”
“Unfortunately, these types of incidents are becoming increasingly common and organizations with some of the most sophisticated IT infrastructure available continue to end up affected,” the co-op said.
Reference: Rice Co-Op Suffers Cyberattack
Victim: Farmer’s Rice Cooperative
Sacramento, California-based Farmer’s Rice Cooperative is a grower-owned rice marketing cooperative. Furthermore, the co-op’s’ rice milling and manufacturing facilities are adjacent to the Port of Sacramento in the City of West Sacramento. Moreover, Farmers works to develop production, milling and marketing programs to ensure a secure supply of rice for consumers.
Incident: Cyberattack at CA Security Firm, Petrusha Enterprises
Eureka, California-based Petrusha Enterprises, Inc. which does business as Advanced Security Systems suffered a cyberattack earlier this summer and the company found personally identifiable information ended up stolen from its network.
“On June 30, 2025, we detected that we were the target of a data security incident,” the company said in a letter to the victims of the attack. “An unauthorized third party attempted to infiltrate our computer network. Upon detecting the incident, we moved quickly to secure our network environment and launched an investigation to determine the scope and extent of any potential unauthorized access of our systems.”
Advanced Security said it conducted an extensive electronic discovery, which concluded on August 7. It found some personal information may have fallen into the hands of the intruders. Moreover, that information may have included the victim’s name, credit card number and CVV code.
Reference: CA Security Firm Hit In Cyberattack
Victim: Petrusha Enterprises, Inc.
Eureka, California-based Petrusha Enterprises, Inc. which does business as Advanced Security Systems is a family-owned and operated security company based in Northern California. The company provides security systems and monitoring for residential, commercial, and government clients. Its area of focus is across Northern California and Southern Oregon.
Victim: Petrusha Enterprises, Inc.
Eureka, California-based Petrusha Enterprises is the corporate name for Advanced Security Systems. It is a family-owned and operated security company based in Northern California. The company provides security systems and monitoring for residential, commercial, and government clients. Its area of focus is across Northern California and Southern Oregon.
Incident: Chemical Maker, Seydel Companies, Suffers Cyberattack
Pendergrass, Michigan-based chemical maker The Seydel Companies, Inc. suffered a cyberattack this past spring that led threat actors to make off with personally identifiable information of victims.
“On April 26, 2025, we identified unusual activity indicating potential unauthorized access to our network,” the company said in a letter to victims of the hack. “Upon learning of the incident, Seydel immediately took steps to secure our systems and commenced a prompt and thorough investigation assisted by external cybersecurity professionals experienced in handling these types of situations to assist us in determining the full extent of the incident and scope of any data impacted.”
The company said its investigation found an unauthorized actor accessed its systems on April 26, and, as a result, possibly viewed and/or obtained certain files.
Reference: Cyberattack At Chemical Maker
Victim: The Seydel Companies, Inc.
The Seydel Companies is a producer of chemicals essential to the textile and apparel, paper and packaging, personal care, agriculture, and metal working industries. Furthermore, the company started up well over 100 years ago in 1907.
Incident: Heavy Equipment Maker, LBX, Affected by Stolen Laptop
Lexington, Kentucky-based heavy equipment maker, LBX Company LLC, responded to a stolen laptop computer that had unencrypted personally identifiable information available.
LBX, a subsidiary of Japanese conglomerate Sumitomo Heavy Industries, discovered an incident on June 18, where a company-issued laptop computer ended up removed from an employee’s vehicle.
“Although this device was password-protected, LBX determined there was unencrypted data saved to the laptop, which may have included your personal information,” the company said in a letter to victims of the attack. “This data could potentially be accessed by an unauthorized person if the person was able to defeat the password protection and gain access to the laptop.”
Reference: Stolen Laptop Affects Heavy Equipment Maker
Victim: LBX Company LLC
Lexington, Kentucky-based heavy equipment maker, LBX Company is an American industrial company manufacturing excavators, forestry equipment and scrap material handlers.
Incident: OH Lighting Maker, Lumitex, Suffers Cyberattack
Brecksville, Ohio-based Lumitex, Inc., a designer and manufacturer of light delivery systems for multiple industry sectors, suffered a cyberattack last month and is in the process of letting victims know.
The breach occurred July 30, when Lumitex experienced an external system breach due to a hacking incident.
“Upon becoming aware, Lumitex began an investigation into the scope and nature of the activity, retained legal counsel and third-party forensic specialists to investigate the incident,” the company said in a letter to its victims. The company also cooperated with federal law enforcement.
Reference: Lighting Maker Hit In Cyberattack
Victim: Lumitex, Inc.
Brecksville, Ohio-based Lumitex, Inc. designs and manufactures light delivery solutions for various applications, including medical, electronics, and industrial. They also produce custom fiber optic devices and lighting systems for surgical and phototherapy purposes. Lumitex has global manufacturing capabilities and offers in-house production, as well as sourcing and supply chain management for clients.
Incident: Cyberattack At Snack Food Maker, Old Dutch Foods
Roseville, Minnesota-based potato chip and snack food maker, Old Dutch Foods, Inc. suffered a cyberattack last year and is now letting victims of the hack know their personally identifiable information ended up stolen.
“Late last year, Old Dutch discovered suspicious activity on its system,” the company said in a letter to victims. “Old Dutch promptly took steps to secure its systems and initiated an investigation into the nature and scope of the event.”
The investigation found Old Dutch’s environment was subject to unauthorized access and between October 16 and October 17, 2024, certain files ended up copied and taken.
Reference: Cyberattack At Chip Maker
Victim: Old Dutch Foods, Inc.
Roseville, Minnesota-based Old Dutch Foods is a potato chip and snack food maker.
Incident: Air France, KLM Suffer Data Breach
Air France and KLM suffered a cyberattack Wednesday where threat actors were able get into a customer service platform and steal personally identifiable information from users.
The airlines said they eliminated attackers’ access to the compromised systems after they discovered the breach. They also said their networks did not fall into the hands of the attackers.
The airline said in a statement: “Air France and KLM have detected unusual activity on an external platform we use for our customer service. This resulted in unauthorized access to customer data.
Reference: Airlines Suffer Data Breach
Victim: Air France–KLM Group
Air France–KLM Group is a multinational airline holding company started up in 2004. Moreover, Air France-KLM provides services to up to 300 destinations in 90 countries. In 2024, the aviation group transported 98 million passengers worldwide. It has a fleet of 564 aircraft and 78,000 employees,
Incident: Cyberattack At Safety Software Firm, Kokomo Solutions
Northbrook, Illinois-based Kokomo Solutions, Inc which does business as Kokomo24/7 suffered a cyberattack in December and is now informing victims what happened during the hack.
Kokomo Solutions is a computer software company that develops health, safety and wellness management platforms for organizations, schools and communities. Among the organizations it works with is Los Angeles Unified School District.
“Unfortunately, we are writing to advise you of a recent incident that may have involved some of your personal information,” Kokomo said in a letter to victims of the attack. “We are writing to advise you of the incident and to provide you with guidance on steps you can take in response to this incident, should you feel it is appropriate to do so.”
“On December 11, 2024, we discovered unusual activity on our computer network,” the letter said. “Upon identifying the issue, we promptly took steps to contain and remediate the incident. We also engaged a forensic security firm to investigate the incident and confirm the security of our computer systems.”
Reference: Cyberattack At Safety Software Firm
Victim: Kokomo Solutions, Inc
Northbrook, Illinois-based Kokomo Solutions, is a computer software company that develops health, safety and wellness management platforms for organizations, schools and communities. Among the organizations it works with is Los Angeles Unified School District.
Incident: Cyberattack at Video Surveillance Firm, DTiQ Technologies
Marlborough, Massachusetts-based video surveillance firm DTiQ Technologies, Inc. suffered a cyberattack where threat actors were able to steal personally identifiable information.
“On January 12, 2025, we identified unusual activity in our network and immediately began an investigation,” the company said in a letter to its victims. “The investigation determined there was unauthorized access to a portion of our network between December 31, 2024 and January 12, 2025.”
The company then said it conducted a comprehensive review of the contents of its network to determine the type of information contained in the attack.
Reference: Video Surveillance Firm Suffers Cyberattack
Victim: DTiQ Technologies, Inc.
Marlborough, Massachusetts-based DTiQ is a provider of video surveillance and loss prevention technology for restaurants, retail, and c-stores. Its solutions help operators prevent theft and fraud, reduce shrink and errors, improve compliance and service, and gain real-time operational visibility. The company integrates AI-powered video with advanced analytics and auditing tools.
Incident: Skin Care Product Maker, Episciences, Suffers Cyberattack
Boise, Idaho-based skin care products maker, Episciences, Inc., suffered a cyberattack in April where victims’ personally identifiable information ended up stolen.
“On April 29, 2025, Episciences learned of suspicious activity on certain systems within its network,” the company said in a letter to victims. “Episciences immediately launched an investigation to determine the nature and scope of the activity. The investigation determined that the unauthorized actor gained access to certain files within the Episciences network between April 27, 2025, and April 29, 2025, and may have copied those files.”
Following an investigation, Episciences undertook a detailed review of all the files potentially impacted to determine what information was present in these files and to whom it related.
Reference: Cyberattack At Skin Care Product Maker
Victim: Episciences, Inc.
Boise, Idaho-based skin care products maker, Episciences' brand, Epionce, is a dermatologist-developed, medical grade skin care brand that focuses on healthy skin. Every product ends up developed, tested and produced at its own manufacturing facility in Boise.
Incident: Cyberattack at TIMEC Oil & Gas
Pasadena, Texas-based TIMEC Oil & Gas, Inc. suffered a cyberattack where employees’ personally identifiable information ended up stolen.
On July 30, TIMEC reported it suffered a data breach this past April where sensitive personally identifiable information and protected health information located within in its systems suffered a compromise.
TIMEC detected unauthorized access to its internal ERP system between April 7 and April 10 during which certain employees’ direct deposit information ended up altered.
Reference: Oil Firm Suffers Cyberattack
Victim: TIMEC Oil & Gas, Inc.
Pasadena, Texas-based TIMEC Oil & Gas has seven additional locations in Rancho Dominguez, California, Benicia, California, Salt Lake City, Utah, Beaumont, Texas, Buffalo, Missouri, Bakersfield, California, and Dickinson, North Dakota. Through its specialty welding team, the company executes piping, fabrication and welding works with industry-leading quality and productivity.
The company focuses on repair and inspection (HRI), and upstream oil-field services through nested maintenance, turnaround or construction services.
Incident: PAC Strapping Products Hit with Ransomware
Exton, Pennsylvania-based PAC Strapping Products, Inc. suffered from a ransomware attack they discovered this past April and now four months later the company is letting victims know some of the details from the incident.
PAC Strapping Products said it experienced a ransomware incident which may have affected personal information from the victims of the attack.
“On or about April 2, 2025, we discovered a ransomware incident that locked us out of certain devices on our system,” the company said in a letter to victims of the attack. “Based on this activity, we contacted our IT team to investigate. The IT team promptly stopped the suspicious activity and reset all user passwords as a precaution. We also engaged IT professionals to perform a scan and analysis of our system.”
Reference: Ransomware Attack At Strapping Maker
Victim: PAC Strapping Products
Exton, Pennsylvania-based PAC Strapping Products is a full-service manufacturer and supplier of plastic strapping, steel strapping, strapping machines, strapping tools, and accessories. The company said its strapping equipment and systems work in multiple industry sectors.
Incident: Baillie Lumber Hit In Cyberattack
Hamburg, New York-based lumber supplier, Baillie Lumber Co., L.P., suffered a cyberattack this past February where personally identifiable information ended up stolen.
“On February 11, 2025, Baillie learned of suspicious activity within its network,” the company said in a letter to its victims. “Baillie immediately launched an investigation to determine the nature and scope of the activity. The investigation determined that an unauthorized actor gained access to certain files within the Baillie network from February 6, 2025 to February 12, 2025, and may have copied those files.”
Following an investigation, Baillie said it undertook a detailed review of all the files potentially impacted to determine what information was present in these files and to whom it related.
Reference: Lumber Supplier Hit In Cyberattack
Victim: Baillie Lumber Co., L.P.
A North American hardwood lumber provider, Baillie is a full-service lumber supplier involved in manufacturing, distribution, importing and exporting. The company specialize in specific width, length, color or grade sorts tailored delivery schedules and shipping solutions.
Incident: Cyberattack at LA Security Firm, Custom Security Systems
Baton Rouge, Louisiana-based security provider, Custom Security Systems, Inc. suffered a cyberattack in August last year where personally identifiable information ended up stolen and after a prolonged investigation it is now informing victims of the attack.
“On or about August 6, 2024, Custom Security became aware of unauthorized activity on our computer network,” the company said in a letter to its victims. “Upon discovery, we immediately took action to address and investigate the event, which included contacting law enforcement and engaging third-party computer forensic specialists to assist with determining the nature and scope of the event.
After a thorough investigation, the company found certain information stored on its network was subject to unauthorized access for a period of time. It then started up a comprehensive and time-consuming review of the potentially impacted data in order to determine the type of information contained within the data and to whom that information related, the company said.
Reference: LA Security Firm Suffers Cyberattack
Victim: Custom Security Systems, Inc.
Custom Security Systems has been providing families and businesses state-of-the-art intrusion and fire detection systems sinced 1977. Custom Security offers a range of security devices and services including camera systems, environmental sensors, and local monitoring with or without phone lines.
Incident: Cyberattack at PA Security Firm, Vector Security
Warrendale, Pennsylvania-based security provider, Vector Security, Inc. suffered a cyberattack late last year where personally identifiable information ended up stolen and the company is now informing victims.
“Vector detected unauthorized activity in our information technology (IT) systems,” the company said in a letter to victims. “Upon discovering this activity, we immediately took protective actions to stop the unauthorized access, notified U.S. federal law enforcement, and launched an investigation with the assistance of leading cybersecurity specialists.”
The investigation indicated personal information may have been accessed by an unauthorized party as early as mid-December 2024. Moreover, the company said it discovered the attack December 18. At this time, Vectoer said it has no reason to believe any victim’s information ended up misused. Out of an abundance of caution, however, the company wanted to keep the victims aware.
Reference: PA Security Firm Hit In Cyberattack
Victim: Vector Security, Inc.
Vector is a sister company of The Philadelphia Contributionship, the nation’s oldest insurance company founded in part by Benjamin Franklin in 1752. Moreover, Vector itself has been in business for over 50 years. It designs, installs and monitors Vector Home Security and Vector Business Security systems for homes, businesses and multi-site retail chains across North America and the Caribbean.
Malware: Third party breach
Hackers linked to Scattered Spider and ShinyHunters (also known as UNC6040) exfiltrated over 2.8 million Allianz Life customer and partner records via third-party attack via Salesforce.
Incident: Cyberattack at Insurance Provider, Allianz
Minneapolis, Minnesota-based Allianz Life Insurance Company of North America suffered a cyberattack in mid-July affecting 1.4 million of its U.S. customers.
The insurance giant discovered the breach July 17 and the company said it occurred July 16 when a “malicious threat actor” accessed a third-party cloud-based system used by the company.
The compromised data includes personally identifiable information belonging to Allianz Life customers, financial professionals, and select employees. While the full extent of the stolen data was not immediately available, the company said a majority of its U.S. customers ended up affected in the hack.
Reference: Insurance Company Hit In Cyberattack
Victim: Allianz
Minneapolis, Minnesota-based Allianz Life Insurance Company of North America is an insurance company.
Incident: House Of Dior Hit in Cyberattack
Fashion couture giant, House of Dior, suffered a cyberattack in January it discovered in May and then started notifying victims in July.
“We take the security of your personal information very seriously, Dior said in a notice to victims. “We are writing to let you know about a recent cybersecurity incident that impacted a database we use to hold your personal information.”
“On May 7, 2025, we identified a potential cybersecurity incident. We promptly conducted an investigation, supported by leading third-party cybersecurity experts. Our investigation determined that an unauthorized party was able to gain access to a Dior database that contained information about Dior clients on January 26, 2025,” the letter said.
The breach involved an exploit through a Salesforce-connected system.
Malware: Third Party Breach
The breach involved an exploit through a Salesforce-connected system.
Reference: Cyberattack At House Of Dior
Victim: House of Dior
Dior is a French luxury fashion house, part of the LVMH (Moët Hennessy Louis Vuitton) group, which is the world’s largest luxury conglomerate. The Dior brand generated an annual revenue of over $12 billion, operating hundreds of boutiques worldwide.
Dior manufactures its products in various locations depending on the product category. Ready-to-wear and leather goods primarily end up made in Europe, specifically in France and Italy. Dior’s perfumes and cosmetics end up produced in the Orléans region of France. Some accessories and other items may also end up manufactured in China. The majority of their high-end fashion and haute couture ends up made in France, particularly in Paris. Dior’s watches end up manufactured in Switzerland.
Incident: Top Hydraulics Suffers Cyberattack
Florence, Oregon-based hydraulic component maker, Top Hydraulics, Inc., discovered a cyberattack earlier in July affecting data entered in February.
Top Hydraulics discovered unauthorized access to payment card information entered on its website initially on May 21, affecting data entered between February 12 and May 21, the company said in an advisory.
In further evidence the attacker possibly was lurking on the network, the company found other unauthorized access in June.
Reference: Hydraulic Component Maker Hit In Cyberattack
Victim: Top Hydraulics, Inc.
Top Hydraulics specializes in remanufactured and upgraded hydraulic components for convertible tops, including cylinders, pumps, and hydraulic lines. The goal of the company is to enhance the performance and longevity of its products with advanced seal technology and precision engineering.
Incident: Vehicle Safety Provider, Safe Fleet, Hit in Cyberattack
Belton, Missouri-based vehicle safety solution provider Safe Fleet Holdings, LLC suffered a cyberattack in April last year where threat actor was able to steal victims’ personally identifiable information.
Safe Fleet discovered suspicious activity in its computer systems on April 13, 2024 and it launched an investigation, with the assistance of third-party cybersecurity specialists, to determine the nature and scope of the event. The investigation found on April 13, 2024, an unauthorized actor gained access to certain systems and accessed or took certain information.
Vehicle Safety Provider Suffers Cyberattack“Safe Fleet conducted a comprehensive, programmatic and manual review to identify what information was accessible and to whom such information relates,” the company said in a letter to victims. “Once complete, Safe Fleet also worked to validate the results, locate appropriate contact information for those potentially affected, and confirm whether the data belonged to another entity such that Safe Fleet would (end up) required to notify the other entity prior to notifying individuals.”
Reference: Vehicle Safety Provider Suffers Cyberattack
Victim: Safe Fleet Holdings, LLC
Safe Fleet Holdings operates as a holding company. The company, through its subsidiaries, provides safety solutions on a global basis for fleet vehicles, such as truck, trailers, bus, rail, and ambulance.
Incident: Cyberattack at Shipping Firm, Keystone
Bala Cynwyd, Pennsylvania-based Keystone Shipping Co. suffered a cyberattack last month and after an investigation discovered attackers stole personally identifiable information from victims.
Keystone just concluded its investigation into the incident, which involved unauthorized access to its computer network on June 3.
“Upon learning of the incident, Keystone immediately took measures to secure its network, commenced an investigation with assistance from external cybersecurity firms, and reported the incident to law enforcement,” said a letter to the victims of the attack.
Reference: Shipping Firm Suffers Cyberattack
Victim: Keystone Shipping Co.
Bala Cynwyd, Pennsylvania-based Keystone Shipping is a U.S.-owned, privately held, full service marine transportation company. It specializes in the safe, reliable, and efficient waterborne transportation of liquid, dry bulk and roll-on/roll-off cargoes. Furthermore, some of the company goals are to receive recognition in the marine industry for its enduring commitment to the highest standards of safety, environmental protection, quality service, and integrity in the operation of its vessels.
Reference: Shipping Firm Suffers Cyberattack
Victim: Keystone Shipping Co.
Keystone Shipping is a U.S.-owned, privately held, full service marine transportation company. It specializes in the safe, reliable, and efficient waterborne transportation of liquid, dry bulk and roll-on/roll-off cargoes. Furthermore, some of the company goals are to receive recognition in the marine industry for its enduring commitment to the highest standards of safety, environmental protection, quality service, and integrity in the operation of its vessels.
Incident: Cyberattack at Food Producer, Vero Foods
Calgary, Canada-based food producer, Vero Foods, suffered a cyberattack where threat actors were able to gain access to email files that contained personally identifiable information.
“On December 6, 2024, Vero Foods became aware of suspicious activity within their environment,” the company said in a letter to victims. “We promptly took steps to secure our network and launched an investigation. The investigation determined that certain email files were accessed without authorization by an unknown actor between December 2, 2024, and December 7, 2024.”
As a result of the attack, Vero Foods did say it has no evidence of any identity theft or fraud occurring in connection with this incident. Vero Foods conducted a review of relevant systems and notified those whose information was present within the systems. The company just completed that review.
Reference: Food Producer Hit In Cyberattack
Victim: Vero Foods
Vero Foods provides imported Italian food to the Canadian market. Additionally, the company makes Regal Fresh Egg Pasta.
Incident: Dental Product Maker, Ergonomic Products, Hit In BEC
Fall River, Massachusetts-based dental equipment manufacturer, Ergonomic Products, Inc., suffered a business email compromise (BEC) where attackers were able to make off with personally identifiable information.
“On November 11, 2024, we discovered suspicious activity potentially related to an employee email account,” Ergonomic Products said in a letter to victims. “Upon discovery, we took action to secure our email system and network. We then began working with third-party computer specialists to investigate the full nature and scope of the incident.”
The company added based on its investigation, researchers were able to determine one employee’s email account was subject to unauthorized access between October 2, 2024 and November 11, 2024.
Malware: Business email compromise
Business email compromise allowed attackers to make off with personally identifiable information.
Reference: Dental Product Maker Hit In BEC
Victim: Ergonomic Products, Inc.
Ergonomic Products is a manufacturer and direct seller of dental equipment.
Incident: VA Nut Provider, Birdsong Peanuts, Suffers Cyberattack
Suffolk, Virginia-based peanut provider, Birdsong Peanuts, concluded its investigation into a cyberattack and found threat actors stole personally identifiable information.
“On June 23, 2025, Birdsong became aware of unauthorized activity on its computer network and quickly engaged third-party specialists to investigate and determine the nature and scope of the activity,” said a notice to victims of the attack.
Birdsong’s investigation found data within the company’s network environment ended up viewed and/or copied by an unknown actor on or before June 23.
Reference: Cyberattack At Peanut Provider
Victim: Birdsong Peanuts
Birdsong buys selected peanuts directly from the farmers’ fields. They then clean, shell, size and ship them in truckload lots to manufacturers who turn them into food items.
The company operates five shelling plants throughout the peanut-growing belt comprised of 11 states extending from Virginia to New Mexico. In addition, the company operates 85 buying points where it buys and stores farmers’ stock. The company also own extensive cold storage warehouses which enable us to keep our product in a protected environment until it’s shipped to the customer. It also has extensive farm operations in Florida and in Texas where the company grows peanuts on land that is 100 percent irrigated.
Incident: Cyberattack at MA Utility
Ludlow, Massachusetts-based utility Massachusetts Municipal Wholesale Electric Company (MMWEC) suffered a ransomware attack where hackers stole personally identifiable information from victims.
“On February 2, 2025, MMWEC discovered suspicious activity in its environment. In response, MMWEC immediately took steps to secure its environment and launched an investigation to determine the nature and scope of the incident,” said a letter to victims of the incident. “The investigation determined that between January 25, 2025 and February 3, 2025, an unknown, unauthorized actor gained access to certain MMWEC computer systems and accessed and/or acquired certain files stored on these systems.
MMWEC said it quickly began a thorough review of the relevant files to identify individuals with personal information potentially impacted. MMWEC completed this review on June 10.
Reference: MA Utility Hit In Cyberattack
Victim: Massachusetts Municipal Wholesale Electric Company (MMWEC)
Massachusetts Municipal Wholesale Electric Company (MMWEC) is a municipal utility dedicated to providing customers with low-cost and reliable electricity. It plans, develops and manages energy resources in an evolving landscape of energy markets, governance and sustainability.
For nearly 50 years, as the Commonwealth’s designated joint action agency for municipal utilities. MMWEC brought value and efficiency of public power joint action to the state’s consumer-owned utilities.
Incident: Cyberattack at Chemical Maker, HEXPOL
Burton, Ohio-based polymer compound maker HEXPOL Holding Inc. suffered a cyberattack this past December and is now informing victim their personally identifiable information ended up stolen in the hack.
On December 22, 2024, HEXPOL detected unauthorized access to its network.
“Upon learning of this issue, HEXPOL took immediate steps to securely contain our network, restore our systems, and launched an immediate investigation in consultation with outside cybersecurity professionals, the company said in a letter to victims of the attack. As part of our investigation, we devoted considerable time and effort to determine what, if any, information ended up impacted by this incident.”
Reference: Chemical Maker Hit In Cyberattack
Victim: HEXPOL Holding Inc.
HEXPOL Compounding is a global developer and manufacturer of polymer compounds. The company provides proprietary compounding solutions including: Rubber compounding,rubber rolls applications, tire and toll, retreading products, specialty product additive and color concentrates, thermoplastic and TPE compounding, and silicone compounding.
Incident: Cyberattack at Water Pump Maker, Dosatron International
Clearwater, Florida-based Dosatron International, LLC, a water-powered dosing pump manufacturer, suffered a cyberattack back in March and is now informing victims of the hack their personally identifiable information ended up stolen.
On March 4, attackers were able to hack into a Dosatron web site and pull customer data off the network.
“We recently learned that an unauthorized party temporarily gained access to the payment portal of one of our websites, https://dilutionsolutions.com,” the company said in a letter to victims of the attack. “Payment card data entered by our customers during this period, including your card data, may have been intercepted by the unauthorized party. On May 28, 2025, we became aware of this unauthorized access to the website and promptly took action to stop it. We also began an investigation of the incident.”
Reference: Water Pump Maker Suffers Cyberattack
Victim: Dosatron International, LLC
Clearwater, Florida-based Dosatron is the original inventor of the water-powered dosing pump. Since the first Dosatron first ended up manufactured in 1974, Dosatron has grown to be a leader in water-powered dosing technology. Dosatron manufactures and sells a wide variety of chemical injectors in over 100 countries worldwide. Moreover, a water-powered dosing pump utilizes the flow and pressure of water to drive a piston or diaphragm pump, accurately injecting chemicals or additives into a water line without the need for electricity. This technology is useful in applications where precise and proportional dosing ends up required, such as water treatment, food processing, and agriculture.
Incident: Medical Device Maker, Artivion, Suffers Ransomware Attack
Kennesaw, Georgia-based medical device maker, Artivion, Inc. just finished an investigation into a ransomware attack where a threat actor gained access to its network and forced the company to shut down systems.
“Upon learning of the incident, Artivion immediately initiated its incident response protocols, including shutting down systems as a protective measure, and began an investigation with outside cyber experts,” the company said in a letter to victims. “The investigation determined that an unauthorized third-party gained access to Artivion’s network between November 20 and November 21, 2024, and obtained certain files.”
Artivion said it conducted a detailed review and analysis of the files involved to identify individuals whose information was a part of the attack. It also had to confirm victims’ contact information. The attack had an impact on its operations including disruptions to some order and shipping processes, as well as to certain corporate operations.
Reference: Ransomware attack hits leading heart surgery device maker
Reference: Ransomware Attack At Medical Device Maker
Victim: Artivion, Inc.
Artivion, Inc. is a medical device company distributing cryogenically preserved human tissues and developing medical devices for cardiac and vascular applications. Formerly CryoLife, founded in 1984 in Florida, it rebranded in January 2022, focusing on aortic disease technologies. Artivion markets aortic-centric products, including stent grafts, surgical sealants, mechanical heart valves, and implantable tissues, in over 100 countries.
The company has manufacturing facilities located in Atlanta, Georgia, Austin, Texas, and Hechingen, Germany. Additionally, it has sales and distribution offices in various countries throughout Europe, Asia, and South America.
Malware: Unidentified ransomware
Type of ransomware remains unidentified
Incident: Rancho Cucamonga Water District Ransomware Attack
An investigation and victim research is finally over and the Rancho Cucamonga, CA-based Cucamonga Valley Water District (CVWD) is informing victims of a ransomware attack the organizations suffered last July.
The Cucamonga Valley Water District discovered the attack on August 15, 2024, that started on July 31. The attack impacted their phone systems and online payment processing. While water service did not end up affected because it operates on a separate network, the attack disrupted their ability to process payments made over the phone, according to the district.
“Upon discovery of ransomware, CVWD immediately engaged third-party specialists and notified federal law enforcement,” the company said in a December update. “CVWD had in place robust software and systems that were able to immediately identify the intrusion and allowed us to react quickly to restore phone and payment systems within days. Within weeks, all systems were fully restored. CVWD did not pay a ransom.”
Reference: CA Water District Ransomware Investigation Completed
Victim: Rancho Cucamonga, CA-based Cucamonga Valley Water District (CVWD)
The district serves 190,000 customers within a 47-square-mile area, which includes approximately 49,000 water connections in Rancho Cucamonga, Upland, Fontana and Ontario.
Incident: Valve Opened in Norway Dam Attack
Hackers were able to get into the systems of a Norwegian dam this past April and open its water valve at full capacity.
The breach occurred at the Lake Risevatnet dam near the city of Svelgen in Southwest Norway. Attackers compromised a weak password on the web-accessible control panel and were able to open valves all the way at the dam. The valve ran at full capacity (497 m3/s above normal) for at least four hours before workers at the dam discovered the unauthorized change. The hack didn’t put anyone in danger, barely moving water output over the dam’s minimum water flow requirement, according to a report in the Norwegian energy news outlet Energiteknikk.
Reference: One Weak Password, Full Process Control: Inside Norway’s 2025 Dam Cyberattack
Reference: Norway Dam Hacked, Valve Opened But No Danger
Victim: Lake Risevatnet dam
Lake Risevatnet Dam in Norway. Is used for farming fish.
Incident: Chemical Maker, JCI Jones Chemicals, Hit in Cyberattack
Sarasota, Florida-based JCI Jones Chemicals, Inc. suffered a cyberattack via a third-party vendor where the attacker was able to make off with personally identifiable information.
“A cybercriminal obtained unauthorized access to a third-party vendor that maintained certain JCI data,” the chemical manufacturer said in a letter to victims. “Through our subsequent investigation, we determined that the unauthorized party accessed and acquired copies of certain JCI files on or about June 9, 2025.”
JCI said the files contained the name and address in combination with Social Security number, driver’s license number, certain limited medical information, and bank account information.
Reference: Chemical Maker Suffers Cyberattack
Victim: JCI Jones Chemicals, Inc.
JCI is a repackager of chlorine and other chemicals used for water purification. Furthermore, the company also provides chemicals and service to producers of everything from paper products to sophisticated computers, from food and beverage products to automobiles. Additionally, the company operates 10 manufacturing and distribution centers located across the US. Founded in 1930, JCI Jones remains a family-owned business.
Incident: Advanced Manufacturing Provider, PanOptimization, Suffers Cyberattack
State College, Pennsylvania-based PanOptimization LLC suffered a cyberattack where employees at the advanced manufacturing firm had some personally identifiable information stolen.
“We are writing to you because of an incident involving access to information associated with your employment records at PanOptimization LLC,” the company said in a letter to victims of the incident. “Although we are unaware of any actual misuse of your information, we are providing notice to you and other potentially affected employees about the incident, and about tools you can use to protect yourself against possible identity theft or fraud.”
On June 2, one of the company’s Microsoft exchange accounts ended up compromised. The threat actor intercepted login credentials via a phishing attack and temporarily gained access to one email account.
Reference: Cyberattack At Advanced Manufacturing Provider
Victim: PanOptimization LLC
tate College, Pennsylvania-based PanOptimization addresses the current simulation and optimization needs of the advanced manufacturing market. The goal is to simulate parts of extreme geometric complexity and to not just predict print outcomes but to improve/optimize them. PanOptimization licenses the PanX solver (a finite element based engineering software) to users in the aerospace and defense, biomedical, and CAE industries, as well as machine OEMs and universities.
Incident: Cyberattack at Transmission Maker, Reseller, American Driveline
Horsham, Pennsylvania-based American Driveline Systems, Inc., the parent company of AAMCO Transmissions, LLC, detected unusual activity within its server network this past April and found attackers stole personally identifiable information from employees.
Upon discovering this activity, American Driveline Systems immediately implemented its response protocols, took measures to contain the attack, and launched an investigation. The company then hired a cybersecurity firm that has assisted other companies in similar situations, and the investigation identified unauthorized access to files on servers in the network between April 11 and April 16.
American Driveline Systems assessed the files involved. By May 21, the company determined the files included the name and Social Security number and/or driver’s license number.
Reference: Transmission Maker, Reseller Hit In Cyberattack
Victim: American Driveline Systems, Inc.,parent company of AAMCO Transmissions, LLC
American Driveline Systems is the parent company of AAMCO Transmissions and also owns Cottman Transmission & Total Auto Care. ADS is a franchisor of these automotive repair brands, with nearly 700 franchised units across the U.S. and Canada. Additionally, they also operate a remanufacturing division called Global Powertrain Systems (GPS).
Incident: NJ Digital Imaging Maker, EFI, Hit in Cyberattack
Londonderry, New Jersey-based Electronics for Imaging Inc. (EFI) suffered a cyberattack last year where personally identifiable information ended up stolen and after an investigation is now letting victims know about the hack.
“On May 22, 2025, EFI became aware that personal information may have been contained within files that may have been subject to unauthorized access following a cyber incident,” said a letter to victims of the attack. “Upon identifying the cyber incident, EFI promptly initiated an investigation into the nature and scope of the incident.
The investigation determined the network fell victim to unauthorized access between September 17, 2024 and October 1, 2024 and copies of certain files ended up taken from the EFI network.
Reference: Cyberattack At NJ Digital Imaging Maker
Victim: Electronics for Imaging Inc. (EFI)
Londonderry, New Jersey-based Electronics for Imaging Inc. (EFI) develops technologies for the manufacturing of signage, packaging, textiles, ceramic tiles, and personalized documents, with a range of printers, inks, digital front ends, and a comprehensive business and production workflow suite.
Incident: Cyberattack Hits Curium Pharma
St. Louis, Missouri-based Curium Pharma suffered a cyberattack last October and is now letting victims know some of their personally identifiable information fell victim to the hack.
“On October 17, 2024, IT staff for Curium Pharma identified suspicious activity within the network,” the company said in a notice to victims. Furthermore, upon discovering the incident, the company took actions to secure the network, an investigation commenced, and an outside cybersecurity firm ended up engaged assist with the investigation.
As a result of the investigation, the company found the unauthorized party was able to access some data within the systems between October 15, 2024, and October 19, 2024.
Reference: Curium Pharma Suffers Cyberattack
Victim: Curium Pharma
Curium Pharma specializes in the production and supply of radioactive tracers used in nuclear medicine.
Incident: Flavorings Maker, Bluegrass Ingredients, Suffers Cyberattack
Flavoring manufacturer, Bluegrass Ingredients, Inc., suffered a cyberattack last year and after a lengthy investigation is now informing victims of the attack.
“On November 9th, 2024, Bluegrass became aware of suspicious activity in its network,” the Bowling Green, Kentucky-based company said in a notice to victims. “Bluegrass immediately launched an investigation to determine the nature and scope of the activity. The investigation determined that an unauthorized actor gained access to Bluegrass’s network between November 5th, 2024 and November 10th, 2024 and copied certain files.”
As a result of the attack, the company undertook a comprehensive review of the files the attackers exfiltrated to determine what information was present, to whom it related. They also had to identify complete address information for the victims of the attack.
Reference: Flavorings Maker Hit In Cyberattack
Victim: Bluegrass Ingredients, Inc.
Bluegrass Ingredients is a manufacturer of flavorings and ingredients that allow brands to concept, test and produce the custom flavors and formulations.
Reference: The Ingram Micro Ransomware Attack: Lessons Learned
Reference: Ransomware Attack At IT Distributor
Incident: Advanced Manufacturing Provider, PanOptimization, Suffers Cyberattack
State College, Pennsylvania-based PanOptimization LLC suffered a cyberattack where employees at the advanced manufacturing firm had some personally identifiable information stolen.
“We are writing to you because of an incident involving access to information associated with your employment records at PanOptimization LLC,” the company said in a letter to victims of the incident. “Although we are unaware of any actual misuse of your information, we are providing notice to you and other potentially affected employees about the incident, and about tools you can use to protect yourself against possible identity theft or fraud.”
On June 2, one of the company’s Microsoft exchange accounts ended up compromised. The threat actor intercepted login credentials via a phishing attack and temporarily gained access to one email account.
Reference: Cyberattack At Advanced Manufacturing Provider
Victim: PanOptimization LLC
PanOptimization addresses the current simulation and optimization needs of the advanced manufacturing market. The goal is to simulate parts of extreme geometric complexity and to not just predict print outcomes but to improve/optimize them. PanOptimization licenses the PanX solver (a finite element based engineering software) to users in the aerospace and defense, biomedical, and CAE industries, as well as machine OEMs and universities.
Incident: ‘Sophisticated’ Attack Hits Valve Maker, Bray International
Houston, Texas-based Bray International, Inc. suffered a “sophisticated cyber incident” over one year ago and after an investigation, it is now letting victims know about the attack.
A global valve manufacturer and supplier, Bray worked with third-party forensic specialists to complete a thorough investigation.
In the investigation, researchers found an unauthorized actor gained access to Bray’s network between April 17, 2024, and April 25, 2024, and may have viewed or taken certain files.
Reference: Valve Maker Hit In ‘Sophisticated’ Attack
Victim: Bray International, Inc.
In 1986, Bray International, Inc. started up as a global flow control partner. Bray offers a comprehensive line of innovative flow control solutions. Bray is a global manufacturer of isolation valves, control valves, and automation and accessories.
Incident: German Napkin Maker Insolvent after Ransomware Attack
German paper napkin manufacturer, Fasana, is now facing insolvency after a ransomware attack this past May disrupted all forms of operations at the company.
In a bit of irony, on May 19, Fasana’s entire printing infrastructure suddenly began producing ransom notes. In the attack, it appeared every laptop and desktop PCs ended up locked down. The next day, May 20, the company was unable to process orders worth over €250,000 ($287,467).
For nearly two weeks, Fasana was unable to: Print delivery notes or invoices, fulfill customer orders and process employee salaries.
In that short timeframe, the company suffered financial losses of over €2 million ($2.3 million). Dr. Dirk Wegener, the court-appointed insolvency administrator, said the company could not conduct basic business operations.
Reference: Ransomware Forces Napkin Maker Into Insolvency
Victim: Fasana
Stotzheim, Germany-based napkin manufacturer, Fasana, employs 240 workers. It just changed ownership in March after Powerparc Group purchased the company. However, the cyberattack forced the company to seek a new buyer.
Incident: Cyberattack At AK Oil Services Firm, Doyon
Fairbanks, Alaska-based Doyon, Limited, which operates a diverse family of companies, including more than a dozen for-profit businesses across the nation in the areas of oil field services, utility management, engineering management, suffered a cyberattack in April.
“On or about April 2, 2024, we discovered that on or about April 1, 2024, an unauthorized actor or actors accessed and acquired files from Doyon’s IT systems,” said a letter sent out to victim of the attack. “We initiated an investigation, retained an outside incident response company, and notified law enforcement.”
The company said it conducted a review with the assistance of external experts to determine if personal information ended up stolen in the attack. Through its investigation, the company found personal information such as names and other pertinent data the company did not reveal.
Reference: Cyberattack At Major Alaskan Company
Victim: Doyon, Limited
Fairbanks, Alaska-based Doyon, Limited, the Native regional corporation for Interior Alaska, is a for-profit corporation with more than 20,000 shareholders. Established under the 1971 Alaska Native Claims Settlement Act (ANCSA), Doyon is the largest private landowner in Alaska, with more than 12.5 million acres allocated to the corporation under ANCSA.
As one of the top Alaska-owned businesses, Doyon operates a diverse family of companies, including more than a dozen for-profit businesses across the nation in the areas of oil field services, utility management, engineering management, information technology services, land and natural resource development, facility management, construction and tourism.
Doyon employs over 800 individuals worldwide and over 550 employees in Alaska.
Incident: IL Baking Manufacturer, Alpha Baking, Hit in Cyberattack
Chicago, Illinois-based Alpha Baking Co. suffered a cyberattack in January and is now letting victims know their personally identifiable information ended up stolen in the hack.
While the company said it has no evidence the stolen data is undergoing any kind of abuse at the moment, the company is issuing notices to victims.
“On January 23, 2025, we identified unusual activity on our computer network,” the company said in a letter sent out to victims of the attack. “We immediately took steps to investigate. A forensic investigation conducted by external experts determined that an unauthorized third party obtained certain files stored on our network.”
Reference: Baking Manufacturer Suffers Cyberattack
Victim: Alpha Baking Co.
Alpha Baking Company started up in 1979 with the acquisition of the Mary Ann Baking Company in Chicago. Founded in 1935, Mary Ann makes the popular Chicago style poppy seed hot dog bun. Additionally, in 1981, Alpha Baking purchased S. Rosen’s Baking Company, a Chicago staple and baker of Jewish hearth rye breads and variety rolls since 1909. Through the years, Alpha Baking continued to grow with the acquisition of Kreamo Bakers in South Bend, Indiana in 1979, National Baking Company in Chicago, Illinois in 1997, and Natural Ovens Bakery in Manitowoc, Wisconsin in 2007.
Incident: Cyberattack At Industrial Technology Provider, General Digital
East Hartford, Connecticut-based industrial and military technology provider, General Digital Corporation (GDC) suffered a cyberattack in January and is now letting victims know their personally identifiable information ended up stolen in the attack.
“GDC recently became aware of suspicious activity within their computer network,” the company said in a letter to victims. “Upon learning of the suspicious activity, GDC immediately took steps to secure their systems and launched an investigation into the nature and scope of the activity with the assistance of third-party cybersecurity and data privacy specialists.”
GDC said the investigation found an unauthorized actor accessed the company’s network at various times between January 10 and January 20 and certain information contained within those systems ended up viewed or copied.
Reference: Cyberattack At CT-Based Industrial Technology Provider
Victim: General Digital Corporation
General Digital is an SBA Small Business Concern with three business units: Designer and manufacturer of industrial- and military-grade monitors, optical bonding display enhancements in-house, efficiently improving brightness and contrast while preventing damage from impacts, and safety-critical software testing and software and product development services for aerospace, avionic, medical, transportation, industrial and other applications.
Incident: Cyberattack at Canadian Airline, WestJet
Calgary, Canada-based low-cost airline, WestJet, said it suffered a cybersecurity breach affecting its internal systems and its app.
“WestJet is aware of a cybersecurity incident involving internal systems and the WestJet app, which has restricted access for several users, the airline said when they first found out about the incident on Friday (June 13). “We have activated specialized internal teams in co-operation with law enforcement and Transport Canada to investigate the matter and limit impacts.”
The company added, “our operation is running safely and remains unaffected by the current situation at this time. We are actively working to understand the extent of impact and have expedited resolution efforts.”
Reference: anadian Airline Suffers Cyberattack
Victim: Westjet
Calgary-Canada-based WestJet is the second-largest airline in Canada and focuses on providing affordable travel options for Canadians.
Incident: Ransomware Attack At BTU International
Westford, Massachusetts-based BTU International, a thermal processing equipment provider, suffered a ransomware attack in August affecting its information technology (IT) systems where personal information ended up stolen.
“On or around August 11, 2025, BTU became the victim of a ransomware attack that affected its IT systems,” the company said in a notice to victims of the attack. “Upon discovering this activity, we immediately took protective actions to stop the unauthorized access, notified U.S. federal law enforcement, including the Federal Bureau of Investigation (“FBI”), assessed the security of our network and systems, and launched an investigation with the assistance of leading cybersecurity specialists.”
BTU suffered a ransomware attack in April 2021 from the DarkSide attack group.
Reference: Ransomware Attack At Thermal Processing Equipment Maker
Victim: BTU International
BTU International is a wholly-owned subsidiary of Amtech Group. It is a global supplier of advanced thermal processing equipment solutions in the electronics manufacturing market. To that end, BTU’s convection reflow ovens end up used in the production of SMT printed circuit board assemblies and in semiconductor packaging processes.
Additionally, BTU also specializes in precision controlled, high-temperature belt furnaces for a wide range of custom applications. Moreover, those applications include, brazing, direct bond copper (DBC), diffusion, aluminum sintering and advanced solar cell processing. Furthermore, BTU has operations in Westford, and Shanghai, China.
Incident: Medical Researcher, Manufacturer, Inotiv, Suffers Cyberattack
West Lafayette, Indiana-based Inotiv, Inc., a medical researcher and maker of products, suffered a cyberattack in August and is now letting victims know their personally identifiable information ended up stolen.
Inotiv, Inc. (“Inotiv”) is a contract research organization that provides nonclinical and analytical drug discovery and development services and research models and related products and services.
“On August 5, 2025, we detected unusual activity on certain Inotiv systems and promptly initiated an investigation,” the company said in a notice to victims of the attack. “On August 8, 2025, we determined that this unusual activity was due to unauthorized actions by a threat actor.”
Reference: Medical Researcher, Manufacturer Hit In Cyberattack
Victim: Inotiv, Inc.
Inotiv is a manufacturer primarily of research-related products like lab animal diets, bedding, and supplies. Furthermore, it is also a major contract research organization (CRO) providing drug development services, including manufacturing and testing services for preclinical phases. Additionally, they manufacture essential items like custom diets and bedding and also produce biological products from their own research models for drug research.
Incident: Cyberattack at Pharma Product Maker, Chiesi USA
Cary, North Carolina-based Chiesi USA, Inc., a pharmaceutical manufacturing and researcher, suffered a cyberattack in August where personally identifiable information ended up stolen in the hack.
“On August 28, 2025, we learned of potential unauthorized access to our U.S.-based systems,” the company said in a letter to victims of the attack. “We launched our investigation in partnership with third-party cybersecurity specialists to determine the nature and scope of the incident and activated our remediation and recovery efforts.”
After the investigation wrapped up, Chiesi determined an unauthorized third party accessed certain information maintained on its U.S.-based systems. Additionally, the company said this access was the result of an IT security issue that impacted part of its internal IT infrastructure.
Reference: Pharma Product Maker, Researcher Suffers Cyberattack
Victim: Chiesi USA, Inc.
Chiesi USA, as part of the global Chiesi Group, takes part in pharmaceutical manufacturing, developing, marketing, and distributing therapies. Furthermore it has a focus on areas like respiratory health, rare diseases, neonatology, and special care, leveraging R&D and production investments. To that end, while they focus heavily on R&D and commercialization, the larger group engages in significant manufacturing activities.
Incident: Medical Instrumentation Maker, Cytek Biosciences, Suffers Cyberattack
Fremont, California-based medical instrumentation maker, Cytek Biosciences, Inc., suffered a cyberattack in November which resulted in threat actors stealing personally identifiable information in the hack.
“Cytek Biosciences experienced a data security incident involving unauthorized access to certain of our systems that occurred on or around November 1, 2025,” the company said in a letter to victims. “Based on our investigation, we learned on or around November 28, 2025, that, in connection with this issue, an unauthorized party obtained certain of your personal information.”
The information varied by affected individual and may have included, to the extent provided to Cytek, name, contact information (e.g., postal address, email address, and phone number), date of birth, Social Security number, driver’s license number, government-issued ID number, citizenship status, signature, health and medical information, financial account and compensation information, as well as Cytek employee account username and password.
Reference: Medical Instrumentation Maker Suffers Cyberattack
Victim: Cytek Biosciences, Inc.
Cytek Biosciences Inc. is a manufacturer and supplier of flow cytometry products and services. Furthermore, Cytek’s instruments and support offerings end up used by researchers and clinicians all over the world. Flow cytometry is an analytical tool used for identifying and quantifying cellular characteristics on a cell-by-cell basis up to tens of thousands of cells per second. This technology sees use in research and clinical studies with various biomedical and therapeutic applications such as investigating the role of the body’s immune system in fighting cancer, diagnosing leukemia and lymphoma, and detecting minimal residual disease in organ transplant patients.
Reference: Cyberattack Alters Food Distributor’s Operations
Incident: First-Aid Product Maker, DC Safety, Hit In Cyberattack
First-aid and preparedness product manufacturer, DC Safety Sales Co. suffered a cyberattack late last year and is now informing victims of the attack where personally identifiable information ended up stolen.
On January 21, 2025, Theodore, Alabama-based DC Safety learned an unauthorized third party exploited a Zero Day vulnerability in a third-party application operating on a limited number of DC Safety’s servers.
Upon discovery of the December 11, 2024 attack, the company isolated the servers, contained the impact, and conducted an investigation, which included working with third-party specialists, to determine the nature and scope of the event.
Reference: First-Aid Product Maker Hit In Cyberattack
Victim: DC Safety Sales Co.
Founded in 1975, DC Safety manufactures and distributes first-aid and preparedness products, and supplies these items as original equipment and accessories to the automotive industry. DC also manufactures and distributes first-aid and preparedness products for non-automotive applications, including marine, powersports, outdoor/hunting/fishing, retail, government agencies and promotions.
Incident: Second Attack In 2 Months For VF Outdoor
For the second time over a two-month period, Denver, Colorado-based VF Outdoor LLC, suffered a credential stuffing attack against one of its brands, this time The North Face.
“On April 23, 2025, we discovered unusual activity involving our website, thenorthface.com, which we investigated immediately,” the company said in a letter to victims. “Following a careful and prompt investigation, we concluded that an attacker had launched a small-scale credential stuffing attack against our website on April 23, 2025.”
A credential stuffing attack is a specific type of cybersecurity attack where the threat actor uses account authentication credentials stolen from another source, such as a breach of another company or website, to gain unauthorized access to user accounts.
Reference: Second Attack In 2 Months For Clothing Maker
Incident: Cyberattack at LexisNexis Risk Solutions
Risk management provider, LexisNexis Risk Solutions (LNRS) suffered a cyberattack where personally identifiable information for over 360,000 customers ended up stolen.
“On April 1, 2025, we learned that on December 25, 2024, an unauthorized third party acquired certain LNRS data from a third-party platform used for software development,” the company said in a letter to victims. “The issue did not affect LNRS’s own networks or systems.
Based on LNRS’ review of the impacted data, the Alpharetta, Georgia-based company determined personal information ended up affected in the attack. There were 364,333 people affected in the attack.
Reference: LexisNexis Risk Solutions Hit In Cyberattack
Victim: LexisNexis Risk Solutions (LNRS)
LexisNexis Risk Solutions (LNRS) provides risk management services to business customers.
Incident: Ransomware Attack at KY Phone Co-Op
Jamestown, Kentucky-based Duo County Telephone Cooperative Corporation, Inc. and Cumberland Cellular, LLC (doing business under the shared branding Duo Broadband) suffered a ransomware attack that exposed personally identifiable information.
Duo Broadband suffered a security incident that may have exposed some of your personal information. There were 42,518 victims in the incident, the company said.
“On February 13, Duo Broadband discovered a data security incident in which a cyber threat actor attempted to disrupt our systems in a possible effort to deploy ransomware, and solicit a ransom payment from us,” the company said in a letter to victims of the incident.
Reference: KY Phone Cooperative Suffers Ransomware Attack
Victim: Duo County Telephone Cooperative Corporation, Inc. and Cumberland Cellular, LLC
Duo County Telephone Cooperative Corporation, Inc. and Cumberland Cellular, LLC (doing business under the shared branding Duo Broadband) is a telecommunications company.
Incident: Oil-Gas Producer, DJH Services, Hit In Cyberattack
Oil and Gas producer, DJH Services LLC, suffered a cyberattack in February and is now informing victims what personally identifiable information ended up stolen.
Houston, Texas-based DJH Services also wrote the notice on behalf of its companies, Harrison Interests, Ltd., Fulshear Oil & Gas, and Ramro.
“On February 13, 2025, DJH discovered a cyber incident affecting our network. Immediately upon detecting this incident, we took steps to secure our environment, began remediation and recovery efforts, and launched a thorough investigation in partnership with third-party cybersecurity experts,” the company said in the notice. “We also reported this matter to the Federal Bureau of Investigation.”
Reference: Oil-Gas Producer Hit In Cyberattack
Victim: DJH Services LLC
DJH works in crude petroleum production, natural gas production, drilling oil and gas wells, along with other agricultural production like beef cattle and other livestock.
Incident: Ransomware Attack At EB Archbald & Associates, a Provider To Oil-Gas Producers
There was a ransomware attack at EB Archbald & Associates, Inc., which provides energy production accounting services to oil and gas producers and operators.
“On March 23, 2025, we discovered that our company had been the target of a so-called ‘ransomware’ attack,” the Oklahoma City, Oklahoma-based company said in a notice to its 17,000 victims. “The attackers hacked into our system and utilized software to encrypt all data on our servers and Microsoft cloud-based portal. In a subsequent communication the attackers demanded payment of a large sum of money in exchange for their release of a ‘decryption key.’
“We immediately contacted the local office of the Federal Bureau of Investigation (FBI) and notified them of the attack. Per recommendations received from the FBI we refused to meet the attackers’ extortion demands. Five days after their initial attack, and following our refusal to meet their monetary demand, we received a communication from the attackers claiming that they had downloaded information from our systems which they intended to release on the world wide web,” the company said in the notice.
Reference: Ransomware Attack At Provider To Oil-Gas Producers
Victim: EB Archbald & Associates, Inc.
There was a ransomware attack at EB Archbald & Associates, Inc., which provides energy production accounting services to oil and gas producers and operators.
“On March 23, 2025, we discovered that our company had been the target of a so-called ‘ransomware’ attack,” the Oklahoma City, Oklahoma-based company said in a notice to its 17,000 victims. “The attackers hacked into our system and utilized software to encrypt all data on our servers and Microsoft cloud-based portal. In a subsequent communication the attackers demanded payment of a large sum of money in exchange for their release of a ‘decryption key.’
“We immediately contacted the local office of the Federal Bureau of Investigation (FBI) and notified them of the attack. Per recommendations received from the FBI we refused to meet the attackers’ extortion demands. Five days after their initial attack, and following our refusal to meet their monetary demand, we received a communication from the attackers claiming that they had downloaded information from our systems which they intended to release on the world wide web,” the company said in the notice.
Incident: Automation Service Provider, Caltrol, Suffers Cyberattack
Automation services provider, Caltrol Inc. suffered a cyberattack over a six-day period at the end of January into February where a threat actor was able to exfiltrated personally identifiable information of victims.
From Monday, January 27 until Saturday, February 1, Caltrol suffered an attack that involved personal information. The company sent out letters saying “we received your information because your parent or spouse is employed by our organization.”
“On February 1, 2025, Caltrol became aware of technical issues related to our server,” the company said in a letter to victims. “Upon discovery, we took immediate action to secure our company’s systems and retained outside cyber counsel and engaged independent IT specialists (at the direction of counsel) to investigate the incident.”
Reference: Automation Service Provider Hit In Cyberattack
Victim: Caltrol Inc.
Established in 1934, Caltrol is a provider of automation including process control solutions, valves, instrumentation, and reliability. Caltrol is an employee owned company and an Emerson Impact Partner. Company headquarters are in Las Vegas, Nevada with locations in Irvine, Ontario, Livermore, Bakersfield, Benicia, Taft, and Paramount, California, Chandler, Arizona, and Honolulu, Hawaii.
Incident: Mississippi Utility Suffers Cyberattack
Municipally owned and operated electric and water utility, Starkville Utilities, suffered from a cyberattack last October where threat actors were able to abscond with personally indefinable information from over 11,000 victims.
The Starkville, Mississippi-based utility discovered the attack October 23, 2024, when they noticed unauthorized activity within its computer network.
“Upon discovery of the incident, Starkville immediately disconnected all access to the network and promptly engaged a specialized third-party incident response firm to assist with securing the environment, as well as, to conduct a comprehensive forensic investigation to determine the nature and scope of the incident,” the company said in a letter to victims.
Reference: MS Utility Suffers Cyberattack
Victim: Starkville Utilities
Starkville is a municipally owned and operated electric and water utility serving more than 14,000 residences, businesses and industries in Starkville as well as the state’s largest university, Mississippi State University. Furthermore, the utility employs 70 workers.
Incident: Ransomware Attack at Security Firm, Andy Frain Services
Security provider, Andy Frain Services (AFS) suffered an October 2024 data breach where 100,964 people fell victim to the hack.
Aurora, Illinois-based AFS said it discovered the breach on October 23, 2024. Ransomware gang Black Basta claimed responsibility for the breach in November 2024, saying it stole 750 GB of data from the private security firm.
In a letter to victims of the attack, Andy Frain did not mention if this was a ransomware attack or not. It did not verify the Black Basta claim.
Reference: Security Firm Hit In Ransomware Attack
Victim: Andy Frain Services (AFS)
Starting up in 1924, Andy Frain Services is a private security company that staffs security personnel at large events and facilities including sporting events, transportation hubs, government offices, shopping centers, and festivals. Its sporting event clients include the NFL, NBA, NHL, MLB, Kentucky Derby, US Golf Open, and NASCAR.
Incident: Dried Fruit Provider, Sunsweet Growers, Suffers Cyberattack
Sunsweet Growers Inc., one of the largest handler of dried tree fruits in the world, suffered a cyberattack where threat actors stole information that may relate to current and former employees.
On December 11, 2024, Yuba City, California-based Sunsweet became aware certain computer network systems were inaccessible.
The company quickly took steps to secure its systems and launched an investigation with the assistance of third-party computer specialists to confirm the full nature and scope of the activity and to restore functionality to the affected systems.
Reference: Dried Fruit Provider Hit In Cyberattack
Victim: Sunsweet Growers
Sunsweet Growers Inc. is the world’s largest handler of dried tree fruits including cranberries, apricots and prunes. A grower-owned marketing cooperative representing more than one-third of the prune market worldwide, Sunsweet processes more than 50,000 tons of prunes a year.
Incident: Cyberattack at Watch Maker, Nixon
Watch maker, Nixon, Inc. suffered a cyberattack that made off with personally identifiable information of various victims.
“On December 18, 2024, we were alerted to unusual activity involving our information technology environment,” the company said in a letter to victims. “In response, we initiated an investigation, took steps to secure our systems, and notified law enforcement.” Additionally, the company hired a third-party forensic firm to assist in the investigation.
“On April 18, 2025, our investigation determined an unauthorized individual accessed files on our systems containing your information,” the company said.
Reference: Watch Maker, Nixon, Suffers Cyberattack
Victim: Nixon, Inc.
Nixon, founded in 1997 by Andy Laats and Chad DiNenna, makes Nixon watches. Nixon specializes in fashionable and affordable watches, particularly within the youth and lifestyle market. Nixon’s core business is in designing and manufacturing their own watch styles.
Incident: Coatings Manufacturer, Huntsman Building Solutions, Suffers Cyberattack
Arlington, Texas-based Huntsman Building Solutions (USA) LLC fell victim to a cyberattack that had an impact on certain files on the company’s information systems.
“On February 11, 2025, we learned that an unauthorized third party had gained access to our information systems,” the company said in a letter to victims of the attack. “The company’s IT team immediately blocked any further access by the unauthorized third party, took steps to ensure our systems are secure and commenced a comprehensive investigation with the assistance of a leading cybersecurity firm.”
Huntsman then conducted a lengthy and thorough analysis of this incident. It was able to determine personal information including name and other personally identifiable information the company did not disclose ended up compromised in the attack.
Reference: Coatings Manufacturer Hit In Cyberattack
Victim: Huntsman Building Solutions (USA) LLC
Arlington, Texas-based Huntsman Building Solutions (USA) LLC manufactures spray polyurethane foam (SPF) and coatings for roof, attic and wall applications. Furthermore, the company formed in May 2020 through the combination of the Demilec and Icynene-Lapolla SPF businesses, Huntsman Building Solutions is a business unit of Huntsman Corporation.
Incident: Architectural And Engineering Firm Hit in Cyberattack
Architectural and engineering provider, Baskervill & Son, P.C & Son, P.C. suffered a cyberattack last September and is now informing victims of the incident their personally identifiable information ended up stolen.
“On September 13, 2024, we learned of an unauthorized access to our systems,” the company said in a notice to victims. “Upon detection, we took immediate action to terminate further access and investigate the incident. We retained legal counsel and, through counsel, engaged external cybersecurity forensic specialists to conduct an investigation.”
On October 23, the forensic investigation revealed on September 13, an unauthorized actor gained access to and exfiltrated data from the Richmond, Virginia-based company’s systems.
Reference: Cyberattack At Architectural And Engineering Firm
Victim: Baskervill & Son, P.C & Son, P.C.
Founded in 1897, Richmond, Virginia-based Baskervill is one of the nation’s oldest continually operating architectural firms. The company offers architectural, interior design, and mechanical, electrical and plumbing (MEP) engineering solutions. The client base varies from hotels and resorts, to workspaces, healthcare facilities, and higher education institutions.
Incident: Cosmetics Maker, Athena Cosmetics, Hit In Cyberattack
Athena Cosmetics, Inc. which does business as RevitaLash Cosmetics in Ventura, California, suffered a cyberattack where threat actors purloined personally identifiable information.
On January 16, cosmetics maker, Athena, said it found suspicious activity in its environment and immediately initiated an investigation with the assistance of independent cybersecurity experts. As a result of the investigation, Athena determined certain files may have been acquired without authorization.
“Upon discovering the event, Athena moved quickly to investigate and respond to the incident, assess the security of Athena systems, and identify potentially affected individuals,” the company said in a notice to victims. “Athena is also working to implement additional safeguards and training to its employees.”
Reference: Cosmetics Maker Hit In Cyberattack
Victim: Athena Cosmetics
Athena Cosmetics, Inc. which does business as RevitaLash Cosmetics, started up in 2006 with one product: The original lash conditioner.
Incident: Cyberattack Hits KWS Manufacturing
Burleson, Texas-based KWS Manufacturing Company, LLC suffered a cyberattack where threat actors made off with personally identifiable information.
“We recently learned of suspicious activity in our computer environment,” the company said in a notice to victims of the incident. “We immediately launched an investigation, with the assistance of outside experts. The investigation determined that an unauthorized third party accessed our computer systems during the period of January 24-25, 2025, and obtained some company files. We conducted a diligent review of the affected files to determine what personal information they contained.”
KWS officials said in the letter there is no indication the stolen personal information ended up misused as a result of this incident, The investigation did determine the affected company files contained your name and an additional amount of information the company redacted from the letter to victims.
Reference: KWS Manufacturing Suffers Cyberattack
Victim: KWS Manufacturing Company, LLC
Founded in 1972, the company manufactures screw conveyors, screw feeders, slide gates, and bucket elevators for process industries, including the food, chemicals, and wood industries. Furthermore, the company has 165 employees and had revenues of $45 million for the twelve months ended September 30, 2023. KWS’ primary customers are end users, power transmission distributors, engineering firms, system suppliers and original equipment manufacturers (OEMs).
Incident: Railway Equipment Maker, Plasser American Corp., Hit In Cyberattack
Railway track maintenance equipment maker, Plasser American Corporation, suffered a cyberattack in February where threat actors copied personally identifiable information.
“On February 4, 2025, Plasser became aware of suspicious activity occurring within its network,” the company said in a notice to victims.
“It initiated a comprehensive investigation to understand the nature and scope of the activity. The investigation subsequently determined that, between February 2, 2025, and February 4, 2025, an unknown actor gained access to certain network servers and copied a limited amount of data,” Plasser said.
Reference: Railway Equipment Maker Hit In Cyberattack
Victim: Plasser American Corporation
Plasser American Corporation is a manufacturer of railway track maintenance equipment, and is actively engaged in all sectors of research, design, production, marketing and customer service.
Incident: Cyberattack at Security Provider, CPI
Security product maker, Chatsworth Products, Inc. (CPI), fell victim to a cyberattack last September and after an investigation is now informing victims of the incident.
“CPI recently became aware of suspicious activity within their computer network,” the company said in a notice to victims. “Upon learning of the suspicious activity, CPI immediately took steps to secure their systems and launched an investigation into the nature and scope of the activity with the assistance of third-party cybersecurity and data privacy specialists.
“The investigation determined that an unauthorized actor accessed the CPI network at various times between September 12, 2024 and September 23, 2024, and certain information contained within those systems ended up viewed or copied by the unauthorized actor during that time,” the company said.
Reference: Security Provider, CPI, Suffers Cyberattack
Victim: Chatsworth Products, Inc. (CPI)
Founded in 1991, CPI specializes in manufacturing products and solutions that protect investments in information and communications technology. From data centers to industrial environments, CPI’s product line includes: Rack Systems, Cabinets, Enclosures and Containment Systems, Cable Management, Cable Runway and Tray, Power Management, Zone Cabling and Wireless Enclosures, Wall-Mount Systems, KVM Systems, Environmental Monitoring and Security, Software, Grounding and Bonding and Seismic Protection Systems. CPI also offers a variety of Thermal Management Solutions to help reduce energy consumption and overcome increasing equipment density requirements.
Incident: Mission Bell, a CA Millwork Maker, Hit In Cyberattack
Morgan Hill, CA-based Mission Bell, an architectural millwork and casework manufacturer, suffered a data security incident that may have involved personally identifiable information.
Moreover, the Mission Bell data breach involved sensitive personal information belonging to an undetermined number of individuals.
“On February 1st, we discovered a security breach that occurred on January 31st. After conducting a lengthy investigation, we determined that unauthorized access to certain personal information may have taken place,” the company said in a letter to victims.
Reference: CA Millwork Maker Hit In Cyberattack
Victim: Mission Bell
Morgan Hill, CA-based Mission Bell is an architectural millwork and casework manufacturer.
Incident: VF Outdoor, Parent to Timberland, North Face, Suffers Credential Stuffing Attack
VF Outdoor, the parent company to The North Face and Timberland, suffered a credential stuffing cyberattack last month and decided to release details of the attack even though the firm said the threat actors did not obtain any customer data from the site.
On March 13, the company ended up alerted to unusual activity involving its website, [thenorthface.com or timberland.com], that prompted it to investigate immediately.
“Following a careful investigation, we concluded that an attacker had launched a small-scale credential stuffing attack against our Website on March 13, 2025,” the company said in a letter to victims. “A ‘credential stuffing attack’ is a specific type of cybersecurity where the attacker uses account authentication credentials (e.g., email addresses/usernames and passwords) stolen from another source, such as a breach of another company or website, to gain unauthorized access to user accounts.
Reference: VF Outdoor Suffers Credential Stuffing Attack
Victim: VF Outdoor
Denver, Colorado-based VF Outdoor is a global apparel, footwear and equipment company, including brands such as The North Face, Vans and Timberland.
Incident: Third Party Attack at Kellogg
Battle Creek, Michigan, food manufacturing giant, WK Kellogg Co. discovered in late February that a vendor it uses for secure file transfers, Cleo, experienced a security incident.
In response, WK Kellogg after discovering the incident Feb. 27 and immediately began to investigate. It contacted Cleo, and the company informed WK Kellogg an unauthorized person gained access on December 7. The attacker got into the servers Cleo hosted and Kellogg used for transferring employee files to human resources service vendors.
Cleo is a technology vendor used by multiple companies for its secure file transfer application.
Reference: Kellogg Falls Victim To Third Party Attack
Victim: WK Kellogg Co.
WK Kellogg Co. is a Battle Creek, Michigan-based food manufacturing giant.
Incident: Seafood Processor, OBI Seafoods, Hit In Cyberattack
OBI Seafoods, LLC suffered a cyberattack involving personally identifiable information related to certain current and former workers and vendors of OBI and Ocean Beauty Seafoods, LLC (“OBS”).
The Seattle, Washington-based company said in a notice letter to 19,014 victims, it remains unaware of any reports of fraud or identity theft as a result of this incident. OBI said it became aware of the security incident on August 16, impacting a portion of its environment.
“Upon detection, OBI immediately took steps to secure its systems and engaged external cybersecurity specialists to assist with the investigation. OBI also notified federal law enforcement of the incident. Through the investigation, OBI determined that information related to current and former workers and vendors of OBI or OBS may (end up) involved.
Reference: Seafood Processor Hit in Cyberattack
Victim: OBI Seafoods
OBI Seafoods is an Alaskan seafood processor with ten shoreside plants producing fresh and frozen seafood and canned salmon. Moreover, the product of a merger between Ocean Beauty Seafoods and Icicle Seafoods, OBI Seafoods is one of the largest Alaska seafood processors with over 100 years of processing history and experience. Furthermore, the company has processing facilities in Petersburg, Excursion Inlet, Cordova, Seward, Kodiak, Larsen Bay, Alitak, Egegik, Wood River (Dillingham) and Naknek.
Incident: McIntosh Laboratory, Audio Product Maker, Hit in Cyberattack
High-end audio equipment maker, McIntosh Laboratory, Inc. suffered a cyberattack in October which disrupted access to various systems within the network.
“On October 21, 2025, McIntosh detected suspicious activity and experienced a disruption of access to certain of our digital systems,” the company said in a notice to victims. “In response, we took immediate steps to secure our network and engaged forensic experts to investigate.”
Based on the investigation, McIntosh found the attacker accessed and acquired certain data between October 17 and 19.
Reference: Audio Product Maker Suffers Cyberattack
Victim: McIntosh Laboratory Inc.
McIntosh Laboratory is a manufacturer of handcrafted high-end audio equipment is headquartered in Binghamton, NY. It is a subsidiary of the McIntosh Group, which the audio equipment giant, Bose Corporation, acquired in November 2024.
Incident: Cyberattack at Cargo Airline 21 Air
Greensboro, North Carolina-based 21 Air, LLC, an air cargo airline, suffered a cyberattack via an email compromise in March and is now letting victims of the attack know about the hack.
“We are writing to inform you of a cyber security incident experienced by 21 Air, LLC that may have involved your information described below,” the company said in a letter to victims. “On June 3, 2025, we discovered suspicious activity potentially related to an employee email account. Upon discovery, we took swift action to secure our email system and network.”
The company said it reported this incident to the Cybersecurity and Infrastructure Security Agency (CISA) regarding the attack which it said started March 17 and discovered June 3.
Reference: Cargo Airline Suffers Cyberattack
Victim: 21 Air, LLC
21 Air is an all-cargo airline of the United States. The airline operates Aircraft, Crew, Maintenance, and Insurance (ACMI) charters with a fleet of Boeing 767s. Furthermore, an ACMI charter is an agreement where one airline provides a fully equipped aircraft to another airline for a set period. That allows the lessee to quickly add capacity without the long-term investment.
Incident: Auto Parts Maker, LKQ, Suffers Another Attack
Antioch, Tennessee-based LKQ Corporation, an auto parts distributor and maker of a some parts, suffered a cyberattack as a result of a third party vulnerability in August where victims’ personally identifiable information ended up stolen in the hack.
Oracle announced a number of security vulnerabilities, including a previously unknown vulnerability in its E-Business Suite application, used by LKQ and other organizations worldwide. In early October, LKQ’s security team became aware of a third party exploiting these vulnerabilities.
This is the second attack LKQ suffered in a year.
Reference: Auto Parts Maker Suffers Another Attack
Incident: Second Third-Party Attack In Year at Vitamin Maker
Palm Beach Gardens, Florida-based Garden of Life, LLC suffered a second third-party cyberattack in a year and this time – like last time – personally identifiable information ended up stolen in the hack.
“On November 11, 2025, Garden of Life became aware of an unauthorized third party claiming to have accessed certain Garden of Life systems,” the company said in a notice to victims. “We immediately responded to this report by taking potentially affected systems offline and initiating an investigation by internal and external experts.”
Through this investigation, the company found on November 14 an unauthorized third party had obtained data about current and former Garden of Life employees, contractors, and business partners.
Reference: Vitamin Maker Suffers Second Third-Party Attack In Year
Incident: Irrigation Product Supplier Suffers Cyberattack
Azusa, California-based irrigation product supplier, Rain Bird Corporation, suffered a cyberattack in February and is now informing victims of the attack.
“On or about July 25, 2025, Rain Bird became aware of suspicious activity affecting certain portions of the Rain Bird Web Store,” the company said in a letter to victims. “Rain Bird immediately took steps to secure our environment and launched a comprehensive investigation with the assistance of third-party cybersecurity specialists.”
The investigation subsequently determined there was fraudulent activity potentially associated with payment cards used to perform transactions on the Rain Bird Web Store between February 11, and September 5.
Reference: Attack At Irrigation Product Supplier
Victim: Rain Bird Corporation
Rain Bird is an international privately held manufacturer and provider of irrigation products and services for landscapes, golf courses, sports fields, and agriculture designed to minimize water consumption.
The firm’s headquarters is in Azusa, California, with offices and manufacturing facilities in Tucson, Arizona; Steele, Alabama; Tijuana Mexico; France; and China. Rain Bird sells more than 4,000 products and services in over 130 countries.
Incident: Cyberattack at NY Engineering Firm
Skaneateles Falls, New York-based Ryan Biggs Clark Davis Engineering, DPC (RBCD), suffered a cyberattack via a business email compromise in September where personally identifiable information ended up stolen in the attack.
“On September 24, 2025, RBCD was subject to a data security incident,” the company said in a notice to victims. “As a result of the incident, an unauthorized actor temporarily obtained access to an employee email data.”
Upon detecting the incident, RBCD contained the threat, and immediately commenced a prompt and thorough investigation.
Reference: Engineering Firm Hit In Cyberattack
Victim: Ryan Biggs Clark Davis Engineering, DPC
Founded in 1973, Ryan Biggs Clark Davis Engineering, DPC, is one of the largest woman-owned engineering firms in Upstate New York. Additionally, specializing in structural engineering; structural investigations and assessments; repair and restoration; and contractor design assist, the company provides services to architects, engineers, developers, and private and public owners.
Incident: Data I/O Corporation Recovers from Ransomware Attack
Data I/O, an electronics manufacturer and software vendor operations were disrupted in the wake of a ransomware attack Aug. 16. The incident impacted internal and external communications, shipping, receiving, manufacturing production and other support functions. The company has been working on restoring impacted systems, but on August 21 it could not provide a timeline for full restoration. “The expected costs related to the incident, including fees for our cybersecurity experts and other advisors, and costs to restore any impacted systems, are reasonably likely to have a material impact on the Company’s results of operations and financial condition,” the company said. A later statement from the company indicates systems were fully restored by early September.
Reference: Costs For Ransomware Recovery Revealed
Reference: Data I/O reports business disruptions in wake of ransomware attack
Victim: Data I/O Corporation
Data I/O Corporation is an electronics manufacturer and software vendor for major automotive suppliers and tech firms. The company provides data programming solutions and security deployment platform to secure the global electronics supply chain and protect IoT device intellectual property from point of inception to deployment in the field.
Incident: Ransomware Disrupts Collins Aerospace Systems, Causing Major Flight Delays Across Europe
A cyberattack disrupted the MUSE (Multi‑User System Environment) check‑in, boarding and baggage handling software operated by Collins Aerospace — a major aviation systems provider and aerospace subsidiary of RTX Corporation. This incident impacted multiple large airports across Europe. Systems affected were automated electronic check‑in desks; boarding pass printing and baggage drop systems; shared passenger processing kiosks.
London Heathrow Airport (UK) reported long delays and manual operations. Brussels Airport (Belgium) reported cancellations and many delayed flights some days saw airlines cancel ~50 % of scheduled departures. Berlin Brandenburg Airport (Germany) experienced check‑in and boarding disruptions, long wait times. Dublin and Cork Airports (Ireland) experienced moderate to minor impacts on check‑in and boarding. Other European airports with MUSE dependency also reported delays.
Reference: Airport Check-In Systems Hit In Cyberattack
Victim: Collins Aerospace
Collins Aerospace operates systems to help passengers check themselves in, print boarding passes and bag tags and dispatch their luggage from a kiosk.
Incident: Oracle Vulnerability Leads to Attack on NCH
Irving, Texas-based NCH Corporation, a maker of industrial maintenance, water treatment and lubricants, fell victim to a cyberattack via a third-party vendor where personally identifiable information ended up stolen in the hack.
“NCH like multiple other organizations use Oracle’s E-Business Suite (“EBS”) software to help manage their operations,” the company said in a notice to victims. “In August 2025, an unauthorized actor leveraged a previously unknown vulnerability in Oracle EBS to take information from numerous organizations’ Oracle EBS applications. NCH learned it was one of those organizations.”
Upon becoming aware of the incident, NCH immediately implemented its response procedures, took measures to secure its implementation of Oracle EBS, and launched an investigation with the support of third-party cybersecurity professionals. NCH also notified law enforcement and is supporting its investigation.
The evidence showed an unauthorized actor obtained files from the NCH Oracle EBS application in mid-August. NCH reviewed the files and, on November 25, determined one or more of the files contained the names, date of birth, Social Security numbers, and benefits enrollment information.
Reference: NCH Cyberattack Based on Oracle Vulnerability
Victim: NCH Corporation
Irving, Texas-based NCH is a global manufacturer of industrial maintenance, water treatment & lubricants for businesses. The company started up in 1919. NCH has over 7,500 employees, with branch offices and manufacturing plants located on six continents.
The company focuses on product areas including: Industrial cleaning and maintenance, water treatment and remediation, and plumbing. Additionally, subsidiaries in NCH’s chemical divisions produce wastewater treatment products, drain cleaners, degreasers, lubricants, grounds care, fuel and water treatment programs and a variety of other biological solutions for industrial and commercial applications.
Incident: Cyberattack at MAG Aerospace
Fairfax, Virginia-based MAG Aerospace, which is a part of MAG DS Corp. suffered a cyberattack in August and personally identifiable information ended up stolen in the hack.
MAG Aerospace delivers highly technical services and engineering aerospace solutions around the world.
“On Aug 30, 2025, we were alerted to suspicious activity within our network,” the company said in a letter to victims. “In response, we launched an investigation with the help of third-party forensic experts. We also took measures to contain the incident, including quarantining assets, disabling affected accounts and domains, blocking access to our network, resetting passwords for affected accounts, and contacting law enforcement.”
Based on the company’s investigation to date, supported by external experts, it appears an attacker gained unauthorized access to stored personal information. The attack occurred between August 30, August 31.
Reference: Aerospace Provider Suffers Cyberattack
Victim: MAG Aerospace
Fairfax, Virginia-based MAG Aerospace, which is a part of MAG DS Corp., delivers command, control, communication, computers, cyber, intelligence, surveillance and reconnaissance (C5ISR) services at the tactical edge with engineering and operational solutions around the world. The company delivers defense technology solutions. As a U.S. government contractor, MAG brings operational and technical capabilities with program management and systems engineering expertise.
MAG engages in manufacturing, particularly for specialized aerospace parts and systems integration. They supply components like toilet systems, seats, and other aircraft parts as a subcontractor. They integrate various technologies into aircraft and systems, requiring physical assembly and manufacturing.
Incident: Blytheco Hit in Cyberattack
Irvine, California-based manufacturing sector software provider, Blytheco, Inc., suffered a cyberattack in August where personally identifiable information ended up stolen.
“On or about August 26, 2025, we detected a network security incident, in which an unauthorized third-party accessed our network environment,” the company said in a letter to victims of the attack. “We quickly engaged third-party forensic specialists to assist us with securing the network environment and investigating the extent of any unauthorized activity. Our investigation determined an unauthorized third party acquired certain individual personal information during this incident.”
In its investigation, Blytheco created a data file of potentially impacted individuals and finalized it November 7.
Reference: Software Provider Hit In Cyberattack
Victim: Blytheco, Inc.
For over 45 years, Blytheco is a software provider in the manufacturing, distribution, construction, professional services, and retail operations sectors.
Incident: Medical Supplier, Inotiv, Suffers Cyberattack
West Lafayette, Indiana-based medical supplier Inotiv, Inc. suffered a cyberattack in August where personally identifiable information ended up stolen.
“On August 5, 2025, we detected unusual activity on certain Inotiv systems and promptly initiated an investigation,” the company said in a letter to victims of the attack. “On August 8, 2025, we determined that this unusual activity was due to unauthorized actions by a threat actor. Our investigation determined that between approximately August 5-8, 2025, a threat actor gained unauthorized access to Inotiv’s systems and may have acquired certain data.”
Reference: Cyberattack At Medical Supplier
Victim: Inotiv, Inc.
Inotiv, Inc. is a manufacturer, primarily of research models (animals like rodents, rabbits, primates), specialized diets, bedding, and enrichment products. Furthermore, it also functions as a Contract Research Organization (CRO). It provides nonclinical drug discovery and development services and products for the pharma/biotech industry. The company produces and supplies essential tools and services.
Incident: Acoustic Equipment Maker, JASCO Applied Science, Hit in Cyberattack
Silver Spring, Maryland-based acoustic equipment maker, JASCO Applied Sciences suffered a cyberattack in July where personally identifiable information of current or former employees ended up stolen in the hack.
“On July 21, 2025, we discovered that an unauthorized party had gained access to our network and engaged in activity which impacted some of our systems,” the company said in a letter to victims. “We responded immediately and took steps to contain the incident, including temporarily taking systems offline.”
Moreover, at the time of the incident, the company said it had no reason to believe any personal information was a part of the attack. However, on October 20, JASCO became aware some personal information ended up purloined in the hack. The company then conducted a review of the data involved and determined some personal information was included in the data set.
Reference: Cyberattack At Acoustic Equipment Maker
Victim: JASCO Applied Science
JASCO Applied Sciences is a manufacturer of specialized oceanographic and underwater acoustic equipment, designing and producing systems like autonomous hydrophones, ocean monitoring instruments, and integrated observatories for scientific and defense applications, alongside providing related services. They develop technology for measuring and analyzing underwater sound, serving sectors like oil and gas, marine construction, and defense.
Incident: Transportation Provider, WEL Companies, Hit in Cyberattack
Transportation provider, De Pere, Wisconsin-based WEL Companies, Inc. suffered a cyberattack last January and is now letting victims know their personally indentifiable information ended up stolen in the hack.
“On January 31, 2025, WEL noted unusual activity on its network,” the company said in a letter to victims. “In response, WEL immediately took steps to secure its digital environment and engaged a leading, independent, cybersecurity firm to conduct an investigation.”
As a result of the investigation, WEL learned attackers gained access to certain data stored on its systems and certain individuals’ personal information may reside in the potentially affected data. According to the noticed, there were 122,960 victims in the attack.
Reference: Transportation Provider Suffers Cyberattack
Victim: WEL Companies
WEL Companies is a temperature controlled warehouse and transportation provider with locations in Wisconsin, Pennsylvania, Georgia, and Florida.
Incident: Energy Software Provider, Enverus Holdings Suffers Cyber Incident
Energy industry software services provider, Austin, Texas-based Enverus Holdings, Inc. fell victim to a third party provider cybersecurity attack in August where personally indentifiable information ended up stolen from victims.
On August 27, Enverus discovered it was one of hundreds of companies affected by the Salesloft Drift Chatbot cybersecurity incident.
“Upon discovery, Enverus activated its incident response plan, promptly disconnected the integration, and engaged cybersecurity experts to help assess the impact to Enverus,” the company said in a letter to victims.
“The investigation determined that, on August 12, 2025, an unauthorized actor leveraged credentials stolen from Salesloft to access a small amount of information from Enverus’s Salesforce instance,” the letter said.
Reference: Cyber Incident At Energy Software Provider
Victim: Enverus Holdings, Inc.
Austin, TX-based Enverus provides energy data and analytics software to help companies in the energy sector. Furthermore, the company offers Software-as-a-Service (SaaS) solutions to deliver insights and predictive analytics for exploration, production, midstream operations, and oilfield services. Additionally, these solutions track drilling activity and streamline operations and manage financial risk.
Incident: Cool Wind Ventilation Suffers Cyberattack
Glendate, New York-based metal ductwork manufacturer, Cool Wind Ventilation Corp. suffered a cyberattack in August where a threat actor was able to make off with personally indentifiable information from victims.
“On or about August 29, 2025, we detected a network security incident, in which an unauthorized third-party accessed our network environment,” the company said in a letter to victims. “We immediately engaged third-party forensic specialists to assist us with securing the network environment and investigating the extent of any unauthorized activity.
Cool Wind Ventilation’s investigation, which it completed on October 17, determined an unauthorized third party acquired certain individual personal information during this attack.
Reference: Metal Ductwork Maker Suffers Cyberattack
Victim: Cool Wind Ventilation
Cool Wind Ventilation Corp has manufactured and installed tens of millions of pounds of sheet metal ductwork in the NYC Metro Area since 1974. Cool Wind provides ductwork for HVAC systems in office buildings, hospitals, laboratories, restaurants and other commercial applications.
Incident: Cyberattack at SC Utility
Greer, South Carolina-based utility Greer Commission of Public Works suffered a cyberattack in June in which a threat actor copied information during the hack and stole personally identifiable information.
“On or about June 26, 2025, Greer CPW became aware of unusual activity in its network environment,” the company said in a letter to victims. “Upon becoming aware, Greer CPW promptly began an investigation into the scope and nature of the suspicious activity and retained legal counsel and third-party forensic specialists to investigate the unusual activity.”
The investigation found certain information ended up copied by an unauthorized individual as part of the event, the company said.
Reference: SC Utility Suffers Cyberattack
Victim: Greer Commission of Public Works
Greer CPW provides water, natural gas, electric and wastewater services to the residents of Greer, SC.
Incident: Transportation Provider Suffers Cyberattack
York, Pennsylvania-based transportation provider, S&H Transport, owner of S&H Express, suffered a cyberattack in June where personally identifiable information ended up stolen by hackers.
On November 12, S&H Transport publicly acknowledged it had had experienced a data breach. According to one report the incident occurred June 8 and the company discovered the breach September 3.
An internal investigation determined that an unauthorized party had gained access to certain company systems and viewed or extracted specific files.
Reference: Cyberattack At Transportation Provider
Victim: S&H Transport
S&H is truck transportation brokerage company. Operating since 1994 as the brokerage division of the S&H Express and The Shellenberger of Companies, S&H specializes in managing full truckload shipments on vans, reefers and flatbeds.
Incident: Cyberattack at VA Wastewater Plant
Virginia Beach, Virginia-based regional wastewater treatment facility Hampton Roads Sanitation District (HRSD) discovered a cyberattack at its facility in October
“On October 6, 2025, HRSD was made aware of unusual activity in its network,” the organization said in a letter to victims. “Upon discovery of the incident, HRSD promptly implemented its incident response plan and began an investigation into the nature and scope of the issue.”
The company’s preliminary investigation found evidence a threat actor accessed HRSD’s network and stole certain files.
Reference: Wastewater Treatment Plant Suffers Cyberattack
Victim: Hampton Roads Sanitation District
Wastewater treatment facility, HRSD’s goal is treat wastewater and recover natural resources to protect public health and the environment.
Incident: Cyberattack at CA Wood Maker
Huntington Park, California-based wood manufacturer GL Veneer suffered a cyberattack in August and is now letting victims know there personally identifiable information ended up stolen in the hack.
“GL Veneer experienced a network disruption that affected our ability to access certain systems,” the company said in a letter to victims. “In response, we promptly initiated an investigation, engaging third-party specialists to assist with understanding the nature and scope of the disruption.”
Meanwhile, as part of its investigation, the company learned certain information within its systems was subject to unauthorized access or acquisition on August 26.
Upon discovery, the company worked to identify and collect the data at risk. Additionally, it then began a thorough review to determine the types of information the attackers stole and to whom it belonged to.
Reference: Wood Manufacturer Hit In Cyberattack
Victim: GL Veneer
Huntington Park, California-based wood manufacturer GL Veneer stocks millions of square feet of raw veneer. Moreover, its manufacturing facility can handle multiple projects and produces cut to size panels, sheet veneer, and plywood panels.
Incident: Engineering Firm, GlobalLogic, Victim Of Oracle Breach
Santa Clara, California-based digital engineering provider, GlobalLogic Inc., fell victim to an attack starting in July through an Oracle Zero Day where former and current employees had some personally identifiable information stolen.
On October 4, Oracle issued a security advisory regarding a previously unknown Zero Day exploit. GlobalLogic uses Oracle E-Business Suite, a collection of applications, to manage core business functions such as finance, HR, accounts payable and receivable.
“As soon as we learned of the vulnerability, GlobalLogic immediately investigated and determined that it had been exploited within our instance of Oracle,” the company said in a letter to its victims. “Once we made this determination, we activated our incident response procedures, engaged leading third-party cybersecurity experts to assist in a comprehensive investigation, and notified law enforcement.”
Reference: Engineering Firm Victim Of Oracle Breach
Victim: GlobalLogic Inc.
GlobalLogic, a Hitachi Group company, focuses on design, data, and digital engineering for some of the world’s largest companies. Since its startup in 2000, the company created multiple digital products.
Incident: Semiconductor Maker, Integrated Silicon Solution, Hit in Cyberattack
Milpitas, California-based semiconductor manufacturer, Integrated Silicon Solution, Inc., (ISSI) suffered a cyberattack in June where personally identifiable information ended up stolen in the hack.
According to their notice, the breach first occurred June 6 and June 7.
“On June 30, 2025, ISSI identified evidence that an unauthorized third party accessed its network,” the company said a letter to victims. “Upon discovering the incident, ISSI promptly activated incident response measures and initiated an investigation.”
Reference: Semiconductor Maker Suffers Cyberattack
Victim: Integrated Silicon Solution, Inc.
With over 35 years of innovation, ISSI manufactures high-quality memory solutions, including DRAM, SRAM, and Flash to name a few. Their products end up featured for automotive, industrial, and medical applications.
Incident: Ransomware Attack at CA Winery
Almost two years ago, Rutherford, California-based Alpha Omega Winery experienced a ransomware attack and it is now reporting on the incident where personally identifiable information ended up stolen.
“On or about December 28, 2023, Alpha Omega Winery experienced a ransomware incident,” the company said in a notice to victims. Upon learning about the incident, they “launched an investigation, engaged a national cybersecurity firm to assist in assessing the scope of the incident and took steps to mitigate the potential impact to our community.”
While the company filed the incident on November 6 2025, they said the attack occurred in December 2023. As it turns out, the company was unaware of the incident until this past summer and notified Cyberscout last month (October) about the attack.
Reference: Winery Hit In Ransomware Attack
Victim: Alpha Omega Winery
Alpha Omega is a family-owned, boutique winery in Rutherford, CA, the heart of Napa Valley. Moreover, in 2006, proprietors Robin and Michelle Baggett founded Alpha Omega.
Incident: Ransomware Attack Disrupts Operations at Turkish Information Technologies and Communication Authority (BTHK)
Bilgi Teknolojileri ve Haberleşme Kurumu, Turkey’s information technology and communication authority, was hit by an attack on March 28, 2025. The company stated that the attack was detected at an early stage and successfully prevented without any data loss or system disruption. "Contrary to claims in some media outlets, all of our Institution's systems continue to operate securely and are closed to the outside world. Additional security measures have been implemented. Necessary updates are being rapidly implemented. In this context, following system improvements, routine work will begin as planned on Monday, April 7, 2025."
On April 4 Kibrispostasi news reported that the website is inaccessible, communication records have been deleted, and number portability between operators has been blocked.
Reference: Cyber attack on BTHK: Prevented without data loss or system disruption!
Reference: Erkut Şahali: Was BTHK brought down by a cyber attack?
Victim: BTHK (Bilgi Teknolojileri ve Haberleşme Kurumu)
Bilgi Teknolojileri ve Haberleşme Kurumu is Turkey’s information technology and communication authority.
Incident: Water and Waste Services Regulatory Authority in Portugal suffers Ransomware Attack.
ERSAR, Water and Waste Services Regulatory Authority in Portugal, suffered a ransomware attack. The company reports significant disruption to its information systems . Access to the ERSAR portal, website, and forum is temporarily unavailable. "ERSAR expects to reestablish its systems and infrastructure as soon as there are guarantees that all systems are secure and fully operational." Until the systems are restored, the reporting and information communication systems with ERSAR will remain inactive. ERSAR opted to use alternative means to communicate with managing entities, such a emailing reports.
Reference: New ransomware gang Warlock strikes government agencies worldwide
Incident: Cyberattack at Hyundai IT Provider
Fountain Valley, California-based information technology (IT) service provider, Hyundai AutoEver America, LLC (HAEA), suffered a cyberattack in February and is now letting victims know their personally identifiable information ended up stolen in a hack.
“On March 1, 2025, HAEA became aware of a cyber incident that impacted our information technology environment,” the company said in a letter to victims. “Upon discovery, we immediately launched an investigation with the support of external cybersecurity experts to assess the scope of the incident, confirm containment, and identify any affected information.
HAEA said it also notified law enforcement and is working with them.
Reference: Hyundai IT Provider Hit In Cyberattack
Victim: Hyundai AutoEver America, LLC
HAEA is an affiliate of Hyundai Motor Group that provides IT consulting, managed services, and helpdesk support for the entire lifecycle of automotive IT from production to retirement.
Its role is to supply IT solutions and services tailored to the automotive industry, particularly for Hyundai and Kia affiliates, including vehicle telematics, OTA (over-the-air) updates, maps, vehicle connectivity, embedded systems, and autonomous driving systems.
Victim: ERSAR (Entidade Reguladora dos Serviços de Água e Resíduos)
Entidade Reguladora dos Serviços de Água e Resíduos (ERSAR) is a water and waste service authority in Portugal.
Incident: Cyberattack at MN Furnace Make
Greenbush, Minnesota-based furnace maker, Central Boiler Companies, Inc. fell victim to a “sophisticated cyberattack” in August and discovered personally identifiable information ended up stolen.
“On August 1, 2025, we discovered we ended up victimized by a sophisticated cyberattack,” the company said in a letter to victims. “Upon discovery, we immediately began working with our IT team and third-party forensic specialists to secure the network, restore our systems to operability, and investigate the full nature and scope of the incident.
Central Boiler also said they reported this incident to federal law enforcement.
Reference: MN Furnace Maker Suffers Cyberattack
Victim: Central Boiler Companies, Inc.
Central Boiler is a privately held manufacturer of outdoor furnaces. The company is North America’s largest manufacturer of outdoor furnaces with a dealership network expanding across the United States and Canada, as well as distributors in Russia and Europe. The company was founded in 1984 by owners Terri and Dennis Brazier.
The company’s Classic outdoor wood furnace was the first in the industry to be UL and CSA certified.
Reference: ERSAR suffers cyberattack
Incident: British COLT Telecom hit by WarLock Ransomware
UK-based telecommunications company Colt Technology Services suffered a cyberattack, The attack caused a multi-day outage of some of the company's operations, including hosting and porting services, Colt Online, and Voice API platforms. The company stated the impacted systems are support services, not the core customer network infrastructure. Warlock is said to be behind the attack. The group has not leaked even a snippet of the data it stole online. Instead it opted to try and sell the data privately via auction
The recovery might not be completed until late November 2025. If Colt's estimated return-to-normal timeframe is accurate, the time spent tackling the disruption would amount to more than three and a half months.
Threat Actor: Warlock Ransomware Group
Warlock is a newly emerged, highly aggressive Ransomware-as-a-Service (RaaS) operation that first surfaced in mid-2025. It is known for its rapid expansion and use of sophisticated tactics, often targeting high-profile entities globally.
Warlock affiliates have been closely linked to exploiting zero-day vulnerabilities in public-facing enterprise applications, most notably the "ToolShell" exploit chain in unpatched Microsoft SharePoint servers, which allows for initial compromise and remote code execution.
Warlock activity has been tied to the China-based threat actor tracked by Microsoft as Storm-2603 (also known as GOLD SALEM).
Research indicates Warlock payload may be a modified variant of other well-known ransomware, such as LockBit 3.0 or a rebrand of a payload named Anylock, which is common in the fluid RaaS ecosystem.
[developing]
Victim: COLT (City of London Telecommunications)
Founded in 1992 as City of London Telecommunications (COLT) and acquired by Fidelity Investments in 2015, Colt is a major telecommunications service provider operating in 30 countries across Europe, Asia, and North America. The company employs 75,000 km of fiber networks linking 900 data centers.
Reference: Colt Telecom attack claimed by WarLock ransomware, data up for sale
Reference: Microsoft: SharePoint flaws exploited in Warlock ransomware attacks
Reference: Cyber Incident Answering your key questions
Reference: UK telco Colt’s recovery from August cyberattack pushes into November
Reference: Telco giant Colt suffers attack, takes systems offline
Reference: Colt Telecom attack claimed by WarLock ransomware, data up for sale
Reference: Our cyber incident response
Incident: Pakistan Petroleum Limited Foiled Ransomware Attempt
Pakistan Petroleum Limited (PPL), an oil and gas exploration firm, reported a ransomware attack on parts of its IT infrastructure, detected on August 6, 2025. The incident was swiftly contained with no compromise of critical systems or sensitive data. PPL shared that a ransomware note was received from an external actor and that no contact was made by PPL. Blue Locker claimed the attack.
Pakistan’s National Cyber Emergency Response Team (NCERT) issued a severe risk advisory to 39 key government ministries and institutions following sophisticated ransomware attacks that significantly impacted the country’s critical infrastructure, particularly the oil and gas sector.
Threat Actor: Blue Locker
Blue Locker ransomware demonstrates sophisticated technical capabilities, utilizing a combination of AES and RSA encryption algorithms while deliberately avoiding system-critical files to maintain persistence.
Blue Locker operates through a PowerShell-based loader that disables security defenses, escalates privileges, and appends “.blue” or “.bulock16” extensions to encrypted files.
The malware’s advanced evasion techniques include obfuscation of target strings, such as disguising “Chrome.exe” as Chinese characters to bypass detection systems.
Victim: Pakistan Petroleum Limited (PPL)
Pakistan Petroleum Limited (PPL) is one of Pakistan's largest exploration and production companies, supplying over 20% of the country's natural gas. It also produces crude oil, Natural Gas Liquid, and Liquefied Petroleum Gas.
Reference: Blue Locker Ransomware Targets Pakistan’s Oil & Gas Industry
Reference: Pakistan Petroleum thwarts ransomware attempt, says no critical data compromised
Reference: Pakistani oil and gas sector under attack from Blue Locker ransomware
Reference: Pakistan Petroleum Limited thwarts cyberattack on its IT infrastructure
Victim: WineLab Retail stores
WineLab, the retail store chain of parent company, Novabev Group.
Incident: Databreach at Swedish Power Grid Operator Svenska kraftnät
Swedish Electricity Provider (Svenska kraftnät) confirmed it suffered a data breach. The incident, disclosed on October 26, 2025, is linked to the notorious Everest ransomware gang. The organization maintains that Sweden’s power infrastructure continues to operate normally, with no disruptions to electricity transmission or distribution across the country. The Everest group alleged that it had stolen 280 GB of data from a file transfer solution.
Victim: Svenska kraftnät
Swedish state-owned power grid operator Svenska kraftnät
Reference: Swedish power grid has been the victim of a data breach
Reference: Everest ransomware group claims breach at Sweden’s Svenska kraftnt
Reference: Everest group claimed the hack of Sweden’s power grid operator Svenska kraftnät
Reference: Hackers Target Swedish Power Grid Operator
Reference: Swedish Power Grid Operator Confirms Breach After Everest Ransomware Claim
Incident: Ransomware Attack at Volkswagen Group France
Volkswagen Group France experienced a ransomware attack attributed to the cybercriminal group Qilin. The group claimed to have stolen approximately 150 GB of sensitive data, including personal information of vehicle owners, detailed vehicle data, and internal documents. The group published six documents online as proof of the breach.
Victim: Volkswagen Group France
Volkswagen Group France
Reference: Volkswagen reportedly hit by ransomware attack
Incident: Japanese High-performance Automotive Suspension Manufacturer Force to Halt Production in Japan and China
TEIN, Inc. suffered a ransomware attack on October 31, 2025. The attack hit the main server, affecting all group companies. Japan HQ factory halted production for one day.
The subsidiary factory in China (TEIN Shock Absorber Manufacturing (Jiangsu) Co., Ltd.) was forced to shut down for one week (from November 3). The company is compensating for the lost time by operating on weekends and expects the final impact to be minimal. Their order/shipping system runs on a separate server and was NOT hit by the incident.
The company has not yet confirmed a data leak, internally or externally.
Victim: TEIN Inc.
TEIN is a Japanese manufacturer that specializes in high-performance automotive suspension products.
Victim: TEIN Shock Absorber Manufacturing (Jiangsu) Co., Ltd.
TEIN Shock Absorber Manufacturing (Jiangsu) Co., Ltd.
Reference: Japanese retailer Askul confirms data leak after cyberattack claimed by Russia-linked group
Reference: Notice of System Disruption due to Ransomware Attack
Incident: Australian Personal Protective Equipment (PPE) Maker Reports Cyber Incident
Ansell Limited, a Australian maker of personal protective equipment (PPE), disclosed unknown attackers exploited vulnerabilities to access company data. The “majority” of data accessed was “non-sensitive business information”. However “a portion… does contain confidential transactional data or personally identifiable information.” Ansell said it had taken “immediate containment action” when the breach was discovered, and that there had been no impact to its operations.
Reference: Ansell has data accessed by unknown attackers
Reference: ASX Announcement: Notification of Unauthorized Data Access
Victim: Ansell Limited
Ansell Limited is an Australian manufacturer of personal protective equipment (PPE) like medical gloves and surgical suits.
Incident: Japanese Chemical Manufacturer Discloses System Failure due to Cyberattack
Kurogane Kasei, a chemical manufacturer and subsidiary of KH Neochem, revealed a system failure believed to be caused by a cyberattack. According to the company, it detected a possible breach of some of its servers on October 16, 2025. System failures have also occurred and are believed to be the result of this breach. The company is currently investigating the scope and cause of the impact, including the possibility of an information leak. The company denies that the outage has had any impact on production activities. RansomHouse claimed the cyberattack on October 23, 2025, and threatened to release sensitive data unless the company engaged in negotiations. The company has not confirmed who is behind the cyberattack.
Victim: Kurogane Kasei
Kurogane Kasei is a chemical manufacturer and subsidiary of KH Neochem.
Reference: System failure occurs, cause and impact investigated – Kurogane Kasei
Reference: Official Company Statement: Notice regarding unauthorized access to our company’s server (Japanese PDF)
Incident: IT Systems Affected at German Smelter Nickelhütte Aue
Nickelhütte Aue has fallen victim to a cyberattack. The attack partially paralyzed its office IT systems by encrypting data. The company explicitly stated that their production IT was not affected, and production continued throughout the incident. A banner appeared on the company website informing visitors that "The company's IT seems to be down, as the company is currently only reachable by phone. The IT department is currently working with external IT security experts to determine the cause and impact."
The company is in close contact with the relevant authorities and is cooperating transparently with all relevant parties, it says. It is unclear how long it will take to resolve the problem.
Reference: IT Systems Affected Following Ransomware Attack
Victim: Nickelhütte Aue GmbH,
Nickelhütte Aue GmbH is a German company with nearly 400 years of history, specializing in the sustainable recycling and smelting of non-ferrous metals, nickel, and copper.
Incident: Aussie Fluid Power Hit by Cyberattack
Aussie Fluid Power experienced a security incident involving unauthorized access to its IT systems. “While the investigation is ongoing, at this stage it appears the event may have resulted in certain employee, customer, and supplier information being compromised.”
Ransomware group Anubis claimed responsibility for the attack.
Threat Actor: Anubis Ransomware Group
The Anubis group is a Ransomware-as-a-Service (RaaS) operation that emerged in late 2024 and gained significant visibility in 2025. Anubis attracts affiliates with flexible revenue splits. They also run a separate data extortion program for criminals who have already stolen data.
Anubis is notable for combining traditional file encryption with an optional file-wiping feature (activated via a /WIPEMODE parameter). This feature permanently erases file contents, making recovery impossible, even after a ransom is paid. This is an unusual and destructive tactic for a financially motivated group, serving to increase pressure on victims to pay for data not to be leaked, even if files cannot be decrypted.
Initial Access is typically achieved through spear-phishing emails containing malicious links or attachments, crafted to look like trusted communications.
Victim: Aussie Fluid Power Pty. Ltd.
Aussie Fluid Power Pty. Ltd. (AFP) is an Australian hydraulic equipment supplier and engineering firm.
Reference: Aussie Fluid Power hit by cyberattack as ransomware group Anubis claims responsibility
Reference: Cyber Incident
Incident: German Machinery Manufacturer’s Systems Offline After Cyberattack
Weber GmbH acknowledged a cyberattack on the home page of their website: 'WEBER GmbH was the target of a cyberattack. Data on our servers was encrypted. As things stand, data has also been leaked and published on the dark web. We are working closely with the State Criminal Police Office and other authorities. The aim is to investigate the incident and restore the systems as quickly as possible. IT security experts are supporting us in this. Personal data has also been affected. We are currently checking which data and groups of people are affected. As soon as we have clarity, we will inform you directly in accordance with the GDPR."
The RansomHouse group claimed responsibility for breaching WEBER GmbH's network, encrypting systems, and stealing sensitive data.
Reference: “Cyberattacke: Information zur aktuellen IT-Sicherheitslage” (Cyberattack: Information on the current IT security situation)
Victim: Weber GmbH
WEBER GmbH is a German automation- and special-machinery manufacturer.
Incident: Ingram Micro Cyberattack Triggers Multi-Day IT Outage and Major Revenue Losses
Ingram Micro, a global technology distributor and IT services company, suffered a cyberattack resulting in global outage and employees working from home. The attack knocked key IT systems offline — including ordering platforms like Xvantage and license management tools — which meant that customers and partners could not place, track or manage orders for IT products and services during the outage. The company restored many of the internal systems and platforms impacted by the attack within days and performed a company-wide password and Multi-Factor Authentication (MFA) reset to restore operations.
The SafePay ransomware gang threatened to leak 3.5TB of data on July 30, 2025.
Victim: Ingram Micro
Ingram Micro is one of the world's largest business-to-business technology distributors and service providers, offering a range of solutions including hardware, software, cloud services, logistics, and training to resellers and managed service providers worldwide. With approximately 24,000 employees and over 50 offices across 57 countries, their corporate base remains in Orange County, California.
Reference: SafePay ransomware threatens to leak 3.5TB of Ingram Micro data
Reference: Ingram Micro starts restoring systems after ransomware attack
Reference: Ingram Micro outage caused by SafePay ransomware attack
Incident: Japanese Aluminum Manufacturer Operations Impacted by Cyberattack
Manufacturer Mino Kogyo Co., Ltd. confirmed a cyberattack and its details on their website. The company detected the attack and initiated a network shutdown on October 4, 2025. Production activities were partially affected but largely continued through individual adjustments. Financial settlement systems were restored quickly. The company later confirmed 300 GB of communications data had been stolen.
SafePay claimed responsibility for the attack. The hackers got access through a regular employee's VPN account using a valid ID and password (not a VPN vulnerability exploit). This led to internal exploration, system administrator privilege escalation (Oct 3), system destruction, and file encryption. Data leak was confirmed on October 28, 2025.
Victim: Mino Kogyo Co., Ltd.
Japanese manufacturer specializing in aluminum die-cast products and construction materials.
Threat Actor: SafePay Ransomware Group
SafePay is a relatively new but highly active ransomware operation known for using a "double extortion" tactic—encrypting victims' files while also stealing their data and threatening to leak it. The group gains initial access to corporate networks using compromised credentials for VPN gateways.
Reference: Comparitech reports ransomware surges 25% in October, hitting manufacturers, healthcare, transportation
Reference: Fourth Report on System Failure Due to Cyberattack
Incident: OR Manufacturer Hit in Ransomware Attack, Operations Affected
North Plains, Oregon-based specialty wood and metal products maker, Jewett-Cameron Trading Co. Ltd., suffered a ransomware attack last month that caused disruption and limited access to portions of the company’s support to operations.
“On October 15, 2025, Jewett-Cameron Trading Co. Ltd. learned that a threat actor had gained unauthorized access to portions of the Company’s information technology environment and claimed to have unlawfully accessed certain Company information and data,” the company said in an 8-K report to the Securities and Exchange Commission (SEC). “The Company immediately activated its cyber incident response process to contain the intrusion, assess and investigate the incident and implement remedial measures.”
Due to the extended period the company has been and may continue to be offline, operations may end up materially impacted, which may also impact financial results for the first quarter of fiscal 2026, according to the notice.
Reference: Ransomware Attack Affects OR Manufacturer’s Operations
Victim: Jewett-Cameron Trading Co. Ltd.,
Founded in Oregon in 1953, Jewett-Cameron Trading designs and manufactures products through its various subsidiaries. The company manufactures patented and patent-pending specialty metal and sustainable bag products and also wholesales wood products. Its manufacturing operations are a key part of its business, alongside its other segments. It also develops and builds premier products in the fencing, pet home, and outdoor living markets.
Incident: MA Energy Technology Firm Suffers Ransomware Attack
Somerville, Massachusetts-based energy technology firm, Form Energy, Inc., along with its subsidiaries Form Factory 1, LLC, and Form Energy Works, LLC, suffered a ransomware attack in September and is now informing victims.
The breach was the result of a ransomware attack, and the company has since taken action to investigate and address the issue.
“On September 16, 2025, Form Energy became aware of a ransomware attack on its systems,” the company said in a letter to victims. “In response, the company took immediate steps to secure affected systems by taking them offline and engaging external cybersecurity experts to assist with the investigation.”
Reference: Ransomware Attack At MA Energy Technology Firm
Victim: Form Energy, Inc.
Founded in 2017, Form Energy specializes in the development and production of multi-day energy storage systems and iron-air battery systems. Form Energy employs over 1,000 individuals and has additional locations in West Virgina and California.
Incident: Cyberattack at Engineering Service Provider
Walnut, California-based RKA Consulting Group suffered a cyberattack in January and is now letting victim know their personally identifiable information ended up stolen in the hack.
That personal information may be the result of working with RKA Consulting on an engineering project.
“On or around January 8, 2025, we discovered suspicious activity on our systems,” the company said in a letter to victims just over four days ago. “We immediately disconnected these systems, began an investigation, and engaged independent computer forensic experts to assist.”
Reference: Engineering Service Provider Suffers Cyberattack
Victim: RKA Consulting Group
RKA Consulting Group is a full-service municipal consulting firm supporting cities and public agencies throughout Southern California. Privately owned and operated, RKA has 40 workers, including engineers, technicians, inspectors, and administrative staff.
Core services include, municipal engineering, engineering design, construction administration, traffic engineering, land survey & entitlement support, NPDES compliance, building & safety services.
Engineering project experience includes: Street and roadway improvements, water, sewer, and storm drain infrastructure, traffic engineering and safety, stormwater and environmental compliance, and public facilities and parks
Building and safety project expertise: Commercial developments, healthcare facilities, historic sites, industrial complexes, mixed-use and storage facilities, parks and recreational facilities, and residential homes.
Incident: BK Technologies Hit in Ransomware Attack
Communications equipment maker, Melbourne, Florida-based BK Technologies suffered a cyberattack in September and it appears a ransomware attack group is taking credit for the hack.
“On or about September 20, 2025, BK Technologies Corporation detected potentially suspicious activity involving its information technology (“IT”) systems,” according to the 8-K report with the Securities and Exchange Commission (SEC). “Upon detecting the issue, the company began taking steps to assess, contain, and remediate the potentially unauthorized activity, including isolating the affected systems and launching an investigation with the assistance of external cybersecurity advisors.”
As a result of the incident, a limited number of non-critical systems experienced minor disruption.
Reference: Ransomware Group Takes Credit For BK Technologies Attack
Victim: BK Technologies
BK Technologies specializes in critical communications equipment, primarily two-way radios and software for military, public safety, and government agencies. The company manufactures and distributes its products globally under the BK Radio brand and offers a range of portable and mobile radios, repeaters, base stations, and accessories. In addition to hardware, they provide cloud-based software solutions like InteropONE, a push-to-talk-over-cellular (PTToC) service for smartphones.
Incident: Cyberattack At Power Plant, Marine Service Provider, Goltens
Marine and power plant service provider, Goltens Worldwide Management Corp. suffered a cyberattack in May after threat actors obtained access via an employee’s email account.
“On May 28, 2025, Goltens became aware of suspicious activity relating to an employee’s email account,” the company said in a letter to victims. “Goltens promptly secured the employee’s email and ensured that the activity did not extend outside of the email tenant.
With the assistance of third-party cybersecurity specialists, Manasquan, New Jersey-based Goltens also launched an investigation to determine the full scope of the incident.
Reference: Cyberattack At Power Plant, Marine Service Provider
Victim: Goltens Worldwide Management Corp.
Goltens is a service organization for shipowners and power plant operators all over the world to minimize asset downtime via diesel services, in-situ machining and BWT system retrofits. Furthermore, the company covers the following industries: Marine, offshore oil & gas, stationary power, petrochemical/refineries, mining, shipyards/shipbuilding, hydro-electric power, wind power, and manufacturing/other industrial. The company also is engine specialist, servicing repairing a wide range of diesel engines and related equipment.
Incident: Cyberattack at Thread Maker, Madeira
High-end embroidery thread maker, Gilford, New Hampshire-based Madeira USA LLC suffered a cyberattack in October and is informing victims as soon as possible their personally identifiable information ended up stolen in the hack.
“On October 8, 2025, Madeira USA LLC identified a security incident that involved unauthorized access to certain servers within its network,” the company said in a letter to victims. “Madeira immediately implemented their incident response plan, took steps to contain the activity, and launched an investigation.”
Madeira immediately took steps to secure the network, notified law enforcement, and launched an investigation into the matter.
Reference: Thread Maker Suffers Cyberattack
Victim: Madeira USA LLC
Madeira has a major market share in the high-end embroidery thread industry. The company is an international producer of high quality threads used for a wide range of fashion applications.
Incident: TN Security, Benefits Provider Hit in Cyberattack
Memphis, Tennessee-based Coalesce, LLC dba Benefitelect (BEI), a full-service employee benefits administration platform and cybersecurity provider, suffered a cyberattack in March and is now informing victims of the attack.
“On April 2, 2025, BEI was alerted to suspicious activity on its systems,” the company said in a notice to victims. “After becoming aware of this activity, we quickly took steps to secure the system and launched an investigation with the assistance of a third-party specialist to determine the nature and scope of the activity.”
The investigation found certain files ended up accessed and/or exfiltrated without authorization between March 30 and March 31.
Reference: Cyberattack At Security, Benefits Provider
Victim: Coalesce, LLC dba Benefitelect (BEI)
At the core of our competencies, BEI said, is its deep experience with cybersecurity and compliance – a critical requirement for sustained success in regulated industry sectors. We apply our expertise in cybersecurity compliance in all our solutions as a service to assist with audits and assess critical gaps, helping our customers identify and overcome potential vulnerabilities, according to the company website.
Incident: Seafood Operator Suffers Cyberattack
Clackamas, Oregon-based seafood operator, Dulcich, Inc. suffered a cyberattack in June last year and is now informing victims their personally identifiable information ended up taken in the hack.
Dulcich, also known as Pacific Seafood, detected unauthorized access to its network June 24, 2024. Upon detecting the unauthorized activity, Dulcich immediately contained the incident and commenced a prompt and thorough investigation.
Dulcich also reported the incident to the Federal Bureau of Investigation. There were over 40,000 victims in the attack.
Reference: OR Seafood Operator Hit In Cyberattack
Victim: Dulcich, Inc.
Founded in 1941 by the Dulcich Family, Pacific Seafood is a family-owned and operated. Pacific Seafood manages all parts of the supply chain from harvesting/fishing to processing, and distribution. The company employs over 3,000 team members across 41 facilities in 11 states.
Incident: Cyberattack Forces DFA Plant Disruptions, Breach of Personal Data
Dairy Farmers of America (DFA) experienced a ransomware attack. The hackers gained unauthorized access to internal systems and disrupted operations before the incident was contained. Multiple DFA manufacturing plants were impacted, although DFA reported affected facilities were brought back online to continue milk receiving and processing as mitigation efforts took effect. DFA completed internal review by 15 September 2025 and began mailing breach notices to impacted individuals in October 2025.
Reference: Dairy Cooperative Suffers Cyberattack
Victim: Dairy Farmers of America Inc. (DFA)
Dairy Farmers of America has 19,000 employees. As a farmer-owned cooperative, DFA has jobs across multiple sectors including manufacturing, accounting, communications, marketing, economics, on-farm field services, and more.
Incident: Cyberattack at VA Engineering Firm
Roanoke, Virginia-based construction engineering firm, The Branch Group, Inc., suffered a cyberattack in January and is now letting employee victims know their personally identifiable information ended up stolen in the hack.
“On or about January 14, 2025, we detected a network security incident, in which an unauthorized third-party attempted to access our network environment,” the company said in a letter to victims. “We immediately engaged third-party forensic specialists to assist us with securing the network environment and investigating the extent of any unauthorized activity.”
The investigation concluded on August 22 and the company found an unauthorized third party acquired certain individual personal information during this incident.
Reference: Engineering Firm Hit By Cyberattack
Victim: The Branch Group, Inc.
Roanoke, VA-based Branch Group touches all aspects of the built environment. Moreover, Branch is a full-service commercial construction solutions partner. The company provides design-build, heavy/highway construction, building development, construction management, structures, general contracting services, specialty metal fabrication, and mechanical, electrical, and plumbing.
Additionally, Branch has revenues of nearly $700 million and workforce of over 1,200 employee-owners.
Incident: MA Asphalt Product Maker Struck in Cyberattack
Andover, Massachusetts-based maker of asphalt products, Brox Industries, Inc. suffered a cyberattack in February that it discovered in March and is now informing victims their personally identifiable information ended up stolen in the hack.
“Brox Industries detected unauthorized access to our network on March 11, 2025,” the company said in a letter to victims of the attack. “Upon learning of this issue, we immediately secured the environment, commenced a prompt and thorough investigation.”
After an extensive forensic investigation and manual document review, Brox said it found on October 3 an unauthorized actor may have accessed and/or acquired certain files containing personal information between February 28, 2025 and March 11, 2025.
Reference: Cyberattack At MA Asphalt Product Maker
Victim: Brox Industries, Inc.
Brox Industries, which started up over 70 years ago, has multiple manufacturing plants and quarries where they produce their products. The company’s manufactured products include hot mix asphalt, various grades of crushed stone, sand, and other aggregate materials. In addition to manufacturing, Brox Industries also provides related services like asphalt paving, recycling, and construction contracting. The company has nine locations across Massachusetts and New Hampshire.
Incident: Cyberattack at WV Sign Manufacturer
Kearneysville, West Virginia sign maker, DALB, Inc. suffered a cyberattack in May and is now informing victims their personally identifiable information ended up stolen in the hack.
“On May 20, 2025, we detected suspicious activity within our network,” the company said in a letter to victims. “We promptly initiated an investigation of the matter and engaged cybersecurity specialists to assist with the incident response.”
As a result of the investigation, the company found certain files may have ended up accessed or acquired without authorization on May 20
Reference: Sign Manufacturer Hit In Cyberattack
Victim: DALB, Inc.
DALB is a manufacturer of printed signage and thermoformed plastic parts for vending equipment OEMs, point-of-sale displays, industrial equipment, and unique proprietary specialized products. The company’s products appeared across a range of applications, including environmentally demanding and high security environments.
Incident: Security Provider F5 Suffers Cyberattack
Cybersecurity provider, F5 Inc. suffered a nation-state cyberattack where source code ended up exfiltrated from its networking product suite, BIG-IP, this past August and per Department of Justice approval, delayed notification of the hack until Wednesday.
“On August 9, 2025, F5, Inc. learned that a highly sophisticated nation-state threat actor had gained unauthorized access to certain company systems,” the company said in 8-K report to the Securities and Exchange Commission (SEC) filed Wednesday, October 15. “The company promptly activated its incident response processes, and has taken extensive actions to contain the threat actor. To support these activities, the company engaged leading external cybersecurity experts.”
Seattle, Washington-based F5 specializes in application security, multi-cloud management, online fraud prevention, application delivery networking, application availability and performance, and network security, access, and authorization. Meanwhile, the company had over $2.8 billion in revenues for its last fiscal year.
Reference: Security Provider F5 Hit In Cyberattack
Victim: F5 Inc.
Seattle, Washington-based F5 specializes in application security, multi-cloud management, online fraud prevention, application delivery networking, application availability and performance, and network security, access, and authorization.
Incident: Organic Personal Care Products Maker Suffers Cyberattack
Johnston, Rhode Island-based organic personal care products maker, Pure Haven, LLC, suffered a cyberattack last month where personally identifiable information ended up stolen by threat actors.
The company identified potentially suspicious activity related to an internal account on September 2.
“Upon discovery we took immediate action to address and investigate the activity, including performing a password reset and engaging third-party specialists to assist in conducting a full investigation,” the company said in a letter to victims of the attack. “Through our investigation, on or around September 5, 2025, we determined that an unauthorized individual may have accessed or acquired certain information on September 2, 2025.”
Reference: Cyberattack At Organic Personal Care Products Maker
Victim: Pure Haven LLC
Pure Haven, a private company founded in 2009, manufactures and sells non-toxic personal care, cleaning, and baby products. The company, acquired by Global Ventures Partners in 2016, produces products at its USDA-certified organic facility, emphasizing safety and effectiveness. Products include shampoos, skincare, cleaning supplies, and essential oils, formulated to avoid harmful chemicals and use plant-based ingredients.
Incident: MA Telecom, Security Provider Suffers Cyberattack
Norwood, Massachusetts-based communications and security provider, LAN-TEL Communications, Inc. suffered a cyberattack this past July and notice is now going out to victims of the hack.
The breach occurred July 11, when an external system suffered compromise through a hack attack. As it turns out, the situation ended up discovered over two months later on September 23.
The company sent out written notifications to victims of the attack on October 9, informing them of the breach and the potential risks associated with it.
Reference: MA Security Provider Hit In Cyberattack
Victim: MA Security Provider Hit In Cyberattack
LAN-TEL Communications, Inc. provides state-of-the-art communications and security solutions for private and public sector customers across all market segments in the New England area. The company configures, installs, and provides ongoing service and maintenance for the following solutions: Structured cabling for voice, data and video services; integrated security systems – video surveillance, access control and intrusion; fiber optics; air blown fiber; audio visual systems; paging and clock systems; wireless LAN/distributed antenna systems; Speech Privacy, and IT infrastructure.
Incident: Widespread Attacks Target Microsoft SharePoint Zero-day Vulnerability
Several hacking groups with ties to the Chinese government have been linked to a recent wave of widespread attacks targeting a Microsoft SharePoint zero-day vulnerability chain. They used this exploit chain (dubbed "ToolShell") to breach dozens of organizations worldwide after hacking into their on-premise SharePoint servers.
Dutch cybersecurity firm Eye Security first spotted zero-day attacks exploiting the CVE-2025-49706 and CVE-2025-49704 vulnerabilities (first demoed during the Berlin Pwn2Own hacking contest by Viettel Cyber Security researchers). The company told BleepingComputer that at least 54 organizations had already been compromised, including several multinational companies and national government entities.
Reference: Whole Foods supplier UNFI restores core systems after cyberattack
Reference: Cyberattack Alters Food Distributor’s Operations
Reference: Microsoft says Chinese hacking groups exploited SharePoint vulnerability in attacks
Reference: Microsoft links Sharepoint ToolShell attacks to Chinese hackers
Reference: SharePoint Attacks Continuing
Reference: Threat IntelligenceSharePoint Under Attack: Microsoft Warns of Zero-Day Exploited in the Wild – No Patch Available
Reference: What we know about the Microsoft SharePoint attacks
Reference: Microsoft releases emergency fix for Sharepoint after cyberattacks
Reference: SharePoint Attacks Continuing
Incident: US Nuclear Weapons Agency Caught up in Microsoft SharePoint Attack
Hours after Microsoft revealed that hacking groups affiliated with the Chinese government have been exploiting a flaw in its SharePoint software, Bloomberg reported that the National Nuclear Security Administration was also breached in the attacks. No sensitive or classified information has leaked according to Bloomberg. “The department was minimally impacted due to its widespread use of the Microsoft M365 cloud. As well as very capable cybersecurity systems,” a department spokesperson said in a statement to Bloomberg. “A very small number of systems were impacted. All impacted systems are being restored.”
Victim: NNSA (US National Nuclear Security Administration)
NNSA is a semi-autonomous U.S. government agency part of the Department of Energy that maintains the country's nuclear weapons stockpile and is also tasked with responding to nuclear and radiological emergencies within the United States and abroad.
Reference: Chinese Hackers Attack US Nuclear Weapons Agency Using SharePoint Loophole, Says Microsoft
Reference: US nuclear weapons agency hacked in Microsoft SharePoint attacks
Reference: US nuclear weapons agency breached in Microsoft SharePoint hack, Bloomberg News reports
Reference: US nuclear weapons agency ‘among 400 organizations breached by Chinese hackers’
Incident: Cyberattack at French Telecom Giant Orange
French telecommunications giant Orange announced it was the victim of an unspecified cyberattack. Orange's cybersecurity subsidiary was “mobilized to isolate the potentially affected services and limit the impacts.” This has led to some operational disruptions, primarily affecting French customers, which are expected to be gradually resolved by July 30.
"At this stage of the investigation, there is no evidence to suggest that any customer or Orange data has been extracted. We remain vigilant in this regard," the company added. Orange has not attributed the cyberattack to a specific hacking group or threat actor.
Reference: Orange, France’s largest telecoms company, hit by cyberattack
Reference: Telecom giant Orange warns of disruption amid ongoing cyberattack
Reference: French telecom giant Orange discloses cyberattack
Reference: The Orange Group announces that it filed a complaint on Monday, 28 July concerning a security incident on one of its information systems
Incident: Cyberattack at French Warship Builder – Hackers Leak 1TB of Data
France's state-owned defense firm Naval Group is investigating a cyberattack. A hacker using the moniker Neferpitou claimed to have stolen approximately 1TB of the company’s internal data. The Naval Group released a statement on July 26. "All of our teams and resources are currently mobilized to analyze and verify the authenticity, origin, and ownership of the data as quickly as possible. At this stage, no intrusion into our IT environments has been detected and there has been no impact on our activities.”
Naval Group was given 72 hours to negotiate an extortion payment. Soon after, Neferpitou leaked the entire 1TB dataset on the forum.
Victim: Naval Group
Naval Group (formerly DCNS) is a French defense contractor specializing in naval defense systems and warships. It is majority-owned by the French government, with the rest held by defense giant Thales Group.
The company designs, builds, and maintains military naval vessels, including frigates, destroyers, nuclear submarines, and aircraft carriers, as well as maritime combat systems and digital warfare technology.
Naval Group is the primary supplier to the French Navy, but it also exports to countries such as Australia, Brazil, India, and Egypt.
Reference: Naval Group Victim of Hacking and Data Leak
Reference: French defense giant Naval Group confirms hack against submarines and frigates
Reference: France’s warship builder Naval Group investigates 1TB data breach
Reference: Naval Group investigate potential cyber attack
Incident: Dell Confirms Cyberattack on Test Lab Platform
A newly rebranded extortion gang known as "World Leaks" breached one of Dell's product demonstration platforms. Dell acknowledged the incident to BleepingComputer. Del confirmed the threat actor breached its Customer Solution Centers platform, which is used to demonstrate Dell products and solutions to customers. The platform is intentionally separated from customer and partner systems, as well as Dell's networks. World Leaks reportedly leaked some of the stolen data.
Reference: Dell confirms breach of test lab platform by World Leaks extortion group
Reference: Dell Confirms Security Breach by Extortion Group, Calls Stolen Data ‘Fake’
Victim: Dell Inc.
Dell Inc. is an American technology company that develops, sells, repairs, and supports personal computers (PCs), servers, data storage devices, network switches, software, computer peripherals including printers and webcams among other products and services. Dell is based in Round Rock, Texas.
Reference: Dell confirms breach of test lab platform by World Leaks extortion group
Incident: Multi-regional Cyberattack at Luxury Fashion Brand Louis Vuitton
Louis Vuitton was the victim of a multi-region cyberattack in July 2025. The attack impacted customers in the UK, South Korea, Turkey, and Portugal. The unauthorized party accessed data such as names, contact information, and purchase history. No financial or payment data was compromised. Louis Vuitton notified affected customers and relevant authorities, including the UK's Information Commissioner's Office (ICO) and the CNIL in Europe. The company is investigating the incident while strengthening its security systems.
Reference: Cybercrime News News Briefs Get more insights with the Recorded Future Intelligence Cloud. Learn more. Recorded Future Louis Vuitton says customers in Turkey, South Korea and UK impacted by data breaches
Reference: Louis Vuitton Korea says systems breach led to customer data leak
Reference: Luxury retailer LVMH says UK customer data was stolen in cyber attack
Reference: Louis Vuitton Notifies U.K. Customers of Data Breach
Reference: Louis Vuitton: personal data of Portuguese clients compromised by cyber attack
Victim: Louis Vuitton
Louis Vuitton exclusively produces its leather goods, footwear, ready-to-wear, watches, jewelry, sunglasses, and fragrances in its owned and operated in manufacturing sites located in France, Spain, Italy, the United States, and Switzerland.
Incident: Large Databreach at Qantas Airlines Affects to 6 Million Customers
Australian airline Qantas disclosed that it detected a cyberattack on Monday. In a press release issued Monday night, the airline states that the attack has been contained. A "significant" amount of data is believed to have been stolen. The breach began after a threat actor targeted a Qantas call centre and gained access to a third-party customer servicing platform. Qantas assured the public that passport details, credit card details and personal financial information were not held in the breached system. Also no frequent flyer accounts, passwords or PIN numbers were compromised.
It is unconfirmed which group is behind the Qantas attack. BleepingComputer learned the incident shares similarities with other recent attacks by hackers known as "Scattered Spider"
Victim: Qantas
Qantas is Australia's largest airline, operating domestic and international flights across six continents and employing around 24,000 people.
Reference: Qantas data breach exposes up to six million customer profiles
Reference: Qantas confirms cyber-attack exposed records of up to 6 million customers
Reference: Qantas discloses cyberattack amid Scattered Spider aviation breaches
Incident: Ransomware Attack at Novabev Group Shuts down 2000 Winelab Liquor Stores in Russia
Ransomware attack caused more than 2,000 WineLab liquor stores across Russia to shut for three days. The attack hit their parent company Novabev Group. The group is one of Russia’s largest alcohol producers. Signs on WineLab doors said the stores were closed due to “technical issues.”
The attack crippled parts of the Novabev Group’s infrastructure, affecting WineLab’s point-of-sale systems and online services. The Novabev Group refused to negotiate with the attackers. Their internal IT team is working “around the clock” to restore operations and strengthen defenses against future threats.
Forbes Russia estimated lost revenue 200 million to 300 million rubles/day ($2.6 million to $3.8 million)for WineLab Cybersecurity experts interviewed by Forbes could not recall a comparable case in which a major Russian retail chain was forced to shut down entirely due to a cyberattack.
Victim: Novabev Group
Novabev Group is a major Russian producer and distributor of spirits, including the Beluga and Belenkaya vodka brands.
Russian alcohol retailer WineLab is a subsidiary of Novabev Group with stores throughout Russia.
Reference: Official statement of Novabev Group and WineLab on the cyberattack
Reference: Russian Beluga Vodka Company by Novabev Group, Hit by Ransomware Attack
Reference: Beluga vodka maker hit by hackers
Reference: Russian alcohol retailer WineLab closes stores after ransomware attack
Incident: Hawaiian Airlines Suffered Cyberattack
Hawaiian Airlines suffered a cyberattack disrupting access to some of systems. The incident didn't affect flight safety and relevant authorities were contacted to assist in the investigation. A banner on the airline's website noted that the incident hasn't impacted flights in any way. The same alert was displayed on the Alaska Airlines website, owned by Alaska Air Group, a company that acquired Hawaiian Airlines last year.
"There has been no impact on safety, and the airline continues to operate safely. We are monitoring the situation," the Federal Aviation Administration told Reuters in a statement. The airline has yet to disclose the nature of the attack. No ransomware operations have claimed responsibility for the incident. This incident follows a similar attack that affected WestJet, Canada's second-largest airline, on June 13.
Victim: Hawaiian Airlines
Hawaiian Airlines is the tenth-largest commercial airline in the United States,
With over 7,000 employees, 235 average daily flights, and a fleet of over 60 airplanes, Hawaiian Airlines connects Hawai'i with 15 U.S. mainland cities and 10 other destinations across Asia and the Pacific
Reference: Flights Uninterrupted Following Hawaiian Airlines Cyberattack
Reference: Hawaiian Airlines hit by cyber attack
Reference: Hawaiian Airlines discloses cyberattack, flights not affected
Incident: Cyberattack on Email Accounts of Several Washington Post Journalists
A cyberattack compromised email accounts of several Washington Post journalists. The attack is believed to have been carried out by a foreign government. The incident was discovered on Thursday evening. An internal memo, signed by Executive Editor Matt Murray, informed employees that Microsoft accounts of a limited number of journalists were affected. Internal sources told The Wall Street Journal that the attack targeted journalists writing on national security and economic policy topics, as well as some who write about China.
Washington Post has not shared publicly any details about the attack.
Victim: Washington Post
Owned by Amazon founder Jeff Bezos, The Washington Post is one of the most influential newspaper publications in the United States.
Reference: Washington Post journalists who cover China had their email accounts hacked
Reference: Washington Post investigating cyberattack on journalists’ email accounts, source says
Reference: Washington Post’s email system hacked, journalists’ accounts compromised
Incident: Cyber incident at Calgary based Airline Westjet
WestJet, Canada's second-largest airline, suffered a cyberattack disrupting access to some internal systems. "WestJet is aware of a cybersecurity incident involving internal systems and the WestJet app, which has restricted access for several users," reads a security advisory on WestJet's site. The attack also prevented users from logging into the website and mobile app, with those services now restored. The attack has impacted access to some of its software and services. It is unclear if the loss of access to its systems is caused by a ransomware attack that encrypted those devices or if they shut them to prevent the spread of the breach.
Victim: Westjet
WestJet, is based in Calgary and is Canada's second-largest airline.
Reference: WestJet dealing with ‘cybersecurity incident’ impacting access to website, app
Reference: WestJet investigates cyberattack disrupting internal systems
Reference: WestJet probes cybersecurity incident affecting app and internal systems
Incident: Cyberattack at United Natural Foods Inc. (UNFI) Causes Widespread Disruption and Shutdown
United Natural Foods Inc. (UNFI), a major U.S. food wholesaler, experienced a cyberattack in June 2025 that disrupted its distribution systems and impacted grocery stores, including Whole Foods, across the U.S..
The attack forced UNFI to shut down systems and switch to manual processes, causing order fulfillment issues and the potential for shortages. The food distributor and wholesaler completely shut down its systems upon discovering the attack. Core systems were restored and normal operating capacity returned within three weeks. The orders United Natural Foods was unable to fill — resulting in empty store shelves and spoilage in the wake of the attack — shows the wide financial impact of cybercrime. The company operates 52 distribution centers that fulfill about 250,000 products from more than 11,000 suppliers to 30,000 customer locations in North America.
Victim: United Natural Foods
United Natural Foods based in USA, supplies Whole Foods and other grocery stores nationwide.
Reference: United Natural Foods says cyberattack will reduce quarterly earnings
Reference: United Natural Foods loses up to $400M in sales after cyberattack
Incident: Salt Typhoon Hackers Attack Telecom Giant Viasat
Viasat Inc. has been identified as a victim of the Chinese-linked Salt Typhoon cyber-espionage operation during last year's presidential campaign, Bloomberg News reported on Tuesday. The breach at the satellite communications firm was discovered earlier this year and Viasat has been working with the government in the aftermath, the report said, citing people familiar with the matter.
Upon completing a thorough investigation, no evidence was found to suggest any impact to customers.
Reference: Viasat identified as victim in Chinese Salt Typhoon cyberespionage, Bloomberg News reports
Reference: Telecom giant Viasat breached by China’s Salt Typhoon hackers
Incident: Databreach at Indian Car Share Company Zoomcar
Indian car share company Zoomcar said hackers stole the personal information of 8.4 million users. The Bengaluru-based company reported the incident to the U.S. Securities Exchange Commission (SEC) on Friday, telling investors that the company initially became aware of the breach on June 9. The hacker contacted employees of the company claiming to have breached systems and stolen data.
Zoomcar said it does not expect the incident to affect the company’s operation but may lead to reputational and remediation costs. The company did not respond to requests for comment.
Victim: Zoomcar
Indian car share company Zoomcar was founded in 2013. Zoomcar now operates in 99 cities across India, allowing people to offer their cars for rental to the platform’s more than 10 million users.
Reference: 8.4 million people affected by data breach at Indian car share company Zoomcar
Reference: Car rental platform Zoomcar says hackers accessed personal data of 8.4 million users
Incident: Cyberattack costs Publishing giant Lee Enterprises $2M in Restoration Costs
Nearly 40,000 people had their Social Security numbers exposed during a cyberattack in February on Lee Enterprises. The company is one of the largest owners of local newspapers in the U.S. In addition, Lee Enterprises newsrooms across the United States reported that the attack triggered a systems outage. The outage forced the publisher to shutdown many of its networks. The shutdown lead to widespread printing and delivery disruptions for dozens of newspapers.
BleepingComputer reported the outage had caused significant issues, including corporate VPNs being down and lost access to internal systems and cloud storage. A week later, the company submitted a filing with the SEC revealing that it got hit by ransomware. Qilin ransomware gang claimed to have stolen 120,000 documents totaling 350 GB in size and threatened to release them all on March 5.
MAY 2025 UPDATE: The newspaper chain said the attack will have lingering impacts on its balance sheet, and its lender waived certain payments. Lee Enterprises said it incurred $2 million in restoration costs.
Victim: Lee Enterprises
Lee Enterprises publishes 77 daily newspapers and 350 weekly and specialty publications across 26 states. The local news provider's newspapers have a daily circulation of over 1.2 million, and a digital audience reaching tens of millions each month. It is one of the largest newspaper groups in the United States.
Reference: Newspaper giant Lee Enterprises says nearly 40,000 Social Security numbers leaked in ransomware attack
Reference: Media giant Lee Enterprises says data breach affects 39,000 people
Incident: Widespread Service Outage at Wisconsin Wireless Provider Cellcom
Wisconsin wireless provider Cellcom has confirmed that a cyberattack is responsible for the widespread service outage and disruptions that began on the evening of May 14, 2025. The incident disrupted voice and SMS services for customers across Wisconsin and Upper Michigan, leaving subscribers unable to make phone calls or send text messages. Cellcom began partial service restoration on May 19, allowing calls and texts between Cellcom users to resume and voice services gradually returning as recovery progressed.
Reference: Mobile Carrier Cellcom Breached, Company Confirms Cyberattack Behind Extended Outages
Victim: Cellcom
Wisconsin wireless provider Cellcom
Reference: Mobile carrier Cellcom confirms cyberattack behind extended outages
Incident: Arla Foods’ Production Disrupted in Germany
Danish food giant Arla Foods confirmed a cyberattack disrupted its production operations. The attack affected its production unit in Upahl, Germany, and resulted in product delivery delays and cancellations. "We can confirm that we have identified suspicious activity at our dairy site in Upahl that impacted the local IT network," stated an Arla spokesperson. "Due to the safety measures initiated as a result of the incident, production was temporarily affected." Production at other Arla sites is not affected. Arla Foods publicly confirmed the cyberattack on 19 May 2025
Victim: Arla Foods
Arla Foods is an international dairy producer and a farmer-owned cooperative with 7,600 members. It employs 23,000 people in 39 countries. The firm has an annual revenue of €13.8 billion ($15.5 billion), and its products, including the brands Arla, Lurpak, Puck, Castello, and Starbucks, are sold in 140 countries worldwide.
Reference: Arla Foods confirms cyberattack disrupts production, causes delays
Incident: Cyberattack Disrupts South African Airlines’ Internal Operations
South Africa’s state-owned airline said a cyberattack temporarily disrupted its website and several internal operational systems. The attack also affected its mobile application; the IT team was able to contain the incident and “minimize disruption to core flight operations.”
The airline did not respond to requests for comment about whether the incident involved ransomware. CEO John Lamola said they are currently investigating the incident to “determine the root cause” and are looking into the potential leak of sensitive information.
Victim: South African Airways (SAA)
South African Airways (SAA)
Reference: South African Airways says cyberattack disrupted operational systems
Reference: South African Airways hacked
Incident: German Sportswear Giant Adidas Disclosed Databreach
German sportswear giant Adidas disclosed a data breach after attackers hacked a customer service provider and stole some customers' data. Adidas has yet to reveal further details regarding this incident, including the name of the impacted service provider, when the incident was detected, how many individuals were affected, and if its own network was compromised during the attack.
Victim: Adidas
Adidas is a German sportswear manufacturer.
Reference: Adidas warns of data breach after customer service provider hack
Reference: Adidas warns of consumer data breach
Reference: Adidas says customer data stolen in cyberattack
Incident: Jaguar Land Rover Shuts Down Retail and Production Sites across the World
“Our retail and production activities have been severely disrupted,” said a statement Tuesday from Jaguar Land Rover (JRL) after the luxury auto vehicle maker suffered a cyberattack. Over a week later JLR announced it will extend the production shutdown for another week, until September 24, following a devastating cyberattack that impacted its systems worldwide at the end of August. JLR also confirmed that the attackers stole "some data" during the breach and instructed staff not to report to work. The disruption has spread throughout its supply chain, threatening thousands of jobs.
On October 7, Bloomberg reports that the UK government has agreed to guarantee a $2 billion emergency loan to help JLR pay its suppliers.
Reference: Jaguar Land Rover Bailout Shows Rising Cost of Cybercrime
Threat Actor: Scattered Lapsus$ Hunters
The Scattered Lapsus$ Hunters group claims to consist of cybercriminals associated with the Scattered Spider, Lapsus$, and ShinyHunters extortion groups.
Scattered Lapsus$ Hunters also claimed responsibility for recent Salesforce data theft attacks.
Victim: Jaguar Land Rover (JLR)
Jaguar Land Rover (JLR) is a standalone entity under Tata Motors India, following its acquisition from Ford in 2008. JLR employs approximately 39,000 people, makes more than 400,000 vehicles each year, and has reported an annual revenue of over $38 billion (£29 billion).
Reference: Cyberattack Shuts Down Jaguar, Land Rover Operations
Reference: Jaguar Land Rover extends shutdown after cyberattack by another week
Reference: Data BreachesNova Scotia Power Says Hackers Stole Customer Information
Incident: Cyberattack at IT Management Software Firm ConnectWise
IT management software firm ConnectWise says a suspected state-sponsored cyberattack breached its environment and impacted a limited number of ScreenConnect customers. "ConnectWise recently learned of suspicious activity within our environment that we believe was tied to a sophisticated nation state actor, which affected a very small number of ScreenConnect customers," ConnectWise shared in a brief advisory.
ConnectWise did not answer BleepingComputer's questions about how many customers were impacted, when the breach occurred, or whether any malicious activity was observed in customers' ScreenConnect instances. However, a source told BleepingComputer that the breach occurred in August 2024.
Victim: ConnectWise
ConnectWise is a Florida-based software company that provides IT management, RMM (remote monitoring and management), cybersecurity, and automation solutions for managed service providers (MSPs) and IT departments.
One of its products is ScreenConnect, a remote access and support tool that allows technicians to securely connect to client systems for troubleshooting, patching, and system maintenance.
Reference: ConnectWise breached in cyberattack linked to nation-state hackers
Incident: Outage at Mathworks, a leading US Simulation Software Co.
MathWorks, a leading developer of mathematical computing and simulation software, has revealed that a recent ransomware attack is behind an ongoing service outage. Online applications and internal systems became unavailable. Customers experienced issues preventing them from creating new accounts, while others who haven't signed in since 11 October 2024 were not able to log in at all. No ransomware gang has claimed the breach, suggesting that MathWorks has either paid the ransom demanded by the attackers or is still negotiating.
Reference: May 2025 Ransomware Incident
Victim: MathWorks
MathWorks is a leading developer of mathematical computing and simulation software. MathWorks develops the MATLAB numeric computing platform and the Simulink simulation, which are used by over 100,000 organizations and over 5 million customers.
Headquartered in Natick, Massachusetts, founded in 1984, MathWorks has over 6,500 employees in 34 offices worldwide.
Reference: MATLAB dev confirms ransomware attack behind service outage
Incident: Massive Cyberattack Hits Salesforce Affecting 760 Companies
Extortion groups claim to have stolen over 1.5 billion Salesforce records from 760 companies. The breach led to unauthorized access to customer data stored within Salesforce instances integrated with the Salesloft Drift app. Customers who had integrated with the Salesloft Drift app and shared data with it were directly impacted.
The attacks were claimed by threat actors stating they are part of the ShinyHunters, Scattered Spider, and Lapsus$ extortion groups, now calling themselves "Scattered Lapsus$ Hunters." Google tracks this activity as UNC6040 and UNC6395.
Victim: Salesforce
Salesforce is an American cloud-based software company that is a global leader in Customer Relationship Management (CRM) technology, providing tools for sales, customer service, marketing, commerce, and analytics.
Founded in 1999, the company offers its Customer 360 platform to help businesses of all sizes digitally transform by using artificial intelligence (AI) and automation to build better customer relationships and gain a unified view of customer data.
Reference: Criminal Groups Target Salesforce
Malware: Vishing (voice phishing)
Vishing, or voice phishing, is a form of social engineering where cybercriminals use voice calls to impersonate trusted individuals or organizations to trick victims into revealing sensitive information, such as passwords or financial details.
Reference: ShinyHunters launches Salesforce data leak site to extort 39 victims
Reference: ShinyHunters claims 1.5 billion Salesforce records stolen in Drift hacks
Reference: Salesforce-Connected Third-Party Drift Application Incident Response
Reference: Salesforce Hack at CCCEP, largest Coca-Cola Bottler
Reference: Almost 1 billion Salesforce records stolen, hacker group claims
Incident: Salesforce Hack at CCCEP, largest Coca-Cola Bottler
Salesforce database at Coca-Cola Europacific Partners (CCEP) was reportedly compromised by the hacking group Gehenna. Data was posted on the web. The Coca-Cola Europacific Partners Salesforce database contained 64 gigabytes of data, including “Salesforce accounts, Salesforce cases, Salesforce contacts and Salesforce products.”
As of now, the incident has not been acknowledged by Coca-Cola or CCEP.
Incident: Ransomware Attack hit Coca-Cola’s Middle East Operations
After an alleged ransomware attack, hackers have publicly released Coca-Cola’s internal data. Coca-Cola’s name showed up on a dark web leak site run by the Everest ransomware gang on May 22nd. The hackers claimed they’d swiped personal data from 959 employees, most tied to Coca-Cola’s Middle East distributor. Everest gave the company five days to contact them and make a deal before they dumped the data. The cartel posted a link on May 27th to a full stolen dataset online. Cybernews researchers investigated the leak and found 1,104 files, including passport scans, visa copies, and IDs, most linked to the U.S. multinational beverage company's Middle East operations, particularly its Dubai office.
Threat Actor: Everest Ransomware Group
The Russian linked Everest group has been responsible for multiple ransomware attacks and data breaches since 2020. Since it surfaced in 2020, the Everest ransomware operation has switched tactics from data theft-only corporate extortion to including ransomware in its attacks to encrypt victims' compromised systems.
Notable victims of Everest ransomware attacks include the Brazilian Government, Coca-Cola, the U.S. space agency, NASA, and the cannabis retail chain, Stiiizy.
Reference: Separate ransomware attacks purportedly hit Coca-Cola, bottling partner
Incident: Japanese Brewer Hit in Ransomware Attack
A major global brewer based in Japan reverted to some manual operations after a ransomware attack hit the company last week. The attack forced it to suspend some of its operations like beer production. “Asahi Group Holdings, Ltd. is currently experiencing a system failure caused by a cyberattack, affecting operations in Japan,” the company said. It suspended the following operations: order and shipment operations at group companies in Japan and call center operations, including customer service desks. All 30 Asahi plants in Japan were forced to temporarily halt operations and beer production reportedly resumed at the six plants on October 2. Asahi Breweries did not specify how much longer it would take to return to full capacity.
Reference: Asahi Confirms Ransomware Attack, Data Stolen from Servers
Reference: Ransomware Attack Hits Japanese Brewer
Threat Actor: ShinyHunters
ShinyHunters first emerged in 2020 and claims to have successfully attacked 91 victims so far. The group is primarily after money, but has also been willing to cause reputational damage to their victims.
ShinyHunters posted on Telegram they have been working with known threat actors Scattered Spider and Lapsus$ to target companies such as Salesforce and Allianz Life. Scattered Lapsus$ Hunters, the newly rebranded group, recently advertised they had started providing ransomware as a service. They claim their service is better than other cyber crime groups offer, such as LockBit and Dragonforce. Rather than negotiating directly with victims, the group often publishes public extortion messages.
The 2025 Coca Cola salesforce databreach suggests possible link with hacker group Gehenna.
Victim: Coca-Cola Europacific Partners (CCEP)
Coca-Cola Europacific Partners plc, also known as CCEP, is a British multinational bottling company operating as world's largest independent Coca-Cola bottler by net revenue.
Reference: Salesforce hack at largest Coca-Cola bottler
Reference: Coca-Cola ignores ransom demand, hackers dump employee data
Incident: Ransomware Attack on Cobb County Offices, GA
Cobb County, Georgia, experienced a ransomware cyberattack in March 2025. The attackers claimed to have stolen 150 gigabytes of data, including personal information such as social security numbers and autopsy photos. The hackers demanded a ransom, which the county declined to pay, instead taking its systems offline temporarily and restoring them afterward. As a result of the breach, Cobb County has notified individuals whose data was identified as part of the incident and is offering them credit monitoring and identity theft protection services.
A hacking group issued a ransom demand, which the county declined to pay.
Data Breach:
The attackers claimed to have exfiltrated approximately 150 gigabytes of data, including personal information belonging to county residents and employees.
Data Released:
The hackers posted some of this data, including social security numbers and driver's license photos, online to prove their possession of the files.
Impact on Residents
Information Exposed:
The breach exposed personal information from Cobb County residents and individuals who have done business with the county.
Notifications:
Cobb County is in the process of notifying everyone whose data was identified as part of the breach.
Security Services Offered:
Affected individuals are being offered credit monitoring and identity theft protection services.
What to Do
Stay Alert:
Cobb County is urging residents to monitor their bank accounts for unusual activity.
Credit Freezing:
It is recommended to freeze your credit to help prevent possible damage from the data breach.
Contact the County:
If you have questions about your data, you can refer to the official Cobb County website for more information and resources.
Local Georgia government target of cyberattack | FOX 5 News
May 4, 2025 — a lot of people potentially at risk here anyone who lives in Cobb County or who has done business with the county. could be impacted. in this data...
YouTube·FOX 5 Atlanta
2m
Cybersecurity expert: Hackers leaked data in Cobb County ...
May 3, 2025 — right Carly we're talking about very very sensitive and personal information and the hackers are saying pay up or they're going to go ahead and pu...
YouTube·Atlanta News First
2m
If you live in this Georgia county, your info may be leaked ...
May 5, 2025 — well the deadline passed. and hackers followed up on their threat 400,000 files that could contain your social security number your personal. info...
YouTube·FOX 5 Atlanta
3:12
Show all
Victim: Cobb County, Georgia,
Cobb County, Georgia
Victim: Cobb County, Georgia,
Cobb County, Georgia, USA
Reference: Qilin announces attack on Cobb County, Georgia
Reference: Local Georgia government target of cyberattack | FOX 5 News
Reference: Patients left in the dark months after cybercriminals leak testing lab data
Reference: Patients left in the dark months after cybercriminals leak testing lab data
Incident: Huge Automaker, Stellantis, Suffers Cyberattack
Global automaker, Stellantis, which owns Chrysler, Dodge, Jeep, Ram and Fiat, discovered unauthorized access to a third-party platform that houses North American customer data.
“We recently detected unauthorized access to a third-party service provider’s platform that supports our North American customer service operations,” the company said Sunday in an advisory.
“Upon discovery, we immediately activated our incident response protocols, initiated a comprehensive investigation, and took prompt action to contain and mitigate the situation,” the company said. “We are also notifying the appropriate authorities and directly informing affected customers.“
Reference: Auto Giant Stellantis Suffers Cyberattack
Victim: Stellantis
Global automaker, Stellantis, which owns Chrysler, Dodge, Jeep, Ram and Fiat, discovered unauthorized access to a third-party platform that houses North American customer data.
“We recently detected unauthorized access to a third-party service provider’s platform that supports our North American customer service operations,” the company said Sunday in an advisory.
“Upon discovery, we immediately activated our incident response protocols, initiated a comprehensive investigation, and took prompt action to contain and mitigate the situation,” the company said. “We are also notifying the appropriate authorities and directly informing affected customers.“
Incident: Contract Drilling Operator, Kanai Drilling, Data Encrypted
Bakersfield, California-based contract drilling operator, Kanai Drilling Limited, suffered a cyberattack where data ended up encrypted and attackers stole personally identifiable information.
“On or about May 19, 2025, Kenai Drilling Limited became aware of a cyber security breach of confidential information which occurred between May 17-May 18, 2025,” said a letter sent out to victims of the attack.
In the letter, the privately held drilling contractor said unauthorized “parties” hacked into Kenai’s Document File Server and gained access to sensitive and confidential information without the knowledge or consent of Kenai.
“The culprits accessed and encrypted files that included employee names, social security numbers, wage information, addresses, email addresses, and phone numbers set up by Kenai for each employee. This breach did not expose the employee’s personnel files kept internally at Kenai,” the notice said.
Reference: Contract Drilling Operator Data Encrypted
Victim: Kanai Drilling Limited
Bakersfield, California-based Kenai is a privately held drilling contractor founded in 1988 as a provider of contract drilling services. The company specializes in the exploration and development of onshore and offshore oil, gas and geothermal wells. Kenai operates a fleet of over 19 drilling rigs across California and the Mid-Continent region. Kenai employs over 50 people.
Editorial: 2025 OT Cyber Threat Report
Incident: Oil and Gas producer, DJH Services, Suffers Cyberattack
Oil and Gas producer, DJH Services LLC, suffered a cyberattack in February and is now informing victims what personally identifiable information ended up stolen.
Houston, Texas-based DJH Services also wrote the notice on behalf of its companies, Harrison Interests, Ltd., Fulshear Oil & Gas, and Ramro.
“On February 13, 2025, DJH discovered a cyber incident affecting our network. Immediately upon detecting this incident, we took steps to secure our environment, began remediation and recovery efforts, and launched a thorough investigation in partnership with third-party cybersecurity experts,” the company said in the notice. “We also reported this matter to the Federal Bureau of Investigation.”
Reference: Oil-Gas Producer Hit in Cyberattack
Victim: DJH Services LLC
Among its multiple businesses, DJH works in crude petroleum production, natural gas production, drilling oil and gas wells, along with other agricultural production like beef cattle and other livestock.
Incident: Ransomware Hits Provider to Oil-Gas Producers
There was a ransomware attack at EB Archbald & Associates, Inc., which provides energy production accounting services to oil and gas producers and operators.
“On March 23, 2025, we discovered that our company had been the target of a so-called ‘ransomware’ attack,” the Oklahoma City, Oklahoma-based company said in a notice to its 17,000 victims. “The attackers hacked into our system and utilized software to encrypt all data on our servers and Microsoft cloud-based portal. In a subsequent communication the attackers demanded payment of a large sum of money in exchange for their release of a ‘decryption key.’
“We immediately contacted the local office of the Federal Bureau of Investigation (FBI) and notified them of the attack. Per recommendations received from the FBI we refused to meet the attackers’ extortion demands. Five days after their initial attack, and following our refusal to meet their monetary demand, we received a communication from the attackers claiming that they had downloaded information from our systems which they intended to release on the world wide web,” the company said in the notice.
Reference: Ransomware Attack at Provider to Oil-Gas Producers
Victim: EB Archbald & Associates, Inc.
E.B. Archbald and Associates is a service organization dedicated to supporting and developing the oil and gas industry's most sophisticated accounting solutions, according to the company’s LinkedIn page. SSI Energy Management System is the general trade name for a line of software products specifically designed for oil and gas exploration, production, drilling and investment companies with additional functionality for oilfield service and supply companies.
Victim: SRAM
SRAM is a leading global bicycle component manufacturer, specializing in groupsets, suspension, and wheels for both road and mountain bikes.
Incident: Italian Bus Operator Mom Sees Ticketing Operations Disrupted for 2 Days.
On April 2, 2025, Mobilità di Marca (Mom) suffered a cyberattack disrupting their electronic ticketing services for two days. The attack targeted servers integral to the Telemaco platform used by Mom and other public transport companies. The timing of the attack suggests a strategic attempt to maximize disruption.
Reference: Avviso importante agli utenti: violazione di dati personali sull’App Atma
Victim: Mobilità di Marca (Mom)
Mobilità di Marca (MOM) is a public transportation company operating buses in the Province of Treviso, Italy.
Reference: Mobilità di Marca Cyberattack: Disruption of Telemaco Ticketing Platform Highlights Security Vulnerabilities
Incident: Ransomware Attack at Italian Industrial Fluid Control Manufacturer
On April 28, 2025, KLINGER Italy was reported to have experienced a data breach. The size of the data leak is currently unknown. The threat actor associated with this breach is identified as Gunra.
Reference: KLINGER Italy Data Breach on April 28, 2025
Malware: Gunra Ransomware
Gunra ransomware, first identified in April 2025, has already compromised companies in the pharmaceutical, industrial and real estate sectors in countries including Japan, Egypt, Panama, Italy and Argentina. The program uses a double extortion strategy, in which sensitive data is extracted before encryption. If the victim refuses to pay the ransom, the operators threaten to publish the stolen data on underground forums.
Gunra is derived from the Conti ransomware code , but features significant improvements in evasion and persistence. After infection, it collects information about the environment, deletes shadow copies via WMI, scans the system, and injects code into trusted processes.
Victim: KLINGER Italy S.r.l.
KLINGER Italy S.r.l. is a leading Italian manufacturer and distributor of industrial fluid control and sealing solutions.
Incident: Hackers Attack Rome’s Municipal Waste Management Company
AMA, the municipal waste management company of Rome suffered a cyberattack on its IT systems. The company took immediate action to deal with the attack and is collaborating with the National Cyber Security Agency. Reportedly operating systems are working, while the online ones are being restored.
Victim: AMA Roma S.p.A.
Ama systems is responsible for waste management in Rome.
Reference: Hacker attack on Ama’s IT systems: “Technicians working to ensure full operability” — Hacker attack on Ama’s IT systems: “Technicians working to ensure full operability”
Reference: Hacker attack on Ama’s computer systems
Reference: Cyber Attack Hits AMA: Technicians Working to Restore
Incident: Busitalia Discloses Databreach
Public transport company BusitaliaIa disclosed data breach on its website: "Busitalia has been the victim of a cyber attack. The attack was detected at an external data center between March 29 and March 30, 2025. It compromised personal data of registered passengers.
The incident particularly concerns digital channels such as the Busitalia Veneto App and the subscription portal. Both are used daily by thousands of users to manage travel and tickets.
Reference: Communication of data breach
Victim: Busitalia
Busitalia is a company within the FS Italiane Group that focuses on bus transport services, both locally and internationally.
It operates directly or through subsidiaries: Busitalia Simet for long-distance routes and Qbuzz in the Netherlands.
Reference: Hacker attack on Busitalia: passenger data compromised
Incident: Data Breach at Italian Mobility Services App Provider
Mooney Servizi/My Cicero was hit by a cyber attack on April 5. The company manages the digital systems of mobility companies in the main Italian cities. Personal data of users of Atm, Tuabruzzo and Unico Campania apps were compromised. The attack caused slowdowns and malfunctions. The compromised data included users' names, contact information, and customer profile.
ATM requested a detailed report from Mooney Servizi, reinforced its security protocols for third-party access, and notified both the Italian Data Protection Authority and the National Cyber Security Agency.
Reference: Hacker Attack on ATM Data Manager: Thousands of People’s Information Stolen
Victim: Società Unica Abruzzese di Trasporto (TUA)
Società Unica Abruzzese di Trasporto (TUA) S.p.A. owns and operates the TUAbruzzo app. The app is used for booking transportation services in the Abruzzo region of Italy.
Victim: UnicoCampania
UnicoCampania manages the unified fare system for local public transportation in the Campania region of Italy. It essentially coordinates the efforts of different transportation companies to integrate fares and ticketing systems.
Victim: L’Azienda Trasporti Milanesi ATM
L’Azienda Trasporti Milanesi ATM, transportation company in the city of Milan
Victim: Mooney Servizi/My Cicero
Mooney Servizi/My Cicero manages the digital systems of transportation companies in the main Italian cities.
Reference: Atm App, the data of the users of the Milanese transport company Atm have been violated
Reference: An attack on the Supply Chain hits the Milanese Transport Company ATM which communicates it to users
Incident: Nucor Steel Suspends Part of Production after Cyberattack
Nucor Corporation's disclosed a cybersecurity incident on their IT network via an 8-K filing. The largest steel producer in the U.S. temporarily suspended production at multiple locations. though Nucor notes it is in the process of gradually restarting them. No details about the date or type of the attack were provided, so it’s unknown if the incident involved data theft or encryption.
Reference: Cyberattack Shuts Down Steelmaker
Victim: Nucor Corporation
Nucor is a major steel producer in the U.S. and scrap recycler in the North America. It is a primary supplier of reinforcing bar that is used extensively in the country’s buildings, bridges, roads, and infrastructure. The company employs more than 32,000 people across numerous mills across the U.S., Mexico, and Canada, and reported a $7.83 billion revenue in the first quarter of the year.
Reference: Steelmaker Nucor halts some production after cyber security incident
Reference: Steel giant Nucor Corporation facing disruptions after cyberattack
Incident: Hackers Stole $10K from Pactiv Everygreen Packaging Company
Pactiv Evergreen, a packaging company in Pennsylvania, suffered a cyberattack in late February. Pennsylvania State Police in Mansfield were called in and found that company emails were hacked and that $10,000 had been stolen from the company.
Victim: Pactiv Evergreen
Pactiv Evergreen is a large packaging manufacturer
Reference: $10K stolen from packaging company in Tioga County, Pa
Incident: CLickFix Compromises Websites of over 100 US Auto Dealerships
Websites of over 100 auto dealerships were found serving malicious ClickFix code in a supply chain compromise. A threat actor infected LES Automotive, a shared video service unique to dealerships. Websites using the video service would serve a ClickFix webpage to their visitors. The attack was using the fake reCAPTCHA variation of ClickFix, relying on PowerShell commands to deploy payloads on the victim’s machine, and ultimately infect them with the remote access trojan.
Victim: LES Automotive
LES Automotive, a company which provides a video services to help car dealerships market vehicles online.
Reference: Supply-chain CAPTCHA attack hits over 100 car dealerships
Reference: ClickFix supply chain attack impacts over 100 car dealerships
Reference: 100 Car Dealerships Hit by Supply Chain Attack
Reference: Cyberattack Slows Manufacturing at Health Care Firm
Incident: Cyberattack at Media Conglomerate Urban One
Media conglomerate Urban One reported a data breach involving the personal information of employees and more. The Maryland-based media company said the cyberattack began on February 13 and was initiated through “a sophisticated social engineering campaign.” The hackers were able to exfiltrate company data. The company only discovered the incident on March 15. The incident did not impact the company’s operations.
Names, addresses, Social Security numbers, direct deposit information and W-2 information was taken during the attack. 355 people in Texas were affected. The attack on Urban One was claimed by the Cactus ransomware gang on March 12.
Reference: Media firm Urban One confirms data breach after cybercriminals claim February attack
Victim: Urban One
Urban One is the largest media company targeting the African American community, running multiple TV channels, dozens of radio stations and news websites.
The company reported about $450 million in revenue in 2024.
Incident: Security Breach at Manufacturer of Bicycle Components
SRAM, a well-known manufacturer of bicycle components, experienced a significant cyberattack in March 2025. The cyberattack reportedly compromised some of SRAM's digital initiatives, including online platforms crucial for customer services and cyclist engagement. Data potentially compromised include customer contact and shipping information. Other subsidiaries and departments within SRAM's global operations might have been affected.
SRAM stated they have initiated robust countermeasures to secure their digital infrastructure and prevent future incidents. The attack raised questions within the cycling technology industry about data security protocols and the management of connected devices.
Reference: SRAM investigating ‘cybersecurity issue’
Reference: SRAM’s Cybersecurity Breach: A Wake-Up Call for Tech Savvy Cyclists
Incident: Unsuccessful Cyberattack at Atlanta Intl Airport
A denial-of-service (DoS) attack briefly disrupted the website for Hartsfield-Jackson Atlanta International Airport on Friday. ATL technology team detected the cyberattack and quickly implemented standard protective measures to restore access. Airport operations were not impacted.
Victim: Hartsfield-Jackson Atlanta International Airport
Hartsfield-Jackson Atlanta International Airport
Reference: Atlanta airport stops potential cyberattack Friday morning
Incident: Ransomware Attack at Oracle
Oracle Corporation confirmed a hacker broke into a computer system and stole old client log-in credentials. An unidentified person began attempting to sell data online that was stolen from Oracle's cloud servers.
It is the second cybersecurity breach that the software company has acknowledged to clients in the last month. Oracle told customers that the data breach is separate from the hacking incident that it flagged to some healthcare customers last month.
Victim: Oracle Corporation
Oracle sells database software, particularly Oracle Database, and cloud computing.
Oracle's core application software is a suite of enterprise software products, such as enterprise resource planning (ERP) software, human capital management (HCM) software, customer relationship management (CRM) software, enterprise performance management (EPM) software, Customer Experience Commerce (CX Commerce) and supply chain management (SCM) software.
Reference: Oracle tells clients of second recent hack, log-in data stolen, Bloomberg News reports
Incident: Versa Networks Acknowledges Cybersecurity Incident
SASE specialist Versa Networks acknowledges a cybersecurity incident. "Investigation confirmed that the incident only affected this non-production environment and that it had no impact on our production systems, our customers' data or that of our employees." The cyber-extortion startup Silent appears to be involved.
Reference: Versa Networks faces cyberattack
Incident: Operations Impacted at Medical Device Manufacturer
Medical device company Masimo Corporation warns that a cyberattack is impacting production operations and causing delays in fulfilling customers' orders. "The Company has been working diligently to bring the affected portions of its network back online, restore normal business operations and mitigate the impact of the incident." The firm believes that the network breach was isolated to on-premise systems, not affecting its cloud-based infrastructure.
The investigation is ongoing, and its full scope and impacts are unknown at this time.
Victim: Masimo Corporation
Masimo Corporation is a California-based medical technology and consumer electronics maker. It's best known for its noninvasive patient monitoring products like pulse oximeters, brain function monitors, hemodynamic monitoring systems, capnography and gas monitoring solutions, and remote patient monitoring platforms.
The company has a reported annual revenue of $2.1 billion (2024) and approximately 3,600 employees worldwide, while it is publicly traded on the NASDAQ (MASI).
Reference: Medical device maker Masimo warns of cyberattack, manufacturing delays
Reference: SEC Form 8-K
Reference: Masimo reports cyberattack slowing manufacturing, sales
Incident: US GlobalX Airlines Hacked over Deportation Flights
On May 5, 2025, hackers defaced one of the websites of GlobalX Airlines. The airline is at the center of a US campaign of deportations to an offshore detention center in El Salvador. Global Crossing Airlines Group Inc. immediately activated its incident response protocols. The Company notified law enforcement and is coordinating fully with them.
A message posted to a subdomain of GlobalX said the site had been hijacked by "Anonymous," a label often chosen to evoke rebellious cyber activism.
Reference: Airline carrying out deportation flights confirms cyberattack to SEC
Reference: Website for US deportation airline GlobalX defaced by hackers
Reference: SEC Form 8-K
Victim: Global Crossing Airlines Group Inc
Global Crossing Airlines Group Inc, which also refers to itself as GlobalX, is a Miami-based airline offering passenger and cargo flights in the U.S., Latin America, Europe and the Caribbean.
It reported a 2023 revenue of $160 million and makes about $65 million annually from its work with ICE.
Incident: Packaging Manufacturer in Canada Resumes Normal Operations Month after Cyberattack
On February 21, 2025, Imaflex packaging company announced they suffered a cybersecurity attack. The incident disrupted Imaflex' systems and operations. The company says it immediately took steps to contain and mitigate any potential impact. Manufacture -, ship - and perform back-office functions continued as required with temporary workarounds.
On March 27 Imaflex confirmed "all systems and data have been fully restored, and operations have returned to normal".
Victim: Imaflex
Imaflex is focused on the development and manufacturing of solutions for the flexible packaging space. Concurrently, the Corporation develops and manufactures films for the agriculture industry.
Reference: Imaflex Inc. announces resumption of normal operations after cybersecurity incident
Reference: Imaflex Inc. announces cyber security incident
Reference: Imaflex Resumes Normal Operations Following Cybersecurity Incident
Incident: Ransomware Attack at Canadian Chocolate Manufacturer Disrupts Operations
Ganong Bros., a Canadian sweets manufacturer based in St. Stephen, New Brunswick, was hit by a ransomware attack. The company discovered the incident on February 22, 2025. Operations at the facility in St. Stephen were temporarily disrupted. Ganong immediately engaged third-party cybersecurity experts and legal counsel.
The PLAY ransomware group claimed responsibility for the attack. Ganong has acknowledged the "IT security incident," and declined to comment on whether a ransom was demanded or paid.
Reference: Ganong Bros. says it’s investigating cybersecurity incident
Victim: Ganong Bros
Ganong Bros., a Canadian sweets manufacturer based in St. Stephen, New Brunswick
Reference: Ganong in St. Stephen hit by ransomware cyber attack
Incident: Extensive Databreach fully Exposes Qualinet’s Operation Methods
The Qualinet Group suffered a ransomware attack on January 10. The company deployed its emergency plan and mobilized a team of specialists to identify the extent of the attack. The Rhysida group claimed the attack. The hackers infiltrated the servers and stole 1.5 million files. Qualinet refused to pay the ransom of seven bitcoins ($870,000) in exchange for its 1.2 terabyte treasure trove of data. Since January 28, all files can be downloaded via Tor software from Rhysida's website. The site exposes company data, including its operating methods, canadian passports and Quebec driver's licenses.
Qualinet operates primarily in the disaster restoration and cleaning services industry and is based in Quebec, Canada.
Victim: Qualinet Canada
Qualinet Canada is a Quebec-based company specializing in post-disaster cleaning and restoration services. They offer a range of services, including cleaning, washing, staining, drying, and decontaminating properties affected by disasters like fire, flood, or strong winds. Their services extend to both residential and commercial properties.
Reference: Data theft: Qualinet will have to defend itself in court
Reference: Qualinet victim of a cyberattack
Incident: Cyberattack Disrupts Tata Technologies’ IT Systems
Tata Technologies reported a security breach by ransomware actors disrupting parts of its IT systems. The company stated operational impact was minimal and client delivery services were not affected. Hunters International ransomware gang claimed responsibility for the attack claiming they stole 1.4TB of data. The hacker group did not post any samples of the stolen files or elaborate on what kind of documents they hold.
Victim: Tata Technologies
Tata Technologies provides engineering and digital solutions for manufacturing industries worldwide. Founded in 1989 and based in Pune, it operates in 27 countries with over 12,500 employees, specializing in automotive, aerospace, and industrial sectors with product development and digital transformation services.
Reference: Hunters International ransomware claims attack on Tata Technologies
Reference: Tata Technologies data leaked by ransomware group on the dark web: Report
Incident: Kitchen Appliance Manufacturer Vorwerk Suffers Data Breach.
Wuppertal-based kitchen appliance manufacturer Vorwerk suffered data breach. For many customers, a Vorwerk Thermomix is only complete with online access, where they can download thousands of recipes. Unknown perpetrators accessed user data from Vorwerk's recipe forum and copied users' personal data. According to the news magazine "Spiegel," the data was offered on a darknet forum. The database reportedly contains information from 3.3 million users. Vorwerk said full names, addresses, birthdays, phone numbers, and email addresses were accessed.
Reference: Millions of user data leaked from Thermomix forum
Reference: Hackers steal millions of user data from Thermomix forum
Victim: Vorwerk
Vorwerk kitchen appliance manufacturer from Wuppertal
Incident: Cyberattack Hits Schwerte’s Municipal Utilities
A municipality in North Rhine-Westphalia has fallen victim to a cyberattack. The city of Schwerte has "taken comprehensive security precautions," according to the Ruhr Nachrichten newspaper. The city's digital connection to the utility company has been interrupted. The Schwerte city administration's systems were fully operational again on March 10. Local newspaper Ruhr News reports that stolen data, including personal data, has been published on the dark web on April 30.
Reference: City of Schwerte gives all-clear after cyber attack on municipal utilities
Reference: Stadtwerke Schwerte: Stolen data after cyber attack on the darknet.
Victim: Schwerte municipal utility company
Schwerte municipal utility company
Reference: Cyber attack on NRW city: “Authorities have been informed”
Incident: Cyberattack on Logistics Service Provider in Germany
The intralogistics service provider Hofmann Fördertechnik suffered a cyberattack at the end of March. "The attackers gained access to the servers, which led to a complete failure of the IT systems," the company stated. All servers were immediately shut down and external specialists were called in. No further details about the attack were provided.
Victim: Hofmann Foerdertechnik GmbH
Hofmann Foerdertechnik GmbH is a solution provider for material flow and intralogistics in companies and manufactures material handling machinery.
Reference: Hacker attack on Hofmann Fördertechnik
Reference: Hofmann Fördertechnik affected by cyberattack
Reference: Elon Musk claims X falls to cyberattack
Reference: What Really Happened With the DDoS Attacks That Took Down X
Victim: X (formerly Twitter)
X (formerly Twitter)
Reference: 200 Million X User Records Released — 2.8 Billion Twitter IDs Leaked
Incident: Hacker Dumps Samsung Support Tickets Online
A cybercriminal offered hundreds of thousands of data records from Samsung Germany on the dark web. The data was copied from Samsung Electronics Germany’s support system by a hacker using the pseudonym “GHNA”. The leaked date sets contain names, addresses, emails, order data, and internal communications. Security specialist Hudson Rock analyzed the breach and found initial access was gained via login credentials stolen by an infostealer in 2021. Raccoon malware harvested login credentials from a third party associated with Samsung’s German ticketing system. These credentials sat dormant until the hacker got their hands on them. And now “270,000 customer tickets have hit the open internet, most of them from 2025, courtesy of a simple login that never got rotated.”
Samsung issued the following statement. “Samsung has been made aware of a data breach impacting one of our system partners in Germany. We take the security of customer data extremely seriously and are working to assess the extent of the incident.”
Reference: Years-old login credential leads to leak of 270,000 Samsung customer records
Reference: Infostealer Strikes Samsung — 270,000 Records Stolen
Incident: Cyberattack Forces Recycling Company to Permanently Shut Down
Recycling specialist Eu-Rec has filed for insolvency after cyberattack took its IT systems completely offline. As a direct result of the attack, orders could no longer be processed. The data compromised in the attack includes email addresses, telephone numbers, postal addresses, contact details, and bank account information. Around 50 employees are affected by the insolvency, but their wages and salaries are secured for the coming months thanks to insolvency benefits.
Eu-Rec offers environmental/waste management services.
Victim: Eu-Rec GmbH
Eu-Rec GmbH specializes in the environmentally friendly recycling of recyclable materials and is considered an established recycling specialist in the region. The family business, run by Simone and Willi Streit, primarily processes plastics and waste paper and is an important player in the local circular economy.
Eu-Rec is based in Hermeskeil, Rhineland-Palatinate and has been committed to environmentally friendly recycling processes for recyclable materials for thirty years.
Reference: Cyberattack pushes family business into insolvency
Reference: Hackers paralyze recycling company – insolvency
Reference: Cyberattack announcement
Incident: German Food & Beverage Wholesaler Suffers Cyberattack
On the night of April 12-13, 2025, FAKO-M Getränke GmbH & Co. KG fell victim to a targeted cyberattack. The entire IT infrastructure at the company's locations in Neuss, Bocholt, and Hamm was subsequently paralyzed. According to the company, business operations are currently continuing in emergency mode. Orders are being processed manually, but regular operations are not possible. "We are working hard to deliver the ordered goods manually despite the lack of systems," explains Managing Director Mr. Siebigteroth.
Victim: FAKO-M Getränke GmbH & Co. KG
FAKO-M Getränke GmbH & Co. KG is a German beverage wholesaler.
Manufacturer of soft drinks; production of mineral waters and other bottled waters industry.
Reference: IT failure at FAKO-M Getränke: Cyberattack hits the beverage industry hard
Reference: FAKO-M-Getränke falls victim to a cyberattack
Reference: FAKO-M Getränke GmbH & Co. KG victim of a cyberattack
Incident: Cyberattack takes Systems Offline at German Tool Wholesaler
Tettnang-based tool wholesaler Layer reported a suspected cyberattack last Thursday. The company's stores closed and their fleet was not making deliveries. On Monday, April 21 a report was issued stating that Layer is working diligently with IT experts to resolve the cyber incident. Core processes were restored on Tuesday, April 22nd.
LAYER-Grosshandel GmbH & Co. KG is a German company that retails hardware supplies, offering a wide range of products including (machine) tools, building hardware, and work clothing.
Victim: LAYER-Grosshandel GmbH & Co. KG
LAYER-Grosshandel GmbH & Co. KG is a German company that retails hardware supplies, offering a wide range of products including tools, building hardware, and work clothing. They serve customers across Germany and operate various locations throughout the country. The company is known for offering tools, machine tools, building hardware, furniture fittings, connection technology, installation material, rough irons, technical lighting, factory equipment, occupational safety, and work clothing.
Reference: Information about the cyber incident at LAYER
Reference: Tool retailer Layer falls victim to cyberattack: What customers should look out for now
Incident: System Outage at Freight Division of Swiss Post in Germany
Swiss Post suffered a cyberattack in its freight logistics division in Germany. The division has been unable to access its IT systems, or has only partial access. Investigations show that a targeted cyberattack is the cause of the system outage. Local logistics, accounting, and HR systems are affected. Data records from the period 2020–2025 were stolen in the cyberattack. The division adjusted workflows and temporarily increased staffing levels as part of an established emergency plan. Approximately 1,600 business customers who use Swiss Post Cargo Germany's warehousing and transport services are affected.
Swiss Post's information security department is working intensively with local experts to stabilize the systems. Swiss Post's systems in Switzerland are not affected.
Victim: Swiss Post Cargo Germany
Swiss Post Cargo Germany is Swiss Post freight logistics division in Germany
Reference: Swiss Post takes action against cyberattack in Germany
Incident: Ransomware Attack Impacts German Sawmill Operations
Large European sawmill operation Holz Ruser GmbH suffered a cyberattack on April 17, 2025. According to owner and managing director Henning Ruser, the full extent of the damage could not be assessed until April 23 due to the holidays. The malware was reportedly spread to the entire IT system at the site and paralyzed its business operations. No further information available at this time.
Victim: Holz Ruser
Holz Ruser offers specially tailored products for the timber trade, timber construction/carpentry and industry with system solutions for further processing.
Reference: Business operations at Holz Ruser paralyzed by hacker attack
Incident: German Beer Brewer Hit by Ransomware Attack
Oettinger German beer and soft-drinks group is investigating a cyberattack on the business. In a brief statement the privately owned company confirmed the breach and said it was looking into the “potential” for data leaks. According to Cybernews, the ransomware group Ransom House claims to hold data from the brewer. Ransom House alleged to have stolen internal files between 2022 and 2025. The brewer and soft drinks maker said production is unaffected.
Reference: German beer powerhouse allegedly hit by ransomware, internal documents at stake
Victim: Oettinger Getränke
Oettingen Beverages is one of the largest drinks manufacturers in Germany and one of the top 25 breweries globally. The business is headquartered in Oettingen in Bayern and the company reportedly boasts an annual revenue of over US$420 million and has approximately 800 employees spread across sites in Oettingen, Mönchengladbach, and Braunschweig.
Reference: Oettinger allegedly compromised by RansomHouse gang
Reference: German drinks group Oettinger confirms cyberattack
Reference: Oettinger Brewery gets hit by ransomware attack
Incident: Hackers Claim to Disrupt Communications on 116 Iranian Ships
A group of hackers claims to have carried out a cyber attack that allegedly disrupted communications on 116 Iranian cargo ships. The group, Lab Dookhtegan, has not publicly disclosed the exact Tactics, Techniques, and Procedures (TTPs) used, open-source reporting indicates the group likely exploited vulnerabilities in the maritime satellite communication systems that these ships rely on.
Iranian authorities have yet to comment on the attack. In past incidents, state media and officials have either denied cyber intrusions or attributed them to foreign intelligence services. If confirmed, this latest operation would mark one of the most significant cyber disruptions targeting Iran’s maritime sector.
Incident: Global Car Rental Giant Hertz Notifies Customers Data Breach
Car rental giant Hertz notified its customers of a data breach. The rental company said the breach relates to a cyberattack on one of its vendors between October 2024 and December 2024.
The stolen data varies by region, but largely includes Hertz customer names, dates of birth, contact information, driver’s licenses, payment card information, and workers’ compensation claims. Hertz said a smaller number of customers had their Social Security numbers taken in the breach, along with other government-issued identification numbers.
Notices on Hertz’s websites disclosed the breach to customers in Australia, Canada, the European Union, New Zealand, and the United Kingdom. Hertz also disclosed the breach with several U.S. states, including California, Maine, and Texas. Emily Spencer, a spokesperson for Hertz, would not provide TechCrunch with a specific number of individuals affected by the breach but said it would be “inaccurate to say millions” of customers are affected.
Victim: Hertz
Car rental giant Hertz, also owns the Dollar and Thrifty brands.
Reference: Hackers are exploiting a flaw in popular file-transfer tools to launch mass hacks, again
Reference: Hertz says customers’ personal data and driver’s licenses stolen in data breach
Incident: Cyberattack Compromised Customer Data at Mobile provider MTN
African mobile giant MTN Group announced that a cybersecurity incident has compromised the personal information of some of its subscribers in certain countries. The telecom giant noted that its network and billing systems weren't impacted by the attack, though an investigation to determine the exact scope and impact is ongoing.
While the company hasn’t said exactly which countries were affected, MTN Ghana revealed that approximately 5,700 customers may have been impacted, prompting Ghana’s Data Protection Commission to launch an investigation. At the time of writing, no ransomware actors have claimed responsibility for an attack at MTN.
Reference: MTN cybersecurity incident, but critical infrastructure secure
Victim: MTN Group (formerly M-Cell)
MTN Group (formerly M-Cell) is Africa's largest mobile network operator, with a strong Asian market presence. The company has nearly 300 million subscribers across 20 countries and an annual revenue surpassing $11 billion.
Reference: Largest telecom in Africa warns of cyber incident exposing customer data
Reference: MTN breach not a glitch but a hack with demands
Reference: MTN Group announced a cybersecurity incident
Reference: Mobile provider MTN says cyberattack compromised customer data
Reference: Ahold Delhaize confirms data theft after INC ransomware claims attack
Incident: Europcar Data Breach Affects up to 200,000 Customers
A hacker breached the GitLab repositories of multinational car-rental company Europcar Mobility Group and stole source code for Android and iOS applications, as well as some personal information belonging to up to 200,000 customers. The actor tried to extort the company by threatening to publish 37GB of data that includes backups and details about the company’s cloud infrastructure and internal applications.
Europcar is in the process of notifying all impacted customers and has notified the data protection authority in the country. It is unclear how the threat actor managed to gain access to Europcar’s code repositories but many recent breaches were fueled by credentials stolen in infostealer compromises.
Victim: Europcar Mobility Group
Europcar Mobility Group is a subsidiary of Green Mobility Holding that operates the Europcar, Goldcar, and Ubeeqo brands with a diverse offering of compact cars, luxury vehicles, vans, and trucks.
Reference: Europcar GitLab breach exposes data of up to 200,000 customers
Reference: Massive Europcar data breach affects around 200,000 customers
Reference: Port of Seattle is notifying 90,000 people of a data breach after personal data was stolen in a ransomware attack in August 2024.
Incident: Ransomware Attack Disrupts Hitachi Vantara Operations
Hitachi Vantara experienced a ransomware incident on April 26. BleepingComputer reports that, while the company's cloud services are not impacted, Hitachi Vantara systems and Hitachi Vantara Manufacturing were disrupted as part of the containment effort. Additionally, while Hitachi Vantara's remote and support operations are down, customers with self-hosted environments can still access their data as usual. The attack has also affected multiple projects owned by government entities.
Reference: Hitachi Vantara Confirms Ransomware Attack
Victim: Hitachi Vantara
Hitachi Vantara, a subsidiary of Japanese multinational conglomerate Hitachi, provides data storage, infrastructure systems, cloud management, and ransomware recovery services to government entities and some of the world's biggest brands, including BMW, Telefónica, T-Mobile, and China Telecom.
Reference: Hitachi Vantara takes servers offline after Akira ransomware attack
Incident: Fortune 500 Dialysis Service Provider Hit by Ransomware Attack
Dialysis service provider, DaVita, reported on April 14, 2025 that it discovered a ransomware attack encrypting part of its network. DaVita became aware of the incident on April 12, 2025 and immediately implemented response protocols to isolate the impacted systems. Despite the attack impacting some operations, patient care continues. DaVita reported it “cannot estimate the duration or extent of disruption at this time,” in its SEC regulatory filing.
The Interlock ransomware gang has claimed the cyberattack and leaked data allegedly stolen from the organization. According to the gang's claim, they have around 1.5 terabytes of data or nearly 700,000 files of what appear to be sensitive patient records, information on user accounts, insurance, and even financial details.
DaVita is a Fortune 500 kidney care provider with more than 2,600 U.S. dialysis centers, 76,000 employees in 12 countries, and an annual revenue exceeding $12.8 billion.
Reference: Dialysis Provider DaVita Faces Ransomware Attack
Reference: Interlock ransomware claims DaVita attack, leaks stolen data
Victim: DaVita
DaVita is a Fortune 500 kidney care provider with more than 2,600 U.S. dialysis centers, 76,000 employees in 12 countries, and an annual revenue exceeding $12.8 billion.
Incident: Ransomware Attack at Sensata Technologies
Sensata Technologies experienced a ransomware attack on April 6, 2025, which encrypted certain devices on its network and impacted operations. Operations affected include shipping, receiving, manufacturing production, and various other support functions. The company confirmed that some files were taken and is investigating the breach. Sensata is working to restore its systems and has not yet provided a timeline for full recovery. At the time of writing, no ransomware group has claimed the attack.
Victim: Sensata Technologies
Sensata Technologies is an industrial technology company that develops, manufactures, and sells a wide range of sensors and sensor-rich solutions, as well as electrical protection components and systems.
The company's products are for automotive, aerospace, and industrial applications. In 2023, Sensata reported an annual revenue of $4 billion.
Reference: Sensata Technologies hit by ransomware attack impacting operations
Reference: Industrial tech manufacturer Sensata says ransomware attack is impacting production
Incident: Ransomware Attack Disrupts Kuala Lumpur Airport
A cyberattack on Kuala Lumpur International Airport's (KLIA) systems caused a disruption lasting several hours on Sunday March 23. The incident, which began in the early hours, rendered the airport's flight information display system, check-in counters and baggage handling inoperative. Airlines and airport staff were forced to switch to manual operations. Initial findings suggested a cyber intrusion compromised KLIA's critical systems. Malaysian Prime Minister Anwar Ibrahim called the disruption "quite heavy" and said that a ransom demand for $10 million had been refused.
Qilin claimed the attack, but the airport has not verified this. Qilin says it stole 2 TB of data from Kuala Lumpur International Airport in the attack.
Reference: Cyberattack on MAHB: Hackers yet to be identified
Reference: Malaysia PM says country rejected $10 million ransom demand after airport outages
Reference: Malaysian PM says “no way” to $10 million ransom after alleged cyber attack against Kuala Lumpur airport
Reference: Ransomware gang says it hacked the Malaysia’s Kuala Lumpur International Airport
Reference: Malaysian Airport’s Cyber Disruption a Warning for Asia
Victim: Malaysia Airports Holdings Berhad (MAHB)
Malaysia Airports Holdings Berhad (MAHB)
Incident: South Africa’s Largest Poultry Producer Profits Fall after Cyberattack
Astral Foods confirmed it suffered a cybersecurity incident on March 16, 2025. The attack lead to downtime in the poultry processing division, impacting deliveries to customers and causing a backlog in production. Although the company swiftly implemented disaster recovery protocols, the temporary halt in operations resulted in financial losses.
Reference: Cyberattack causes delays for South Africa’s largest chicken producer
Reference: Astral Foods Hit by Cyberattack, Expects R20 Million Loss in Profits
Victim: Astral Foods
South African chicken producer Astral Foods
Incident: Ukrainian Railways IT Services Outage After Cyberattack
On March 23 when the ukrainian rail company Ukrzaliznytsia notified passengers about a failure in its IT system. Passengers were advised to buy tickets on site or on trains. Valeriy Tkachev, deputy head of the commercial department of Ukrzaliznytsia, said the company needs "one or two weeks" to restore all services.
For a country at war where commercial aviation is prohibited, disruption on such a vital travel network threatened country-wide chaos. The railway in Ukraine these days transports everything from the military, the wounded, to the evacuation of the civilians, and international diplomats.
Victim: Ukraine’s state-owned railway Ukrzaliznytsia
Ukraine's state-owned railway Ukrzaliznytsia, the country's largest carrier.
Reference: ’89 hours of non-stop work’ — Ukrainian Railways’ battle against a cyberattack by ‘the enemy’
Reference: Ukraine’s railways restore half of IT services hit by cyber attack so far
Reference: Ukraine railway says its online systems targeted in large-scale cyberattack
Incident: Iran Stopped Cyberattack on Infrastructure
Iran repelled a large cyber attack on its infrastructure on Sunday, said the head of its Infrastructure Communications Company, a day after a powerful explosion damaged its most important container port and another round of talks with the U.S. over Tehran's disupted nuclear programme. "One of the most widespread and complex cyber attacks against the country's infrastructure was identified and preventive measures were taken," Behzad Akbari said on Monday, according to semi-official Tasnim news agency, without giving more detail.
Reference: Iran repelled large cyber attack on Sunday
Reference: Iran claims it stopped large cyberattack on country’s infrastructure
Victim: Iran – infrastructure
Iran - infrastructure
Reference: Lab Dookhtegan cyber attack on Iranian oil tankers disrupts operations
Reference: Cyber Hackers Claim to Have Disabled Iranian Ship Communications
Reference: Hackers claim to have disrupted communications on 116 Iranian ships
Reference: Iran repelled large cyber attack on Sunday
Reference: Cyber group says it disrupted Iranian shipping communications
Incident: Disruption at Cleveland’s Municipal Court
Nearly three weeks after announcing a cyber attack had brought down its systems, Cleveland’s Municipal Court did not recover, hampering dozens of trials that had been slated to begin in March. An employee said they are forced to complete some tasks by hand and do not have access to the internet. Reportedly the court is still in the process of updating computers with new security features and passwords.
Victim: Cleveland’s Municipal Court
Cleveland’s Municipal Court
Reference: Cleveland Municipal Court closes Monday after ‘cyber incident,’ officials say
Reference: DeWine sends National Guard to assist with Cleveland Municipal Court cyberattack
Reference: It’s been 3 weeks. Cleveland Municipal Court is still not back to normal after cyber attack
Reference: Municipalities in four states are struggling with cyberattacks limiting services
Reference: ‘Cyber incident’ shuts down Cleveland Municipal Court for third straight day
Incident: Texas Border City Declares State of Emergency After Cyberattack on Government Systems
The government of Mission, Texas, filed a state of emergency declaration this week after a cyber attack exposed all of the data held on city systems. The city government notified residents of the incident, telling them cybercriminals targeted portions of their network. Police officers have lost the ability to run license plates and driver’s licenses through state databases. The attack also caused police laptops to stop working.
The city council extended the disaster declaration for an additional seven days. The mayor's letter to Governor Abbott mentioned that the city's entire computer server was at risk of a cyberattack.
Reference: City of Mission extends disaster declaration following cyber attack
Victim: CIty of Mission, Texas
Mission, Texas
Reference: Mission, Texas, requested state of emergency after cyberattack. Some analysts aren’t so sure
Reference: Texas border city declares state of emergency after cyberattack on government systems
Incident: Cyberattack hits Nova Scotia Power and Parent Co. Emera
Nova Scotia Power and its parent company Emera suffered a cyberattack in April. Unauthorized access to parts of their Canadian network and servers used for business applications was discovered. Nova Scotia Power said their investigation showed customers personal information was accessed and taken. “We are seeing a significant ramp up in utility impersonation fraud,” Shipley says. “Criminals trying to defraud individuals trying to look like Nova Scotia Power.”
The utility says there remains no disruption to any of its Canadian physical operations, including at Nova Scotia Power’s generation, transmission and disruption facilities, the Maritime Link or the Brunswick Pipeline. However, on a social media post Monday morning, Nova Scotia Power said it was experiencing a technical issue with their phone line and customers being able to access their accounts.
Reference: Nova Scotia Power, Emera Inc. responding to ‘cybersecurity incident’ impacting certain IT systems
Victim: Emera Incorporated
Emera Incorporated is an electric power generation, transmission and distribution corporation: a publicly traded Canadian multinational energy holding company based in Halifax, Nova Scotia.
Victim: Nova Scotia Power
Nova Scotia Power Inc. is a vertically integrated electric utility in Nova Scotia, Canada. It is privately owned by Emera and regulated by the provincial government via the Nova Scotia Utility and Review Board.
Reference: NS Power cyberattack sparks conversations about the need for enhancing security measures
Incident: Disruptive Ransomware Attack hit Presto Home Appliance Manufacturer
National Presto Industries Inc disclosed a material cybersecurity incident that occurred on March 1, 2025. The company reported the system outage in a filing with the Securities and Exchange Commission. The attack interrupted shipping and manufacturing processes causing delivery delays. The company has instituted temporary measures to uphold critical operations. Presto began mailing data breach notification letters to impacted individuals on April 25. Ramifications of the incident on National Presto’s financial health and operational performance could be materially significant.
InterLock ransomware gang added National Presto Industries’ subsidiary National Defense Corporation to its Tor-based leak site. The hacker group says it stole vast amounts of data from the company, including roughly 450,000 folders containing close to 3 million files. National Presto Industries has made no public statement regarding the group’s claims.
Malware: ClickFix
A ClickFix attack relies on malicious code on a webpage to display a prompt to the user, asking them to fix an error or perform a reCAPTCHA challenge, to prove they are human. When the user clicks on the prompt, a malicious command is copied to the clipboard, and the user is also instructed to perform keyboard combinations that open the Windows Run prompt, paste the copied command into the prompt, and execute it.
The social engineering technique has been used for a couple of years, but started gaining popularity among cybercriminals and APTs last year
ClickFix attacks have been adopted by a wide range of threat actors: Interlock and other ransomware gangs and North Korean hackers.
Threat Actor: Interlock
Interlock ransomware operation launched in late September 2024. The group cannot be classified as a “Ransomware-as-a-Service” (RaaS) group, as no advertisements for recruiting affiliates or information about affiliates have been found as of March 2025.
The Interlock ransomware gang now uses ClickFix attacks that impersonate IT tools to breach corporate networks and deploy file-encrypting malware on devices.
Interlock has a Data Leak Site (DLS) called “Worldwide Secrets Blog” exposing victim’s data, and providing a way to negotiate the ransom price to the victims.
Reference: Ransomware Group Takes Credit for National Presto Industries Attack
Reference: Home appliance company Presto says cyberattack causing delivery delays
Victim: National Presto Industries Inc
National Presto Industries is divided into three business segments (divisions), Housewares/Small Appliance; Defense; and Safety.
Originally called "Northwestern Steel and Iron Works" the company changed its name to the "National Pressure Cooker Company" in 1929 and then National Presto Industries, Inc. 1953. The company originally produced pressure canners for commercial, and later home, use. Beginning in 1939, the company introduced small home-use cooking appliances. The company was admitted to the New York Stock Exchange on March 3, 1969.
Reference: SEC FORM 8-K
Reference: National Presto reports significant cybersecurity incident
Reference: Polish space agency confirms cyberattack
Incident: Cyberattack at Polish Space Agency (POLSA)
Poland's Minister for Digitalization, Krzysztof Gawkowski, said a cyberattack was detected at the Polish Space Agency (POLSA) on March 1. Unauthorized access to the IT infrastructure was detected. The agency's network was immediately disconnected from the internet to secure data, and intensive operational activities are underway to identify the perpetrator.
Sources inside the agency, who asked to remain anonymous, claimed the attack appears to be related to an internal email compromise and that staff are being told to use phones for communication instead. The incident is being analyzed, and cybersecurity services are investigating, amid concerns of potential destabilization attempts.
Reference: Cyberattack detected at Polish space agency, minister says
Incident: Sensitive Argentine Defense Industry Information Compromised in Ransomware Attack
A cyberattack on Fabricaciones Militares, a key state-owned company for the Argentine defense industry, has resulted in the theft of over 300 GB of sensitive data. The compromised data includes plans for cutting-edge weapons projects. Negotiations are reportedly underway to recover the stolen information. The cyberattack was first reported by specialized publications FalconFeeds.io and Cyber Press, who identified it as a ransomware attack claimed by the "MONTI" group.
Fabricaciones Militares holds a crucial position in Argentina's defense sector, as it oversees the Villa María Military Powder and Explosives Factory. The company's current transition and the government's privatization plans have created a delicate situation, especially considering the sensitive nature of the stolen data.
Threat Actor: MONTI
Monti was first discovered in June 2022, Monti ransomware appeared as a clone of Conti, as it used most of its code following a leak from a Ukrainian researcher. In September 2022, an Intel471 report highlighted the increased likelihood of Monti being a rebrand of Conti based on their identical initial network access methods.
Members of the gang do not consider themselves cybercriminals or their software malicious. They refer to the tools they use as utilities that reveal security problems in corporate networks, and call their attacks penetration testing, for which they want to get paid. If the victim company does not pay, they publish the name of their victims on their data leak site, under a section called "Wall of Shame."
Despite the terms used to describe their activity, the Monti group behaves like any other ransomware gang, breaching company network, stealing data, and asking for a ransom.
Victim: Fabricaciones Militares
Fabricaciones Militares holds a crucial position in Argentina's defense sector, it oversees the Villa María Military Powder and Explosives Factory.
Reference: Cyberattack on Military Manufacturing, Security Risk and Official Silence
Incident: Cablevision Suffers Cyberattack
On March 2, 2025, Cablevision, a subsidiary of Bell providing internet and cable television services, became the target of a "cybersecurity incident." The incident disrupted the company's operations and affected its customers. The company's website, which is currently inaccessible, displays a message explaining that a system outage is affecting its computer systems. As a result, customers are unable to access their accounts, place orders, or manage billing-related tasks. Cablevision has acknowledged the issue and assured that they have taken swift action to secure the affected system. They are currently investigating the incident and working towards restoring their systems and operations.
Reference: Cablevision Victim of a “Cybersecurity Incident”
Victim: Cablevision
Cablevision is a subsidiary of Bell providing internet and cable television services.
Incident: More Outages at Russian Telecom Company
Russian telecom Beeline suffered a targeted distributed denial-of-service (DDoS) attack. Internet services for its over 44 million subscribers were disrupted. The attack caused difficulties accessing the company's mobile app, website outages, and internet disruptions. The attack originated from 1,600 IP addresses.
Reference: Russian telecom Beeline facing outages after cyberattack
Incident: DDoS Attack Compromised Systems at Popular FlightRadar24.
Flightradar24, a popular flight tracking service, was affected by a cyber incident that compromised their systems. The incident may have exposed email addresses and password hashes of some users. The attack prompted the company to reset passwords and instruct affected users to change them. No personal or payment information was compromised, and the company has taken steps to contain the incident.
Reference: We are aware of some users experiencing a variety of issues
Victim: Flight Radar 24
Flight Radar 24 tracks as many as 200,000 flights globally every single day, displaying them in real-time using ADS-B data from a massive network of more than 40,000 receivers around the world.
The website and its accompanying app have proven incredibly popular, not only with aviation buffs but also the wider public, who have often turned to Flight Radar 24 to watch in real-time flights around the world.
Reference: The World’s Most Popular Flight Tracker is Fighting An Ongoing DDoS Cyber Attack
Incident: Ransomware Attack at Polish Truck and Trailer Parts Company
Ransomware attack at Suder, a Polish company specializing in selling truck and trailer parts. A company notification explained that on March 6, 2025, Suder's IT staff noticed issues with their information systems. Upon investigation, it was discovered that the servers had been encrypted using malicious ransomware software. The attack affected Suder's operations and sensitive information was reportedly accessed. A group of anonymous hackers known as Qilin leaked evidence of the attack online, this included a packing list, a medical certificate for a driver-warehouseman, an employment contract, and two Polish passports.
Suder promptly engaged a professional entity to manage the incident response, with a primary goal of determining the extent and impact of the breach. The company acknowledged the possibility of unauthorized access to personal data, which could lead to various risks for affected individuals.
Victim: Suder
Suder & Suder is one of the largest truck, trailers and buses' spare parts specialists located in Poland. Founded in 1991.
Reference: Attack on Polish store. Cybercriminals showed evidence
Reference: NOTIFICATION OF SUSPECTED VIOLATION OF PERSONAL DATA PROTECTION REGULATIONS
Incident: Cyberattack on AERTiCKET Disrupts Booking System and Travel Offers
A cyberattack on Berlin-based travel booking provider AERTiCKET disabled its Cockpit ticketing platform, disrupted offers for global travel agencies. The attack forced deployment of a temporary booking workaround and resulted in a multi-week operational outage of its core booking system. The attack impacted its customers worldwide, systems were restored over several weeks. .
Reference: Cyberattack on Aerticket – Several offers affected
Reference: Technical outages at AERTiCKET due to a cyberattack
Reference: Technical outages at AERTiCKET due to a cyberattack
Victim: AERTiCKET
AERTiCKET is a general Information developer of an airline ticket wholesaling platform intended for the travel agencies, tour operators and internet portals.
Incident: DDoS Attack on Clermont-Ferrand Auvergne Airport’s website.
The Aéroport de Clermont-Ferrand-Auvergne's website was targeted by a DDoS attack. The attack caused a brief interruption of service, but did not impact the airport's operations.
The attack was claimed by a hacker group called "Diplomat". The motivations behind the attack are unclear.
Reference: DDoS Alert
Reference: Website of Clermont-Ferrand Auvergne Airport victim of cyberattack
Victim: Clermont-Ferrand Auvergne Airport
Clermont-Ferrand Auvergne Airport, France
Incident: Cyberattack Takes SeneNews.com Temporarily Offline
SeneNews.com suffered a cyberattack rendering the website temporarily inaccessible. The attack involved over 300 million requests, prompting an immediate response from technical teams to identify the source and restore access, with the company prioritizing security and user data protection during this time. SeneNews.com has emphasized its commitment to protecting user data and ensuring the security of its digital services.
The attack on SeneNews.com has been described as unprecedented in its scale and impact. The website, known for its comprehensive coverage of Senegalese and international news, has become a trusted source of information for millions of readers. However, the cyberattack has disrupted its operations, leaving its readers without access to the latest news and updates.
Reference: SeneNews.com Victim of Unprecedented Cyberattack: Site Hard to Access
Victim: Senenews.com
SEnenews.com is a website known for its comprehensive coverage of Senegalese and international news. The site has become a trusted source of information for millions of readers.
Incident: Cyberattack Impacts Retail Stores of Swiss SPAR Handels AG
The supermarket chain Spar has been hit by a cyberattack. ATMs are malfunctioning. The goods ordering system has also been affected, and management is deploying cyber specialists. “Dear customers, unfortunately we have to inform you that we are the victim of a cyberattack,” Spar announced on its website on Saturday. “It may also happen that some products are temporarily unavailable in our stores.”
"Initial analyses have shown that the systems are extensively affected and the EC devices in the branches are not working." Payments in the stores are currently only possible via Twint or cash.
Victim: Swiss SPAR Handels AG
The Swiss Spar Group operates 143 Spar neighborhood stores, 97 Express Convenience Stores, 10 mini-markets, and 11 TopCC hypermarkets.
Reference: Spar employees can only order goods manually
Reference: Cyberattack hits Spar Switzerland
Reference: Spar warns customers that products may run out
Incident: Cyberattack Takes São Paulo Intl Airport Website Offline for Several Hours
A cyber incident occurred at GRU Airport, leaving its official website unstable and offline for several hours. The airport's operations were not impacted, and all security protocols were adopted to restore the site. A hacker, identifying as "Azael", claimed responsibility for the attack, which was announced prior to its execution.
Reference: Guarulhos Airport website goes offline after hacker attack
Reference: GRU Airport suffered a hacker attack this afternoon
Victim: São Paulo/Guarulhos International Airport
The Guarulhos International Airport, officially known as the São Paulo/Guarulhos – Governor André Franco Montoro International Airport, is one of the busiest airports in Brazil and serves as a major hub for both domestic and international travel. The airport is managed by GRU Airport, a concessionaire company.
Reference: Orange Group hack confirmed following leak by HellCat ransomware member
Reference: Schneider Electric Clawed by ‘Hellcat’ Ransomware Gang
Incident: French Orange Group Confirms Cyberattack
A hacker claims to have stolen thousands of internal documents with user records and employee data after breaching the systems of Orange Group, a leading French telecommunications operator and digital service provider. The threat actor published on a hacker forum details about the stolen data after trying to extort the company unsuccessfully.
Orange confirmed the breach to BleepingComputer saying that it occurred on a non-critical application. The company initiated an investigation and is working to minimize the impact of the incident.
Reference: Orange Group confirms breach after hacker leaks company documents
Incident: Data Breached at Telefónica, a Spanish Telecommunications Company
Spanish telecommunications company Telefónica confirms an internal ticketing system was breached after a Telefónica Jira database was leaked on a hacking forum. .In an email to BleepingComputer today, Telefónica confirmed its ticketing system was breached and are investigating the incident.
Three people behind this attack, Grep, Pryx, and Rey, are also members of a recently launched ransomware operation known as Hellcat Ransomware.
Victim: Telefónica
Telefónica is a Spanish multinational telecommunications company operating in twelve countries with over 104,000 employees. The company is the largest telecommunications firm in Spain, operating under the name Movistar.
Reference: Telefónica confirms internal ticketing system breach after data leak
Incident: Swiss Global Solutions Provider Ascom Confirms Cyberattack
Swiss global solutions provider Ascom has confirmed a cyberattack on its IT infrastructure. HellCat hacking group claimed the attack and told BleepingComputer that they stole about 44GB of data that may impact all of the company’s divisions. Ascom says that the hackers compromised its technical ticketing system, the incident had no impact on the company’s business operation
Ascom is a telecommunications company with subsidiaries in 18 countries focusing on wireless on-site communications.
Threat Actor: Hellcat ransomware gang
Hellcat ransomware gang emerged in mid-2024 and employs a ransomware-as-a-service (RaaS) model, offering ransomware tools and infrastructure to affiliates in exchange for a share of the profits. The group has so far focused on high-value targets, such as government and critical sectors like energy and education.
Hellcat’s double extortion tactics indicate a deeper psychological element aimed at humiliation and public pressure.
Victim: Ascom
Ascom is a telecommunications company with subsidiaries in 18 countries focusing on wireless on-site communications.
Reference: HellCat hackers go on a worldwide Jira hacking spree
Reference: Ascom affected by cyber attack
Incident: Glass and Tile Designer and Manufacturer Discloses Cyberattack
Custom glass and tile designer and manufacturer, Oceanside Glasstile Company suffered a cyberattack. Threat actors gained access to certain servers within the IT network on or around August 15 2024 and subsequently obtained a copy of certain files containing personally identifiable information, said the company.
The company said it has no evidence of actual misuse of any information stolen in the incident. No further information was immediately available as to the type of attack the company suffered and who was behind it.
Victim: Oceanside Glasstile Company
Oceanside Glasstile Company is a custom glass and tile designer and manufacturer.
Reference: Oceanside Glasstile Suffers Cyberattack
Incident: Cyberattack at Metal Finishing Company
Purecoat International, LLC and its sister company Purecoat North suffered a cyberattack where attackers stole personal identifiable information in a data breach.
On January 13, 2025, Purecoat identified a cyber incident impacting certain of its systems. Through its investigation, Purecoat confirmed sensitive personal information in certain files in its network may have ended up viewed and obtained by an unauthorized third party between November 19, 2024, and January 12, 2025.
Victim: Purecoat International
West Palm Beach, Florida- base Purecoat International applies specialized metal finishes to components for the aerospace, electronics, transportation and microwave industries.
Its sister company, Purecoat North, is a metal finishing company that offers gold, silver, tri-alloy and copper coatings to maximize conductivity and substrate protection; and a variety of finishes which conforms to high-end military and commercial specifications.
Reference: Metal Finishing Company Suffers Breach
Incident: US Mineral Mining Firm Discloses Cyberattack
Mineral exploration services company, Boart Longyear Group, Ltd., suffered a cyberattack last summer.
The attack occurred between June 29, 2024 and August 31, 2024. The company discovered it August 31 when identified suspicious activity within the network. Upon discovering the activity, the company took steps to secure the network.
After an investigation, notified victims about the hack on March 6, 2025. The company said "An unauthorized actor gained access to certain files within the network containing some personal information".
Victim: Boart Longyear
Boart Longyear is an international mineral exploration company founded in 1890. Along with its Salt Lake City, headquarters, it has regional offices and operations in the Asia-Pacific region, North and South America, Europe, and Africa.
The company provides mineral exploration services and drilling products for the mining industry and also has a presence in drilling water exploration, environmental sampling, energy, and oil sands exploration.
Reference: Cyberattack At Mineral Mining Firm
Incident: Bavaria Sausage Suffers Cyberattack
Bavaria Sausage, Inc., a maker of sausage and meat products, suffered a cyberattack at its Fitchburg, Wisconsin-based facility. Bavaria Sausage determined this incident may have involved payment card information for customers who made a purchase through the online store between April 6, 2024, and January 17, 2025. Bavaria Sausage identified all potentially affected customers.
No further information was immediately available as to the type of attack the company suffered and who was behind it.
Victim: Bavaria Sausage, Inc
Bavaria Sausage, Inc., is a maker of sausage and meat products based in Wisconsin, USA
Reference: WI Sausage Maker Hit In Cyberattack
Reference: National Presto reports significant cybersecurity incident
Reference: National Presto Industries Cyberattack Affects Manufacturing
Incident: Construction Framing Maker Suffers Cyberattack
Erickson Companies, LLC suffered a “sophisticated” cyberattack after it detected unusual activity on its internal network in November 2024. “On February 19, 2025, Erickson determined that customer and employee records may have potentially been accessed by unauthorized individuals.” The company said the information stolen included names, addresses, Social Security numbers, and driver’s license numbers.
Victim: Erickson Companies
Erickson Companies is a provider of construction services and manufactures pre-fabricated building components to single and multi-family residential builders in Arizona, California and Nevada.
It provides turn-key framing, truss and mill work services in all of its markets. The company employs over 1,000 workers.
Reference: Construction Framing Maker Suffers ‘Sophisticated’ Attack
Incident: Aircraft Engine Maker States it Suffered Data Breach in Feb. 2024
Aircraft engine maker, Continental Aerospace Technologies, Inc., suffered a cyberattack in February 2024 and it is just now {March 2025) letting victims of the attack know about what happened.
Mobile, Alabama-based Continental experienced a network disruption that affected its ability to access certain systems. In response, the company quickly initiated an investigation, and engaged third-party specialists to assist with understanding the nature and scope of the disruption. Continental Aerospace did not reveal the type of attack the company suffered and who was behind it.
Victim: Continental Aerospace Technologies
Continental Aerospace Technologies is an aircraft engine manufacturer located at the Brookley Aeroplex in Mobile, AL.
It originated at automobile engine manufacturer Continental Motors Company in 1929 and was owned by Teledyne Technologies from 1969 until December 2010.
The company is now part of Aviation Industry Corporation of China (AVIC), which is a Government of the People’s Republic of China state-owned aerospace company headquartered in Beijing.
Reference: Cyberattack At Aircraft Engine Maker
Incident: Data Breach at Colorado-based Trinity Petroleum Management
Denver, Colorado-based Trinity Petroleum Management, LLC suffered a cyberattack after discovering an unauthorized party was able to access information that had been provided to the company.
Trinity Petroleum said the incident resulted in an unauthorized party being able to access consumers’ personally identifiable information, which includes first and last names, addresses, and Social Security numbers. The incident affected 46,659 victims, the company said in an advisory.
Victim: Trinity Petroleum Management
Trinity Petroleum Management is an energy services company specializing in oil and gas accounting, land management, and regulatory compliance solutions.
The company provides comprehensive back-office support for independent oil and gas operators, helping them manage financial reporting, production accounting, and lease administration. With a focus on streamlining operations and ensuring regulatory compliance. The organization employs 50 people and generates an estimated $10 million in annual revenue.
Reference: Oil Services Provider Hit In Cyberattack
Incident: Data Breach at Colorado based IKAV Energy
Pueblo, Colorado-based IKAV Energy Inc. said it suffered a network disruption late last year that resulted in the theft of personally identifiable information.
Victim: IKAV Energy Inc.
IKAV Energy originates, constructs, finances, operates and manages a broad range of renewable energy assets including PV, CSP, wind, geothermal and energy efficiency projects, as well as conventional energy assets such as oil and gas upstream, midstream and power plants.
IKAV’s U.S. headquarters in Durango and it belongs to the global energy infrastructure group, IKAV. IKAV has worldwide offices in Hamburg, Luxembourg, Milan, Madrid, Lisbon, Munich, and Paris and launched its U.S. franchise in 2019 managing and operating a billion-dollar portfolio on a long-term basis.
Reference: Energy Provider Hit In Cyberattack
Incident: Cryptolocker Attack Impacts Logistics at Italian Precision Measurement Manufacturer
Marposs, a company specializing in precision measurement equipment, was hit by a Cryptolocker cyberattack. The impact of the cyberattack has been significant, particularly in the logistics sector. The production processes were less severely affected.
Marposs has implemented a solution to limit the consequences of the attack. The activation of emergency situation tool, "Cassa Integrazione Ordinaria" (Redundancy Fund) has been requested until February 7. This is a redundancy fund which helps companies to maintain the labour force in times of economic difficulties. It is unknown at this time how long it will take to decrypt the data stored in the company systems and restart the company's activities.
Victim: Marposs
Marposs is a precision measurement equipment manufacturer. Marposs specializes in cutting-edge solutions for quality control in the shop floor environment, and is a primary supplier to major automotive manufacturers, as well as the aerospace, biomedical, consumer electronics, semiconductor and glass industries.
Reference: Marposs under Cryptolocker attack, layoffs triggered
Reference: Marposs, hit by a cyber attack, has put its employees on redundancy
Incident: Databreach Reported at French Delivery Company Chronopost and Pension fund, Caisse des dépôts.
A cyberattack on Chronopost, a delivery company, exposed personal data of 210,000 customers Another attack on the Caisse des dépôts compromised data of 70,000 individuals, mostly public sector contract workers and local elected officials.
Victim: Caisse des Dépôts (CDC)
Caisse des Dépôts (CDC) is a pension fund for public sector employees in France.
Victim: Chronopost
Chronopost is a French delivery company and subsidiary of the La Poste group.
Reference: Data of hundreds of thousands of Chronopost and Caisse des Dépôts users hacked
Incident: German Medical Technology co. Eckert & Segler Targeted by Cyberattack
Eckert & Ziegler SE suffered a cyberattack on parts of its IT systems, which were temporarily shut down to minimize impact. External cyber security experts are working to restore normal operations and analyze the incident. The company's production is largely unaffected and no significant adverse effects on the business expected.
Reference: Eckert & Ziegler Affected by Cyber Attack
Victim: Eckert & Ziegler Group
Eckert & Ziegler Group is one of the world's largest providers of isotope technology for medical, scientific and industrial use.
Incident: UK Book Printer CPI Hit by Ransomware Attack
The UK’s leading book printer, CPI was hit by a ransomware attack. Clients of CPI, including Welsh independent Firefly Press, have been majorly affected.
Production at 8 factories shut down for over 12 days. Customers reported delays in printing their books as long as 18 days after the initial attack.
Victim: The Agency
The Agency is a London-based literary agency
Victim: CPI Print
CPI is UK's leading book printer
Reference: CPI tackles cyber attack
Reference: CPI and The Agency suffer cyber attacks as publisher profits ‘hit significantly’
Incident: Cyberattack Hits Port of Ostende
The Port of Ostend was targeted by a cyberattack. The attack affected its community system, Ensor, which contains ship arrival and departure data. No critical data was compromised, and other systems remain unaffected, with port operations continuing uninterrupted. A team, supported by external experts, is working to restore the system as quickly as possible.
The Port of Ostend is an essential part of the regional economy, and any disruption to its operations could have significant consequences
Reference: Port of Ostend files police complaint after cyberattack
Reference: Port of Ostend targeted by cyber attack
Reference: Port of Ostend targeted by cyberattack
Victim: Port of Ostend
Port of Ostend, Belgium
Incident: Systems Hacked at Russia’s Largest System Integrator LANIT
A significant cyber incident occurred at LANIT, a major Russian IT service and software provider, potentially impacting LLC LANTER and LLC LAN ATMservice. Russia's National Coordination Center for Computer Incidents (NKTsKI) is warning organizations in the country's credit and financial sector. The breach may have compromised the security of banking technology and services, including software for ATMs and payment systems, prompting warnings from Russian authorities to rotate passwords and access keys.
Russia has issued an urgent warning to its financial sector following the cyberattack.
Reference: LANIT Hack: A Cybersecurity Wake-Up Call for the Financial Sector
Reference: Major Russian IT service provider hit with cyberattack
Victim: LANIT Group
LANIT Group is a significant and influential company in Russia's information technology sector, considered the country's largest system integrator.
Reference: Russia warns financial sector of major IT service provider hack
Incident: Wisconsin based Heavey Equipment Maker, Power Test Industries, Reports Cyberattack
Sussex, Wisconsin-based Power Test Industries, LLC, experienced a network outage that was the result of a cybersecurity attack. “On April 29, 2024, Power Test experienced a network outage,” the company said in a letter to victims of the attack. “We immediately initiated an investigation and determined that Power Test was under a cybersecurity attack. In response, Power Test engaged Kroll, a leading cybersecurity firm, to help contain the attack, investigate the incident, and restore our systems in a safe manner.”
Victim: Power Test Industries, LLC
Power Test Industries, LLC designs, manufactures, and sells dynamometers, heavy equipment testing systems, and related data acquisition and control systems.
For over 40 years, Power Test has provided specialized test equipment to manufacturers, and rebuilding facilities and distributors in the mining, oil & gas, power generation, marine, trucking, construction, rail, and military markets in more than 90 countries on six continents.
Reference: Heavy Equipment Maker Suffers Cyberattack
Incident: Production Disrupted at Swiss Metal and Plastic Component Manufacturer
Adval Tech, an industrial conglomerate, has fallen victim to a cyberattack. The attack forced the company to shut down its IT systems worldwide as a precautionary measure. Production disruptions are expected at various locations. Adval Tech is working diligently with internal and external cybersecurity experts and relevant authorities to restore operations and resume business activities as soon as possible.
Reference: Hackers paralyze Swiss industrial group Adval Tech
Reference: Adval Tech affected by cyber attack
Victim: Adval Tech Holding
Adval Tech develops tools and stamping presses and manufactures metal and plastic components, mainly for the automotive industry. Adval Tech Holding is based in the canton of Bern, Switzerland. The group employs around 1,200 people and operates a total of nine production plants in Switzerland, Germany, Hungary, China, Malaysia, Mexico and Brazil.
Incident: Large Scale DDoS Attack at Large Russian Telecoms MegaFon
A significant cyberattack hit MegaFon, one of Russia's largest mobile and internet operators. The failure in Megafon's operation occurred on the morning of January 24. The cause was a carpet DDoS attack on the mobile operator. Forbes reports the attack was carried out by one of the groups of "politically motivated hackers" (the IT army of Ukraine). The attack “was effective, and degradation of services was observed at the international level.”
Later the Russian media revealed the true cause of the disruptions – a highly effective “carpet-bombing DDoS attack” targeting MegaFon. While the company claimed its network was operating “smoothly,” it admitted to “possible access issues” caused by factors beyond its control.
Victim: MegaFon
MegaFon is one of Russia’s largest mobile and internet operators
Reference: Ukrainian Hackers Hit Russia’s Megafon Mobile Operator
Reference: Ukrainian intelligence launches cyberattack on Russian telecom giant
Reference: The cause of the failure on Megafon networks was an attack by “politically motivated hackers”
Incident: DDoS Attack at Russian Telecom Beeline
Beeline experienced a failure due to a DDoS attack. About 6,000 users complained about the problems on Downdetector. "Specialists are taking all necessary measures to minimize possible consequences and maintain stable operation of services," the operator's press service said.
Reference: Beeline’s service was disrupted by a DDoS attack
Incident: Rostelecom Investigates Data Leak
Rostelecom, a major Russian telecommunications provider, says it’s investigating a cyberattack on one of its contractors. A hacker group calling itself Silent Crow, earlier released a batch of allegedly stolen company data. The company admitted it had previously detected “information security incidents” at one of its contractors. According to Rostelecom, the unnamed contractor is responsible for maintaining its corporate website and procurement portal. Both were reportedly targeted by hackers.
Reference: Russian telecom giant Rostelecom investigates suspected cyberattack on contractor
Reference: Rostelecom, Russia telecom giant, investigates leak of company data
Incident: DDoS Attack on Russian Telecom Beeline Causes Outages
Some Russians had their internet disrupted on Monday due to a targeted distributed denial-of-service (DDoS) attack on the telecom Beeline — the second major attack on the Moscow-based company in recent weeks. Beeline confirmed the attack to local media following reports from several outage-tracking services and user complaints. The provider has more than 44 million subscribers.
Data from the internet monitoring service Downdetector indicates that most Beeline users in Russia faced difficulties accessing the company’s mobile app, while some also reported website outages, notification failures and internet disruptions.
Russia’s communications watchdog, Roskomnadzor, reported that subscribers in Moscow and surrounding regions had filed mass complaints over connectivity issues following Monday’s incident.
Reference: Beeline reported that the consequences of the DDoS attack had been eliminated, services are operating normally
Reference: Russian telecom Beeline facing outages after cyberattack
Incident: Polish Space Agency (POLSA) Takes Network Offline after Cyberattack
Polish cybersecurity services have detected unauthorized access to the Polish Space Agency's (POLSA) IT infrastructure. The Minister for Digitalisation Krzysztof Gawkowski made the statement on Sunday. The agency confirmed to news agency PAP that a cybersecurity incident had occurred. The situation is being analyzed. In order to secure data, the POLSA network was immediately disconnected from the Internet.
Victim: Polish Space Agency (POLSA)
Polish Space Agency (POLSA), founded in 2014, is part of the European Space Agency (ESA). POLSA oversees the country's contribution to space exploration and development of technology such as satellites. It facilitates the collaboration between academia and industry members, and helps Polish aerospace companies access funding from the ESA.
Reference: Cyberattack detected at Polish space agency, minister says
Reference: Polish space agency confirms cyberattack
Reference: Cyberattack detected at Polish space agency, minister says
Reference: Canadian government discloses data breach after contractor hacks
Incident: Widespread Fallout after Lockbit Double Extortion Attack at Global Moving Services Provider, Sirva
Moving services provider Sirva Relocation LLC is accused of insufficient security practices after a 2023 cyber attack exposed the financial, medical, and personal information of at least 480,000 individuals. A complaint was filed in the US District Court for the Central District of California.
Lockbit targeted Sirva between September and October 2023. The gang exfiltrated 1.5 terabytes worth of files. Sirva failed to implement and maintain reasonable security practices—such as encrypting consumer personal data. This violated the California Consumer Privacy Act.
The incident was a “double extortion event” with hackers both exfiltrating the data and orchestrating a ransomware attack on Sirva’s information systems to encrypt them and take them offline. A class action against Sirva was also filed in Canada in February over the same breach. The Canadian government has contracted with SIRVA Canada since at least 2009, government records show.
Reference: LockBit may have stolen 24 years of data on Canadian government employees
Reference: Sirva Data Breach: What & How It Happened?
Incident: Trident Maritime Systems (TMS) Discloses Cyberattack Two Years After
in a letter dated February 17, 2025 Arlington, Virginia-based Trident Maritime Systems (TMS), LLC is notifying victims of a cyberattack that occurred two years ago. “In February 2023, we discovered suspicious activity on our computer network,” TMS officials said in a letter to victims. "The investigation determined an unauthorized actor gained access to our computer network between February 1, 2023 and February 10, 2023, and may have accessed or taken certain data from TMS’ systems." The company added its investigation and review wrapped up in January 2025. TMS said while attackers stole data, it is not aware of any identity theft or fraud as a result of this incident.
Victim: Trident Maritime Systems (TMS)
Trident Maritime Systems employs over 2,000 maritime professionals – engineers, project managers, designers, technicians, craftsmen, and integrators in 19 countries. The company’s focus is on engineering solutions in marine interiors, distributed ship systems, electromechanical solutions, and automation and control. The company serves shipbuilders and owners in the cruise, military, offshore oil + gas, and commercial ship markets.
Reference: Two Years to Notify Victims of Cyberattack
Incident: Countertop Manufacturer Discloses Cyberattack in 2024.
Countertop manufacturer, Hartson-Kennedy Inc., suffered a cyberattack affecting employees and their children. The company announced in a letter that on October 9, "we were alerted to a dark web posting by an attacker claiming to have accessed and removed data from IT systems.” Parts of the manufacturer's network was accessed. Files related to workers, as well as the workers’ children, fell into the hands of the attackers. To date, there is no evidence any personal information ended up misused by the attackers for identity theft or fraud.
The attackers accessed their systems through a malicious advertisement starting on June 24.
Victim: Hartson-Kennedy Inc.
Hartson-Kennedy Inc., founded in 1948, is a leading countertop manufacturers.
Reference: Workers’, Children’s PII Stolen in Attack
Incident: Databreach at UK Hearing Protection Manufacturer
Philadelphia, Pennsylvania-based operation of Racal Acoustics Ltd. suffered a cyberattack against its employees that started in May 2024. “On January 9, 2025 we learned which employees had their information accessed. The company immediately provided notice of the incident and afforded these employees identity protection.
Victim: Racal Acoustics
Racal Acoustics, part of the INVISIO Group, develops and manufactures advanced and robust hearing protection and communication headsets for use in environments with constant high noise.
Customers are mainly in defense, but also rescue services and the aviation sector. Racal Acoustics’ headquarters is in London and the operations employ 55 people.
Reference: Hearing Protection Provider Hit in Cyberattack
Incident: Cyberattack at Agricultural Machinery Maker Daedong-USA
Wendell, North Carolina-based Daedong-USA, Inc., a maker of agricultural machinery, suffered a cybersecurity incident. The incident involved unauthorized access to certain systems and occurred on or around January 23, 2024. In October 2024 the company's investigation discovered an unauthorized party obtained certain personal information of 10,643 victims.
Victim: Daedong Corporation (aka Kioti)
Daedong Corporation, also known by the brand name Kioti in North America, is a South Korean agricultural machinery manufacturer founded in 1947 and headquartered in Daegu, South Korea. Its main products include tractors, combine harvesters, all-terrain utility vehicles and engines.
Reference: Agricultural Machinery Maker Suffers Cyberattack
Incident: Manufacturer Nuna Baby Essentials’ Checkout Page Compromised for Almost 3 Months
Morgantown, Pennsylvania-based Nuna Baby Essentials, Inc identified suspicious activity on its website’s payment platform. Through its investigation, the company found information entered on the checkout page between September 8 and December 6 may have ended up copied or accessed by an unauthorized party. Nuna said in a notice to the 16,676 victims it promptly took steps to secure the website and began an investigation to better understand the nature and scope of this activity.
Victim: Nuna Baby Essentials, Inc.
Morgantown, Pennsylvania-based Nuna Baby Essentials, Inc. is a high-quality maker of baby product accessories from car seats to strollers.
Reference: Baby Product Maker Suffers Cyberattack
Incident: Data Breached at NY Chemical Manufacturer Anellotech
New York-based Anellotech Inc. fell victim to a ransomware attack in late December. On January 13, Anellotech – a maker of sustainable chemicals – said it became aware of a ransomware attack. The company took affected systems offline, engaged external cybersecurity experts, communicated with law enforcement, began remediation and launched an investigation. Anellotech said in a letter to their workers: “While the forensic investigation is continuing, we believe that your personal information may have been affected,”
Victim: Anellotech
Anellotech is a sustainable technology company. The company invented and is developing technologies to produce cost effective, renewable chemicals and fuels from recycled mixed plastic and non-food biomass. Additionally, Anellotech’s long-term strategic partners include R Plus Japan, Suntory, Toyota Tsusho, IFPEN, Axens and Johnson Matthey.
Reference: Ransomware Attack at Sustainable Chemical Maker
Incident: Cyber Incident at Pneumatic Technology Manufacturer in Indiana, US.
Manufacturer of pneumatic technology for industrial automation, SMC Corporation of America, fell victim to an attempted ransomware attack. The company quickly discovered the incident on December 8 and retained third-party cybersecurity experts who implemented security measures to contain the Incident.
Indiana-based SMC said the stolen information potentially exposed included employment data, which could include sensitive personal information, such as: first and last name, date of birth, address, bank account information, driver’s licenses, certain payroll information, SMC employee account number and position, Social Security Number, SMC employee benefit information, data related to certain medical information in connection with SMC benefits, and other identifying information.
Victim: SMC Corporation of America
SMC Corporation of America is a manufacturer of pneumatic technology for industrial automation.
Reference: Pneumatic Technology Maker Hit in Ransomware Attempt
Incident: Databreach at Mid-State Industrial Manufacturer
Lakeland, Florida-based Mid-State Industrial Maintenance fell victim to a cyberattack. “Our investigation determined that between January 23, 2025, and January 24, 2025, certain files and folders were copied from our network without authorization,” the company said in a letter to its victims.
Victim: Mid-State Industrial Maintenance
Mid-State started up in 1973. The company provides in-house machining and fabrication services with large scale capabilities. Mid-State employes 500 engineers and shop personnel that work in manufacturing, repairing, designing, disassembling and transporting equipment and machinery ranging from gearboxes and trommels, to structural piping, tanks and more.
Reference: FL Machining Provider Hit in Cyberattack
Incident: Cybersecurity Incident at McMillan Electric
Woodville, Wisconsin-based McMillan Electric Company suffered a cyberattack. The threat actor gained access to the firm’s network an stole personal information. The attack affects 6,162 victims. The company discovered on January 13 the unauthorized attacker acquired some personal information, and conducted an extensive forensic investigation.
Reference: Cyberattack at Electric Motor Maker
Incident: Ransomware Attack at Circuit Board Maker Unimicron
Unimicron Technology ransomware attack impacted its China-based subsidiary. Unimicron did not confirm a data breach, stating the impact of the attack is limited. The manufacturer engaged an external cyber forensic team to conduct incident analysis. Sarcoma ransomware group has claimed the attack and listed the attack on its Tor-based leak website on February 11.
The cybercriminals are threatening to make the stolen data public in less than a week unless a ransom is paid. The samples leaked on its extortion portal appear authentic.
Reference: Ransomware Attack at Circuit Board Maker
Victim: Unimicron
Unimicron is a public company manufacturing rigid and flexible PCBs, high-density interconnection (HDI) boards, and integrated circuit (IC) carriers.
The company is one of the largest PCB manufacturers in the world, with plants and service centers in Taiwan, China, Germany, and Japan. Its products are extensively used in LDC monitors, computers, peripherals, and smartphones.
Reference: Sarcoma ransomware claims breach at giant PCB maker Unimicron
Incident: Pennsylvania Lighthouse Electric Company Suffered Cyberattack
Canonsburg, Pennsylvania-based Lighthouse Electric Company suffered a cyberattack. “Our investigation determined that certain files on LEC’s network may have been copied without authorization between October 21, 2024, and October 26, 2024”. The company said it is continuing its review to enhance its existing safeguards, policies, and procedures.
Victim: Lighthouse Electric Company (LEC)
LEC is an electrical contractor that focuses on electrical and technology design construction. The company is one of the largest electrical contractors on the East Coast.
Reference: Electrical Contractor Suffers Cyberattack
Incident: Databreach at NH Textile Manufacturer
Textiles Coated, Inc. (TCI) suffered a cyberattack in November. TCI determined that from November 1 to November 4 certain systems in its environment ended up accessed by an unknown actor. Certain files may have been copied without authorization.
Victim: Textiles Coated, Inc. (TCI)
TCI, which started up in 1985, is a manufacturer of high-performance fluoropolymer films, laminates, and composites. TCI’s products work in the most demanding environments and focus on working under harsh chemical and thermal conditions.
TCI’s facilities have over 180,000 square feet of manufacturing space. The company has customized coating, lamination, fabrication, film, mixing, maintenance, research and development, and laboratory departments. The company has over 300 employees.
Reference: NH Textile Maker Hit in Cyberattack
Incident: Utility Provider O’Connor Corporation Announces 2024 Cyberattack.
On December 2, the Power Generation Maintenance and Construction and Water and Wastewater provider, O’Connor observed a network disruption that affected the operability of certain systems. The Canton, Massachusetts-based company launched an investigation which was completed on January 2. They informed victims of the incident on February 2025: “The types of information relating to you that our review located in the accessible data included: Name, Social Security number, and financial account information,” the company said in the advisory.
Victim: O’Connor Corporation
O’Connor Corporation is a power Generation Maintenance and Construction and Water and Wastewater provider.
Reference: Utilities Sector To Be a Focus of Executive Order Directing Development of Critical Infrastructure Cybersecurity Framework
Reference: Cyberattack at Power Gen, Water Services Provider
Incident: Data Breached at Aerospace Wire Manufacturer GIGAFLIGHT
Greendale, Wisconsin-based GIGAFLIGHT Connectivity, Inc. (GCI) suffered a cyberattack over a period of time in 2024. “Upon identifying the activity, GCI took steps to secure the accounts and began our investigation,” the company said in an advisory. “The investigation determined that an unauthorized person may have accessed the email accounts between May 20, 2024, and November 22, 2024. On January 29, 2025 GCI commenced mailing notifications to victims.
Victim: GIGAFLIGHT Connectivity, Inc. (GCI)
GIGAFLIGHT makes high performance electronic cables, connectors, and cable assemblies for use in aerospace and defense products, as well as other demanding applications.
Reference: Aerospace Wire Manufacturer Hit in Cyberattack
Incident: Cyberattack Leads to Order Delays at Sportbrand Mizuno
Sports equipment and sportswear brand Mizuno suffered a ransomware attack over the weekend of February 4th, targeting the USA corporate network. This cyberattack led to significant business disruption, including phone outages, delays in shipping products, and website issues. nnThe ransomware attack came at a bad time for Mizuno. They just launched their Mizuno Pro 221, 223, and 225 golf irons on February 3rd, which were preordered and eagerly anticipated by many customers. Customers who preordered the irons faced delays with no way to contact the company for more information. Also, Mizuno resellers can no longer access Mizuno's 'Direct Connect' B2B website used by resellers to place orders.
Mizuno is not providing a public statement about what is causing their week-long outages. At this time, it is unknown what ransomware gang is behind the attack.
Reference: Sports Equipment Maker, Mizuno, Suffers Cyberattack
Victim: Mizuno
Mizuno is a Japanese sports equipment and sportswear company with over 3,800 employees and locations throughout Asia, Europe, and North America.
The company sells a wide variety of sports equipment but are best known for their golf clubs, running sneakers, and baseball gear.
Reference: Sports brand Mizuno hit with ransomware attack delaying orders
Incident: Mississippi Utility Company Confirms 2024 Security Breach Affected 20K Customers.
Mississippi Yazoo Valley Electric Power Association was attacked by cybercriminals last summer. The incident exposed the information of more than 20,000 residents.
The company initially warned customers through social media on August 26 that, due to software problems, they were unable to process payments. The system was restored by August 30. In breach notification letters filed with regulators on January 30 2025, the utility confirmed it discovered “suspicious activity” on August 26 and initiated an investigation.
The ransomware gang known as Akira later claimed responsibility, stating they had stolen Social Security numbers and company financial records.
Reference: MS Electric Utility Hit in Cyberattack
Victim: Yazoo Valley Electric Power Association
Mississippi-based Yazoo Valley Electric Power Association.
Reference: Mississippi electric utility warns 20,000 residents of data breach
Reference: Mississippi electricity provider breach hits over 20K
Reference: Max Trans Data Breach Investigation
Incident: TN based Trucking Company Max Trans LLC Hit by Cyberattack
Transportation and shipping provider, Max Trans, LLC, suffered a cyberattack in late November and is now letting victims know about what happened. “On December 10, 2024, we became aware that an unauthorized actor accessed specific systems in our network and copied certain files on November 29, 2024"
After the December discovery, the Humboldt, Tennessee-based company completed its investigation of the impacted data on January 2. Furthermore, the company determined files contained some of personal information of various victims.
Victim: Max Trans, LLC
Max Trans, LLC is a transportation and shipping provider based in Humboldt, Tennessee.
Reference: Transportation Firm Hit in Cyberattack
Incident: Official .uk Domain Registry Confirms Network Breach
Nominet, the official .UK domain registry and one of the largest country code registries, has confirmed that its network was breached two weeks ago using an Ivanti VPN zero-day vulnerability. Since it detected suspicious activity on its network, the company has reported the attack to relevant authorities, including the NCSC, and restricted access to its systems via VPN connections. "The entry point was through third-party VPN software supplied by Ivanti that enables our people to access systems remotely," Nominet says in a customer notice shared with BleepingComputer. ""e currently have no evidence of data breach or leakage.
Victim: Nominet
Nominet manages and operates over 11 million .uk, .co.uk, and .gov .uk domain names and other top-level domains, including .cymru and .wales.
It also ran the U.K.'s Protective Domain Name Service (PDNS) on behalf of the country's National Cyber Security Centre (NCSC) until September 2024, protecting over 1,200 organizations and over 7 million end users.
Reference: UK domain registry Nominet confirms breach via Ivanti zero-day
Incident: Hewlett Packard Enterprise (HPE) is Investigating Claims of Cyberattack
Hewlett Packard Enterprise (HPE) is investigating claims of a new breach after a threat actor said they stole documents from the company's developer environments. "HPE became aware on January 16 of claims being made by a group called IntelBroker that it was in possession of information belonging to HPE," spokesperson Clare Loxley told BleepingComputer.
IntelBroker put up another archive of data (including credentials and access tokens) allegedly stolen from HPE's systems almost one year ago, on February 1, 2024. The company also said at the time that it was investigating the threat actor's claims but had no evidence of a security breach.
Victim: Hewlett Packard Enterprise Company (HPE)
Hewlett Packard Enterprise Company (HPE) is an American multinational information technology company based in Spring, Texas. It is a business-focused organization which works in servers, storage, networking, containerization software and consulting and support.
Reference: HPE investigates breach as hacker claims to steal source code
Reference: Conduent confirms cybersecurity incident behind recent outage
Reference: Engineering giant Smiths Group discloses security breach
Incident: Security Breach at British Engineering Firm IMI
British-based engineering firm IMI plc has disclosed a security breach after unknown attackers hacked into the company's systems. An IMI spokesperson declined to comment when asked by BleepingComputer provide more details about the attack, such as the date it was detected, whether it impacted its operations, and whether the threat actors stole company or customer information from compromised systems.
Victim: IMI
IMI is a global engineering group with manufacturing facilities in 18 countries, focused on precision fluid engineering and providing services in the process and industrial automation, climate control, life science, and transport sectors.
Listed on the London Stock Exchange since 1966, it is included in the FTSE100 Index (the United Kingdom's best-known stock market index) and employs around 10,000 people in over 50 countries across three divisions (IMI Hydronic, Norgren, and IMI Critical).IMI
Reference: British engineering firm IMI discloses breach, shares no details
Incident: Cyberattack at UK Engineering Firm Smiths Group
U.K. engineering firm Smiths Group — whose operations span 50 countries across a range of sectors — has detected “unauthorised access” in its systems, the company informed the London Stock Exchange on Tuesday. Smiths Group said it “rapidly isolated affected systems and activated business continuity plans” after it detected the activity.
Victim: Smiths Group
The Smiths Group was founded in 1851 and has more than 15,000 employees. The group reported fiscal 2024 revenues of about $3.89 billion.
Industries include mining, oil and gas, clean energy and semiconductor testing. Its Smiths Detection arm builds security screening technology used in airports and other ports of entry.
Reference: UK engineering giant Smiths Group investigating ‘unauthorised access’ to network
Reference: Engineering firm IMI hit with cyber attack just days after Smiths Group incident
Reference: Cyber Security Incident
Victim: Telecom Argentina
Telecom Argentina
Victim: Tver
The northwestern Russian city of Tver
Incident: Chinese AI platform DeepSeek Disabled Registrations after Cyberattack
Chinese AI platform DeepSeek has disabled registrations on its DeepSeek-V3 chat platform due to an ongoing "large-scale" cyberattack targeting its services.
Just as the DeepSeek AI Assistant app overtook ChatGPT as the top downloaded app on the Apple App Store, the company was forced to turn off new registrations after suffering a cyberattack. "Due to large-scale malicious attacks on DeepSeek's services, we are temporarily limiting registrations to ensure continued service," reads a message on the DeepSeek status page. "Existing users can log in as usual. Thanks for your understanding and support."
While no details about the attack were shared, it is believed that the company is facing a distributed denial-of-service (DDoS) attack against its API and Web Chat platform. While the attack is impacting their registration process, you can now log in with your Google account to gain access.
BleepingComputer reached out to DeepSeek to learn more about the attack but did not receive a response.
Victim: DeepSeek
DeepSeek is a relatively new AI platform that has quickly gained attention over the past week for its development and release of an advanced AI model that allegedly matches or outperforms the capabilities of US tech giant's models at significantly lower costs.
The news of the new model in January 2025 led to a massive sell-off in the US stock market as the AI arms race heats up.
Reference: DeepSeek halts new signups amid “large-scale” cyberattack
Reference: DeepSeek hit by cyberattack as users flock to Chinese AI startup
Reference: Cyberattacks against DeepSeek escalate with botnets joining, command surging over 100 times: lab
Reference: Cyberattack on DeepSeek, including brute-force assault, started in US: Chinese state media
Incident: Town of Bourne’s IT Systems Compromised in Cyberattack
The Town of Bourne's information technology systems were compromised in a cyberattack, leading to the cancellation of scheduled town meetings. The police department and 911 services were not impacted, but the town's IT network was breached, potentially exposing sensitive information. The town's library and schools may have been affected, with the library's public computers and Wi-Fi unavailable due to the incident.
Victim: Town of Bourne
Town of Bourne, MA, USA
Reference: Bourne Cyberattack: Here’s What We Know
Incident: New Brunswick Liquor Corp. Stores Accept Cash Only after Cyberattack
The New Brunswick Liquor Corporation experienced a cyber security incident causing disruptions to operations, forcing customers to use cash for transactions. A third-party security expert was hired to investigate. The company pulled the plug on the network to contain the incident, raising concerns about data accessibility and potential phishing attacks.
Victim: New Brunswick Liquor
New Brunswick Liquor and Cannabis N.B. locations
Reference: New Brunswick Liquor, Cannabis N.B. stores accepting cash-only due to security concerns
Reference: N.B. Liquor cyber security woes continue
Incident: Free Parking for Russian City Residents after Alleged Cyberattack
Residents of the northwestern Russian city of Tver were able to park for free for nearly two days due to what local authorities referred to as a “technical failure” in the digital parking payment system. Ukrainian Cyber Alliance claims the cyberattack on the city’s administrative network.
Reference: Suspected pro-Ukraine cyberattack knocks out parking enforcement in Russian city
Incident: Cyberattack Destroys Infrastructure of Russian Internet Provider Nodex
Russian internet provider Nodex's network was destroyed in a cyberattack claimed by the Ukrainian Cyber Alliance. The attack resulted in significant service disruptions and data theft. Nodex confirmed the attack and began working on restoring services. The Ukrainian Cyber Alliance shared screenshots of hacked systems and data they allegedly stole.
Threat Actor: Ukrainian Cyber Alliance
The Ukrainian Cyber Alliance (UCA, Ukrainian Language Український кіберальянс, УКА) is a community of Ukrainian cyber activists from Ukraine and around the world. The UCA was formed in spring of 2016 by a merger of two cyber activist groups, FalconsFlame and Trinity. It was joined later by group RUH8 and individual activists from the CyberHunta group. These hacktivists have united to counter Russian aggression in Ukraine.
Victim: Nodex
Russian internet provider Nodex
Reference: Russian internet provider confirms its network was ‘destroyed’ following attack claimed by Ukrainian hackers
Incident: Government Cadastral Departments in Slovakia District Temporarily Closed Offices
A cyber incident affected the Úrad geodézie, kartografie a katastra SR, a Slovakian government agency, causing a technical failure of all systems and services, and limiting access to electronic services and information systems. The agency's team is working to restore full functionality and ensure the security of systems. The incident's cause and extent are being analyzed, with updates provided through official channels.
The offices of the cadastral departments were temporarily closed. This affected the information system used by the cadastral departments of district offices.
Victim: Úrad geodézie, kartografie a katastra SR
Úrad geodézie, kartografie a katastra SR, a Slovakian government agency
Reference: Cadastral departments of district offices resume operations after cyberattack
Reference: Cadastral departments of district offices will not provide services until the consequences of the cyber attack are eliminated, the case is being handled by the police
Reference: Additional cadastral departments will start providing services from Monday, gradually recovering from the attack
Incident: Cyberattack at Japan’s Largest Mobile Carrier, NTT Docomo
Japan’s largest mobile carrier, NTT Docomo, reported a cyberattack temporarily disrupted operations. Its system were targeted by a distributed denial-of-service (DDoS) attack.
From early Thursday morning until late afternoon, local users were unable to access NTT Docomo’s news website, video streaming platform, mobile payment and webmail services. The company reported that access to most services had been restored late afternoon, although some content updates might still face delays.
Reference: Japan’s largest mobile carrier says cyberattack disrupted some services
Reference: Notice from Docomo
Incident: Australian Automotive Manufacturer Confirms Cyberattack
Australian automotive manufacturer Clutch Industries has confirmed it was targeted in a cyberattack, days after the Lynx ransomware group listed the company on its darknet platform.
“Following a recent cyber incident, Clutch Industries has become aware that a third party has named the company online alongside some data,” a spokesperson for Clutch Industries told Cyber Daily, adding that the company is investigating the extent of the breach, with initial findings suggesting the impacted data is primarily internal and operational.
Threat Actor: Lynx Ransomware Group
The Lynx Ransomware-as-a-Service (RaaS) group has been found operating a highly organized platform, complete with a structured affiliate program and robust encryption methods. The group actively recruits experienced penetration testing teams through underground forums.
The group provides its affiliates with an "All-in-One Archive" that contains binaries for Windows, Linux, and ESXi environments.Affiliates receive an 80% share of ransom proceeds, handle all negotiations and maintain control over the ransom wallet. Lynx also offers additional services, such as a call center to harass victims and advanced storage solutions for high-performing affiliates.
Victim: Clutch Industries
Australian automotive manufacturer Clutch Industries
Reference: Australian automotive manufacturer hit by cyberattack
Reference: Aussie manufacturer Clutch Industries confirms cyber incident
Incident: Over 46 Japanese Businesses, incl Banks and Government Agencies,Targeted by Cyberattacks
At least 46 Japanese entities, including banks and government agencies, were targeted by cyberattacks utilizing the same malware, causing temporary service suspensions. According to Trend Micro Inc., Japan Airlines Co., NTT Docomo Inc. and major banks were among the victims of distributed denial-of-service, or DDoS, attacks in which networks are overwhelmed by data from multiple sources over a short period, causing temporary service suspensions. The Japan Weather Association said on Thursday it was hit by a cyberattack that rendered its information website inaccessible for over nine hours from around 7 a.m. A similar cyberattack on Sunday that affected both the web and app versions of the weather site took over 7 hours to resolve.
"We can't rule out the possibility that multiple groups conducted attacks at the same time," a Trend Micro official said. The hackers were able to simultaneously control devices including cameras and home appliances connected to the internet to carry out the attacks, the security firm said.
Reference: 46 Japanese entities hit by cyberattacks since year-end
Incident: Widespread Issues Reported after Cyberattack on US Business Services Giant and Government Contractor Conduent
American business services giant and government contractor Conduent confirmed that a recent outage resulted from what it described as a "cybersecurity incident. One week ago, the govtech giant also said it "supports approximately 100 million U.S. residents across various government health programs."
The outage affected customers' operations across multiple U.S. states, impacting organizations such as the Wisconsin Department of Children and Families, Oklahoma Human Services, and others. This caused widespread issues for those relying on the affected organizations to make payments via electronic transfer or EBT cards.
"We experienced a service interruption that affected the Wisconsin Support Collections Trust Fund's ability to process payments," Conduent told BleepingComputer on Tuesday, two days after restoring systems and bringing services back online for Wisconsin's Department of Children and Families.
"The Conduent technology team worked to resolve the issue. We sincerely regret the inconvenience this incident may have caused."
Victim: Wisconsin Department of Children and Families,
Wisconsin Department of Children and Families
Victim: Conduent
Conduent has over 31,000 employees and provides services to half of Fortune 100 companies and over 600 government and transportation agencies. These include nine top U.S. health plans, four of five top global automakers, and multiple U.S. banks and pharma companies.
Reference: Conduent confirms cybersecurity incident behind recent outage
Incident: Prodinger Verpackung Hit by Cyberattack
On January 21, 2025, the PRODINGER Group, a German packaging solutions provider, issued a statement regarding a cyber-attack that had recently affected their corporate group. The company, headquartered in Coburg, Germany, announced that they had successfully and completely resolved the security threat resulting from this incident.
Victim: Prodinger Verpackung
Prodinger Verpackung , a German packaging solutions provider, includng industrial transport packaging.
Reference: Cyberattack on Prodinger Group
Incident: Cyberattack Affects > 18,000 Workstations at Telecom Argentina.
On July 18, top Argentinian telecom provider Telecom Argentina announced that it was the target of a ransomware attack. The effects of the attack were first noticed when the Telecom’s employees started facing issues and lag in their systems while accessing the company’s VPN (virtual private network). The internal security systems instantly set-off the alarms but not before the ransomware was installed in over 18,000 workstations.
The attackers demanded nearly $7.5 million, threatening to raise the ransom to $15 million if they weren’t compensated within three days. Telecom Argentina confirmed that none of its dependent services were affected.
Reference: Telecom Argentina ransomware attackers demand $7.5m
Reference: Hackers Demand $7.5 Million to Free-up Telecom Argentina’s Systems
Reference: Ransomware Attackers Demand Millions from Telecom Argentina
Incident: Cyberattack Targetted E.Leclerc’s Primes énergie Program
E.Leclerc was the victim of a cyberattack . By targeting their Energy Bonus program , hackers managed to access sensitive data. The attack focused on E.Leclerc's Primes énergie program . This program provides financial assistance to individuals for their energy-saving work. The information stolen includes names, first names, email addresses, file numbers, bonus amounts and descriptions of services. There is also a risk that access credentials have been compromised (such as passwords or their encrypted versions).
Victim: SIPLEC / E. Leclerc Energy
SIPLEC is the E. Leclerc Group's Department responsible for all Energy products. Siplec is also in charge of procurement of manufactured products (hardline, textile and shoes) made in France, Europe and abroad.
Victim: E. Leclerc
E. Leclerc is a French cooperative operating in the retail business. The company opened its first store in 1949 and today operates over 700 locations in the form of hypermarkets and supermarkets across France, with additional stores in Spain, Portugal, Poland and Slovenia.
Reference: France is the victim of an unprecedented wave of cyberattacks, 4.5 million data have been hacked!
Reference: E.Leclerc victim of a cyberattack: CNIL informs on the consequences
Incident: Troxler Electronic Laboratories, Inc. Suffered Two Separate Cyberattacks
Durham, North Carolina-based Troxler Electronic Laboratories, Inc. suffered two separate cyberattacks where hackers were able to steal personal information.
“On November 10, 2024, Troxler detected suspicious activity in its network environment,” the company said in an advisory. “Upon discovery of this incident, Troxler promptly took steps to secure its network and engaged a specialized cybersecurity firm to investigate the nature and scope of the incident. As a result of the investigation, Troxler learned that an unauthorized actor accessed certain files and data stored within our network.”
Victim: Troxler Electronic Laboratories
Troxler Electronic Laboratories is a manufacturer of testing/quality control measurement equipment for the construction industry and for nuclear moisture/density gauges, along with making gyratory compactors and asphalt ignition ovens.
Reference: NC Testing Equipment Maker Hit in 2 Cyberattacks
Incident: Security Provider LenelS2 Hit in Cyberattack
Physical security provider, Framingham, Massachusetts-based LenelS2, suffered a cyberattack in November and after an investigation is now letting victims know about the attack.
Victim: LenelS2
LenelS2 provides advanced physical security solutions, including access control, video surveillance and mobile credentialing, according to the company’s website. Its technology includes web-based and mobile applications enhanced by cloud-based services. Incorporating open architecture, LenelS2 provides scalable, unified security management solutions ranging from global enterprises to small- and mid-size businesses.
Reference: Physical Security Provider Hit in Cyberattack
Incident: Paper Manufacturer Avery Products Hit by Ransomware
Brea, California-based paper products provider, Avery Products Corporation, discovered a ransomware attack that persisted for almost five months affecting “certain systems.” “On December 9, 2024, Avery became aware of a ransomware attack relating to certain systems,” the company said in a letter to victims. “Avery immediately launched an investigation, with the aid of forensic experts, to determine the nature and scope of the activity.
“Our investigation determined that an unauthorized actor inserted malicious software used to “scrape” credit card information used on our website avery.com between July 18, 2024, and December 9, 2024,” the company said. Avery then proceeded with a lengthy investigation to identify the personal information contained in the affected system, and then reviewed its internal records to locate the appropriate mailing addresses of those that ended up victimized by the attack. There were 61,193 victims of the attack, the company said.
Victim: Avery Products Corporation
Avery Products Corporation is a Brea, California-based paper products provider.
The company started up in 1935 when it invented the first self-adhesive labels. It then ultimately ended up with 18 patents and establish Avery Adhesives, a company that went on to transform how brands and businesses deliver information. Avery merged with Dennison Manufacturing in 1990 to become Avery Dennison.
In 2013, CCL Industries Inc., a leader in specialty label and packaging solutions for corporations, small businesses and consumers, bought the Office and Consumer Products division from Avery Dennison and renamed it Avery Products Corporation, a publicly reportable operating segment. CCL boasts more than 20,000 employees and 168 state-of-the-art manufacturing facilities in 40 countries.
Reference: Paper Products Maker Hit by Ransomware
Incident: US Meat Producer Hit in Cyberattack
Hanford, California-based Central Valley Meat Co. Inc. suffered what appears to be a ransomware attack this past May and is now letting victims know some details of the attack.
“On May 23, 2024, Central Valley Meat identified unusual activity on our computer systems that impacted company operations. We took prompt steps to confirm the security of our systems and initiated a comprehensive investigation to determine the extent of impact to our network. We completed the review, and subsequent address lookup, on November 26, 2024. While we have no evidence of misuse of any data, we are notifying potentially impacted individuals out of an abundance of caution.”
Reference: CA Meat Producer Hit in Cyberattack
Victim: Central Valley Meat Co Inc.
Central Valley Meat Co Inc is a full line beef harvesting operation, processing over 1500 beef cattle aday. Variety of graded and non-graded boxed beef cuts, trimmings, and offal products available to processors, food service, and retail customers.
Incident: Great Star Tools USA Fell Victim to Cyberattack
Saddle Brook, New Jersey-based Great Star Tools USA, Inc. fell victim to a cyberattack for a two-week period in August 2023 and is now sending out a notice to victims of the hack.
“On August 17, 2023, Great Star observed some unexpected and suspicious activity that impacted our computer systems,” the company said in a notice to the California Attorney General’s office. “We secured our systems and, with the assistance of third-party cybersecurity specialists, investigated to confirm the nature and scope of the activity. The investigation determined that, between August 2, 2023 to August 17, 2023, an unauthorized actor accessed certain Great Star systems and may have viewed or copied data from within those systems.” No further information was available as to what kind of attack this was and who was behind it.
Reference: Tool Maker Suffers Cyberattack
Victim: GreatStar Tools USA
GreatStar Tools USA is a privately held company that manufactures hand tools for professional, DIY, and industrial use. The company is a subsidiary of Hangzhou GreatStar Industrial Co., Ltd., a Chinese manufacturer of hand and power tools.
Incident: US Vitamin and Supplement Maker Garden of Life, LLC Discloses Cyberattack
Natural specialty vitamin and supplement provider, Garden of Life, LLC, suffered a cyberattack in July, but did not discover it until December. “On December 18, 2024, Garden of Life determined that an unknown third party gained access to the software that its website uses to collect payment card information for online purchases,” the company said in a notice to victims of the attack. “The unauthorized access to Garden of Life’s website appears to have occurred in July 2024.
“The software at issue in this incident (ended up) provided by a vendor and is separate from other areas of the Garden of Life website. There is no indication that any other Garden of Life systems or areas of its website were compromised,” the company said. No further information was immediately available as to who was behind the hack and what kind of attack it was.
Victim: Garden of Life, LLC
Garden of Life, LLC is a natural specialty vitamin and supplement provider owned by Nestlé Health Science. Garden of Life is a supplement company that makes vitamins, probiotics, and protein powders. Nestlé acquired Garden of Life in December 2017 for $2.3 billion
Reference: Vitamin Maker Suffers Cyberattack
Reference: Volt Typhoon Compromises US Internet Companies
Reference: Singtel Data Breach: Volt Typhoon’s Test Run Before Targeting US Telecoms
Incident: Singtel Reportedly Hacked as Test Run for Further Hacks against US Communications companies.
Chinese government cyberspies Volt Typhoon reportedly breached Singapore Telecommunications over the summer of 2024 as part of their ongoing attacks against critical infrastructure operators. The digital break-in was discovered in June, according to Bloomberg, citing "two people familiar with the matter" who told the news outlet that the Singtel breach was "a test run by China for further hacks against US telecommunications companies." The hackers used a web shell and exploited a Versa SD-WAN vulnerability. (see separate incident dated June 12).
In February, the feds and other nations' governments warned that the Beijing-backed crew had compromised "multiple" critical infrastructure orgs' IT networks in America and globally, and were "disruptive or destructive cyberattacks" against those targets.
Reference: Volt Typhoon Compromises US Internet Companies
Reference: Singtel detected and ‘eradicated’ malware said to be from Chinese hacking group
Reference: Chinese group accused of hacking Singtel in telecom attacks
Reference: China state-linked group accused of hacking SingTel, Bloomberg News reports
Reference: China’s Volt Typhoon reportedly breached Singtel in ‘test-run’ for US telecom attacks
Victim: Moscollector
Moscollector is responsible for wastewater collection, and district (community hot water) heating to Moscovites.
Incident: USAF Sentinel UAV Drone Hijacked by Iran
Iran guided the CIA's "lost" stealth drone to an intact landing inside hostile territory by exploiting a navigational weakness long-known to the US military, according to an Iranian engineer now working on the captured drone's systems inside Iran.
Iranian electronic warfare specialists were able to cut off communications links of the American bat-wing RQ-170 Sentinel, says the engineer, who works for one of many Iranian military and civilian teams currently trying to unravel the drone’s stealth and intelligence secrets, and who could not be named for his safety. Using knowledge gleaned from previous downed American drones and a technique proudly claimed by Iranian commanders in September, the Iranian specialists then reconfigured the drone's GPS coordinates to make it land in Iran at what the drone thought was its actual home base in Afghanistan.
Victim: unmanned aerial vehicle (UAV)
unmanned aerial vehicle (UAV)
Reference: Iran–U.S. RQ-170 incident
Reference: Exclusive: Iran hijacked US drone, says Iranian engineer
Incident: HOYA Corporation Hit by Cyberattack
Japanese optical products manufacturer HOYA Corporation was hit by a cyber attack at the end of February which led to a partial shutdown of its production lines from Thailand for three days.
The company disclosed that around 100 computers were infected with a malware strain designed to steal user credentials from the machines it compromises and to drop a cryptocurrency miner during the infection process' second stage.
Reference: Hoya hit by cyberattack in Feb., disrupting Thai factory operations
Reference: Cyber Attack Shuts Down Hoya Corp’s Thailand Plant for Three Days
Reference: Russian hacker is set to face trial for the hack of a local power grid
Incident: Hackers Paralyze Operations of Textile Manufacturer Erfo
Cyberattack at textile fashion brand and manufacturer, Erfo, causes entire operational business to come to a standstill. Not even lawyers were able to access the documents. The company saw only one way out: filing for bankruptcy at the relevant district court. Erfo is also looking for a possible investor.
“Textil Wirtschaft” has learned from internal sources that a high ransom was demanded in the cyberattack. No further information about the attack is known so far.
Victim: Erfo
Textile Manufacturer Erfo
Reference: Erfo hacker attack leads to insolvency of textile company
Incident: Ukraine Claims Attack on Russian Center for Space Hydrometeorology
Pro-Ukraine hackers have reportedly breached a Russian scientific research center, Ukraine's defense intelligence directorate (GUR) said. Ukrainian hacktivists claimed destruction of a critical state-run meterology institute essential to Russia's aerospace industry and military.
While there is no independent confirmation of the damage to the supercomputers, it is likely the HVAC shutdown plus the destruction of data during war-time would have rendered such destruction permanent as trade embargoes prevent ordering new parts, system repair, and restoration.
According to GUR’s report on Wednesday, the hacker group called “BO Team” attacked the and destroyed its database and valuable equipment.
Planeta is a Russian state enterprise that receives and processes data from 11 domestic and 23 foreign Earth observation satellites, according to its website. This data is then used by other Russian state entities.
Ukraine's intelligence claimed that hackers attacked the eastern branch of the organization, described as “the largest of the three.” The agency hasn’t responded to a request for a comment to confirm the attack.
Reference: Ukrainian hackers claim attack on Russian scientific research center
Reference: Ukraine: Hack wiped 2 petabytes of data from Russian research center
Victim: Planeta
Planeta is the Russian State Research Center on Space Hydrometeorology. An enterprise that receives and processes data from 11 domestic and 23 foreign Earth observation satellites, according to its website. This data is then used by other Russian state entities.
Reference: Devastating Consequences of Ukrainian Cyberattack on Center for Space Hydrometeorology Felt by russians Even in Arctic
Incident: Ransomware Attack Causes Disruption To Ukrainian National Post Services
Ukrposhta is restoring the operation of IT systems after a significant technical failure. This was announced on the company's Facebook page. "Our IT systems have experienced a significant technical failure. Our specialists are actively working to resolve the issue and restore full operation, but this may take some time," the message says.
The attack was mostly mitigated but may have resulted in delivery delays and other issues.
Victim: Ukrposhta
Ukrposhta is Ukraine's national post service
Reference: Ukrposhta resumes operations after large-scale cyberattack
Reference: Ukrainian energy giant, postal service, transportation agencies hit by cyberattacks
Reference: Cyberattack on a Chicago children’s hospital has shut down its systems for a week
Incident: Ransomware Attack takes Hospitals Offline Across Romania
The Romanian national cybersecurity agency (DNSC) has pinned the outbreak of ransomware cases across the country's hospitals to an incident at a service provider. The service provider operates the Hipocrate Information System (HIS) – a multipurpose healthcare management platform used by hospitals across the country. All hospitals caught up in the ransomware scourge are thought to have been breached via the HIS.
The scale of the ransomware emergency in Romania is bordering on the unbelievable as now more than 100 hospitals have been either disconnected from the internet or had their files encrypted. The hackers demanded 3.5 Bitcoin, worth over £130,000, to unlock important files that they had encrypted. However, Romanian cyber officials confirmed that data had recently been backed up, minimizing the impact.
Reference: Over a hundred Romanian hospitals affected by ransomware attack
Reference: Ransomware attack hits dozens of Romanian hospitals 13 February 2024
Reference: Ransomware Attack Takes 100 Hospitals Offline
Reference: Romanian hospital ransomware crisis attributed to third-party breach
Incident: Cyberattack Causes Widespread Outage at Casino del Sol, AZ
A February 21 cyberattack caused widespread system outage at The Casino del Sol in Tucson, Arizona. The attack disabled ATMs, credit card systems, Wi-Fi, TV, phones, and electronic door keys systems.
Fifteen days later, on March 7, Casino Del Sol posted an update saying “all restaurants and bars are now able to accept card payments. Food and Beverage vouchers are still unable to be processed at this time but rewards lost will be honored ta a later date.”
Phone lines are still down and new reservations still cannot be made, but all current bookings are being honored.
Reference: Casino Del Sol Experiences Attempted Cyber Attack, Raising Concerns of Possible Data Breach
Reference: Casino Del Sol releases new update on recovery from attempted cyberattack
Victim: Casino del Sol
Casino del Sol in Tucson, Arizona.
Reference: Casino del Sol in Tucson Fighting Cyber Attack
Incident: Aircraft Unable to Receive GPS Signals in Baltic Sea, the Black Sea and Eastern Mediterranean.
Russia is suspected of launching a record-breaking 63-hour-long attack on GPS signals. The Baltic Sea, the Black Sea and the eastern Mediterranean - the regions where Russia's military has been most active - have seen an increase in disruption to the Global Positioning System (GPS). This has left aircraft unable to receive GPS signals.
The incident, which affected hundreds of passenger jets, occurred amid rising tensions between Russia and the NATO military alliance more than two years since the start of Russia’s full-scale invasion of Ukraine.
Reference: Russian Jamming Is Wreaking Havoc on GPS in Eastern Europe. But Is It Hybrid Warfare?
Reference: Intensified GPS jamming is side effect of Russia’s self-protection of Kola bases
Reference: Russia blamed for GPS interference affecting flights in Europe
Reference: Estonia summons Russian embassy chief over GPS jamming
Reference: Unprecedented GPS jamming attack affects 1600 aircraft over Europe
Incident: Black Basta Attack Disrupts Ascension Hospital Network
Ascension, one of the largest hospital networks in the USA, suffered a BlackBasta ransomware attack. The hackers encrypted digital systems throughout the 19-state health system operations, leading hospitals to disconnect their networks and revert to manual operations and work-arounds.
Victim: Ascension
Ascension is one of the largest private U.S. healthcare systems. The health network reported a total revenue of $28.3 billion in 2023 and operates 140 hospitals and 40 senior care facilities across the United States.
Reference: Ascension: Health data of 5.6 million stolen in ransomware attack
Reference: Ascension confirms data breached in Black Basta ransomware attack
Reference: Russia is trying to sabotage European railways, warns Prague
Incident: ICS Malware Fuxnet Disrupts Russian Infrastructure
ICS malware Fuxnet allegedly used by Ukrainian Blackjack group to disrupt industrial sensors and other systems belonging to a Moscow infrastructure firm.
BlackJack claimed to have significantly impacted Moscollector’s IOT sensor gateway network deployed throughout underground utility corridors, providing telecommunications, district heating, water, and sewage services throughout Moscow. Claroty analyzed a Fuxnet malware sample from the attack adding credibility to BlackJack’s claims. Fuxnet has the capability of sending spurious commands over RS-485/MBus protocols and bricking sensor gateways by destroying their flash memory chips.
Threat Actor: Blackjack group
The Blackjack hacking group is believed to be affiliated with Ukrainian intelligence services.
Malware: Fuxnet
Fuxnet is malware designed to impact the industrial network infrastructure managing control system sensors for utility operations in Moscow.
Reference: Unpacking the Blackjack Group’s Fuxnet Malware
Reference: Russian infrastructure disrupted by Ukrainian hackers
Reference: Destructive ICS Malware ‘Fuxnet’ Used by Ukraine Against Russian Infrastructure
Reference: Taiwan United Renewable Energy: A cyberattack caused the factory to shut down
Incident: Taiwan United Renewable Energy Corporation Confirms Cyberattack
Taiwan United Renewable Energy Corporation announced that due to a cyberattack on some information systems, the factory is currently shut down and the impact on the company's finances is still being evaluated.
The company's information department has fully launched relevant defense mechanisms and recovery operations, and is coordinating with technical experts from external information security companies.
Victim: Taiwan United Renewable Energy Corporation
Taiwan United Renewable Energy Corporation
Incident: Hackers Compromised Systems of Belarus’ Largest Chemical Company
The hacker group "Cyberpartisans" claims to have hacked the computers and security systems of Belarus' largest chemical company, Grodno Azot. The hackers promise to restore the data when the plant's employees arrested during protests against the results of the 2020 presidential election, as well as 75 political prisoners with the worst health conditions, are released.
The hackers claim to have taken control of the company's website, email, hundreds of work computers, servers, security systems, and surveillance cameras. The boiler room has also been disrupted.
The Grodno Azot website has been down since April 17. “The situation has not affected, and will not affect, the production activities of the enterprise,” the offical company said.
Victim: Grodno Azot
Grodno Azot: Belarus' largest chemical company.
Reference: Hackers attacked a Belarusian factory, demanding the release of political prisoners
Reference: Belarusian hackers claim to breach fertilizer plant in retaliation for support of Lukashenko regime
Incident: Ransomware Attack at Puerto Nuevo Terminals in Puerto Rico
Puerto Nuevo Terminals, the private consortium that operates part of the container facilities in San Juan, was subjected last April 20 to a ransomware cyberattack that although it failed to stop operations created serious delays in cargo movement and truck dispatch for a number of days. The FBI office in Puerto Rico is investigating the situation.
Victim: Puerto Nuevo Terminals
Puerto Nuevo Terminals in Puerto Rico operates part of the container facilities
Reference: FBI assists in the investigation on a cyberattack against the company that operates cargo docks in San Juan
Reference: Hearing on “Port Safety, Security, and Infrastructure Investment” Tuesday, April 30, 2024
Reference: Estonia blames Russia for GPS interference that forces Finnair to suspend flights
Reference: Finnair pauses some Estonia flights due to GPS interference
Incident: Finnair Suspends Flights between Helsinki and Tartu after GPS Jamming
Finnair cancelled flights between Helsinki, Finland, and Tartu, Estonia, because of GPS jamming. Flights between Helsinki and Tartu were suspended until an alternative navigation system for landing approach was put in place.
Cases of GPS jamming, which is when strong radio signals drown out or interfere with satellite navigation systems, have surged since 2022, after Russia launched its full-scale invasion of Ukraine.
Victim: Finnair
Finnair - Official airline of Finland
Reference: Airlines grapple with spike in GPS interference. Experts say it’s collateral damage from global conflicts
Incident: Several Critical Safety Services Down in Pakistan’s Islamabad
Islamabad’s Safe City Authority experienced a significant disruption when its online system was breached by hackers, prompting an immediate shutdown.
The Pakistani project aimed for the development of a system of 1,950 surveillance (CCTV) cameras and the installation of a 2900 square meter bomb-proof command center in Islamabad to safeguard the region. The absence of backup servers and contingency plans forced a complete shutdown of the affected software and applications. Law enforcement officials scrambled to assess the damage and restore operations.
Victim: Safe City Islamabad Project
The Safe City Islamabad Project, initiated by the PPP-led government and backed by a Chinese government concessional loan, aimed to enhance the capital’s surveillance and security capabilities with the installation of 1,950 CCTV cameras, a bomb-proof command center, a 4G communication network, and advanced monitoring systems such as facial recognition technology.
Incident: Volt Typhoon Compromises US Internet Companies
A Chinese hacking group exploited a software bug to compromise several internet companies in the United States and abroad, a cybersecurity firm said on Tuesday. The hackers took advantage of a previously unknown vulnerability in Versa Director - a software platform used to manage services for customers of Santa Clara, California-based Versa Networks. Reportedly four U.S. victims and one Indian victim had been identified, although they were not identified.
Lumen researcher Ryan English said that the internet companies were targeted for the attackers to surveil their customers. The hacking campaign kicked off as early as June 12, 2024. Reportedly Volt Typhoon hacked Singapore Telecommunications early that month as test run for further hacks against US communications companies.
Victim: Versa Networks
Founded by security and network industry veterans, Versa Networks is an innovative leader in SASE, security, networking, SD-WAN, cloud, and analytics. Versa enables Service Providers and large Enterprises to transform wide area networks and branch networks to achieve business advantages.
Reference: Chinese hackers exploited bug to compromise internet companies, cybersecurity firm says
Reference: China’s Volt Typhoon reportedly targets US internet providers using Versa zero-day
Incident: After Sabotage Acts Significantly Disrupt French Railsystem Operations, SNCF Falls Victim to Cyberattack
Just hours before the opening ceremony of the Olympic Games in Paris, the French railway company SNCF reported arson attacks on several high-speed lines. The attacks caused major transport disruptions and affected thousands of people traveling to Paris. Shortly thereafter, the French train network fell victim to a large-scale cyberattack. Hackers exploited vulnerabilities in the trains' digital control systems, leading to more delays and cancellations.
Many commuters and travelers were forced to seek alternative transportation, leading to increased road traffic.
Reference: “Massive attack” against the SNCF: what you need to know
Victim: SNCF
Société Nationale des Chemins de fer Français - SNCF is France's national state-owned railway company.
Reference: France reports 68 cyberattacks related to Paris Olympics
Reference: Cyber Attack Paralyzes French High-Speed Train Network
Reference: SNCF reports “massive attack” on high-speed train network
Reference: Cyberattack Paralyzes French High-Speed Train Network
Incident: Ransomware Attack Caused Operational Disruptions at Grand Palais Rmn
Around forty French museums and tourist sites were hit by a cyberattack. The Grand Palais Réunion des musées nationaux (Rmn) in France suffered a cyberattack on Saturday night, August 3, 2024. All access to its servers was cut off. No data extraction has been observed at this stage" and the attack had no effect on the operation of the Grand Palais, currently used by Olympic Games events and connected to the Paris 2024 networks.
French media Sud Ouest reports that the shut down of systems disrupted the bookstores and boutiques at numerous museums in France. However, a solution was created that allowed the stores and boutiques to operate autonomously.
Victim: Grand Palais Réunion des musées nationaux (Rmn)
Grand Palais Rmn is an institution responsible for managing several museums and cultural sites in France. It oversees various aspects of the museum's operations, including exhibitions, cultural programming, and operations.
Reference: Cybersecurity: Grand Palais and several museums including the Louvre victims of ransomware attack
Reference: Cybersecurity: Grand Palais and several museums including the Louvre victims of ransomware attack
Reference: France’s Grand Palais discloses cyberattack during Olympic games
Incident: Small Swiss Dairy Farmer Refuses to Pay Ransomware
A farmer from the Swiss canton of Zug became the target of a ransomware attack. The exact target of the attack was a milking robot. The robot, responsible for milking the animals, suddenly no longer received data. he milking robot records and stores all relevant data for each individual cow. The hackers, who remain unknown to this day, demanded 10,000 dollars (8,500 Swiss francs) from Bircher.
The machine also collected data about when individual cows had been inseminated. Since Bircher refused to pay the ransom, he was denied access to this data. Later, complications arose with one of the cows and she had to be put down.
Birchermade two serious mistakes: he had neither backups nor an emergency plan. At least the milking systems were not completely dependent on the computer, so the farmer was able to continue milking his cows.
Victim: Private farmer
A farmer from the Swiss canton of Zug
Reference: Cow dies after cyberattack on milking robot
Reference: Hacking, ransom demands and a dead cow
Reference: A farmer from Zug is hacked. As a result, one of his cows dies – can a cyber attack now affect all farmers?
Reference: Ransomware attack paralyzes milking robots — cow dead
Incident: Bus Services Disrupted after Turkish Transportation App Hack
Ekomobil mobile application has been compromised by a previously unknown group calling itself “Cund El Aksa.” The app is a key tool used by residents of Kocaeli for accessing public transportation services. The group sent threatening messages to users and caused disruptions to the city’s bus services.
After gaining control of the application, the hackers sent a chilling message to subscribers. This incident has raised concerns about the security of public digital services as well as the cybersecurity of government funded apps in Türkiye.
Victim: Ekomobil
Ekomobil is a mobile application. A key tool used by residents of Kocaeli,Turkey for accessing public transportation services.
Reference: E-Komobil hacked
Reference: Anti-Zionist group hacks Turkish transportation app
Incident: Texan Level 1 Trauma Center Diverts Patients after Cyberattack Hits IT System
A ransomware attack on the only level 1 trauma center within 400 miles of Lubbock, Texas was forced to divert newly incoming emergency and non- emergency patients. The attack disrupted their IT systems.
A ransomware group identifying itself as Interlock claimed responsibility for the attack. Neither the HSCs nor UMC have confirmed or denied Interlock as the attacker. Insurance covered both the paid ransom amount paid and recovery costs.
Reference: UMC paid ransom with insurance, data was restored, not sold on dark web
Reference: Crucial Texas hospital system turning ambulances away after ransomware attack
Victim: University Medical Center (UMC) Health System
University Medical Center (UMC) Health System
Reference: We still don’t know how the Lebanon pager attack happened. Here’s what we do know about our own electronic devices
Reference: Turning Everyday Gadgets into Bombs is a Bad Idea
Reference: Hezbollah pager attacks: The legal risks facing Netanyahu
Reference: Automatic Tank Gauges Used in Critical Infrastructure Plagued by Critical Vulnerabilities
Incident: Israel Hacks Beirut Airport Control Tower
Israel has allegedly breached the communication network of the control tower at Beirut-Rafic Hariri International Airport and warned an Iranian plane against landing, prompting the aircraft to turn around and return to Tehran, Israeli media reported on Saturday. Lebanon's transport minister, Ali Hamieh intervened and directed the incoming plane to divert its flight path and return to Iran.
Reference: Israel reportedly hacks Beirut airport control tower, warns Iranian plane not to land
Reference: Mega hack shuts down Putin’s online state media
Incident: Cyberattack Disrupts Operations at Russian State Media Company VGTRK
Russian state television and radio broadcasting company VGTRK was hit by a cyberattack on Monday. The company confirmed in a statement to local news agencies that its operations were disrupted due to the attack.
Local media reported that the broadcast of several television channels owned by VGTRK, including Russia 1 and Russia 24, was cut off mid-program and resumed nearly an hour later. An anonymous source at the company told the Russian media outlet Gazeta.ru that the hackers erased data from the company's servers, including backups. This was not independently verified.
Victim: VGTRK
VGTRK owns and operates five national TV channels, five radio stations, and 80 regional TV and radio networks in Russia.
Reference: VGTRK announced an unprecedented hacker attack on the media holding’s online services
Reference: Russian state media company operation disrupted by ‘unprecedented’ cyberattack
Incident: Japanese Auto Parts Manufacturer Yorozu suffers Cyberattack.
Japanese auto parts manufacturer Yorozu suffered a cyberattack. The attack forced the company to disconnect and isolate infected systems. The company issued a statement 9 days later saying they are "assessing the extent of the impact and the state of damage. Through our investigations so far, we have confirmed the possibility of some leakage of personal - and confidential information".
The resulting delay in the submission of the semi-annual report is expected to have financial implications.
Victim: Yorozu Corporation
Yorozu Corporation is a Japanese autoparts manufacturer
Reference: Yorozu Undergoes Ransomware Attack, Isolates Affected Servers
Reference: Notice of Ransomware Attack Incident (2nd Report)
Reference: Yorozu Data Breach on October 22, 2024
Reference: Yorozu Corporation Faces Cyberattack, Delays Financial Report Submission Amid Data Breaches
Incident: ISP Windstream Routers Stop Working after Cyberattack
Unknown threat actor with equally unknown motives forces ISP to replace routers: one day last October, subscribers to an ISP known as Windstream began flooding message boards with reports their routers had suddenly stopped working and remained unresponsive to reboots and all other attempts to revive them. After eventually determining that the routers were permanently unusable, Windstream sent new routers to affected customers. Black Lotus Labs has named the event Pumpkin Eclipse.
Victim: Windstream Holdings, Inc.
Windstream Holdings, Inc. (Kinetic Broadband Service) is a leading provider of advanced network communications and technology solutions for consumers, small businesses, enterprise organizations and carrier partners across the U.S. Windstream offers bundled services, including broadband, security solutions, voice and digital TV to consumers.
Reference: Mystery malware destroys 600,000 routers from a single ISP during 72-hour span
Incident: Local UK Newspaper Production Shut Down after Cyberattack
The printing Henley Standard was delayed after its publisher was victim of a cyber attack. The attack brought down the company’s production, web and communications systems and also impacted its website.
Technical teams have been working through the night since Monday to restore the processes required to produce the paper. It is hoped that the Henley Standard can be printed and distributed later today (Thursday 21 November).
Victim: Henley Standard
Henley Standard is a flagship local newspaper title with a distinguished history in providing local news to the Henley-on-Thames and South Oxfordshire region
Reference: This week’s paper delayed
Incident: DDoS Attack on Gazprombank Affects Customers
Russian users have reported difficulties accessing services at Gazprombank, one of the country’s largest privately owned banks, following an alleged cyberattack by Ukraine’s military intelligence agency.
Data from several website outage tracking services indicates that Gazprombank customers have complained about being unable to make transactions or pay bills through the bank’s app or website. Earlier this week, Ukraine’s military intelligence agency (HUR) claimed responsibility for launching a powerful distributed denial-of-service (DDoS) attack on Gazprombank, disrupting its online and mobile banking services.
Reference: GUR paralyzed the work of Russia’s Gazprombank – source
Victim: Gazprombank
Gazprombank is one of the largest banks in Russia. The institution's clients are about 3 million individuals and about 45 thousand legal entities.
Reference: Russian users report Gazprombank outages amid alleged Ukrainian cyberattack
Incident: Azerbaijani Jet Confused for Ukrainian Drone
A Russian anti-aircraft system may have downed the passenger jet that crashed in Kazakhstan on Christmas Day, a US official told CNN. The signs point to a Russian system striking Azerbaijan Airlines flight J2-8243 before it crashed near the city of Aktau, the US official said Thursday. Russian air defense units may have fired on the commercial airliner believing it was a long-range Ukrainian attack drone, they added Friday.
On Saturday, Putin “apologized for the fact that the tragic incident occurred in Russian airspace” in a phone call with Azerbaijan’s President Ilham Aliyev, adding that Russian air defenses were active at the time but stopping shot of admitting fault. The aircraft attempted to land twice without GPS, but heavy fog made them abort and return to their origin at Baku. Minutes after diverting from Grozny, the Embraer was hit by Russian anti-aircraft fire, lost control, and crashed near Aktau while attempting an emergency landing.
Thirty-eight of the 67 people on board died in the crash. Among the survivors were two children.
Victim: Azerbaijan Airlines
Azerbaijan Airlines
Reference: Russia may have downed Azerbaijani jet after confusing it for Ukrainian drone, US official says. Here’s what we know
Reference: IATA Statement on Azerbaijan Airlines Flight 8243
Reference: Costa Rica refinery cyberattack was first deployment for new US response program, ambassador says
Incident: Letland’s SmartLynx Airlines Hit by Cyberattack
SmartLynx Airlines recently experienced a cyberattack on its systems. Thanks to a swift and decisive response, all operationally critical services remain secure and uninterrupted. "While our initial investigation cannot confirm which specific data may have been affected, we remain committed to identifying any impacted information."
Victim: SmartLynx Airlines
SmartLynx Airlines, Letland
Reference: SmartLynx Airlines experienced a cyber attack
Incident: Ransomware Attack impacts Operations at French Medical Imagining Systems Manufacturer DMS
Diagnostic Medical Systems Group, a specialist in manufacturing digital radiology systems, was hit by a ransomware attack on February 2. The group reported "internal systems are being reset in preparation for the full restoration of backup data." DMS Group expects a gradual resumption of activity starting next week, with priority given to operations (Production and Procurement).
In October '24 the company reported a loss of €1.4 million, attributed to the strengthening of the IT infrastructure following a cyberattack and strategic investments, particularly in research and development.
Victim: Diagnostic Medical Systems (DMS) Group
DMS is a French industrial company specialized in digital radiology.
Reference: DMS GROUP: Interception of a cyberattack
Reference: DMS Group Intercepted Ransomware Cyberattack, Limited Impact On Q1
Reference: DMS Group posts 10% growth in the first half of 2024
Incident: Databreach at French Telecommunications Service Provider Zeop
Zeop informs its customers that it has suffered a computer attack "which could have led to the exfiltration" of their personal data. "The more precise analysis nevertheless revealed that the security of Zeop's information systems had not been called into question."
Reference: Zeop victim of a computer attack
Victim: Zeop
Zeop offers fixed telephony and internet services that support high-speed streaming and downloading through its network of fiber optics.
Reference: Major cyber attack paralyzes Makassar order processing
Incident: Cyberattack at Pau Airport and the Pau Business School
Pau airport and the Pau business school (of the Eklore group) were victims of a cyberattack on the night of May 12 to 13, 2024. According to the CCI, the consequences are limited, no data was lost.
Victim: Pau airport
Pau airport, France
Reference: Pau Airport and Business School Victims of Cyberattack
Incident: Cyberattack Targets France’s Largest News Agency AFP
On Friday, France's largest news agency AFP was the target of a cyberattack. The company’s website suffered from intermittent outages and many pages were routed to a “Under Maintenance” landing page. According to the world's third-largest agency, all systems are fully functional. "However, it cannot be ruled out that the access data for the delivery of AFP content has fallen into the hands of the attackers."
Victim: AFP (Agence France-Presse)
Founded in 1835, Agence France-Presse (AFP) is one of the world’s largest and well-known news agencies, with offices in 150 countries and stories in dozens of languages.
Reference: Agence France-Presse says cyberattack targeted IT systems
Reference: Cyber attack on the world’s third largest news agency
Incident: Cyberattack Adds Complication to Daily Lives of French Farmers
The IT platform hosting Synel and all other animal notification modules in south-west France has been hit by a cyber-attack. Since December 15, approximately 30,000 farmers in 22 departments in the southwest have been affected by a cyberattack. The Synel herd management software used by cattle, sheep and goat farmers is unusable. They have returned to the age of paper declarations.
The Synel software usually ensures the identification of animals by declaring birth, death or sale. Any change affecting the herd must be scrupulously reported within seven days. In the event of failure to comply with these obligations, farmers are exposed to financial penalties during checks.
Reference: Cyber attack: animal identification
Victim: Synel herd management software
Synel herd management software used by cattle, sheep and goat farmers in France
Victim: Arsoé de Soual
Arsoé de Soual, based in Tarn, IT company responsible for putting agricultural digital services online.
Reference: “They contacted us via encrypted messaging to obtain a ransom”: this cyberattack makes life impossible for breeders
Reference: Hive ransomware attacks State Railways, hacker group uses Cryptolocker trojan
Incident: Widespread Fallout after Cyberattack hits Italy’s National Railway Company
Italian State Railways (FS) and its subsidiaries Trenitalia and Italian Rail Network (RFI) suffered a major ransomware attack on March 23 . The attack severely impacted ticketing systems, passenger information displays, and internal communications.
FS implemented emergency measures, allowing passengers to purchase tickets on trains without penalties. The primary focus was on restoring critical systems and minimizing further disruption to passenger services. Freight transport by rail was temporarily suspended for 24 hours. Reportedly affecting FS, Metrans Rail of Czech Republic, HUPAC of Switzerland and Lineas of Belgium.
Metrans Rail of Czech Republic shutdown their Italian operations for 24 hours the following day. They stated it was temporarily not possible to cross the border at Austria and Slovenia. Marc Jansen, director of operations at carrier Hupac, said trains have been standing still for 24 hours. Arno van Deursen, Country Manager Lineas NL said “Our trains to and from Italy have been standing still for about 15 hours".
Elements were found on the computer network of Trenitalia and RFI that could be linked to a cryptolocker infection. Italian authorities, including the Postal Police's National Cybercrime Center (Cnaipic) and the National Cybersecurity Agency (Acn), launched a joint investigation.
Reference: Italian Railways hit by cyber attack
Victim: Lineas
Lineas is Europe's largest private rail freight operator based in Belgium.
Victim: HUPAC
HUPAC is a leading intermodal rail freight transport operator in Europe based in Switzerland.
Victim: Metrans Rail
Metrans Rail is a Czech railway operator. It operates regular freight trains connecting container terminal of its parent Metrans in Prague-Uhříněves with Rotterdam. It is presently a wholly-owned subsidiary of the German logistics company HHLA
Reference: Hacker Attack on the Italian Railway Infrastructure
Victim: Ferrovie dello Stato Italiane (FS)
Ferrovie dello Stato Italiane (FS). is Italy’s national railway company. Trenitalia SpA is the primary train operator of Italy and a subsidiary of FS.
RFI, also part of FS, is responsible for managing Italian railway infrastructure.
Reference: Cyber attack on Italian railway company stops traffic
Reference: Italian railway IT system suffers major cyber-attack
Incident: Ransomware Attack at Pittsburgh Regional Transit
Pittsburgh Regional Transit is investigating a ransomware attack that the company detected on Thursday, Dec. 19. It's currently unknown if any sensitive data was compromised during the attack. While rail service experienced temporary disruptions on Thursday morning, transit services now operate normally. However, as of Monday afternoon, other rider services remained negatively impacted, including PRT's Customer Service Center, which was temporarily unable to accept or process senior and child ConnectCards. IT officials at PRT are still examining whether data was stolen and pledged to provide public updates as the investigation evolves.
The agency declined to answer questions about what group was behind the attack and when full service would be restored.
Victim: Pittsburgh Regional Transit
Pittsburgh Regional Transit
Reference: Pittsburgh Regional Transit attributes recent service disruptions to ransomware attack
Reference: Local News Pittsburgh Regional Transit investigating cybersecurity incident
Incident: Cyberattack on Grocery Store Chain in Canada
Since December 12, Avril supermarkets have been operating at a slow pace. The grocery store chain with 13 branches in Quebec, was the victim of a cyberattack. Computer and telephone systems were affected. No stores had to close, but service was somewhat slowed.
Customers' personal data is not believed to have been compromised. It is too early to measure the financial losses associated with this event.
Victim: Avril
Avril is a grocery store chain of healthy, natural and organic supermarkets, offering grocery, ready-to-eat meals, supplements and cosmetics in Quebec, Canada
Reference: Attack Slows Manufacturing For Finland’s Peikko Group
Reference: Avril channel slowly recovering from cyberattack
Reference: The French food giant Avril victim of a cyberattack
Reference: Avril chain victim of cyberattack
Reference: We know where your car is
Reference: Customer data from 800,000 electric cars and owners exposed online
Incident: End of Year Cyberattack at Russian Oil Company Lukoil
Cyber specialists of Ukraine’s Main Intelligence Directorate (HUR) carried out a cyberattack on Russian oil company Lukoil. The attack compromised the company's digital resources. Customers were unable to make payments at gas stations via the mobile app. In addition the DDOS attack caused disruptions and financial losses across the retail sector due to payment system failures.
Reference: Ukraine’s intelligence disrupts Lukoil services with cyberattack
Victim: Lukoil
Lukoil is a Russian oil company
Reference: Ukraine’s Intel Disrupts Lukoil: Cyberattack Sparks Payment Failures and Holiday Chaos in Russia
Reference: The Ukrainian Defense Intelligence Agency has conducted a cyberattack on Russian infrastructure
Incident: Ransomware Attack at Automotive Parts Manufacturer Yorozu
Japanese Automotive Parts Manufacturer Yorozu was hit by a Ransomware attack. Files stored on multiple servers were encrypted. A notice published on Yoruzo's website reads: "Our group immediately set up a task force at our headquarters. ... currently investigating the extent of the impact and the extent of the damage." (machine translated)
Victim: Yorozu
Yorozu is an automotive parts manufacturer in Japan
Reference: Yoruzu Notice of Ransomware Attack
Reference: NTT Docomo reports system glitch after cyberattack
Reference: Japan’s NTT Docomo reports system glitch after cyberattack
Victim: NTT DOCOMO
NTT DOCOMO, Japan's leading mobile operator.
Reference: Japan’s largest mobile carrier says cyberattack disrupted some services
Reference: Hong Kong cyberattack cost Arup £25m
Incident: Cyberattack Impacts Operations at Finnish Manufacturer Peikko Group
Peikko Group has experienced a cyberattack during the last weekend of 2024. The website reports manufacturing and deliveries are impacted, with some countries forced to operate manually.
Jan 3 update: Restoring actions are ongoing 24/7.
Victim: Peikko Group
Peikko Group Corporation is a Finnish supplier of Slim Floor Structures, Wind Energy Applications and Connection Technology for Precast and Cast-in-situ.
Peikko is a family-owned and run company with over 2,000 employees. Peikko was founded in 1965 and is headquartered in Lahti, Finland.
Peikko has subsidiaries in over 30 countries in Asia-Pacific, Europe, Africa, the Middle East and North America, with certified manufacturing operations in 12 countries. Peikko's turnover in 2021 is EUR 240 million.
Reference: Peikko encountered a cyber attack
Incident: DDoS Attack at Milan Airports
The websites of Milan’s Linate and Malpensa airports were hit by a cyberattack on Saturday morning, Corriere della Sera reported.
The hack caused no disruption to operations, the Italian newspaper said, with the main impact felt by travelers attempting to check the status of their flights.
Italy’s Foreign Ministry website and a number of other sites were also taken down at least temporarily.
The pro-Russian group NoName claimed responsibility for the action via a message on Telegram, according to the newspaper. Italy’s Postal Police’s cybercrime unit is working on the case to support affected targets and help with an investigation.
Victim: Milano Malpensa Airport (MXP)
Milan's Malpensa Airport (MXP)
Victim: Milano Linate Airport (LIN)
Linate airport in Milan
Reference: Cyberattack on Malpensa and Linate sites, the expert: «Forms of sabotage, it’s like putting glue in the lock»
Reference: Milan Airports’ Websites Hit by Hackers, Corriere Reports
Reference: Cyber chaos: Pro-Russian hackers hit Italian airports
Reference: Linate and Malpensa: hacker attack on Milan’s airports
Malware: Information-stealing malware
Information-stealing malware campaigns are running rampant in 2024, used in many different campaigns to steal infected users' browser information, cookies, saved credentials, credit cards, and cryptocurrency wallets.
These stolen credentials are then used to breach corporate networks, bank accounts, cryptocurrency exchanges, and email accounts. Unfortunately, for those who become infected with an infostealer, it can lead to devastating financial losses as threat actors steal cryptocurrency and access victims' bank accounts. The best way to prevent these types of attacks is to enable two-factor authentication with an authenticator app on all accounts that offer the protection.
Reference: (#1) The biggest cybersecutiry and cyberattack stories of 2024
Reference: White House links ninth telecom breach to Chinese hackers
Incident: Multiple US Telecom Providers Hacked by Chinese Threat Actors.
The FBI and the U.S. Cybersecurity & Infrastructure Security Agency (CISA) have disclosed that Chinese hackers breached commercial telecommunication service providers in the United States.
A Chinese state-sponsored hacking group known as "Salt Typhoon" is linked to the attack. The hacking group reportedly focused on infiltrating telecom infrastructure to steal text messages, phone call information, and voicemails from targeted people. They also targeted the wiretapping platforms used by the US government, raising serious national security concerns.
A White House briefing revealed that Salt Typhoon's operations also impacted telecommunications providers in dozens of countries. In the US, these attacks prompted concerns about weaknesses in telecom infrastructure and the security of government surveillance platforms.
Reference: (#2) The biggest cybersecurity stories of 2024
Reference: US says Chinese hackers breached multiple telecom providers
Threat Actor: Salt Typhoon
Chinese state-sponsored hacking group known as "Salt Typhoon" is linked to a series of cyberattacks targeting telecommunications firms globally. These breaches compromised at least nine major telecom providers, including AT&T, Verizon, and T-Mobile. The group reportedly focused on infiltrating telecom infrastructure to steal text messages, phone call information, and voicemails from targeted people. The threat actors also targeted the wiretapping platforms used by the US government, raising serious national security concerns.
Reference: (#5) The biggest cybersecurity stories of 2024
Reference: No. 7 Snowflake data Theft attacks – The biggest stories of 2024
Reference: The biggest cybersecurity and cyberattack stories of 2024
Incident: Monstrous National Public Data Breach Affects Millions of People in US
In August, almost 2.7 billion records of personal information for people in the United States were leaked on a hacking forum, exposing names, social security numbers, all known physical addresses, and possible aliases.
The data was stolen from National Public Data, a company that collects and sells access to personal data for use in background checks, to obtain criminal records, and for private investigators.
Have I Been Pwned's Troy Hunt analyzed the breach and determined it contained 134 million unique email addresses, making this a monstrous data breach.
The threat actors behind the breach attempted to sell it for $3.5 million, but it was eventually leaked for free on a hacking forum.
(as reported in BleepingComputer's overview of biggest 2024 cybersecurity stories.)
Victim: National Public Data
National Public Data, a company that collects and sells access to personal data for use in background checks, to obtain criminal records, and for private investigators.
Reference: Hackers leak 2.7 billion data records with Social Security numbers
Reference: Japanese publisher paid $3 million to hacker group after cyberattack
Incident: DDoS Attack Delays Flights at Japan Airlines
Japan Airlines said it was hit by a cyberattack, causing delays to more than 20 domestic flights but the carrier said it was able to stop the onslaught and restore its systems hours later. JAL said the problem started Thursday morning when the company’s network connecting internal and external systems began malfunctioning.
JAL said the issues began around 7:25 a.m., delaying more than 70 domestic and international flights by up to four hours and leading to the cancellation of four domestic flights. While ticket sales were temporarily halted, reservations that had previously been made remained valid. JAL said it determined the cause and that the system was restored at around 1:20 p.m.
Japan Post Co. said mail and parcel deliveries were affected by JAL's flight disruptions.
Reference: Japan Airlines cyberattack disrupts flights as holiday season begins
Victim: Japan Airlines
Japan Airlines
Reference: Airline hit by a cyberattack, delaying flights during the year-end holiday season
Victim: Orange S.A.
Orange is a French multinational telecommunications corporation founded in 1988 and headquartered in Issy-les-Moulineaux, near Paris. Orange offers mobile, landline, internet and Internet Protocol television (IPTV) services. Orange employs > 130,000 people.
Reference: Anonymous Sudan attacks again, this time in Uganda
Reference: Stormous ransomware gang takes credit for attack on Belgian brewer Duvel
Incident: Ransomware Attack at Indonesian Railway company
State-owned railway company Kereta Api Indonesia (KAI) fell victim to a ransomware attack. Pratama Persadha, Indonesia’s Cybersecurity Research Institute chairman, said the current cyberattack was the most severe to hit Indonesian government agencies and companies since 2017. “The disruption to the national data center and days-long needed to recover the system means this ransomware attack was extraordinary.” Persadha said. “It shows that our cyber infrastructure and its server systems were not being handled well.”
The government was asked to pay a ransom of 11.69 Bitcoin.
Reference: Indonesia won’t pay$8 million ransom after cyberattack compromised its national data center
Victim: Kereta Api Indonesia (KAI)
State-owned railway company Kereta Api Indonesia (KAI)
Reference: Stormous Hackers Breach KAI’s Network, Exposing Customers Data
Reference: Cyber Siege at PT. Kereta Api Indonesia: The Collapse of Security Walls and Resisting the Threat
Reference: Indonesia won’t pay$8 million ransom after cyberattack compromised its national data center
Incident: Cyberattack on the Swiss Media Log-in Platform Onelog
A cyber attack on the Swiss media log-in platform Onelog resulted in login issues for numerous online portals, affecting over 40 media companies, including Tamedia, Ringier, and SRG. The attack disrupted access to content and commenting functionality, prompting media houses to make their content temporarily freely accessible. The incident highlights the vulnerability of centralized login platforms and the need for robust cybersecurity measures to protect against such attacks.
Reference: Hackers restrict access to Swiss media titles
Reference: Hacker attack causes log-in problems for Swiss media
Victim: Onelog platform
Onelog platform is used by over 40 online portals across the media landscape in Switzerland
Incident: Cybersecurity Measures in place at Libération Helped Mitigate Cyberattack
A French newspaper, Libération, was targeted by a cyberattack that utilized ransomware to disrupt its systems. The attackers aimed to extort money from the publication. The newspaper's digital publishing systems, journalist data, and subscriber data were not affected. The IT teams managed to prevent the paralysis of work tools and limit the attack's effects. The website continued to function normally, and measures were taken to ensure the paper's publication.
Victim: French newspaper Libération
French newspaper Libération
Reference: Press release “Liberation” targeted by cyberattack
Incident: Hungarian Defense Procurement Agency sees Sensitive Information Published
The Védelmi Beszerzési Ügynökséget (VBÜ), a Hungarian state-owned company responsible for defense and security procurement, was hit by a ransomware attack. The attackers, identified as the Inc. Ransomware group, gained access to sensitive information, including financial reports, organizational data, and procurement lists. The group demanded a $5 million ransom in exchange for the decryption key, and published some of the stolen data online, compromising the confidentiality and integrity of the information.
The VBÜ has stated that it is working to restore its systems and recover from the attack.
Victim: Defense Procurement Agency (VBÜ – Védelmi Beszerzési Ügynökséget)
Hungarian Defense Procurement Agency
Reference: The state-owned company responsible for military and police procurement was hacked, sensitive data was made public
Incident: Cyberattack at Krispy Kreme Impacts Online Ordering in US
A cyberattack at Krispy Kreme resulted in operational disruptions, particularly affecting online ordering in parts of the United States. The incident has had a material impact on business operations and financial condition. Costs are expected to be partially offset by cybersecurity insurance. The full scope and nature of the attack are still under investigation.
Victim: Krispy Kreme
Krispy Kreme, Inc. (previously Krispy Kreme Doughnuts, Inc.) is an American multinational doughnut company and coffeehouse chain.
Reference: Hackers find hole in Krispy Kreme Doughnuts
Reference: Krispy Kreme is struggling to fulfill online orders after it was hit with a cyberattack Jordan Valinsky
Reference: Krispy Kreme targeted in cyberattack
Incident: Ransomware Attack at Port of Rijeka
The Port of Rijeka in Croatia was targeted by a cyberattack conducted by the 8Base ransomware group. The attack resulted in the theft of sensitive data, including financial records, personal information, employment contracts, and NDAs. Despite the data breach, the port's systems were restored using backups, and the ransom was not paid.
Reference: Hackers attack Port of Rijeka! They demand ransom for stolen accounts, files and confidential information
Victim: Port of Rijeka
The Port of Rijeka handles all types of cargo, except Ro-Ro. It is home to the Adriatic Gate Container Terminal, where ICTSI holds a 51% stake and the Port of Rijeka owns the remaining 49%.
Reference: Cyberattack targets Port of Rijeka, data stolen
Incident: Data Breach at Hong Kong Clothing Manufacturer
Popular athleisure clothing brand Halara is investigating a data breach after the alleged data of almost 950,000 customers was leaked on a hacking forum. Halara told BleepingComputer that it is aware that customer data was allegedly stolen and leaked online and is investigating a potential breach.
Victim: Halara
Popular athleisure clothing brand Halara was founded in 2020 and quickly became very popular through the many videos promoting its clothing on TikTok.
Reference: Halara probes breach after hacker leaks data for 950,000 people
Incident: Ransomware Attack at IPS Securex Holdings
IPS Securex Holdings encountered a ransomware incident making its network inaccessible. The company maintains that for now, there is no "material impact" on its operations and financials from the attack.
Victim: IPS Securex Holdings Limited
IPS Securex Holdings Limited and its subsidiaries (collectively, the “Group”) is one of Singapore's leading providers of security products and integrated security solutions to commercial entities and government bodies and agencies in Asia-Pacific.
Reference: IPS Securex’s servers hacked; no evidence of data exfiltration from cyberattack
Reference: ES Group, IPS Securex hit by separate ransomware attacks
Incident: Cyberattack on Mobile Phone Provider Orange in Spain
The Spanish unit of telecommunications operator Orange suffered a cyberattack on Wednesday that affected an undisclosed number of customers who could not access certain websites, a company spokesman said.
In a message on social media platform X, the French company stated that customers' data was not at risk.
Reference: Hacker hijacks Orange Spain RIPE account to cause BGP havoc
Reference: Major Spanish mobile carrier suffers three-hour outage after account takeover
Reference: Orange suffers cyber attack affecting clients’ internet access in Spain
Reference: Cyberattack at Orange affects internet access of customers in Spain
Reference: Security incident at IT service provider of the Chamber of Crafts
Incident: German IT Firm ODAV AG Confirms Malware Attack
ODAV AG announced on Thursday morning that a malware attack had been detected in the data center. The Straubing-based company is the technology partner of chambers of trades throughout Germany. It continued: "Immediately after the incident became known, we set up an internal crisis team and initiated precautionary security measures." This included taking all systems offline and cutting off connections to customers and partners.
The attack took place on Friday, January 5th. The following Monday, numerous Chambers of Crafts went public and informed about the "security incident". It is unclear how long the pages will be offline.
Reference: Hacker attack confirmed: Chambers of Crafts in NRW still offline
Reference: Hacker attack on chambers of crafts throughout Germany
Victim: ODAV AG
ODAV AG, is the technology partner of chambers of trades throughout Germany.
Reference: Straubing company confirms: Chambers of Crafts affected by cyber attack
Incident: Cyberattack on Beirut Airport, Lebanon
Threat actors hit the Beirut International Airport Rafic Hariri in Lebanon and breached the Flight Information Display System (FIDS) replacing plane departure and arrival data. The baggage inspection system was briefly disrupted but did not implact flights. The personnel at the airport were forced to use police dogs to complete the inspection procedures of the baggage.
The hackers displayed a message on screens at the airport claiming that Hezbollah and Iran are taking the country to war ignoring the will of the Lebanese people. The message also states that the arms smuggling will lead to the bombing of the airport.
The cyberattack also disrupted the baggage inspection system known as Baggage Handling System (BHS). The personnel at the airport were forced to use police dogs to complete the inspection procedures of the baggage.
Reference: Lebanon airport screens display anti-Hezbollah message after being hacked
Reference: Hamiye: No Details on Airport Cyberattack Yet
Victim: Rafic Hariri International Airport, Beirut
Rafic Hariri International Airport is the main international airport serving Beirut, the capital of Lebanon. The airport is named after Rafic Hariri, a former Prime Minister of Lebanon, and it is located about 9 kilometers (5.6 miles) from the city center of Beirut. The airport is a key gateway for both domestic and international air travel.
Reference: A cyber attack hit the Beirut International Airport
Incident: Cyberattack on Russian Telecommunications Provider
Hackers linked to Ukraine’s main spy agency have breached computer systems at a Moscow-based internet provider in retaliation for a Russian cyber attack against Ukrainian telecom giant Kyivstar, a source with direct knowledge of the operation told Reuters on Tuesday.
The hacking group, dubbed "Blackjack", has previously been linked to the Security Service of Ukraine (SBU). The hackers deleted 20 terrabytes of data at M9 Telecom, a small Russian internet and TV provider, leaving some Moscow residents without internet, the source said.
Victim: M9 Telecom
M9 Telecom is a telecommunications provider in Russia
Reference: Hackers hit Moscow internet provider in response to Kyivstar cyber attack – source
Incident: DDoS Attack on Norwegian iNews
DDOS attack has taken down the site of iNyheter. Readers were unable to access the site for a few hours in the afternoon.
Victim: iNyheter
iNyheter is a Norwegian online newspaper that publishes news from Norway and abroad and opinion articles.
Reference: iNews exposed to DDOS attack
Reference: Stadtwerke Meiningen’s Post 21 March
Incident: Stadtwerke Meiningen Lost Control of Social Media Accounts for 2,5 Months
Two and a half months after a hacker attack of January 11, Meiningen municipal utilities have regained control of their two Facebook pages.
The municipal utilities use Facebook to provide information about their work and the offers at the leisure center on the Rohrer Stirn with outdoor pool, indoor pool, restaurant and camping site.
Reference: Stadtwerke Meiningen’s Post
Victim: Stadtwerke Meiningen
Stadtwerke Meiningen (municipal utilities), Germany
Reference: Meiningen public utilities have regained control
Incident: Hackers Gain Access to Mail Accounts at Microsoft
The Microsoft security team detected a nation-state attack on our corporate systems on January 12, 2024. Microsoft has identified the threat actor as Midnight Blizzard, the Russian state-sponsored actor also known as Nobelium.
Beginning in late November 2023, the threat actor used a password spray attack to compromise a legacy non-production test tenant account and gain a foothold, and then used the account’s permissions to access a very small percentage of Microsoft corporate email accounts, including members of senior leadership team and employees in our cybersecurity, legal, and other functions, and exfiltrated some emails and attached documents.
The investigation indicates they were initially targeting email accounts for information related to Midnight Blizzard itself.
Reference: Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard
Reference: Hacker attack: DONAU 3 FM falls victim to cyber criminals
Reference: If necessary, they play themselves
Incident: German Radiostation Continues Broadcasting by Switching to Analogue
On Wednesday January 17, 2024, DONAU 3 FM fell victim to a major hacker attack, and since then most of the station's digital devices have stopped working. The hackers are demanding a ransom to unlock the devices again. The station dusted off analogue equipment to continue broadcasting. On January 20 most important systems were up and running again.
Victim: DONAU 3 FM
DONAU 3 FM German radio station
Reference: Cyberattack on DONAU 3 FM: We just make “radio like before”
Incident: Ransomware Attack at Nexus Telecom, Switserland
The ransomware gang 8Base has allegedly stolen "a large amount of confidential information" from Nexus Telecom. The victim supplies network monitoring software to providers worldwide.
CEO Marco Rhyner confirmed on Wednesday that Nexus Telecom had been affected by a cyber attack. He was unable to comment on the stolen data or the extent of the damage. Apparently, investigations are still ongoing.
Victim: Nexus Telecom Switzerland AG.
Nexus Telecom develops network monitoring software for the mobile communications industry. Customers include major providers in Europe, such as British Telecommunications (BT) and Deutsche Telekom, as well as overseas providers.
Reference: Swiss mobile phone supplier Nexus Telecom hacked
Reference: Swiss software company that supplies mobile phone providers worldwide hacked – consequences unclear
Incident: DDoS attack at Belgium’s State-owned Rail Company
Rail company NMBS reported problems with their website, app and information screens in the stations yesterday. All services are now once again up and running. The cause of problems with the app and information screens is unclear. The rail company is filing a complaint with the judicial authorities and apologises to passengers.
The company claims that it was the target of a massive cyber attack last night. The attack triggered a decision to close down the website. Station information screens and the rail company app also experienced problems, but NMBS says these difficulties were not linked to the attack.
Victim: NMBS rail
NMBS is Belgium’s state-owned rail company
Reference: Rail company NMBS suffers cyber attack
Reference: Grangnården temporarily closed stores due to a technical incident
Incident: Largest Telecom Operator in Central and South America Hit by Ransomware Attack
Claro, the biggest telecoms brand in South and Central America, suffered a ransomware attack on January 25, 2024. The attack inflicted damage to some of its network elements. Claro shared the news after more than a week of disruption to services in in Costa Rica, El Salvador, Guatemala , Honduras and Nicaragua. Disruption affected access to payments; videocalls, activation of new lines, internet services; cable tv.
On February 15, Claro issued a press release stating “the management services and customer interaction platforms are now back in operation".
Reference: Claro normalizes customer service for prepaid customers
Victim: Claro (América Móvil)
Claro is a brand of América Móvil, the telecoms business owned by Carlos Slim, the Mexican billionaire who has previously been the richest person in the world.
Threat Actor: Trigona
Trigona is a successor to users of the CryLock ransomware. They are believed to have begun operations in October 2022 and have already achieved a degree of infamy. A pro-Ukrainian group of white hat hackers stated that they had taken Trigona’s web servers offline in 2023, but evidently Trigona has resurrected itself since.
Reference: Ransomware Attack Hits Claro across Latin America
Reference: Claro confirmes that it was the victim of a cyberattack that affects services
Incident: Unauthorized Access at U.S. portal on Chemical Plant Security
Hackers may have accessed sensitive information about the nation’s chemical facilities during a cyberattack in January, the Cybersecurity and Infrastructure Security Agency (CISA) confirmed on Monday June 24, 2024.
In March CISA confirmed that two systems were taken offline in response to the attack, which was conducted through a vulnerability in Ivanti IT products. It found no evidence that the hackers exfiltrated data but noted the intrusion “may have resulted in the potential unauthorized access” to site security plans, security vulnerability assessments (SVA), and user accounts within the CSAT system.
They also may have accessed “Top-Screen surveys,” which carry information on facilities, including the quantity and concentration of chemicals, their properties, and types of containers used to store them. The other documents held in the system covered how cyber and physical vulnerabilities were addressed by chemical facilities and what kind of alarms, barriers and cybersecurity controls are in place.
Victim: CISA – Cybersecurity & Infrastructure Security Agency
CISA - Cybersecurity & Infrastructure Security Agency, USA
Reference: Chemical Security Assessment Tool Targeted by Attackers
Reference: CISA discloses breach of Chemical Security Assessment Tool
Reference: CISA confirms hackers may have accessed data from chemical facilities during January incident
Reference: Chemical Security Assessment Tool (CSAT) Ivanti Notification
Incident: Cyberattack Cripples Computer System at Eneo, Cameroon’s Power Utility
Eneo, Cameroon's power utility, has warned that it is suffering from a cyber-attack that occurred on January 29 and significantly crippled its computer system.
Eneo did not provide details about the infiltration, but did say that some firm apps had been deactivated as a precaution and to allow measures to secure their system. Prepaid and postpaid operations were significantly impacted.
Reference: Eneo hit by a cyberattack
Reference: Cyberattack: Malicious software takes control of the computer system in Cameroon
Reference: @InsideEneo
Reference: Cameroon’s power utility suffers a cyber attack
Incident: Cyberattack on Gas Station System in Cuba
A cyberattack on gas stations forced the Cuban government to postpone a planned increase in fuel prices of more than 400%. The Ministry of Economy said that a virus that allegedly originated from abroad had affected the cybersecurity of gas stations.
Fuel shortages in recent days have led to widespread, hours-long power outages on the island, but Cuban state-run media reported Wednesday that the cyber-attack would not affect the supply of fuel for power generation.
Cuba`s Banco Metropolitano earlier today said it was having difficulties with electronic payments and services, but later said those problems had been resolved. It was not immediately clear whether the two issues were related.
Victim: Ministry of Economy, Cuba
Ministry of Economy, Cuba
Reference: Cuba delays Feb. 1 fuel price hike, cites cyberattack
Reference: Cuba delays Feb. 1 fuel price hike, cites cyberattack
Incident: Anydesk Software Development Systems Hacked
Anydesk recently struggled with disruptions, the company now confirms that it is the victim of an IT incident. The company activated its emergency plan.
The company has revoked all security-related certificates. Systems have been repaired or replaced where necessary. The code signing certificate used to date will be withdrawn shortly and the manufacturer has started using a new one. Anydesk systems are not designed to store private keys, security tokens or passwords, Anydesk adds in the statement.
AnyDesk suffered a four-day outage during which the company disabled the ability to log in to the AnyDesk client. On Feburary 1 access was restored.
Reference: Remote maintenance software Anydesk struggles with disruptions
Victim: AnyDesk Software GmbH
AnyDesk is a remote access solution that allows users to remotely access computers over a network or the internet. The program is very popular with the enterprise, which use it for remote support or to access colocated servers.
The software is also popular among threat actors who use it for persistent access to breached devices and networks.
Reference: AnyDesk says hackers breached its production servers, reset passwords
Reference: AnyDesk Incident Response 5-2-2024
Reference: IT security incident: Anydesk confirms break-in into production systems
Incident: Telecom Namibia Confirms Cyberattack
Telecom Namibia has confirmed a cyberattack that led to the theft of sensitive customer information, including ID numbers, payslips, and banking details. This confirmation follows an earlier denial by the company’s CEO, Stanley Shanapinda, regarding reports of a data breach.
Reference: Telecom confirms cyberattack – nbc
Victim: Telecom Namibia
Telecom Namibia
Reference: Telecom Namibia Statement on Cyber Incident
Reference: Compass Group Hit by Medusa Ransomware
Reference: Medusa Ransomware Group Targets Compass Group Australia
Incident: Ransomware Attack at NZ Compass Communications
The RA World ransomware group has claimed responsibility for a cyberattack targeting Auckland-based telecommunications provider Compass Communications. According to RA World’s darknet leak site, the group alleges it has stolen 250 gigabytes of data, including financial records, customer details, human resources files, and project-related information. Although the group has not disclosed a ransom amount, it has set a payment deadline of January 1, 2025.
Compass Communications confirmed the breach in a statement.
Victim: Compass Communications
Compass Communications, established in 1995, is a Kiwi-owned provider of broadband and mobile services for businesses and individuals with over 100 employees.
Threat Actor: RA World
RA World, active since at least April 2023, primarily targets organizations in the United States and South Korea. The group utilizes a modified variant of the Babuk ransomware, which includes a built-in messaging application for victim communication. They reportedly exploit poorly secured internet-facing systems to gain initial access, followed by credential theft and lateral movement within the network. Security researchers have also suggested a possible link between RA World and a Chinese hacking group known as Bronze Starlight.
Reference: New Zealand Telecom Provider Compass Communications Confirms Ransomware Attack
Reference: Exclusive: Kiwi telco Compass Communications confirms ransomware attack
Incident: French Ride-on Mower Manufacturer Tries to Recover from Ransomware Attack
On February 2nd 2024, Etesia SAS in France was the victim of a major cyber-attack, which rendered virtually their entire IT network and server data unavailable. As a result, the whole operation was effectively shut down from that date when the attack was discovered. This meant that the company lost all IT related services, emails, production, parts distribution, manufacturing etc.
Nearly two months later, the investigation is ongoing and no ransom has been paid to the pirates. The company hopes to rebuild cash flow as it resumes shipments, trying to prevent lay-offs. All employees should be able to resume work by mid April, with all production lines and shipping services back in operation.
Victim: Etesia
ETESIA is the only French manufacturer of ride-on mowers in the Alsace with a workforce of 160.
Reference: Green spaces: Etesia tries to recover from its cyberattack
Reference: ETESIA SUFFER CRIPPLING CYBER-ATTACK
Reference: Etesia victim of a cyberattack, 160 employees on partial activity
Incident: Malware Turns Off Traffic Lights in Liechtenstein
On Saturday morning, February 3, 2024, there was a total failure of the traffic lights in the Gnalp-Steg tunnel in Liechtenstein. According to initial assessments by the manufacturer, the failure was caused by malware. How this got onto the traffic lights' server is currently the subject of investigations.
"Traffic control was carried out manually on Saturdays and Sundays by employees of the Office for Civil Engineering and Geoinformation. This meant that traffic could be managed without problems at the weekend. On Monday, February 5, 2024, a construction site traffic light was set up to temporarily regulate traffic in the tunnel. During this phase, short waiting times are to be expected in some cases. The responsible authority and the manufacturer of the traffic lights are working on restarting the traffic lights. The restart should take place before the weekend.}
Reference: Malware turns off traffic lights in Liechtenstein
Reference: Hacker attack on Steger traffic light: Was it negligent?
Victim: Liechtenstein
Liechtenstein
Reference: Failure of the traffic light system in the Gnalp-Steg tunnel
Incident: DDoS attack at Times of Malta
Cybercriminals targeted the Times of Malta website on Tuesday morning. Servers were flooded with millions of requests, but no data breach suspected. No source has been identified in the attack.
“The attack lasted several hours but thanks to our tech team’s work to mitigate it, end users were only impacted for a brief period,” Times of Malta online editor Bertrand Borg said.
Victim: Times of Malta
Times of Malta
Reference: Times of Malta targeted in major DDoS cyberattack
Incident: Russian Drone Control Programs Breached by HUR
Ukrainian hackers working within Ukraine's Military Intelligence (HUR) have successfully breached Russian drone control programs. The servers responsible for the “friend or foe” identification system for Russian drones ceased functioning, resulting in its military losing access to its drones.
Reference: Rashists have a large-scale failure of their drone control program: details of the GUR cyberattack
Victim: Russian Military
Russian Military
Reference: HUR Initiates Cyberattack on Russian Drone Control Programs
Incident: DDoS Attack on Icelandic News Website mbl.is
An attack was launched on the web services of mbl.is this afternoon. The attack took place around 5:15 PM and the website was down for a few minutes. Árvakur's technicians responded quickly and the website was back online quickly and safely.
Reference: A cyberattack was carried out on mbl.is
Reference: A cyber attack was carried out on mbl.is
Incident: Ignitis ON Customers Unable to Charge Cars in Lithuania
On Sunday afternoon, some Ignitis ON users were disconnected from the Ignitis ON app, were unable to charge their electric vehicles, and all the company’s charging points in Lithuania were disconnected. A few hours later, all Ignitis ON charging points were restored and users disconnected from the app were also able to use the charging service again.
Hackers are suspected to have gained unauthorized access to the data of the EV charging service system, which operates in the cloud, and to have taken the information of around 20,000 customers, including their names, email addresses, a list of user authentication tokens (RFID).
Reference: Hackers leak data data of around 20,000 Ignitis ON customers in Lithuania
Victim: Ignitis Group
Lithuanian energy company Ignitis Group
Reference: Data of 20,000 Ignitis ON clients leaked in cyber incident
Reference: Update: Services in 18 hospitals in Romania impacted by ransomware cyberattack
Reference: UPDATE Cyber attack on several hospitals in Romania: List of the 18 medical units attacked by hackers
Incident: Cyberattack on a technology company Aztech Global in Singapore
Aztech Global Ltd wishes to inform ".... experienced a cybersecurity incident. Cyber criminals gained unauthorized access to its IT network and deployed a ransomware attack. ..the Group took immediate action, including shutting down all its servers over the lunar new year break. .The cybersecurity incident does not have any material impact to the Group’s financials or its operations."
Reference: Aztech Global suffers ransomware attack on IT network Read more at: https://ciosea.economictimes.indiatimes.com/news/security/aztech-global-suffers-ransomware-attack-on-it-network/107692042
Victim: Aztech Global Ltd
Aztech Global is a technology company based in Singapore
Reference: Cybersecurity Incide
Incident: Meduza Media Outlet Faces “most Intense Cyber Campaign Ever”
The Russian independent media organization Meduza said that it has been targeted by an “unprecedented” cyber campaign ahead of the upcoming presidential election this month. “In February 2024, the Russian authorities launched a series of cyberattacks against Meduza, more intense than any we’ve ever faced,” the organization said in a statement on Monday.
There is no evidence so far that the attacks were conducted by the Russian state, apart from Meduza’s statement.
Reference: Meduza, Russian-Language News Outlet, Says It Faced Unprecedented Attacks
Victim: Meduza
Meduza markets itself as one of the few Russian independent media outlets whose coverage remains free from control or censorship by the Kremlin. Meduza relocated its office to Latvia back in 2014, and people living in Russia today can only access its website through a VPN.
In 2023, the Russian government designated Meduza as an “undesirable organization” in Russia, subjecting it to heavy fines and potential prison sentences for employees.
Reference: Meduza is facing the most intense cyberattack campaign in its history
Reference: Russian independent media outlet Meduza faces ‘most intense cyber campaign’ ever
Incident: Ransomware at Logistics Company AB Texel in The Netherlands
"On February 15, 2024, AB Texel fell victim to the Cactus ransomware group. The recovery operation was immediately initiated. The attack has no impact on our services. Our operation continues, we supply our customers. We keep customers and employees informed." says a statement on the company website. "AB Texel takes this incident very seriously and has filed a report with the police and immediately reported it to the Dutch Data Protection Authority. The digital attack ended at the end of March."
Victim: AB Texel
AB Texel : Logistics Company in The Netherlands
Reference: Notification
Incident: South Australian Bakery Vili’s Targeted in Cyberattack.
“Vili’s Family Bakery experienced a cyber incident on February 15 within the company’s IT systems that impacted emails and our ordering and invoicing capabilities,” a company spokesperson told The Adviser. Black Basta claims the attack and are threatening to release it within the next week. The attack appeared to have no impact on Vili’s operations.
Vili's Family Bakery has a distribution network across Australia and around the world.
Victim: Vili Family Bakery
Vili's Family Bakery bakes authentic pies, pasties and sweets for distribution across Australia and globally around the world.
Reference: Black Basta claims 350GB stolen from Vili’s
Reference: Cyber attack leaves Vili’s dry as pie giant investigates the sauce
Incident: Liquid Transportation Carrier GCA Nederland Hit by Ransomware Attack
The claim of a cyberattack against the carrier GCA (Charles André Group) in the Netherlands appeared on Monday, February 26, 2024, on the RansomHouse showcase site.
In a message addressed to its customers the carrier GCA (Charles André Group) says it was the victim of a cyberattack on the night of February 17 to 18. "As a precautionary measure, we have decided to cut off external Internet access to our systems while we carry out a complete diagnosis of the situation and can restart securely as soon as possible," we can read there. For the time being, "the usual email addresses, landlines, EDI and API connections are not functional." In fact, the reception line, in particular, rings into the void.
Victim: GCA Nederland
GCA Nederland is part of the pan European logistics provider Groupe Charles Andre. A specialist in the transport and logistics of liquid chemicals, gas and liquid food products.
Reference: RansomHouse Adds Webber International University, GCA Nederland to Victim List
Reference: GCA: Claim Appears on RansomHouse Storefront
Incident: Cyberattack on Ball Bearings Manufacturer SKF in Sweden
SKF Mekan was targeted in a cyberattack that disrupted its IT systems. The attack, which was reportedly stopped by the company's security team, had an impact on the company's operations. The incident is believed to have been a ransomware attack, with the attackers seeking financial gain.
Victim: SKF
SKF is the world's largest bearing manufacturer and employs 44,000 people in 108 manufacturing units. It has the largest industrial distributor network in the industry, with 17,000 distributor locations encompassing 130 countries.
Reference: Cyber attack against Katrineholm’s company
Incident: Ransomware Attack at HAL Allergy Impacts Customer Deliveries
HAL Allergy was hit by a ransomware attack on February 19, 2024. HAL Allergy engaged external cybersecurity experts to assist in restoring the affected network and investigate the issue.
On March 22 the company website states: "Following the ransomware attack on February 19, several of HAL Allergy’s IT systems have been restored. The recovered systems were gradually activated in recent weeks to enable deliveries to most of our customers. As of March 14, orders that predate the ransomware attack and were ready for shipment have now been delivered to customers in Germany and the Benelux. Orders placed after February 19 will be processed as of today, March 22, except for the so-called named patient products. As soon as the named patient deliveries can also be processed you will be informed."
Victim: HAL Allergy Group
HAL Allergy Group is a pharmaceutical company that develops, produces and sells products for allergy diagnostic and allergen immunotherapy (AIT).
Reference: First deliveries have been successfully resumed
Reference: NOTIFICATION STATEMENT
Reference: The official Twitter account of Copenhagen Airport (CPH)
Incident: EAS Europe Says it Shut Down Operations after Ransomware Attack
On February 26th EAS Europe was the victim of a ransomware attack. The attackers encrypted the EAS Europe servers and have potentially stolen sensitive data from the EAS servers. Customer and supplier data may have been taken.
This incident has caused the operations in the Netherlands to shut down while we restore the back ups.
We sincerely apologize for any delays caused by this incident.
Victim: EAS Europe
EAS develops, produces and sells components and turnkey systems for quick tool changes on plastic injection molding machines as well as on presses, stamping and die casting machines.
Reference: Ransomware attack
Incident: Politically Charged Promo Code Linked to Cyberattack at Burger Singh, India
Burger Singh, a popular Indian fast-food chain, faced a cyberattack orchestrated by a Pakistani hacking group Team Insane PK. The Indian fast-food chain drew the hacker group's attention when it released a politically charged promo code, 'FPAK20'
The company shared the news through their social media account on X (formerly Twitter), choosing to temporarily not act against the security breach. Rather than swiftly erasing the digital graffiti, Burger Singh made an unconventional decision to leave it up for a day, transforming the incident into what they dubbed as an "open mic night for hackers".
Victim: Burger Singh
Burger Singh, a popular Indian fast-food chain
Reference: Pakistani hackers attack Burger Singh website; company responds with humour
Threat Actor: Team Insane PK
Team Insane PK is a group known for its activities in the realm of religious hacktivism. This group, allegedly based out of Pakistan, has been involved in numerous cyberattacks targeting Indian businesses and government websites. Their operations often involve the use of Distributed Denial of Service (DDoS) attacks, a common tactic in cyber warfare that overwhelms a network with traffic, rendering it inaccessible.
Religious hacktivism, a form of digital jihad, involves the use of digital tools and cybercrime techniques to carry out attacks driven by religious ideologies. These attacks aim to promote a certain belief system or discredit others.
Reference: Pakistani group hacks Burger Singh website, company reacts in hilarious manner
Incident: Half of Estonian Population affected in Data Breach at Healthcare Supplier Allium UPI OÜ
Allium UPI OÜ, a major supplier of pharmacy and hospital supplies in Estonia, Latvia and Lithuania is informing its Estonian customers about a data leak. According to the report almost half of the Estonian population is affected by a cyberattack on a customer card system for pharmacies. Those affected are now being informed. The data breach comprised information from the years 2014 to 2020, since it concerned a backup copy of a database that did not hold real-time information.
Victim: Allium UPI OÜ
Allium UPI OÜ's field of activity is pharmacy cosmetics, dietary supplements, vitamins and hospital supplies, wholesale of medical technology.
Allium UPI is, along with the Apotheka pharmacy chain and the Pet City chain of stores, a part of the Magnum pharma conglomerate, owned by Margus Linnamäe, a reclusive businessman who also owns the media group that publishes daily Postimees and its related titles, alongside several major companies.
Reference: Estonia: Almost 700,000 customer data leaked from pharmacy service provider
Reference: Cybercriminals steal data of around 700,000 Apotheka pharmacy customers
Incident: Ransomware Attack at New Zealand Auxo Software Company
Confidential client information has been stolen in a cyberattack and blackmail attempt by overseas hackers against Software company Auxo.
Auxo software is used in 50 per cent of vehicle workshops nationwide, and at 40 per cent of NZ vehicle dealers.
Auxo - which is wholly owned by the Motor Trade Association (MTA) - will not say how many clients may have been affected nor how much the ransom demand was for.
Victim: Auxo
Auxo software is used in 50 per cent of vehicle workshops nationwide, and at 40 per cent of NZ vehicle dealers. Auxois wholly owned by the Motor Trade Association (MTA) in New Zealand.
Reference: Auxo calls in cyber security experts
Reference: Impact of Auxo cyber security issue minimised
Reference: Cyber attack: Hackers steal confidential client information from auto software company Auxo, demand ransom
Incident: German Manufacturer Kreisel Struggles to Continue Business Operations
Kreisel GmbH & Co. KG is an internationally operating plant manufacturer based in Krauschwitz. It now finds itself in difficult waters.
The company's current financial difficulties are primarily due to increased financing costs and a deterioration in earnings due to the consequences of the corona pandemic, the increase in raw material and energy prices, and a cyberattack. The latter had limited the company's ability to act for several weeks in the first quarter of 2024. The geopolitical crisis of recent years with wars and embargoes did the rest. Despite a generally good demand situation, it led to a weak economy and cautious investment decisions on the part of customers. Since the financial difficulties could not be remedied out of court despite the management's restructuring efforts, the management dutifully and logically filed for insolvency on November 19, 2024.
Reference: This is how Kreisel wants to get back on its feet
Victim: Kreisel GmbH & Co
Kreisel, a medium-sized company, is an expert in bulk material handling and specializes primarily in customized conveyor systems.
In 1912 Wilhelm Kreisel founded the metalworking and autogenous welding company in the town of Keula. The first product manufactured was air filters. Kreisel GmbH & Co. KG developed over the decades into an internationally active plant manufacturer. In addition to its headquarters in Krauschwitz, the company also has locations in Hamburg, Bavaria and the Harz region.
Reference: Traditional conveyor system manufacturer in self-administration: KREISEL uses modern judicial restructuring to reposition itself
Reference: What the remediation process means for the plant manufacturer
Reference: Cyberattack on global plant manufacturer Kreisel in Krauschwitz
Incident: Wheels Manufacturing, a CO Bicycle Parts Maker, Hit In Cyberattack
Louisville, Colorado-based Wheels Manufacturing, LLC, suffered a cyberattack between early October and early November where attackers were able to exfiltrate personal information.
“We have been informed that between October 7, 2024 – November 4, 2024, malware was present on our website potentially resulting in unauthorized access to customer information,” the company said in a December 6 letter to victims. “Because our records indicate that you placed an order with us during the impacted date range, we are notifying you of this security incident.”
Wheels Manufacturing is one of the world’s largest suppliers of high-quality bicycle derailleur hangers, small parts, repair parts, and specialty tools, according to the company’s LinkedIn profile.
Reference: CO Bicycle Parts Maker Hit In Cyberattack
Victim: Wheels Manufacturing LLC
Wheels Manufacturing is one of the world’s largest suppliers of high-quality bicycle derailleur hangers, small parts, repair parts, and specialty tools, according to the company’s LinkedIn profile.
Incident: Auto Parts Company LKQ Hit in Cyberattack, Halts Operations
Automobile parts giant LKQ Corporation revealed they discovered a Canadian business unit suffered a cyberattack November 13 where attackers ended up stealing data and hurting operations.
Chicago-based LKQ specializes in automotive replacement parts, components, and services to repair and maintain vehicles. The company has 45,000 employees in 25 countries and operates numerous brands, including Keystone, Tri Star, and ADL.
In a December 13 8-K filing with the Securities and Exchange Commission (SEC), LKQ said one of its business units in Canada suffered an attack Nov. 13, disrupting business operations.
“On November 13, 2024, LKQ Corporation detected unauthorized access to information technology (IT) systems of a single business unit in Canada. The attack disrupted the business unit’s operations,” the company said in the SEC filing.
Reference: Cyberattack Halts Operations At Auto Parts Maker LKQ
Victim: LKQ
Chicago-based LKQ specializes in automotive replacement parts, components, and services to repair and maintain vehicles. The company has 45,000 employees in 25 countries and operates numerous brands, including Keystone, Tri Star, and ADL.
Incident: Production Halted at Glass Plant in Belgium
A ransomware attack hit Sprimoglass, one of the largest glass manufacturers in Belgium. As a result production was halted and down for 10 days. All 500 employees were sent home, 350 Employees were able to return to work after 10 days. The company expects to catch up on lost production time and fulfill customer orders. The financial impact is not known at this time. Ransom demanded was not paid.
Victim: Sprimoglass
Sprimoglass is a large glass manufacturer in Belgium
Reference: Hackers claim Sprimoglass attack: “We punish companies that neglect employee and customer privacy”
Reference: After cyber attack Duvel Moortgat: production at second major Belgian company Sprimoglass also largely halted for the same reason
Reference: Sprimoglass Company, from Sprimont, Victim of Cyberattack
Reference: After the Duvel Moortgat cyberattack: production is also largely halted at the second major Belgian company Sprimoglass for the same reason
Incident: Belgian Telecom Operator EDPnet Reports Cyberattack
Hackers have penetrated Edpnet’s computer systems. Although the Belgian telecom operator does not report data theft. Hackers were able to penetrate its administrative systems.
Customers have been unable to log into their accounts since Saturday. According to Edpnet, this is caused by technical problems. No impact can be felt on Internet services, the company said. Edpnet provides these internet services as an independent part of Citymesh, a recent player in the Belgian telecom market.
Victim: Edpnet
Edpnet; Belgian telecom operator
Reference: Belgian telecom operator Edpnet reports cyber attack on systems
Reference: Cybersecurity status: Recovery after cyberattack
Incident: Cyberattack at Belgium Goed pharmacies and home care stores
The network of Goed pharmacies and home care stores, has been the target of a cyber attack. Hackers managed to steal and encrypt data.
Goed's home care stores and pharmacies remain open in the meantime, but are experiencing some disruptions. For example, payment with Bancontact is not possible everywhere and there are problems consulting digital prescriptions.
"A restart plan is being worked on to restart our systems step by step and in a controlled manner in the coming hours and days."
Reference: Cyber attack on pharmacies and stores CM
Victim: Goed
Goed, Belgium, has about 90 pharmacies and about 35 home care stores. Last year, the chain sold its more than 60 hearing centers, which have been owned by Audika since September, but are almost all located in Goed stores. These hearing centers operate on a separate network and are not expected to experience any disruption.
Reference: Still experiencing disruption at CM healthcare store chain Goed after cyber attack
Incident: Cyberattack Against Two Major French Media Outlets
Several Altice group media outlets were confronted with a cyberattack . According to the two media, this action was claimed by the Epsilon group. Altice Médias group were affected, including those of BFMTV, RMC, RMC Sport, "Estelle Midi", "Apolline Matin" and "Les Grandes gueules".
"Well then @KremlinRussia_E we lost members? That'll teach you to speak badly of President Macron" could be read on these X accounts. Another message, accompanied by the hashtag #FreePalestine, claimed responsibility for the attack by attributing it to the Epsilon group, a group of hackers behind the theft of personal data from some of the customers of the IT brand LDLC in early March
Reference: Cyberattack: what we know about the hacking of “unprecedented scale” of government services
Reference: BFMTV and RMC victims of hacking on the social network X
Reference: BFMTV and RMC victims of a cyberattack on social networks
Victim: RMC BFM
RMC BFM is a French media company, division of CMA CGM.
In 2000, the NextRadioTV company was founded by Alain Weill. In 2021, NextRadioTV becomes Altice Média to accentuate the group's multi-media convergence around 5 themes: information, economy, sport, high-tech and discovery. Four months after announcing that it had reached a deal, Altice completed the sale of its media division in July 2024 to CMA CGM. The company was later renamed RMC BFM.
Incident: Cyberattack on Railway Company in Iran
Hacker group APT Iran has infiltrated the cyber infrastructure of Iran's Railway Company in the latest such attack on government networks, with documents revealing mandates for female employees to wear Islamic attire.
The Cyberban News Agency confirmed the hack from the anti-government group though the agency downplayed the extent of the breach, dismissing reports of an attack on the main railway infrastructure as propaganda.
APT Iran claimed the breach aimed to alert railway officials about security lapses after previous breaches of the IranCell Communication Services Company and State Organization for Registration of Deeds and Properties.
Among the leaked documents is a directive signed by Mohsen Tabatabaei Atabak, the Director General of Planning and Monitoring of Passenger Services, outlining guidelines for employee conduct, including adherence to mandatory hijab for female staff.
Reference: Cyber Attack On Iran’s Railway Network
Victim: Intermarché
Intermarché supermarket chain in Europe
Incident: Intermarché Hackers Took Advantage of Mestdagh Brand Take-over-phase
Dozens of former Mestdagh supermarkets of Intermarché fell victim to a cyber attack last Sunday. For some stores this led to supply problems.
Cybercriminals targeted the former Mestdagh supermarkets that were taken over by Intermarché on Sunday – and whose IT systems were not yet fully integrated with those of the Musketiers. The attack was mainly aimed at the internal ordering system. The attackers also demanded a ransom , L'Echo reports.
"Not all stores were affected in the same way. The most significant impact of this cyberattack was on internal order flows and in some cases had repercussions on deliveries, causing supply problems. However, there were no leaks of personal data," said an Intermarché spokesperson. Stores, in Waterloo in particular, reflected supply disruption on the shelves.
Everything should be back to normal by Friday at the latest, says the retailer, who has filed a complaint.
Reference: Former Mestdagh taken over by Intermarché victims of cyberattack
Reference: Cyber attack on Intermarché’s Mestdagh stores
Incident: Cyberattack on Street Newspaper in United Kingdom
The Big Issue Group experienced a cyber incident. “On becoming aware of this, we took immediate steps to restrict access to our systems, working with external IT security experts, and the investigation into the incident is ongoing,” said the company’s chief executive Paul Cheal.
Victim: The Big Issue,
The Big Issue, a street newspaper in the United Kingdom famed for providing homeless people with a legitimate income by paying them as vendors to distribute the magazine.
Reference: Ransomware gang attacks the Big Issue, a street newspaper supporting the homeless
Incident: Cyberattack on US Provider of Medical Products
On or about March 27, 2024, OraSure Technologies determined that it had experienced a cybersecurity incident in which an unauthorized third party gained access to portions of its information environment.
On April 10, 2024, OraSure Technologies reported the incident in a Form 8-K filing, according to the filing, OraSure Technologies’ investigation into the extent of the incident remains ongoing.
Reference: OraSure reports data breach, says impact contained
Reference: Files taken from Orasure systems in cybersecurity incident
Victim: OraSure Technologies
OraSure Technologies is a medical equipment manufacturing company based in Pennsylvania. Founded in 1987, OraSure Technologies, together with its wholly-owned subsidiaries, DNA Genotek, Diversigen, and Novosanis, provides its customers with end-to-end solutions that encompass tools, services and diagnostics. Additionally, OraSure Technologies and its family of companies are leaders in the development, manufacturing, and distribution of rapid diagnostic tests, sample collection and stabilization devices, and molecular services solutions designed to discover and detect critical medical conditions.2 Headquartered in Bethlehem, Pennsylvania, OraSure Technologies employs over 500 individuals.
Reference: OraSure Technologies Data Breach Investigation
Reference: OraSure Technologies, Inc.
Reference: Possible Customer Data Breach Due to Hacker Attack
Incident: Broadcasting of Ukrainian TV Interrupted
One of Ukraine's main media companies, 1+1 Media, said its satellite TV channels had suffered a cyberattack on Wednesday. It said in a statement that 39 channels, including some of its own, were currently unavailable. Ukraine's 24 Channel said on its website that its satellite broadcast had also been affected as hackers "launched their propaganda". "After two hours of the attack, the signal was restored, but the attack started again," it said.
European provider SES that operates Astra told Reuters a few dozen video distributors in Europe faced outages caused by "external radio frequency interference" on Wednesday. It added that satellites were safe.
Reference: Russian cyber attacks on satellite operating by SES and Eutelsat to interrupt the work of Ukrainian media
Victim: SES S.A
SES S.A., trading as SES is a Luxembourgish satellite telecommunications network provider supplying video and data connectivity worldwide to broadcasters, content and internet service providers, mobile and fixed network operators, governments and institutions.
SES is one of the world's leading satellite owners and operators with over 70 satellites in two different orbits: geostationary orbit (GEO) and medium Earth orbit (MEO).These include the well-known European Astra TV satellites, the O3b and O3b mPOWER data satellites and others with names including AMC, Ciel, NSS, Quetzsat, YahSat and SES.
Victim: 1+1 Media
1+1 Media, Ukrainian media company
Victim: Eutelsat Communications SA
Eutelsat Communications SA
Reference: Ukraine’s 1+1 media group satellite TV channels hit by cyberattack
Incident: National Outage at Omni Hotels after Cyberattack
Omni Hotels & Resorts has been experiencing a chain-wide outage that brought down its IT systems on Friday, impacting reservation, hotel room door lock, and point-of-sale (POS) systems.
The official website was down on Friday, and an alert was added after it came back online over the weekend, warning customers, "Dear valued guest, we are currently experiencing technical difficulties, please try back at a later time."
According to some Omni Hotels employees, the IT team is now manually restoring affected servers from scratch, with staff being informed that systems will be available again on Thursday.
Omni Hotels & Resorts was the recent target of a ransomware attack by the Daixin Team ransomware group. The incident led to disruptions across Omni Hotels & Resorts, and the Daixin Team and claimed the theft of information pertaining to visitors from 2017 onwards.
“The attack is already pretty significant; however, considering the ransom amount has been dropped and the systems have been restored, it is likely that Omni Group has a good backup of information. Financial information is probably protected through encrypted to PCI requirements.
“This is a new target vertical for the Daixin ransomware group. In the past, they have mainly gone after healthcare providers.
Victim: Omni Hotels & Resorts
Omni Hotels & Resorts operates 50 hotels and resorts across the United States, Canada, and Mexico, with approximately 23,550 rooms and 28 golf courses.
Reference: Omni Hotels experiencing nationwide IT outage since Friday
Reference: Omni Hotels says widespread outages caused by cyberattack
Reference: Experts weigh in on Omni Hotel ransomware incident
Reference: Cyberattack hits Omni Hotels systems, taking out bookings, payments, door locks
Victim: International Paper
International Paper, US
Victim: FlyDubai
FlyDubai, airline in UAE
Victim: Eurotrol B.V.
Eurotrol is a medical Equipment and Supplies Manufacturing. A specialist in custom-made quality control solutions for in vitro diagnostics.
Victim: NorthBay Health
NorthBay Health operates two hospitals and multiple clinics in Solano County, USA
Victim: Pharmascience
Pharmascience is a large Canadian-owned pharmaceutical company,
Victim: San Agustín Commune
San Agustín Commune, municipality in Argentina
Incident: IVC Technologies, a Vibration Monitoring Firm, Suffers Cyberattack
Lebanon, Ohio-based IVC Technologies fell victim of a cybersecurity incident this past October that resulted in a threat actor obtaining unauthorized third-party access to certain personal data.
“We recognize that cybersecurity is a significant concern in today’s world, and we know that many individuals have been impacted by other cybersecurity incidents that are completely unrelated to IVC, such as cyberattacks impacting schools, hospitals, and other businesses,” the company said in a letter to the victims.
The company – which provides vibration analysis programs throughout the United States and has the expertise and software to diagnose equipment’s most difficult mechanical and electrical failure modes – said as of right now, there is no evidence any personal data ended up removed from our information systems.
Reference: Cyberattack Shakes Vibration Monitoring Firm
Victim: IVC Technologies
Lebanon, Ohio-based IVC Technologies provides vibration analysis programs throughout the United States and has the expertise and software to diagnose equipment’s most difficult mechanical and electrical failure modes.
Incident: Computer Accessory Maker, Targus, Hit In Cyberattack
Computer accessory maker, Targus, fell victim to a cyberattack this past April and it now letting victims know about what happened.
Targus is a privately owned multinational mobile computing accessories company that designs, manufactures, and sells laptop and tablet cases, computer accessories such as mice, keyboards, and privacy screens, as well as universal docking stations.
“On or around April 6, 2024, Targus discovered that it had fallen victim to a cybersecurity incident,” the company said in a letter to its victims. The company said it “promptly engaged a team of cybersecurity experts to assist it with conducting a forensic investigation” in an effort to determine whether any data or personal information ended up impacted by the incident.
Reference: Computer Accessory Maker Hit In Cyberattack
Victim: Targus
Targus is a privately owned multinational mobile computing accessories company that designs, manufactures, and sells laptop and tablet cases, computer accessories such as mice, keyboards, and privacy screens, as well as universal docking stations.
Incident: ENGlobal, Energy Contractor, Suffers Ransomware Attack
A major contractor for the energy industry, ENGlobal Corp., confirmed it is dealing with a ransomware attack from last week that limited some of its operations.
Houston, Texas-based ENGlobal filed a report to the Securities and Exchange Commission (SEC) Monday night explaining it discovered the ransomware attack November 25.
“On November 25, 2024, ENGlobal Corporation became aware of a cybersecurity incident,” the company said in an 8-K report to the Securities and Exchange Commission (SEC). “The preliminary investigation has revealed that a threat actor illegally accessed the company’s information technology system and encrypted some of its data files.
“Upon detecting the unauthorized access, the company immediately took steps to contain, assess and remediate the cybersecurity incident, including beginning an internal investigation, engaging external cybersecurity specialists, and restricting access to its IT system,” the company said.
Reference: Energy Contractor Hit In Ransomware Attack
Victim: ENGlobal
NGlobal designs and builds automated control systems used by commercial companies and the federal government. The company started up in 1985 and it offers planning and facility design in the energy field on a global basis. The company reported $5.7 million in revenue for the quarter ended in September and $18.4 million for the first nine months of the year.
Incident: Medical Device Maker, Artivion, Hit in Ransomware Attack
Medical device manufacturer, Artivion, Inc. suffered a ransomware attack late last month that forced the company to take systems offline and disrupted orders and shipments.
Company officials identified and began taking measures to address a cybersecurity incident on November 21, 2024, the company said in an 8-K report to the Securities and Exchange Commission (SEC).
“Artivion’s response measures included taking certain systems offline, initiating an investigation, and engaging external advisors, including legal, cybersecurity, and forensics professionals to assess, contain, and remediate the incident.
“The incident involved the acquisition and encryption of files. The Company is working to securely restore its systems as quickly as possible and to evaluate any notification obligations,” the company said in its filing.
Reference: Medical Device Maker Suffers Ransomware Attack
Victim: Artivion, Inc.
Kennesaw, Georgia-based Artivion, which reported third-quarter revenues of $95.8 million, is a leading cardiac and vascular surgery company focused on aortic disease. Artivion’s four major groups of products include: Aortic stent grafts, surgical sealants, On-X mechanical heart valves, and implantable cardiac and vascular human tissues. Artivion markets and sells products in more than 100 countries worldwide.
Incident: Kurita America, Water Treatment Chemical Company, Hit By Ransomware
Japan’s Kurita Water Industries Ltd.’s Minnesota-based U.S. headquarters suffered a ransomware attack at the end of November, company officials said.
Kurita America Inc., a consolidated subsidiary in North America, found evidence of unauthorized access and ransomware infection on multiple servers.
On Friday November 29 at 3 p.m., there was an alert detected on KAI’s security monitoring system. At that time, the company conducted an investigation with external experts leading to the confirmation that multiple servers had experienced a ransomware attack and had been encrypted.
Reference: Water Treatment Chemical Company Hit By Ransomware
Victim: Kurita America Inc.
Kurita creates chemicals used to treat water and wastewater. Additionally, the company, founded in 1949, is one of the largest manufacturers of the products, with 2024 earnings of $2.4 billion. Most of the company’s sales are in Japan and across Asia, but 17 percent of sales are in North and South America.
Incident: Australian Call Center Operator Hit by Lockbit Ransomware Attack
Nissan Oceania has revealed the call centre it set up to handle customer inquiries after a cyber incident late last year has itself been breached. The car maker said it enlisted OracleCMS, which operates call centers across Australia, to manage the “dedicated cyber incident call centre” it set up after a December 5 breach that impacted up to 100,000 customers.
LockBit appears to be behind the attack on OracleCMS. LockBit has published more than 60 gigabytes of data in a single compressed archive. A folder named "clients" contains more than 50 folders for organizations, ranging from local councils to aged-care services. OracleCMS has so far declined to comment on the incident
Reference: Huge trove of Australian client data leaked following OracleCMS call centre hack
Reference: OracleCMS cyber security incident
Reference: OracleCMS data breach
Reference: Notice: Cyber security incident impacting Nissan Australia and New Zealand
Reference: Nissan A/NZ’s outsourced cyber incident call centre breached
Incident: Irish Telecommunications Company Hit by Cyberattack
Telecoms company Magnet+ is investigating a possible breach of its systems that may have exposed the private information of staff and customers.
The incident, which took place on April 8th, was picked up by the company’s internal IT security systems. Magnet+ said it disconnected all potentially affected servers from the company’s network, stopping the onslaught.
Victim: Magnet+
Magnet+ , Telecoms company
Reference: Telecoms company Magnet+ investigating possible cyber attack
Incident: Customers affected after Cyberattack at Swedish IT Company
IT provider Advania was hit by a cyber attack on Tuesday attack.
Around 60 of the company's customers are affected, of which between 10 and 15 are healthcare centres. "We cannot read any medical records or take any samples and can only write paper prescriptions. We cannot receive any patients," says Per Svensson, director of operations at Herkules care center in Borås, to Borås Tidning. Some health centers have closed completely on Wednesday, while others receive patients on drop-in and write with paper and pencil because they do not have access to the medical record system.
There is no indication that ransomware has been introduced into the system. There is currently no forecast for when the problem may be fixed.
Reference: Cyberattack hits Swedish cloud provider Advania, healthcare services impacted
Victim: Advania
Advania, IT provider in Sweden.
Reference: Cyber attack against an IT supplier – around 60 customers are affected
Incident: Production Shut Down at Swedish Dairy
During Tuesday, Norrmjerier discovered that the dairy in Umeå had been exposed to a cyber attack. All production in Umeå is down and a crisis management team has been activated.
By Tuesday afternoon, Norrmejerier announced the resumption of food fat production at the Umeå dairy following the cyberattack. However, other operations remained suspended as efforts to investigate the cyberattack were underway.
Despite the disruption, milk collection has been ongoing, with transportation to Norrmejerier’s daries in Burträsk and Luleå, which are unaffected by the attack. Additionally, Arla and Falköping dairy have extended assistance to Norrmejerier.
Reference: How Norrmejerier moves on after the IT attack – “Costly”
Reference: Norrmejerier has been exposed to a cyber attack
Reference: Norrmejerier Targeted by Cyberattack
Victim: Norrmejerier
Norrmejerier is a high-tech food industry
Reference: Cyber attack against Norrmejerier in Umeå – production down
Reference: Electrica Group Tackles Ongoing Cyberattack
Incident: Cyberattack on Austrian Electronics Company BECOM
There was a cyber attack on the electronics company BECOM. Encryption was prevented. The incident occurred on Tuesday, April 23rd. Management announced that they intervened in time and restricted the connection
The top priority now is to be able to restart the production areas - specialists are currently working on this.
Victim: BECOM
Austrian Electronics Company BECOM
Reference: BECOM Electronics was the target of a cyber attack
Incident: Ransomware Attack at Swiss BKW Building Solutions Group
At the beginning of April, the Swisspro companies belonging to the BKW Building Solutions Group became the target of a cyber attack. The company confirmed this when asked by inside-it.ch. "Ransomware was discovered in Swisspro's old IT environment," wrote the BKW media office. "The current operational IT environment of both Swisspro and the other BKW companies is not affected. Despite the incident, Swisspro is able to provide services to customers," it is emphasized.
Victim: BKW Building Solutions Group
Swisspro companies belong to the BKW Building Solutions Group
Reference: Cyberattack on BKW subsidiary Swisspro
Incident: Barnett’s Couriers Shuts Down Operations after Cyberattack
Long-running Wollongong trucking operator Barnett’s Couriers has closed, blaming a crippling cyber-attack earlier this year for its demise. A recorded message on an emergency mobile number confirmed the news.
“As you know, Barnett’s Couriers has been the victim of a cyber incident and consequently our business cannot operate productively,” said the message. “Although we have been working tirelessly with leading IT consultants to restore our systems, regrettably we have been unable to overcome these challenges and have made the difficult decision to cease operating Barnett’s Couriers.
“We want to thank you, our customers, for the loyalty you have shown to our business over 40 years.”
Victim: Barnett’s Couriers
Wollongong trucking operator: Barnett’s Couriers
Reference: Barnett’s shuts after cyber attack cripples Illawarra trucking company
Reference: Illawarra trucking company closes doors after alleged cyber-attack
Incident: Kansas City Scout System Systems Shut Down
Early in the morning on Thursday, April 25, 2024, all KC Scout systems went down until further notice. The shut down affected the service's dynamic information boards, the official website as well as the real-time camera system.
Official statement from MoDOT and KDOT (June 20): "..on the morning of Thursday, June 20, motorists on Kansas City metro highways will see real-time messages displayed on the highway digital signs. Returning real-time information is considered the first step to restoring all KC Scout systems and services. Additional restoration efforts continue and include having the website operational, camera views available online, and camera stream access for media partners."
Victim: KC Scout,
KC Scout is a a bi-state initiative between the Missouri and Kansas Departments of Transportation to provide travel and traffic information and service for the Kansas City metro area.
Reference: Joint Statement from MoDOT and KDOT About KC Scout Services
Reference: Still crippled by cyberattack, KC Scout to test initial phases of restoration
Reference: KC SCOUT ALERT
Incident: Cyberattack at Romanian Energy Supplies
On Monday, Electrica announced it is collaborating with authorities to investigate an "ongoing cyberattack." "Initial investigations show that it was a ransomware attack. The network equipment has been removed and is not affected," Energy Minister Sebastian Burduja said. "The SCADA systems of Distributie Electric Power Romania are fully functional and insulated, and our technical teams, together with our security partners, are already on the ground to eliminate any risk."
To secure its infrastructure, Electrica Group has implemented temporary protective measures, which have led to some disruptions in customer interactions. However, the company emphasized that these measures are precautionary and designed to ensure the overall security of its operations. Electrica’s primary concern is maintaining the continuity of electricity supply while also safeguarding the personal and operational data of its customers.
Reference: Romanian energy group Electrica faces cyberattack, urges caution among consumers
Victim: Distributie Electric Power Romania / Electrica Group
Electrica Group, a key player in the Romanian electricity distribution and supply market serves over 3.8 million users with nationwide coverage for electricity supply, maintenance, and energy services, distributing electricity to customers across Transilvania and Muntenia.
Electrica was established as a National Electricity Company (CONEL) division in 1998 and became an independent entity in 2000. Since 2014, Electrica has been double-listed on the Bucharest and London stock exchanges.
Reference: Romanian energy supplier Electrica hit by ransomware attack
Incident: Merseytravel and Mersey Ferries Hit by Cyberattack
Liverpool City Region Combined Authority issued a statement on Friday afternoon saying its had been informed on Thursday by one of its third-party suppliers that it was the victim of a cyber-attack. In response the CA shut down both the Merseytravel and Mersey Ferries websites, although both appeared to be functioning normally again on Friday afternoon.
“This attack has potentially affected some of our online services provided via our Merseytravel and Mersey Ferries websites."
Reference: Cyber attack in Merseyside as ‘immediate steps taken’
Reference: Cyber attack hits Merseytravel and Mersey Ferries
Victim: Liverpool City Region Combined Authority
Liverpool City Region Combined Authority operates Merseytravel and Mersey Ferries.
Incident: BT Group Shuts Down Some of its Servers after Black Basta Ransomware Attack
Multinational telecommunications giant BT Group (formerly British Telecom) confirmed its BT Conferencing business division shut down some of its servers following a Black Basta ransomware breach. "The impacted servers do not support live BT Conferencing services, which remain fully operational, and no other BT Group or customer services have been affected."
Black Basta ransomware gang claimed they stole 500GB of data, including financial and organizational data, "users data and personal docs," NDA documents, confidential information, and more.
Reference: British telecoms giant BT confirms attempted cyberattack after ransomware gang claims hack
Victim: BT Group (formerly British Telecom)
Multinational telecommunications giant BT Group (formerly British Telecom) is the United Kingdom's leading fixed and mobile telecom provider. It also provides managed telecommunications, security, and network and IT infrastructure services to customers in 180 countries.
Reference: BT unit took servers offline after Black Basta ransomware breach
Incident: Email System Temporarily Down at Atlantic States Marine Fisheries Commission
The Atlantic States Marine Fisheries Commission (ASMFC), a fisheries management organization for the East Coast, is dealing with a cyber incident following claims by a ransomware gang that it stole data.
ASMFC said this week that its email system is down. The organization was forced to create a temporary email address and provide a phone number people can use to contact the information.
The 8Base ransomware gang added the organization to its leak site, giving officials four days to pay an undisclosed ransom. The group claimed it stole invoices, personal data, contracts and more.
In a July notification ASMFC shared that 9,895 people could affected by the data breach.
Reference: US Atlantic Fisheries Commission Goes Offline: Ransomware Attack or Routine Maintenance?
Reference: Atlantic Marine Fisheries Commission Confirms Data Breach: Nearly 10,000 Affected
Victim: Atlantic States Marine Fisheries Commission (ASMFC
Atlantic States Marine Fisheries Commission (ASMFC) is an 80-year-old organization created by Congress and made up of officials from the Atlantic coast states.
Reference: Atlantic fisheries body confirms cyber incident after 8Base ransomware gang claims breach
Incident: DDoS Attack at Port of Tyne’s Website.
The Port of Tyne confirmed its site was down for some time on Tuesday following a distributed denial of service (DDOS) attack, which attempts to overload a website to make it hard to use or inaccessible.
A spokesman for the port said operational systems, which are separate, had not been affected and all data was "safe and secure".
"Full website accessibility was restored quickly and the Port is working with all relevant parties to investigate the source of the attack," they added.
Victim: Port of Tyne
Port of Tyne
Reference: Port website hit by cyber attack
Reference: Port of Seattle shares details of a cyberattack
Incident: Ivanti Flaw Exploited in MITRE Corporation Cyberattack
MITRE's unclassified collaborative research and development network — where prototyping and other work is housed — was compromised by a foreign nation-state threat actor. MITRE’s work supports a variety of government agencies. MITRE is working to restore operational alternatives for collaboration in an expedited and secure manner.
The company said unidentified threat actors performed reconnaissance on its networks by exploiting one of its VPNs through two vulnerabilities in Ivanti Connect Secure. At the time, Ivanti said the two vulnerabilities — CVE-2023-46805 and CVE-2024-21887 — were used in attacks on at least 10 of its customers.
Reference: Advanced Cyber Threats Impact Even the Most Prepared
Victim: MITRE Corporation
The MITRE Corporation is chartered as a private, not-for-profit company to provide engineering and technical guidance for the United States Air Force.
Reference: MITRE was breached through Ivanti zero-day vulnerabilities
Reference: MITRE Response to Cyber Attack in One of Its R&D Networks
Incident: Numerous Customers Suffer from Ransomware Attack at Cloud Provider Tietoevry
Cloud hosting services provider Tietoevry announced that one of its datacenters in Sweden “was partially subject to a ransomware attack” this weekend, affecting numerous customers and forcing stores to close across the country.
According to the Finland-based technology company’s statement on Monday, the attackers used the Akira ransomware-as-a-service tools. The incident was limited to “one part of one of our Swedish datacenters” and is believed to have only impacted services to some of Tietoevry's customers in Sweden. However, these customers include Primula, a widely used payroll and HR company in Sweden, including by the majority of the country’s universities and more than 30 government authorities. Staff at these organizations cannot submit personal leave or expenses requests.
Primula customers include the Swedish State Service Centre (SSC), which itself manages administrative services including payroll for nearly 170 government agencies. Swedish businesses currently reporting issues due to the incident include cinema chain Filmstaden and retailer Rusta. As a result of the ransomware attack, Granngården announced its grocery stores across the country would be closed on Monday.
On April 24, the company reports: With the exception of efforts continuing with few customers, all other impacted customer services were fully restored by mid-March.
Reference: Tietoevry: conclusions on the ransomware attack
Malware: Akira ransomware-as-a-service
The Akira ransomware-as-a-service tools.
Victim: Tietoevry
Tietoevry is a Finnish IT services company offering managed services and cloud hosting for the enterprise. The company employs approximately 24,000 people worldwide and had a 2023 revenue of $3.1 billion.
Reference: Akira ransomware hits cloud service Tietoevry; numerous Swedish customers affected
Incident: Ransomware Attack on Skanlog Triggered Nationwide Alcohol Shortage
Systembolaget's wine and spirit distribution in Sweden was disrupted after Skanlog, a logistics company was the victim of a ransomware attack. The incident has disrupted supplies. Skanlog has not suggested when operations might return to normal. Systembolaget’s spokesperson said the company had a backup plan if its distributor was unable to resume deliveries. “It affects about a quarter of our sales volume." says Teodor Almqvist, press officer at Systembolaget.
The logistics company Skanlog told Swedish media that it first identified a ransomware attack by hackers based in North Korea on Monday morning (April 22). It was not clear how they determined a possible source, and Skanlog did not immediately respond to a request for comment.
Victim: Systembolaget
Systembolaget is Sweden's sole retailer of alcoholic beverages.
Reference: Risk of empty shelves at Systembolaget after cyber attack
Reference: Systembolaget’s shelves are at risk of being empty after a cyberattack
Reference: Shelves look empty after IT attack against Systembolaget
Victim: Skanlog
Swedish logistics company Skanlog
Reference: Alcohol sales disrupted in Sweden after reported ransomware attack
Reference: Sweden’s liquor shelves to run empty this week due to ransomware attack
Incident: Hackers Post Fabricated Statements on Czech Press Agency (ČTK) News Site
An unknown attacker posted fabricated texts that were not produced by ČTK on the news website Česká noviny (ČN), which is operated by the Czech Press Agency (ČTK).
It was a text with the headline "BIS prevented an assassination attempt on newly elected Slovak President Petr Pelligrini" and a fabricated extraordinary statement by Foreign Minister Jan Lipavský on the same. The attacker placed it on the ČN website in Czech and English. The disinformation was also published with relevant notifications in the ČN mobile application.
The news was removed from the České noviny website and access was blocked.
Victim: Czech Press Agency (ČTK)
Czech Press Agency (ČTK).
Česká noviny (ČN), news website is operated by ČTK
Reference: Attacker attacked the Česká noviny website, CTK news service was not affected
Incident: Hackers Steal 20 Million Pesos from Municipality in Argentina
The San Agustín Commune suffered a cyber attack in which 20 million pesos were stolen from its central account. The thieves stole the money on Friday through four different transfers of $4.9 million pesos each. "They wanted to do two more operations, but there was no more money," he confirmed.
The main concern is the recovery of the money intended for paying suppliers and salaries. If the illegally stolen funds are not recovered, the municipality will face financial difficulties that could affect the payment of salaries, the execution of works and the provision of services planned for the well-being of our citizens.
Reference: Comuna de San Agustín’s FB Post
Reference: Cyberattack on the San Agustín Commune: 20 million pesos were hacked and stolen
Incident: Dropbox Cybersecurity Incident Isolated to Dropbox Sign Infrastructure.
Dropbox said a cybersecurity incident “has not had, and we do not believe it is reasonably likely to have” a material impact on overall operations. The episode was isolated to Dropbox Sign infrastructure, and did not impact any other Dropbox products.
The cloud-storage company earlier reported unauthorized access to data such as email, user names, phone numbers and hashed passwords. The company said there was no evidence that intruders accessed account contents.
Victim: DropBox
DropBox is a cloud storage service provider
Reference: A recent security incident involving Dropbox Sign
Reference: Dropbox says cybersecurity incident is unlikely to have a material impact on operations
Incident: Outage Affected All LucidLink Customers
LucidLink experienced a malicious attack resulting in an outage that affected all customers. Access was fully restored for everyone on May 1, 2024 at 12:06 UTC.
The company believes that, “the root cause of the event to be malicious exploitation of an internal server with access to the production environment. This server was utilized to gain elevated privilege and to execute a script that corrupted the disk attached to each metadata server.”
As LucidLink clients became disconnected, they contact the discovery service to determine the IP address of the metadata server they need to reconnect to. Having all of the company’s clients attempt to do this at once overloaded the discovery service, leading the company to initially suspect a DDoS attack.
Reference: LucidLink suffers outage
Reference: LucidLink contacts FBI and explains cyber attack
Reference: LucidLink outage on April 29, 2024
Victim: LucidLink
LucidLink is a File sharing platform
Incident: New Website and Email Addresses after GA Electricity Provider Suffers Cyberattack
The Sawnee Electric Membership Corporation (EMC) has advised its customers not to use their original website after a “cybersecurity incident.” Since they lost control of their original website, they have relaunched it at www.sawnee.coop. The company said a “comprehensive investigation is ongoing” into the cybersecurity incident, and they’ll update customers when more information is available.
Sawnee EMC serves parts of seven counties in north Georgia, including Fulton, Cherokee, Gwinnett, Forsyth, Hall, Dawson and Lumpkin.
Victim: Sawnee Electric Membership Cooperation – EMC
Sawnee EMC serves parts of seven counties in north Georgia, USA, including Cherokee, Dawson, Forsyth, Fulton, Gwinnett, Hall, and Lumpkin.
Reference: Sawnee EMC asking customers to use new website after cybersecurity incident affected original one
Reference: Sawnee EMC warns customers not to use website after ‘cybersecurity incident’
Incident: Cyberattack at Brazilian Port of São Francisco do Sul
The Port of São Francisco do Sul released an official statement informing that, on Monday, the 6th, it suffered a cyber attack on its server, with the encryption of some data.
To prevent the spread of the attack, the systems were temporarily disabled, and the Port's IT team, with support from service providers, managed to partially resume the system's functionalities on May 7. The partial recovery of the system enabled the full resumption of port operations in less than 24 hours. The Port informs that it is still investigating the extent of the affected data.
Access control and security systems, such as automatic license plate reading, biometrics and CCTV are gradually being reinstated.
Victim: Port of São Francisco do Sul (APSFS)
Port of São Francisco do Sul (APSFS), responsible for the Port of São Francisco do Sul in Santa Catarina, Brazil. The port is a crucial trade hub, particularly for importing fertilizers, and plays a significant role in the state's economy.
The Administration of the Port of São Francisco do Sul is the main economic activity in the municipality where it is located, contributing around 70% of the local revenue. It accounts for 45% of total exports via maritime transport in Santa Catarina, showcasing its importance in the industry. The port stands out for its comprehensive infrastructure, including terminals and storage facilities, as well as well-established road and rail links to nearby areas. Its 9.3-mile canal provides crucial connectivity to global shipping routes, making it a vital trade hub.
Reference: Official Note – Port resumes operations in less than 24 hours after cyber attack
Incident: DDoS Attack at Washington Metropolitan Area Transit Authority Website
DDoS attack on the website of Washington Metropolitan Area Transit Authority. On the evening of May 7, Metro stated that Metro’s website, WMATA.com, was temporarily down. No data was compromised according to METRO.
Victim: Washington Metropolitan Area Transit Authority
Washington Metropolitan Area Transit Authority
Reference: Cyber attack shut down Metro’s website | NBC4 Washington
Reference: Attention customers: Our website (http://wmata.com) is temporarily down.
Incident: Disruptive Cyberattack Affects Content Management System at Large UK Media Group, Newsquest
A cyberattack at Newsquest, one of the UK’s largest regional media groups, has disrupted operations at its local news outlets, causing intermittent website outages and leaving journalists unable to file stories.
UK’s Hold the Front Page (HTFP) online news site for journalists posted : The attack is affecting content management systems, causing websites to malfunction, and leaving journalists unable to upload stories, images, and media.
Reference: UK’s Newsquest media group disrupted by cyberattack
Reference: Newsquest cyber attack: DDoS attack impacts news publishing on several sites
Incident: Local British News Sites Targeted in Coordinated Cyber Campaign
Dozens of regional titles owned by Newsquest were targeted in a coordinated cyber campaign over the weekend. The news sites were defaced with stories entitled “Pervoklassniy Russian Hackers Attack”, which were accompanied by a black and white logo. The articles were attributed in Russian script to an author named “Daniel Hopkins”.
Another story, which appeared on the Bolton News website, showed a picture of the Russian flag alongside the headline: “Our president has gone crazy, shock content.” The articles, which first appeared over the weekend, have since been taken down.
A Newsquest spokesman said: “For a brief period on Saturday 11th May, a limited amount of unauthorized content was posted to Newsquest sites. We acted immediately and removed the content with no further disruption.”
Victim: Newsquest
Newsquest is one of the UK’s largest regional publishers with more than 250 local news brands. It is owned by Gannett, the largest newspaper publisher in the US.
In 2022, Newsquest struck a deal to buy East Anglia-based rival Archant, which owns titles including the Eastern Daily Press, from buyout group Rcapital.
Reference: Oxford Mail publisher hit by ‘Russian hackers’ in cyber attack
Reference: Newsquest Media allegedly defaced by Russian hackers
Reference: ‘Russian’ hackers deface potentially hundreds of local British news sites
Incident: USA Amateur Radio Association Operations Disrupted for Months after Cyberattack
The American Radio Relay League (ARRL) announced that it suffered a cyberattack that disrupted its network and systems and online operations, including email and the Logbook of the World.
"We are in the process of responding to a serious incident involving access to our network and headquarters-based systems. Several services, such as Logbook of The World and the ARRL Learning Center, are affected," explained ARRL in a press release.
Victim: American Radio Relay League (ARRL)
The American Radio Relay League (ARRL) is the national association for amateur radio in the United States, representing amateur radio interests to government regulatory bodies, providing technical advice, and promoting events and educational programs for enthusiasts around the country.
Reference: ARRL Systems Service Disruption
Reference: American Radio Relay League cyberattack takes Logbook of the World offline
Reference: Groningen Water Company customer data possibly stolen in cyber attack
Incident: Widespread Fallout after Ransomware Attack at Service Provider for Customer Communication in the Netherlands
AddComm's systems were recently hit by a ransomware attack. The hack took place between May 5 and May 17. On May 17, the security incident became known to AddComm because the systems were encrypted by the cybercriminals.
=ABN Amro reports that it will no longer use Addcomm's services for the time being, but says that it is in close contact with AddComm.
=Energy Suppliers Essent en Vattenfall energy companies warn customers of dataleak at AddComm.
=The Hague housing corporation Staedion; Waterbedrijf Groningen; the Drenthe drinking water company WMD; the Regional Tax Group (RBG); Hoogheemraadschap Hollands Noorderkwartier (HHNK) ; and the Amsterdam housing corporation Eigen Haard also issued warnings .
Victim: Eigen Haard
Amsterdam housing corporation Eigen Haard
Victim: Hoogheemraadschap Hollands Noorderkwartier (HHNK)
Hoogheemraadschap Hollands Noorderkwartier (HHNK) works to protect the land against the water, against flooding and water shortage, for clean and healthy surface water and for safe (sailing) roads.
Victim: Regional Tax Group (RBG)
Regional Tax Group (RBG)
Victim: WMD
Drenthe drinking water company WMD in The Netherlands
Victim: Waterbedrijf Groningen
Waterbedrijf Groningen is a water and waste water company in Groningen, NL
Victim: Staedion
The Hague housing corporation Staedion
Reference: Essent and Vattenfall Warn Customers for Addcomm Data Leak
Victim: ABN AMRO
ABN AMRO Bank in The Netherlands
Victim: Addcomm
Addcomm is a service provider for customer communications in the Netherlands
Reference: Possible ABN Amro customer data leaked in cyber attack
Reference: Addcomm Hit by Ransomware
Reference: Matadero de Gijón has reportedly been compromised by the RansomHub ransomware group.
Reference: Ransomware Attack on Matadero de Gijón
Reference: El Matadero, paralyzed on Monday by the “hacking” of the sewage treatment plant
Reference: Ransomhub Attacking Industrial Control Systems To Encrypt And Exfiltrate Data
Incident: Massive Cyberattack at Regional Swiss Broadcasting Company
Since Tuesday afternoon, there have been irregularities or disruptions in the online, radio and television offerings of Radio and Tele Top. Not all programs can be broadcast as announced and some have to be repeated, the top media wrote on their website.
According to Gjusi Brändli, RadioTop's program director, the attack is massive and they are also being blackmailed. The technicians are currently working around the clock to get the program back on track. The radio and TV programs are running on emergency mode. It will probably take a few more days until things are back to normal, said Brändli.
"Nothing works anymore in the Radio and TeleTop system!
An encryption Trojan is currently affecting large parts of the Radio and Tele Top systems. Nevertheless, it is said that "an almost normal program" was able to be broadcast. Experts are on the trail of a solution to the problem.
Victim: RADIO TOP
RADIO TOP supplies the cantons of Zurich, Thurgau, St.Gallen, Schaffhausen and the two Appenzells from its main studio in Winterthur.
Reference: Radio and TeleTop hacked and blackmailed
Reference: Top media outlets affected by Trojans
Incident: TV Weather Forecast Disrupted at RTBF Partner Studio
The Charleroi production studio Dreamwall was the victim of a computer hack on Wednesday evening, leading to the disruption of several programs on RTBF, with which it collaborates.
Analyses are continuing within RTBF to determine whether a potential "Trojan horse" could have infiltrated its computer system. No date has yet been set for a normal resumption of filming of the impacted programs.
Dreamwall studio has not yet wished to communicate on this subject.
Victim: RTBF
RTBF (branded as rtbf.be), is a public service broadcaster delivering radio and television services to the French-speaking Community of Belgium, in Wallonia.
Reference: A cyberattack disrupts RTBF weather forecast
Reference: Programs disrupted due to hacking at RTBF: “We have cut all ties with the studio”
Incident: Alleged Cyberattack on Delivery Service in Russia
A little-known hacker group claimed responsibility for an attack that has disrupted service for days at CDEK, one of Russia’s largest delivery companies. The Russian-speaking hackers, who call themselves Head Mare, said they encrypted the company’s servers with ransomware and destroyed backup copies of its corporate systems.
CDEK hasn’t attributed the disruption to a cyberattack, but an anonymous source within the company told Russian media outlet Vedomosti that it was a ransomware attack. Recorded Future News couldn’t verify this claim, as CDEK couldn’t be reached for comment.
The company attributed disruption to its services over the weekend to a “massive technical failure” that affected the functionality of its website and mobile application. CDEK also suspended parcel shipments “to avoid errors during manual processing.” “On Monday, we made significant progress in restoring full operation, but unfortunately we were not ready to resume our service,” the company said. “All your parcels are safe, and we are doing everything necessary to ensure that they reach you as quickly as possible.”
Victim: CDEK
CDEK, one of Russia’s largest delivery companies.
Reference: Major delivery company down for three days due to cyberattack
Reference: Major Russian delivery company down for three days due to cyberattack
Incident: Data from Nidec Precision, Vietnam Leaked Online After Negotiations Broke Down
One of Nidec Corp's subsidiaries - Nidec Precision - suffered a cyberattack. Nidec Precision focuses on the design and manufacturing of precision components, particularly in the areas of robotics, electronics, and industrial automation. This company is based in Vietnam.
Among the information stolen in the attack are 50,694 files, including internal documents, letters from business partners, documents related to green procurement, labor safety and health policies, business documents (purchase orders, invoices, receipts), contracts, and more.
The Japanese tech giant says the threat actors tried to extort the company and decided to leak the information after their demands were not met. The attack did not encrypt files and the incident is considered fully remediated at this time.
Victim: Nidec Corporation
Nidec Corporation is a Japanese multinational company specializing in electric motor technology, producing a wide range of motors for applications such as automotive, industrial, and home appliances.
Reference: Nidec confirms ransomware attack leaked company data online
Reference: Security Incident at Nidec Instruments Corporation
Reference: Tech giant Nidec confirms data breach following ransomware attack
Incident: Cyberattack at Newfoundland Broadcasting Co.
The Newfoundland Broadcasting Company Limited (“NBCL”) – owners and operators of NTV and OZFM experienced a cybersecurity incident. It has not affected the on-air operations of NTV or OZFM.
"The event resulted in unauthorized access to information in parts of our system environment. We are also aware that an unauthorized third party intends to post data online, claiming it is ours,” says Newfoundland Broadcasting COO Lindsey Andrews.
Victim: Newfoundland Broadcasting Company Limited (“NBCL”)
Newfoundland Broadcasting Company Limited (“NBCL”) – owners and operators of NTV and OZFM
Reference: Newfoundland Broadcasting Co. victim of cyberattack
Incident: False Article Appears on Polish Press Agency’s Feed
Poland's state news agency PAP was probably hit by a Russian cyberattack on Friday, a government minister said, after a false article about military mobilization appeared on its news feed. Warsaw has repeatedly accused Moscow of attempting to destabilize Poland because of its role in supplying military aid to Ukraine, allegations Russian officials have dismissed.
"Everything indicates that we are dealing with a cyberattack that was directed from the Russian side," Digital Affairs Minister and Deputy Prime Minister Krzysztof Gawkowski told private broadcaster Polsat News, adding that special services including the Internal Security Agency were investigating.
Victim: Polish Press Agency, or PAP
Polish Press Agency, or PAP
Reference: Polish news agency probably hit by Russian cyberattack, minister says
Reference: Poland to probe Russia-linked cyberattack on state news agency
Incident: Data Breach at Australian Ticketek
Ticketek has been hit by a “cyber incident” with personal information of Australian customers stolen from a third-party global cloud-based platform. The incident affected many Australians but appears restricted to the release of names, dates of birth and email addresses.
Reference: Ticketek customer details exposed in cybersecurity breach
Victim: Ticketek
TIcketek is a ticket sales company in Australia
Reference: Statement Regarding Ticketek Cyber Incident
Victim: Dendreon Pharmaceuticals LLC
Dendreon Pharmaceuticals LLC – specialises in oncology and developing immunotherapy treatments for prostate cancer.
Victim: Endo Pharmaceuticals Inc
Endo Pharmaceuticals Inc – develops medication for areas such as urology, endocrinology and pain management.
Victim: Acadia Pharmaceuticals Inc
Acadia Pharmaceuticals Inc – creates treatments for central nervous system disorders
Victim: GlaxoSmithKline Group
GlaxoSmithKline Group – a global organisation catering to a wide range of medical treatments such as vaccines, pharmaceuticals and consumer healthcare.
Victim: Sumitomo Pharma America Inc
Sumitomo Pharma America Inc – specialises in neurology, oncology, and psychiatry.
Victim: Genentech Inc
Genentech Inc – a leader in biotechnology which has made strides in the treatment of cancer.
Victim: Incyte Corporation
Incyte Corporation – developer of drugs like Jakafi which is used to treat a type of bone marrow cancer called myelofibrosis.
Victim: AbbVie Inc
AbbVie Inc – the creator of Humira, used to treat rheumatoid arthritis, among other things.
Victim: Regeneron Pharmaceuticals Inc
Regeneron Pharmaceuticals Inc – known for ophthalmology, oncology and immunology treatments.
Victim: Bayer Corporation
Bayer Corporation – major pharmaceutical firm known for the origin and first marketing of aspirin.
Reference: 11 big pharma firms affected in Cencora cyber attack
Incident: No Details Disclosed after Cyberattack at Pharmascience, Canada
Largest Canadian-owned pharmaceutical company, Pharmascience, was the target of a cyberattack. The company confirmed that it had discovered an intrusion into its computer system on June 1 , but refused to provide details on the extent and duration of the attack.
The Montreal-based generic drug manufacturer – which offers more than 1,400 products – declined to confirm whether a ransom was demanded or paid, or whether data was stolen.
The company says it responded quickly by hiring cybersecurity experts, which helped "secure" its computer systems. "We have since resumed operations safely and effectively," the email sent to us reads.
Reference: Cyberattack at Pharmascience
Incident: Belgian IPM Group’s Newspapers and TV Channel Hit by Cyberattack
The newspapers La Libre Belgique and DH-Les Sports, as well as the news channel LN24, were victims of a cyberattack detected this Wednesday morning.
The IPM Group is monitoring the situation, our websites and applications are operating normally. Release of some paper editions was compromised for part of the day.
"The DH and the Libre will be available in paper form. However, we are going to merge some regional editions at the DH level. In the interests of simplification and to be able to absolutely ensure the delivery of newspapers tomorrow morning. For the rest, the group's other titles are not impacted ."
Victim: IPM Group
PM Group is a major Belgian media and internet services company active in news, entertainment, advertising, gaming and Innovation. The group holds major brands as La Libre Belgique, lalibre.be, La DH-Les Sports, dh.be, DH Radio, Paris Match Belgique, parismatch.be, cinebel.be, Logic-Immo.be, betFIRST, Zeturf.be.
Reference: The IPM press group (La Libre, la DH, etc.) targeted by a computer attack
Reference: The IPM group reports the cyber-attack
Reference: La Libre Belgique, DH and the news channel LN24 were victims of a cyberattack
Reference: Regarding issues occurring on multiple KADOKAWA Group websites
Incident: Cyberattack Impacted Kadokawa’s and its Subsidiary’s Operations.
Japanese publisher Kadokawa has confirmed a data leak affecting 254,241 people due to a cyberattack. On June 8, Kadokawa Group subsidiary Niconico suffered a significant ransomware attack that initially compromised its video portal, before affecting the wider Kadokawa Group corporate conglomerate.
This incident has had a ripple effect across the conglomerate, impacting online merchandise orders for stores under the Kadokawa group, as some systems are currently unable to process and ship orders as well as infrastructure related to company-run websites. At one point the perpetrator remotely restarted servers to continue the attack and spread ransomware, forcing staff to physically disconnect power and communications cables from affected servers in order to halt the attack.
The attack halted the flow of orders but also reduced production output and caused delays in physical distribution. The impact is evident in the sudden drop in publication releases as well as the halt in payments to partners. The further shut down of support systems for domestic editing and production of both print and digital publications has compounded the impact of the incident. The ransomware gang BlackSuit claimed responsibility for the attack.
Kyodo News commissioned an investigation and reports on December 12 that $2.98 million in cryptocurrency was paid to BlackSuit on June 13.
Victim: Kadokawa Corporation
Kadokawa operates various businesses in the film, publishing, and gaming industries. It runs a Japanese e-book store called BookWalker, which sells manga, novels, and magazines from various publishers, and it also holds a majority stake in FromSoftware, the developer of the popular video game Elden Ring.
Reference: Japanese media giant investigating another reported data leak by BlackSuit hackers
Reference: Kadokawa confirms data leak of 254,000 people due to cyberattack
Incident: Class-action Lawsuit Follows Cyberattack at Findlay Automotive
Findlay Automotive shared that a June 10 cybersecurity issue impacted its sales and service departments. Since June 10, Findlay Automotive hasn’t shared much information on the nature of the ransomware attack or the impact on its customers. The company said vehicle sales couldn’t be finalized, service appointments couldn’t be scheduled online and only cash payments could be accepted. The company didn’t answer questions on when its systems got back to normal or how it was able to return to normal.
In the wake of the cyberattack, the company was hit with two class-action lawsuits last month that allege Findlay Automotive didn’t properly protect customers’ sensitive financial and personal information.
It is unknown at this time if this attack was part of the widespread CDK attack reported a month later.
Victim: Findlay Automotive
Findlay Automotive Group began in 1961 with one dealership Pete Findlay Oldsmobile. Findlay Automotive Group sells a variety of new and used cars at about a dozen dealerships in the Las Vegas area and in Arizona, Idaho, and Utah.
Reference: Findlay Automotive provides (some) new information about cyberattack
Reference: What happened to Findlay Auto Group? Is it the same cyberattack as CDK Global?
Reference: Findlay operations nearly idled, losses mount from cyberattack; suit filed
Incident: Location Tracking Life360 App Consumer Data is Leaked Online
A threat actor has leaked a database containing the personal information of 442,519 Life360 customers collected by abusing a flaw in the login API. Life360 is a family networking app designed to provide location and safety services.
Known only by their 'emo' handle, they said the unsecured API endpoint used to steal the data provided an easy way to verify each impacted user's email address, name, and phone number. "When attempting to login to a life360 account on Android the login endpoint would return the first name and phone number of the user, this existed only in the API response and was not visible to the user," emo said.
Life360 did not disclose how the threat actor breached its platform, but the company stated that it had taken steps to protect its systems from further attack.
Victim: Life360
Life360 provides real-time location tracking, crash detection, and emergency roadside assistance services to more than 66 million members worldwide. In December 2021, it acquired Bluetooth tracking service provider Tile in a $205 million deal.
Reference: Life360 confirms a hacker stole Tile tracker IDs and customer info
Reference: Over 400,000 Life360 user phone numbers leaked via unsecured API
Reference: Thousands of Life360 users have data leaked following breach
Incident: Mining Company Iluka Resources Wards off DDoS Cyberattack
Iluka Resources, an Australian mining company, suffered a denial-of-service attack. Hackers intended to disrupt Iluka’s external website. However, there was “no infiltration of our internal systems and hence no loss of data or privacy concerns,” the company said.
Victim: Iluka Resources
Iluka Resources is an Australian resources company, specializing in mineral sands exploration, project development, operations and marketing
Reference: Iluka Resources fends off cyberattack after CEO Tom O’Leary called out China’s rare earths ‘weaponisation’
Reference: Second Australian rare earths producer suffers cyber attack
Incident: Geopost Reports Cybersecurity Incident
Geopost announces having identified a cybersecurity incident consisting of a recent unauthorized access to a database operated by its subsidiary in Spain. After becoming aware of the incident, the company proactively informed the National Cybersecurity Institute (INCIBE) and the Spanish Data Protection Agency (AEPD), for the appropriate purposes, and promptly began an investigation with the assistance of cybersecurity experts
Reference: Geopost provides Information on Cybersecurity Incident
Victim: Geopost
Geopost offers parcel delivery and solutions globally.
Reference: Geopost provides Information on Cybersecurity Incident
Incident: Utility Company in Cali, Colombia Blocks Cyberattack
A cyberattack was carried out on Emcali, Cali's main public company's commercial, billing and information systems. Hackers targeted commercial, billing and information systems. The attack was contained and blocked in less than two hours.
Victim: Emcali – Empresas Municipales de Cali
Empresas Municipales de Cali / Emcali utility company in Colombia
Reference: This is how Emcali managed to protect itself from a cyber attack on its servers
Incident: Systems Offline at National Health Laboratory Service (NHLS) in South Africa
The National Health Laboratory Service (NHLS) has confirmed that it experienced an information technology (IT) security breach compromising its systems and infrastructure. A preliminary investigation, suggests that no patient data has been lost or compromised. The organisation’s systems remain inaccessible both internally and externally, including to and from healthcare facilities until the integrity of the environment is secured and repaired.
“It has been established that sections of our system have been deleted, including in our backup server and this will require rebuilding the affected parts. Stakeholders and the public will be informed as soon as more information becomes available. all of its laboratories are currently fully functional and are receiving and processing clinical samples.
Under normal circumstances, the laboratory reports are automatically generated and sent to clinicians or made available on web view, but the incident has disabled that functionality. “However, all urgent results are communicated telephonically to requesting clinicians.”
Victim: National Health Laboratory Service (NHLS)
National Health Laboratory Service (NHLS) in South Africa
Reference: National Health Laboratory Service hit by cyber attack
Incident: Cyberattack at Cambridge University Press & Assessment (CUPA)
Cambridge University Press & Assessment (CUPA) has been hit by a cyber attack. In a statement on Thursday (27/06), CUPA announced employees were facing “technical disruption following a cybersecurity incident affecting part of our publishing operation”.
A spokesperson for Cambridge University Press & Assessment said: “We recently experienced a cybersecurity incident, affecting a part of our publishing operation. As soon as we became aware of the incident, we took some of our systems offline as a precautionary measure and engaged external IT and forensic experts to respond to and investigate the matter. ”
Victim: Cambridge University Press & Assessment (CUPA)
University of Cambridge's publishing arm
Reference: University of Cambridge publishing arm hit by cyberattack
Reference: University publishing house faces cyber attack
Incident: TeamViewer Reports Databreach
Software company TeamViewer says that a compromised employee account is what enabled hackers to breach its internal corporate IT environment and steal encrypted passwords in an incident attributed to the Russian government.
TeamViewer said a Kremlin-backed group tracked as APT29 was able to copy employee directory data like names, corporate contact information and the encrypted passwords, which were for the company’s internal IT environment. The company reaffirmed that the hackers were not able to gain access to the company's product environment or customer data, and that the breach appears to be contained.
Victim: TeamViewer
TeamViewer offers remote connectivity and support solutions software.
Reference: TeamViewer IT security incident
Reference: TeamViewer: Hackers copied employee directory and encrypted passwords
Incident: Ransomware Attack Affects Cultural Organizations in France
Forum Sirius, a ticketing software provider was informed on June 28 that it had been the target of a cyberattack. Forum Sirius serves more than 400 cultural organisations.
The Forum Sirius database contains 5,986,188 records including user IDs, names, addresses, phone numbers, emails, and other personal information although bank details are claimed to have been protected. It is claimed that those behind last month’s attack are offering to sell the database to a single buyer for $2,000 (£1,500/€1,850).
Reference: Forum Sirius hack continues to damage French cultural organisations
Reference: Ticketing provider targeted by cyberattack, MC2 affected
Reference: National cyberattack hits Toulouse theatre, customer data ‘potentially’ affected
Reference: Theft of personal data: in Mulhouse, a cyberattack targeted a service provider of Filature and the Opéra National du Rhin
Victim: Forum Sirius
Forum Sirius provides ticketing software for hundreds of cultural organizations including festivals, performance halls, and arenas across France.
Incident: Databreach at Dairy co-op Agropur
Agropur, one of the largest dairy cooperatives in North America, is notifying customers of a data breach after some of its shared online directories were exposed. The firm said the breach does not extend to its transactional systems and hasn't disrupted its core business operations.
Reference: Dairy co-op Agropur hit by ‘limited’ cyberattack
Victim: Agropur
Agropur is one of the largest dairy cooperatives in North America
Reference: Dairy giant Agropur says data breach exposed customer info
Incident: TÜV Rheinland Suffers Cyberattack
A ransomware gang has managed to penetrate a TÜV Rheinland training network. Access data may have leaked in the process. The affected network segment was deactivated immediately after the attack was detected. TÜV Rheinland's corporate network and the other training network were not affected by the incident.
A well-known hacker group called Ransomexx claims to have infiltrated IT systems of the Cologne-based testing service provider TÜV Rheinland AG and stolen a total of 650 GB of company data. As can be seen in a screenshot shared by Falconfeeds.io on X , the attackers have not yet given any details about the stolen data. "The post will be available shortly ," says Ransomexx's data leak page.
Reference: Unauthorized access to parts of TÜV Rheinland Akademie GmbH’s training network
Reference: Hackers steal data from TÜV Rheinland
Victim: TÜV Rheinland
TÜV Rheinland Academy conducts more than 15,000 continuing education events in 132 subject areas every year. Seminars, courses, online training, e-learning and conferences are offered by more than 2,500 speakers, with around 200,000 people taking part every year.
Incident: Helpdesk Portal of Canadian Router Maker Compromised
Cyberattack at the helpdesk portal of router manufacturer, Mercku. BleepingComputer has confirmed that support requests submitted to the router maker are being auto-responded to with Metamask phishing emails.
Victim: Mercku
The Canadian router manufacturer, Mercku provides equipment to Canadian and European Internet Service providers (ISP) and networking companies including Start.ca, FibreStream, Innsys, RealNett, Orion Telekom, and Kelcom.
Reference: Router maker’s support portal hacked, replies with MetaMask phishing
Incident: Bangladesh Meteorological Department’s (BMD) Website Hacked
The Bangladesh Meteorological Department (BMD) website was hacked and was down for over two hours before it was recovered. "We've successfully recovered the website after the hack. We don't know who is involved in the hacking. The authorities are now checking if any damage was done to the server," Monowar Hossain, a meteorologist at BMD, told The Daily Star.
The users were unable to access the site for two hours and 27 minutes this morning. The hackers left a message saying: "HACKED BY ODIYAN911. TE4M UCC INDIAN H4CKERS…..".
Reference: BMD website hacked, recovered after 2 hours
Victim: Bangladesh Meteorological Department (BMD)
Bangladesh Meteorological Department (BMD)
Incident: Safety Equipment Giant Cadre Holdings’ Shut Down some Systems after Cyberattack
Florida-based safety equipment giant Cadre Holdings disclosed a cyberattack. In response to the incident, some systems were shut down, which impacted some of the company’s operations.
Cadre Holdings has stated that while some operations have been impacted, it is currently unclear whether the breach will materially affect the company's financial health or operational results.
Victim: Cadre Holdings, Inc.
Cadre Holdings, Inc.,is a company specializing in orthopedic, prosthetic, and surgical appliances
Reference: Cadre Holdings reports cybersecurity breach
Reference: Safety Equipment Giant Cadre Holdings Hit by Cyberattack
Incident: Cyberattack at Macao’s Public Broadcaster TDM
The website and mobile app of Macao’s public broadcaster TDM was impacted by a cyberattack.
Victim: Teledifusão de Macao (TDM)
Teledifusão de Macao (TDM) is a local broadcaster in Macao
Reference: Macao’s public broadcaster TDM was hit by a cyber attack
Victim: Globes
Globes newspaper reports on Business News in Israel
Incident: Databreach at SunExpress Airlines
SunExpress has warned its customers that their email addresses have fallen into the hands of scammers. An external service provider responsible for sending newsletters on behalf of SunExpress was the target of a cyber attack. The incident affects around 250,000 of the airline's customers.
Victim: SunExpress
SunExpress is a Turkish holiday airline
Reference: Cyber attack on IT service provider affects 250,000 Sun Express customers
Reference: Data Breach at SunExpress
Incident: Central Texas 911 Systems Hacked
A cyberattack threatened to shut down Central Texas' 911 call system Sunday. Intermittent 911 outages were the result of a denial-of-service attack in which hackers flooded call centers with robocalls. The attack caused technical difficulties in Austin, Cedar Park, Hays County and Lakeway.
CAPCOG said it was notified about the hack around 1 p.m. by Round Rock's 911 call center. It determined the robocalls came from AT&T numbers, so it worked with the provider to identify and disconnect them. Normal operations were restored around 8 p.m.
CAPCOG said the attack disrupted service at call centers in at least seven of its 10-county area, affecting 21 law enforcement and first-response agencies in Central Texas.
Victim: Capital Area Council of Governments CAPGOG
Capital Area Council of Governments CAPGOG, Texas
Reference: Hackers attacked the Austin area’s 911 call system on Sunday. Here’s what that means.
Incident: Cyberattack on Mining Company in Mexico
Mexican mining company Industrias Peñoles was the victim of a cybersecurity incident involving unauthorized access to computing equipment and information.
In a statement to the Mexican stock exchange, Peñoles Industries said it was still assessing the scope of the attack but that its business units were operating normally through alternate and backup systems.
Reference: Industrias Peñoles Reports Cybersecurity Incident
Reference: Peñoles Industries suffers cyber attack
Victim: Industrias Peñoles
Mexican mining company Industrias Peñoles, is one of the world's largest silver producers<
Reference: Car rental giant Avis data breach impacts over 299,000 customers
Incident: Databreach at AVIS Car Rental affects 300.000 Customers
Car rental giant Avis is notifying hundreds of thousands of people that their personal information and driver’s license numbers were stolen in an August cyberattack. Avis did not disclose the nature of the cyberattack and details of the incident remain scarce
Victim: Avis
Avis owns the Budget car hire and Zipcar car-sharing brands, has more than 10,000 rental locations in 180 countries. Avis made $12 billion in revenue during 2023
Reference: Data BreachesAvis Data Breach Impacts 300,000 Car Rental Customers
Reference: Thousands of Avis car rental customers had personal data stolen in cyberattack
Reference: Data of nearly 300,000 exposed in Avis cyberattack
Reference: CERP Bretagne-Atlantique victim of a cyberattack
Incident: French Pharmacy Wholesaler hit by Cyberattack
The cyberattack at CERP began on Saturday, October 19. It targeted "information" systems. The company buys medicines from manufacturers to resell them to pharmacies. As of Saturday morning, pharmacies were asked to postpone their medication orders until Monday. According to the Brittany Regional Health Agency, they have been able to place orders online again since yesterday evening. Orange Cyber Defense teams worked all weekend to counter the cyberattack.
Reference: CERP cyberattack: how the healthcare sector defends itself against hackers
Victim: CERP
CERP buys medicines from manufacturers to resell them to pharmacies. it is a cooperative for distribution of pharmaceuticals in Atlantic Britany, France.
Reference: Breton pharmacy wholesaler CERP victim of cyberattack
Reference: In Hazebrouck, Direct Signalétique victim of a cyberattack: “Nothing works anymore”
Victim: SwissCom
SwissCom is a telecommunications provider in Switserland
Incident: DDoS Attack on SwissCom
Swisscom has apparently fallen victim to a major DDoS attack. According to its own statements, it was able to defend itself successfully after initial problems.
Swisscom said its experts fend off cyber attacks every day. But Friday's attack was a major one. The company did not know who was behind it.
Reference: Cyberattack on Swisscom: Twint and e-banking down
Reference: The Port of Seattle and Sea-Tac Airport say they’ve been hit by ‘possible cyberattack’
Victim: Sea-Tac Airport
Seattle WA airport
Incident: Shares Fall after Cyberattack on India’s Kernex Microsystems
India's Kernex Microsystems, safety systems and software services co, on Thursday reported cybersecurity incident, targeting its infrastructure.
No additional information available at this moment.
Reference: Intimation Of Cyber Security Incident
Victim: Kernex Microsystems (India) Limited
Kernex Microsystems (India) Limited is engaged in the manufacture and sale of safety systems and software services for railways. The Company provides a track record in providing professional electronic systems that can operate under stringent/harsh environmental conditions.
Reference: India’s Kernex Microsystems falls after cyber attack on co
Reference: Kawasaki’s European HQ recovers from cyber attack
Incident: Amber Beverage Group (ABG) Announces Cyberincident
Amber Beverage Group (ABG) informs that the company has experienced a cyberattack incident. The company is implementing all the necessary technical measures and enhancements, ensuring the security of the company's systems and data.
No further details are available.
Victim: Amber Beverage Group (ABG)
Amber Beverage Group (ABG) is Producer and distributor of alcoholic beverages.
Reference: Amber Beverage Group informs on a cyberattack incident
Incident: UK Rail Network Wi-Fi Hacked
The British authorities are investigating after commuters at 19 train stations saw an Islamophobic message when they tried to log on to a public Wi-Fi system. The Wi-Fi system, managed by communications group Telent, was quickly taken offline. Network Rail suspended the Wi-Fi service at all its stations nationwide while addressing the issue. The issue emerged at 19 stations across Britain. Investigation is underway
Victim: UK Train Stations
various UK Train Stations
Reference: Cyber Attack Displays ‘Islamophobic’ Message on U.K. Trains, Officials Say
Reference: UK passenger wifi network hacked
Reference: Admin account blamed for rail terror message hack
Incident: Vodka Maker Stoli Group Files for Bankruptcy after Crippling Cyberattack
The Stoli Group USA filed for Chapter 11 in US Bankruptcy Court in Dallas last week after a “malicious cyber-attack” forced the company to operate its global business manually “while the systems are rebuilt,” chief executive Chris Caldwell said in a statement.
Victim: Stoli Group USA
Stoli Group is a subsidiary of Luxembourg-based SPI Group, which owns other spirts and wines, including Kentucky Owl bourbon. (Stoli Group USA and Kentucky Owl are in bankruptcy).
Stoli Group is the maker of Stolichnaya vodka. After the Ukraine invasion in March 2022 the name of the company changed to Stoli from Stolichnaya.
Reference: Stoli Vodka files for bankruptcy after cyberattack, legal feud with Russia
Incident: DDoS attack on Ports in Belgium
A cyber attack targeted the websites of several Belgian municipalities and ports on Tuesday. It is the second attack in two days by the pro-Russian hacker collective NoName057, according to the Centre for Cybersecurity Belgium (CCB).
A list of Belgian cities and ports was posted on the Telegram channel of the pro-Russian hacker group at 8.44am on Tuesday morning. Websites of the ports of Antwerp, Zeebrugge, Liège were targeted.
Reference: New cyber attacks by pro-Russian hackers hit port and local authority websites 8 October 2024
Incident: Rumpke Trash Service Collection Not Impacted
Rumpke is investigating after a "cyber security incident," according to a spokesperson with the company. "At this time, we do not believe any customer payment information or payment processing systems have been impacted." Rumpke's trash services in the Greater Cincinnati area will not be impacted by the incident, the spokesperson said.
Victim: Rumpke
Trash Service Collection in Cincinnati, OH
Reference: Rumpke investigating after possible cyberattack, says services will not be impacted
Reference: Rumpke investigating ‘cyber security incident’
Incident: Cyberattack at Frozen Food Company in France
The frozen food chain was the victim of a cyberattack on Tuesday, November 12. It has notified the 45,000 customers affected, who are among the 11 million members of its loyalty program.
Victim: Picard
Picard is a frozen food chain operating in France
Reference: Picard victim of a data leak, thousands of customers affected
Reference: Name, first name, contact details… 45,000 Picard customers affected by a data leak
Reference: Recope reinforces manual operations and guarantees sufficient inventories to ensure fuel supply
Incident: Costa Rica RECOPE Switches to Manual Operations
Costa Rica’s state oil refinery RECOPE switched to manual operations Wednesday after a ransomware attack targeted its computer systems. While fuel sales continue without interruption, RECOPE has directed all staff to avoid using digital platforms as cybersecurity teams assess the damage from the early morning attack on November 27.
This incident was the first real-world test of the U.S. State Department’s new rapid response tool for cybersecurity incidents; Foreign Assistance Leveraged for Cybersecurity Operational Needs, or FALCON. FALCON is one of several U.S. initiatives developed to bolster allies and infuse global digital norms with American values.
Victim: RECOPE – Refinadora Costarricense de Petróleo
Refinadora Costarricense de Petróleo, known by most as RECOPE, imports, refines and distributes fossil fuels across the country while also operating pipelines stretching from its Caribbean to Pacific coasts.
Reference: Costa Rica state energy company calls in US experts to help with ransomware attack
Reference: Major Cyberattack Disrupts Costa Rica RECOPE Digital Systems
Incident: Dewan Farooque Motors Limited (DFML) Suffers Severe Cyberattack
Dewan Farooque Motors Limited (DFML) has fallen victim to a severe cyberattack. DFML’s operations and access to critical financial and operational data were severely impacted, with the recovery process expected to take considerable time. “We regret to inform you that owing to malware and cyber-attack, our IT servers have crashed, and data have been badly corrupted, resulting in postponing the board meeting,” the company stated.
Victim: Dewan Farooque Motors Limited (DFML)
Dewan Farooque Motors Limited, established in Pakistan on December 28, 1998, as a public limited company, focuses on assembling, progressively manufacturing, and selling vehicles within the country.
Reference: Cyberattack hits Dewan Farooque Motors: Data loss and server outages disrupt business operations
Reference: Cyberattack delays Dewan board meeting
Reference: Servers crash, data corrupted as cyber-attack hits Dewan Farooque Motors Limited
Incident: Cyberattack on VOSSKO Food Company in Germany
VOSSKO fell victim to a ransomware attack in which the internal systems and databases were encrypted. The malware affected operational processes, but affected systems and production have already been restored, the company reports on their website.
"We have done everything we can to regain access to our systems as quickly as possible," emphasizes the management. "In the course of restoring and resuming production, all internal systems are being continuously checked and monitored to ensure complete security.'
Victim: VOSSKO
VOSSKO with headquarters in Ostbevern, specializes in ready-made products with poultry, beef and pork as well as vegetarian and vegan items. Customers include well-known companies such as Edeka, Aldi, Iglo and Wagner.
Reference: Vossko hit by ransomware attack
Reference: Cyber attack at VOSSKO – systems and production restored
Incident: Cyberattack on Engineering Firm in Germany
The engineering office Fritz Spieth Beratende Ingenieure GmbH has fallen victim to a targeted hacker attack by criminals.
Immediately after discovering the attack, our management informed the authorities and filed a complaint. At the same time, all IT systems were shut down or isolated to protect our customers, suppliers and employees.
By consistently implementing an emergency protocol and IT emergency plan, our company has returned to normal operations. In the future, we will have a compromise assessment carried out by independent experts on a continuous basis to further increase our IT security level and go beyond our previous standards.
According to the assessment of independent IT experts, there is currently no evidence that the portals we use and the emails we send pose an increased risk.
Victim: Fritz Spieth Beratende Ingenieure GmbH
Fritz Spieth Beratende Ingenieure GmbH Engineering
Reference: Cyberattack on our engineering office
Incident: Cyberattack at São Paulo Sanitation Company
The Basic Sanitation Company of the State of São Paulo, Sabesp, announced on Tuesday (22) that it was the victim of a cyberattack, which resulted in instability in its digital network. Company immediately implemented security measures and activated its contingency plan to re-establish compromised systems. The company also assured that the attack did not affect the essential operations of water supply, collection and sewage treatment.
Reference: Sabesp is the target of a cyber attack and records instability in the digital network
Reference: Sabesp: “insignificant” amount of personal data was leaked in cyber attack
Victim: Sabesp
The Basic Sanitation Company of the State of São Paulo - Sabesp
Reference: Sabesp (SBSP3) suffers cyber attack and faces instability in digital services
Reference: OMO registers cyber attack without affecting operations
Incident: Karat Packaging in US reports Cyberattack
Karat Packaging Inc. (industrial supplier and manufacturer of beverages and catering products) discovered unauthorized access to its information systems on October 18, 2024 and activated its cybersecurity response plan. The investigation is still ongoing, but the company believes that the incident did not disrupt its commercial activities. The company notified the federal authorities and filed a report with the Securities and Exchange Commission.
Reference: SEC Form 8-K
Victim: Karat Packaging Inc.
Karat Packaging Inc. (industrial supplier and manufacturer of beverages and catering products)
Incident: Broadcasting Systems Paralyzed on Reunion Island
The Cirano group, which includes several media in Reunion Island, was the victim of a massive computer attack with ransomware during the night of August 20 to 21, paralyzing broadcasting systems.
The teams are working to restore functionality as soon as possible. The media affected include Antenne Réunion, NRJ, Chérie FM, RER and EXO FM.
Reference: Cyberattack on Reunion media: OCOI delivers its recommendations
Reference: Large-scale computer attack: Reunion Island media victims of a cyberattack
Reference: Cyber-attack on Antenne Réunion: the perpetrators are demanding a ransom
Reference: Massive computer attack against the Cirano Group’s media
Victim: The Cirano group
The Cirano group includes several media in Reunion Island
Incident: Operations Disrupted at BVI Electricity Corporation (BVIEC)
The BVI Electricity Corporation (BVIEC) was the victim of a cyberattack that affected its internal and external operations. The energy company works with experts and security agencies to solve the problem and restore normal operations. Despite this incident, BVIEC continues its efforts to restore electricity in the British Virgin Islands after the passage of tropical storm Ernesto
Victim: BVI Electricity Corporation (BVIEC)
BVI Electricity Corporation (BVIEC)
Reference: BVIEC suffers cyber attack
Incident: Cyberattack Causes Serious Fallout for French Online Retailers
Friday, August 16, 2024 was a dark day for Octave, specializing in ERP solutions and e-commerce services. A ransomware attacked knocked out half of the company's information system. The company is doing everything it can to restore its services as soon as possible, but the situation remains complex and delicate. All Octave customers , whether they use ERP solutions, e-commerce site services or any other service of the company, are directly affected by this attack. "The complexity of the actions required to restore the systems securely adds uncertainty as to the rapid resolution of the situation."
. Octave set up a crisis unit, called on a cybersecurity specialist and filed a complaint.
Some of Octave's customers, mostly independent physical stores that have an online shopping site such as cobra.fr, agripartner.fr, ardent-peche.fr, kazed.fr or 3as-racing.com, remain inaccessible this Wednesday, September 11, 2024.
Reference: Octave.biz customers victims of the effects of a cyberattack
Reference: Angers-based Octave company victim of cyberattack with lasting effects
Reference: Fifteen days after the cyberattack, the OCTAVE company takes stock of the situation
Victim: Octave
Octave is a French SaaS business software publisher, specializing in retail. Acquired by the Canadian group Valsoft in January 2023
Incident: Cyberattack at Italian Waste Management Co. Contarina
The waste management company Contarina was the victim of a cyberattack, which made garbage bag dispensers inaccessible. The attack had an impact on the company's services.. Activity blocked since Friday, August 16, recovery completed yesterday with system backup. "We are investing more in security"
Investigations are underway to determine the causes and consequences of the attack.
Reference: Hacker attack on waste company Contarina: bag dispensers out of order
Victim: Contarina
Contarina waste management company
Incident: Editorial Tools at a Standstill at Bayard Publishing House
The attack forced the press group to shut down "most editorial, production and marketing tools," according to an internal message sent Monday morning, which "Le Monde" was able to consult.
La Croix readers did not receive their daily newspaper on Tuesday, September 10. The operation of the newspaper, and of the Bayard Group, has been seriously disrupted by a cyberattack that began on Sunday, September 8. This Tuesday morning, the editorial office was still running at a slow pace. "We still don't have Internet, and the day promises to be even more complicated, because all of Bayard has been affected ," confided a journalist in the morning.
Reference: Bayard press group victim of ransomware
Victim: Bayard Presse
Bayard Presse is a French press and publishing companies, being founded in 1870. The company has various media outlets both in its native France and abroad. As of 2019, it reports approximately two thousand employees, two hundred magazines with five million subscribers, and eight million annual book sales
Reference: Le Groupe Bayard a été victime d’une cyberattaque
Reference: The newspaper “La Croix” and the Bayard Group victims of a cyberattack by ransomware
Incident: Third Largest Energy Distributor in Colombia hit by Cyberattack
The company is operating normally and the provision of energy services was not affected. A complaint was filed with the Public Prosecutor's Office for the incident that occurred on September 2,
Reference: Air-e reports that it suffered a cyber attack that affected its systems
Victim: Air-e
Air-e, formerly Caribe Sol, is jointly owned by Empresa de Energía de Pereira and Latin America Capital Corp. It is the third largest distributor in Colombia, serving 1.25mn users in the departments of Atlántico, La Guajira and Magdalena.
Incident: Large Swedish Electrical Wholesalers, Elektroskandia, Loses Millions
On September 5, Elektroskandia, with a large central warehouse in Örebro, was exposed to a cyber attack. Since then, all common IT systems have been down. Elektroscandia could neither pick nor deliver orders for almost two weeks.
Victim: Elektroskandia
Elektroskandia offers electrical equipment and systems to customers who are active in the areas of: electrical installation, industry, infrastructure, security, lighting and white goods. The company is part of the Sonepar Group.
Reference: Elektroskandia was pressed for money after the cyber attack
Reference: Cyber attack costs Elektroskandia millions
Reference: Website online again!
Incident: Medusa Demands $1M from Israeli Newspaper Globes
The Israeli newspaper Globes was the victim of a sophisticated cyberattack conducted by an international criminal group, which led to restrictions on access to its computers and certain services. Despite this, the newspaper has managed to continue to provide its content to its readers on its website and in its paper edition. The investigation is underway to assess the consequences of the attack and take measures to prevent further attacks.
Reference: Globes’ servers hacked, $1M ransom demanded by Medusa group
Reference: Cyber Attack on “Globes” news outlet Sparks Economic Terrorism Concerns
Reference: Update on cyberattack at “Globes”
Victim: Split Airport
Split Airport, Croatia
Incident: Operations Disrupted at Split Airport
The Split Airport IT system was hacked on Monday, July 22. This was announced by the Deputy Director of the San Girolamo Airport, Pero Bilas. “Due to a cyber attack, the IT system of the San Girolamo Airport went haywire,” Bilas said. “Specialized services are working intensively to remove the consequences of this attack. We are in contact with all airlines and are looking for alternative solutions together. We ask all passengers to be patient,” Bilas said.
Reference: Split Airport restoring functions after cyberattack
Reference: Split Airport Falls Victim to Hackers: We Won’t Negotiate
Reference: Croatia: Hacker attack on Split airport claimed by Akira group
Incident: Cyber Incident at Software co. Formpipe’s Danish Subsidiary
Formpipe has reported a computer security incident within its Danish subsidiary. The incident resulted in a data security breach, but details on the extent and consequences of the incident are not yet available. The investigation is ongoing to determine the causes and implications of the incident.
Reference: Cybersecurity incident at Formpipe’s Danish subsidiary
Victim: Formpipe
Formpipe is a Swedish provider of Content Management tools for the Swedish and Danish public sectors and the global private sector.
Incident: German Medical Technology Company Reportedly hit by Cyberattack
aap Implante AG, a German medical technology company, has reported a possible cyberattack that could have compromised the security of its systems and data. The company took immediate action to contain the incident and launched an investigation to determine the extent of the attack. Details of the incident and possible consequences are not yet available.
Victim: aap Implante AG
aap Implante AG, a German medical technology company
Reference: aap Implantate AG: Possible cyber attack on aap
Reference: Possible cyber attack on aap
Incident: Finnish Watch Manufacturer Polar Disables Online Store Access
The Finnish company Polar, a manufacturer of connected watches, was the victim of a cyberattack that compromised the order information of some customers of its online store in the United States. The attackers tried to make fraudulent purchases using the compromised accounts and also created new fraudulent accounts. Polar has temporarily disabled the login and registration functions on all its online stores, as a precautionary measure.
Reference: Polar says your health data is safe following cybersecurity attack
Reference: Polar investigates security incident that has affected its consumer online store
Victim: Polar,
Polar, a manufacturer of connected watches in Finland
Incident: Angola’s Airline TAAG Hit by Cyberattack
On September 16, Angolan airline TAAG reported a cyber attack targeting its technological infrastructure, affecting some local servers. However, the airline assured that its operations remained unaffected.
In a statement, TAAG confirmed the disruption to certain “on-premises” services but emphasized that flight operations continue to meet national and international safety regulations. TAAG adds that it is guaranteeing the continuity of the operation, ensuring the general schedule of flights and respective services.
Victim: TAAG
TAAG is Angolia 's official airline
Reference: https://www.verangola.net/va/en/092024/Transports/41490/TAAG-targeted-by-cyber-attack.htm
Reference: Angolan airline TAAG targeted by cyber attack
Reference: Angolan airline TAAG targeted by cyber attack
Incident: Broadcasting Operations Brought to Standstill at German Radiostation.
The Geretsried radio was the victim of a massive cyberattack, led by Russian hackers, who encrypted all the music files and demanded a high ransom. The management team and the board of directors are working at high pressure to solve the problem. Meanwhile, the radio station broadcasts an emergency program.
Victim: Radio Geretsried
Radio Geretsried is a local radio station in Bavaria, Germany
Reference: Radio Station Paralyzed
Reference: German radio station forced to broadcast ’emergency tape’ following cyberattack
Incident: Japanese Manufacturer ZARCOS hit by Ransomware Attack
Zacros was the victim of a ransomware attack which encrypted some of its servers. An emergency team was set up to investigate the incident and restore the systems, with the help of external experts and the police. The extent of the cyberattack has not yet been fully assessed, but the company apologizes to its partners and customers for the inconvenience caused.
Reference: Company website announcement
Victim: ZACROS
Fujimori Kogyo, also known as ZACROS, a Japanese converter of flexible films and packaging established in 1914 as well as the head office of ZACROS AMERICA.
Incident: Cyberattack at Japanese Logistics Company Kantsu
The Japanese company 関通 (Kantsu) was the victim of a cyberattack with ransomware on September 12, 2024, resulting in the detection of an infection on some of its servers and the cutting of its networks to prevent further attacks. An emergency team was set up to investigate the incident and take measures to repair the damage and prevent new attacks.
Reference: Notice regarding the occurrence of a system outage at our company due to a cyber attack
Victim: KANTSU
The Japanese company 関通 (Kantsu) is a provider of innovative logistics services that incorporate the latest advances in the field of IT.
Incident: Giant Latin American Software Company TOTVS Hit by Cyberattack
“TOTVS was the target of a cyberattack and reacted quickly. The attack was carried out by the BlackByte group, known for its double extortion tactic. Although TOTVS has indicated that encryption is under control, there is evidence that *data exfiltration* was significant, with samples already circulating on the dark web.
This suggests that confidential information may have been compromised, increasing the challenge of containing the impact of the attack.
Reference: Cyber attack on TOTVS group by BlackByte group
Reference: Attack on TOTVS reinforces the need to rethink cybersecurity strategy, explains expert
Reference: TOTVS faces cyber incident
Victim: TOTVS
TOTVS is the largest enterprise software company in Latin America. Everyday more than 100,000 businesses use our products to manage their processes. We partner with amazing companies.
Incident: Swedish IT Logistics Company Aurdel Hit by Cyberattack
Aurdel, a subsidiary of an IT company, Dist IT, was the victim of a cyberattack that caused a financial impact. The attack began on Thursday and the systems were taken offline to minimize the damage, resulting in delays in deliveries. The perpetrators of the attack had access to data, but it is too early to assess the extent of the violation.
Aurdel was created by merging two of the Nordic regions' biggest distributors – Aurora Group and Deltaco.
Victim: Aurdel Sweden AB
Aurdel is a part of DistIT Group, a fast-moving, market-leading group of distributors – all specialists and front-runners within technology. DistIT acquires and develops niche distributors within IT, mobility e-charge, audio, home electronics, networks, data communication, and AV products in Europe.
Aurdel, a subsidiary of an IT company, Dist IT, was created by merging two of the Nordic regions' biggest distributors – Aurora Group and Deltaco.
Reference: Dist IT’s subsidiary hit by cyber-attack – ’causes some financial impact’
Victim: DistIT AB
DistIT AB engages in the acquisition, provision, and distribution of information technology products
Reference: Cyber attack wipes out DHL delivery tracking systems causing issues for Nisa retailers
Incident: IT System Shutdown at Textile Manufacturer SOFITEX, Burkina Faso
SOFITEX, a Burkina Faso company, was the victim of a cyberattack on the night of November 16-17, 2024, resulting in the total shutdown of its computer system. Technicians are working to understand the origin of the attack and restore the infrastructure from the data backup system. A crisis unit has been set up to ensure the continuity of services.
Reference: Burkina Faso: SOFITEX’s computer system attacked (Press release)
Reference: Attack on SOFITEX’s IT system, General Management reassures that the situation is under control
Victim: SOFITEX
SOFITEX produces cotton textiles. The Company specializes in purchase, transport, and ginning of seed cotton and is located in Burkina Faso.
Reference: Not going to pay a ransom and block foreign traffic
Reference: Cyberattack on editor of the Morgunblaðið
Victim: Agata
Polish furniture store chain Agata
Incident: Axido Said “Return to Production Will Be very Long”
(auto-translated) Axido isolated its information system and mandated a third party to conduct the investigations. Part of the production environment of its hosted customers has been compromised by the attackers.
Axido is unable to move forward "on specific deadlines for restarting the environments of [its] customers". The company said that "the return to production will be very long". "in the interest of the security of our customers and their data, we will take the time to carry out all these operations".
"In accordance with the recommendations of the ANSSI, we have chosen not to come into contact with the attackers."
Reference: Cyberattack: Axido confirms partial encryption of a production environment
Reference: ESN: Axido (Proxiteam group) faced with a cyber attack
Victim: Axido
Axido is an IT service provider and information technology company
Incident: DDoS Attack Took Down TankerTrackers Online Service
A DDoS attack has taken down the TankerTrackers online service, that tracks and report shipment of crude oil. This was timed to coincide with a simultaneous kinetic attack by the Houthis against the Marshall Island flagged, US-owned, Greek-operated tanker MV CHEM RANGER. If the information is valid, this is the first time a coordination of cyber and kinetic attacks has occurred.
Reference: DDoS attack against TankerTrackers
Reference: NORMA Cyber Annual Threat Assessment 2024
Victim: TankerTrackers.com
TankerTrackers.com is an independent online service that tracks and reports shipments of crude oil in several geographical and geopolitical points of interest.
Reference: Cybersecurity Breach at Eastern Shipbuilding Group, Inc.
Incident: US Cyberattack on Iranian Military Ship in Red Sea
Three U.S. officials have confirmed an operation to hack the computer systems of an Iranian spy ship, identified as the converted freighter Behshad. The ship is widely suspected of providing targeting information and intelligence to Yemen's Houthi rebels, who have been launching missile and drone attacks on merchant shipping since November.
Victim: Iranian Military
Iranian Military
Reference: Report: U.S. Carried Out Covert Cyberattack on Iranian Spy Ship
Reference: U.S. conducted cyberattack on suspected Iranian spy ship
Reference: US conducts cyberattack against Iranian ‘spy ship’ to deter Houthi attacks in Red Sea
Reference: US Cyberattack Hit 2 Iranian Military Ships in Red Sea
Reference: Ransomware Attack on Blue Yonder Hits Starbucks, Supermarkets
Reference: Wake Up And Smell The Ransomware—Starbucks Impacted By Cyber Attack
Incident: Big Ripple Effects after AI-driven Supply Chain Software Supplier Blue Yonder Cyberattack
A ransomware attack targeted Blue Yonder, a major supply chain technology provider, affecting several retailers including Starbucks and Sainsbury's. The attack disrupted operations, including scheduling and inventory management, prompting the companies to trigger backup plans to manage inventories and other essential systems. The incident highlights the potential consequences of cyber attacks on supply chain technology providers and the need for robust cybersecurity measures to prevent and respond to such incidents.
Morrisons, a U.K.-based grocery chain, said the Blue Yonder incident impacted delivery of goods to stores in the UK. Availability of some product lines at wholesale and convenience locations could drop to as low as 60% of normal availability. Sainsbury’s added that it was putting contingency processes in place. Starbucks is reverting to manual operations after back-end process for employing scheduling and time-tracking was affected by the attack.
Blue Yonder describes itself as a world leader in digital supply chain transformation with an AI-driven platform that helps with everything from fulfillment to delivery logistics.
Reference: UK, US retail giants hit by ongoing disruption after ransomware attack on supply chain firm
Victim: Starbucks Corporation
Starbucks Corporation is an American multinational chain of coffeehouses and roastery reserves headquartered in Seattle, Washington
Reference: Starbucks confirms Blue Yonder attack impacted employee scheduling platform
Victim: Sainsbury
Sainsbury UK grocery chain
Reference: Blue Yonder ransomware attack breaks systems at UK retailers
Victim: Blue Yonder
Blue Yonder, a specialist supply chain management software provider based in the US
Victim: Morrisons
Morrisons, a U.K.-based grocery chain
Reference: Ransomware hits supply chain software firm Blue Yonder ahead of Thanksgiving
Reference: Newpark Resources discloses October ransomware attack
Incident: The Plastic Bag Company Confirms Cybersecurity Incident
Sydney-based bag manufacturer The Plastic Bag Company suffered a data breach as passports and tax details were published online as evidence of the hack. A spokesperson for The Plastic Bag Company confirmed it had suffered a cyber security incident but declined to comment any further on the incident.
Victim: The Plastic Bag Company
Sydney-based bag manufacturer The Plastic Bag Company
Reference: The Plastic Bag Company falls victim to Sarcoma ransomware attack
Incident: Australian Perfection Fresh Confirms Ransomware Attack
Australian produce firm Perfection Fresh has been listed on the Sarcoma ransomware group’s dark web leak site overnight, making it one of three Australian victims listed in the span of 24 hours. Sarcoma claims to have stolen 690 gigabytes of data, which it lists as “Files, SQL” in its 10 October leak post.
Perfection Fresh has confirmed the incident.
Victim: Perfection Fresh
Perfection Fresh : "Since 1978, Perfection Fresh has been sourcing new fresh-produce varieties from around the globe, bringing them to Australia to grow and sell domestically."
Reference: Perfection Fresh data breach
Reference: New Ransomware Attacks On Australian Businesses Sparks Urgent Calls For Boards To Prioritise Cyber Maturity
Reference: Aussie fresh produce company Perfection Fresh confirms ransomware attack
Incident: Alleged Ransomware Attack Australian Steel Fabricator Meshworks
The Sarcoma threat group listed Meshworks on its dark web leak site, claiming to have stolen 8 gigabytes of “files”. It appears the threat group has begun ransom negotiations with Meshworks, this has not been verified by Cyber Daily.
Cyber Daily has contacted Meshworks for more information and is awaiting a response.
Threat Actor: Sarcoma Group
The Sarcoma Group is a ransomware group that emerged in October 2024. In November 2024, cybersecurity specialists at CYFIRMA warned: “Sarcoma ransomware is rapidly becoming a significant threat due to its aggressive tactics and increasing victim count.” In December 2024, operational technology cyber threat intelligence company Dragos listed Sarcoma among the most important emerging threats for industrial organizations worldwide. A report by RedPiranha shares more details about Sarcoma, explaining that its operators employ phishing emails and n-day vulnerabilities exploitation to gain initial access, while they have also conducted supply chain attacks to pivot from service vendors to their clients.
Post-compromise, Sarcoma engages in RDP exploitation, lateral movement, and data exfiltration. However, the tools the threat group uses have not been analyzed yet, so although the threat group’s operation indicates experience in the field, its exact origin and tactics haven’t been deciphered yet.
Victim: Meshworks
Meshworks is an Australian organisation that manufactures “steel welded wire mesh for the mining, construction, rural, fabrication, safety, storage, temporary fencing and materials handling industries”. Its products are 100 per cent recycled.
Reference: New Ransomware Group Sarcoma Targets Australian Companies
Reference: Australian steel fabricator Meshworks suffers alleged Sarcoma ransomware attack
Incident: Philippines’ Largest Fast-food Chain hit by Data Breach
Philippines’ largest fast-food chain, Jollibee Foods Corporation said the data breach may have exposed personal data of 32 million customers and 650 million records related to the Jollibee's food delivery operations.
The compromised data reportedly includes sensitive customer information such as names, addresses, phone numbers, email addresses, and hashed passwords. Additionally, extensive records of food delivery orders, sales transactions, and service details have been exposed.
Victim: Jollibee Foods Corporation
Philippines’ largest fast-food chain, Jollibee Foods Corporation.
Incident: Philippines Maxicare Hit by Cyberattack
Health maintenance organization Maxicare on June 19, confirmed a data breach that exposed personal information of 13,000 members representing less than 1 percent of its membership base
The exposed records are believed to be of those who used Lab@Home, a booking platform of their third-party home-care provider. It added that Lab@Home maintained a separate database for booking requests, which is not integrated with Maxicare’s system. The company also affirmed customers that its business operations, network, and customer data has not been impacted in any way.
Victim: Maxicare
Maxicare has more than 20,000 affiliated doctors and specialists linked with over 1,300 hospitals and clinics, over 700 dental clinics and 140 rehabilitation, dialysis, and eye centres. It now services over 1.8 million members across the country from corporate segment, small and medium-sized enterprises to families and individuals.
Reference: Philippines Maxicare, Jollibee Foods Corporation hit by data breach
Incident: Operations Disrupted at Co-op locations in Western Canada
Federated Co-operatives Limited (FCL) has been forced to shut down internal and customer-facing systems at local retail Co-op stores and cardlock fuel locations across Western Canada as a result of a cybersecurity incident. The unplanned outage was first noted on social media by local Co-ops on Wednesday, June 26.
Supply problems varied by store, stocks of food items like bread, fresh produce, baking supplies and dairy products were slim or non-existent. Cardlock fuelling stations were hit hard in the first few days.
Victim: Federated Co-operatives Limited (FCL
FCL is owned by around 160 member co-operatives across Western Canada.
Reference: Westview Co-op among those affected by cyber attack on Federated
Reference: Federated Co-op retail and cardlock system experiencing cyberattack
Reference: Federated Co-ops says it’s making progress as cyberattack woes enter 2nd week
Reference: Major Western Canada wholesaler FCL still dealing with cyberattack
Reference: Biotech company hacked in 2023 pays states $4.5 million over breached data
Incident: Ukrainian Railway Company Ukrzaliznytsia Hit by Cyberattack
On December 13, 2016, the Ukrainian railway company, Ukrzaliznytsia, announced it had been targeted by a cyberattack that affected its online ticketing system, causing delays in ticket purchases and train scheduling. The attack not only impacted the railway system but also had broader consequences for the country’s economy, as the rail network plays a vital role in transporting goods and people throughout Ukraine.
The group behind the attack, known as “Sandworm,” was later identified as a state-sponsored hacking group with links to the Russian government.
Reference: Throwback Attack: Ukrainian railway hit by cyberattack, stranding passengers
Victim: Ukrzaliznytsia
Ukrainian railway company, Ukrzaliznytsia
Reference: Ukraine’s Kyivstar allocated $90 million to deal with cyberattack aftermath
Reference: Russian hackers infiltrated Ukrainian telecom giant months before cyberattack
Reference: Ukraine mobile network Kyivstar hit by ‘cyber-attack’
Reference: Attack on Ukraine’s Kyivstar Telecom Company Started with a Compromised Employee Account
Reference: Russian hackers were inside Ukraine telecoms giant for months
Reference: Ukrainian energy giant, postal service, transportation agencies hit by cyberattacks
Incident: Sumo Energy Confirms Extensive Data Breach
The NSW Government acknowledges the cyber incident affecting Sumo, an Australian electrical, gas and internet provider. Sumo reported the incident to the OAIC in May, claiming that customer data was accessed by an unknown person, via a third-party file storage application.
Sumo have since investigated and assessed the cyber incident and has confirmed that their systems were not affected.
Victim: Sumo
Australian energy and internet provider Sumo
Reference: Sumo data breach
Reference: Sumo slammed by data breach
Reference: Australian energy and internet provider Sumo confirms customer data breach
Incident: British Engineering Company confirmed Employee Duped in Transfering HK$200m (£20m)
The British engineering company Arup has confirmed it was the victim of a deepfake fraud after an employee was duped into sending HK$200m (£20m) to criminals by an artificial intelligence-generated video call.
Reference: Company worker in Hong Kong pays out £20m in deepfake video call scam
Reference: UK engineering firm Arup falls victim to £20m deepfake scam
Victim: Arup
Arup, one of the world’s leading consulting engineering firms, employs more than 18,000 people and famously provided the structural engineering for the Sydney Opera House including its distinctive concrete shells.
Recent project involvements include the Crossrail transport scheme in London and the Sagrada Família in Barcelona.
Incident: Nordic Utility Fortum Reports Daily Cyberattacks are Unsuccessful.
Fortum, the biggest power utility in Finland, is being subjected to daily attempts of cyber attacks and cyber breaches, while suspicious individuals and drone activity have been spotted near its energy assets, CEO Markus Rauramo told Reuters.
“There are different kinds of cyberattack attempts, or cyber security breach attempts, against us daily, and then less frequently, drones and different kinds of suspicious movement around our assets,” Rauramo said. Satellite connections have been disturbed in recent months, too.
Security services in Finland and Sweden declined to comment on specific incidents,
Victim: Fortum
Nordic utility Fortum (FORTUM.HE) has hydro, wind, solar, nuclear and combined heat and power (CHP) plants in Finland and Sweden.
Reference: Exclusive: Finnish utility Fortum reports pick up in cyberattacks and surveillance
Reference: Finland’s Top Power Utility Targeted With Daily Cyber Attacks
Incident: IT Systems Compromised at Eni’s Libya Joint Venture Mellitah Oil & Gas
Italian energy corporation Eni confirmed reports of a cyber attack on Mellitah Oil and Gas Company. The attack, attributed to "RansomHub," raised concerns after the group threatened to disclose 1TB of data unless a $50 million ransom is paid, according to local sources.
Production and operational activities have not been impacted, and the gradual restoration of the compromised IT systems is underway
Victim: Mellitah Oil & Gas Company
Mellitah Oil & Gas Company, Libya
Reference: Eni confirms: the Libyan company Mellitah Oil and Gas was the victim of a cyber attack
Reference: Mellitah company hacked and blackmailed by international hacker group
Reference: Italian energy giant Eni reports cyber attack on Mellitah Company
Incident: Ransomware Attack at Major U.S. Oil and Fuel Distributor Atlas Oil
Major U.S. oil and fuel distributor Atlas Oil was claimed to be compromised by the Black Basta ransomware operation, which purportedly stole 730 GB of data.
Atlas Oil is a major US fuel distributor responsible for delivering over 1 billion gallons (3.78 billion liters) of fuel annually to 49 states.
Victim: Atlas Oil
Atlas Oil specializes in local, regional, and national fuel delivery.
Reference: Major US fuel distributor allegedly breached by Black Basta
Reference: Atlas Oil: The Consequences of a Ransomware Attack
Victim: London Drugs
London Drugs is a Canadian retail pharmacy chain based in Richmond, British Columbia. As of August 2024, the chain has 79 stores in Western Canada. In addition to pharmacy services, London Drugs locations also sell electronics, housewares, cosmetics, and a limited selection of grocery items.
Incident: Canadian London Drugs Refused to Pay $25M Ransom
The ransomware attack on London Drugs paralyzed operations across 79 stores in Western Canada for over a week, and further disrupted services in the other Canadian provinces. On May 7 all stores had fully reopened. London Drugs improvised so about half of its chain could provide pharmacy services to ensure existing prescriptions wouldn’t be interrupted.
The breach resulted in the theft of sensitive corporate files, including extensive employee records like immigration applications, termination letters, and personal data such as financial information and medical records.
Reference: London Drugs confirms it was victim of ransomware attack
Reference: London Drugs Gets Cracked By LockBit: Sensitive Employee Data Taken
Reference: Opinion: London Drugs’ response to cyberattack a case study in crisis management
Reference: London Drugs confirms employee data held for ransom
Incident: Data Leak at Alexion Pharmaceuticals after Vendor’s Systems Compromised
On May 14, 2024, Alexion Pharmaceuticals (“Alexion”) filed a notice of data breach with the Attorney General of Vermont after discovering that a vendor used by the company experienced a data security incident.
In this notice, Cisiv explains that the incident resulted in an unauthorized party being able to access consumers’ sensitive information, which includes their name, address, email address, and phone number, as well as information regarding surveys taken regarding Alexion’s products.
Victim: Cisiv
Developer of a web-based software platform designed for collecting data in medical research. The company's platform provides a set of web-based tools.
Victim: Alexion Pharmaceuticals, Inc.
Alexion Pharmaceuticals, Inc., a subsidiary of AstraZeneca, is a pharmaceutical company headquartered in Boston, Massachusetts that specializes in orphan drugs to treat rare diseases.
Reference: Alexion Pharmaceuticals Confirms Patient Data Leaked Through Third Party Data Breach at Cisiv, Ltd.
Reference: Cyber Resilience Cybersecurity Incident Response Risk Management Merck’s Cyberattack Settlement: What Does it Mean for Cyber Insurance Coverage?
Reference: Overflowing Water Tank Linked to Russian Cyber Attack
Reference: Breaches by Iran-affiliated hackers spanned multiple U.S. states, federal agencies say
Reference: States and Congress wrestle with cybersecurity after Iran attacks small town water utilities
Reference: Russian hackers claim cyberattack on Indiana water plant
Incident: NC City Payment System Compromised After July Attack
City of Apex leaders on Thursday said that the hack that knocked the town network offline was an attempted ransomware attack, but the town has yet to get any demands. Since July 2, residents have been unable to pay bills or apply for permits electronically. Emergency services like 911 remained online. "At no time did any life safety services cease to operate," Galloway said.
In September the town of Apex addresses resident concerns about unusually high utility bills - reportedly up to $1800
Victim: City of Apex, NC
City of Apex, NC
Reference: Utility Account Access / Payment
Reference: No leads in Apex ransomware attack
Reference: Ransomware attack leaves some Apex residents with utility bills as high as $1,000
Reference: People charged up to $1,800 for water bill following Apex cyberattack
Reference: High utility bills reported in Apex after cyberattack: ‘Working on a resolution’
Incident: Data Breach at French Telecommunications Operator SFR
Telecommunications operator SFR has been the subject of a leak of its customers' data. The group confirmed this to Agence France-Presse (AFP) on Friday, September 20, after letters addressed to its subscribers were released.
The operator detected a security incident on September 3, affecting its customers' order data, including IBANs for some.
Victim: SFR Telecommunications
Telecommunications operator SFR in France
Reference: SFR data leak exposes sensitive customer information, including IBANs
Reference: Free files complaint after cyberattack on its subscribers’ personal data, the extent of which remains unknown
Incident: Large French Telecom Co. Hit by Cyberattack
Free, the second-largest internet service provider in France, confirmed being hacked following the attempted sale of purportedly stolen customer information on a cybercrime forum.
The Paris-based company has issued a warning that personal data was compromised in the incident, has filed a criminal complaint with the country’s public prosecutor and has notified France’s cybersecurity agency, as reported by newspaper Le Monde on Saturday.
Victim: Free
Free, the second-largest internet service provider in France
Reference: Free, France’s second-largest telecoms company, confirms being hit by cyberattack
Incident: Ransomware Possibly Involved in Cybersecurity Incident at Arkansas City Water Treatment Facility
Arkansas City, a small city in Cowley County, Kansas, was forced to switch its water treatment facility to manual operations over the weekend to contain a cyberattack detected on Sunday morning. City manager Randy Frazer confirmed \the cyberattack has not affected water treatment operations.
"Out of caution, the Water Treatment Facility has switched to manual operations while the situation is being resolved. Residents can rest assured that their drinking water is safe, and the City is operating under full control during this period."
Reference: Hackers target Arkansas City water treatment plant, prompting federal investigation
Reference: Arkansas City water treatment facility hit by cyberattack
Victim: Arkansas City water treatment plant
Arkansas City water treatment plant in Cowley County, Arkansas, USA
Reference: Kansas water plant cyberattack forces switch to manual operations
Reference: CiphBit Ransomware Strikes MPM Medical Supply in Latest Attack
Incident: Cyber Incident at Grendi Group
Italy’s Grendi Group has reported a cyber-attack on its IT systems stemming from a malicious email attachment.
Victim: Grendi Group
The Grendi Group is specialized in the collection and distribution of goods throughout South Italy: Sardinia, Sicily, Calabria, Puglia and Basilicata
Reference: Cyber incident at Grendi Group
Reference: talian Realities Hit, Iranian APT Offensives Traced, New Operations in Ukraine
Reference: British software company Microlise confirms hackers compromised corporate data
Incident: Cyberattack Shuts Down Distribution at Israeli Pharma Company Rekah
Israeli pharmaceutical company, Rekah, shut down its distribution system in response to a cyberattack. The company is preparing to restore the distribution system as quickly as possible while testing manual alternatives to operate the computerized system.
Preliminary estimates suggest the extent of the damage is not substantial, according to Rekah. "Pharmacies usually have a reasonable stock. We don’t deliver every day. If there is no supply for a day or two, it won’t harm the company or the customers."
Victim: Rekah
Rekah, a public company with a market value of $37 million, is a producer of medicines, cosmetics, vitamins, and nutritional supplements. The company has been under the control of the Fimi fund since 2015.
Reference: Israeli Pharma Firm Suffers Cyberattack
Incident: Recovery Cost from Ransomware Attack Cost City of Hamilton Nearly $10M
City of Hamilton has spent nearly $10 million recovering from a cyberattack on its municipal IT network, according to a new report to council (November 2024). Hamilton did not pay the “huge” ransom demanded by the hackers. The February '24 ransomware attack affected 228 different internet technology applications, disabling municipal services like phone lines, electronic payments, computer-aided fire dispatch and online permits — but to date, the city believes no resident personal information was stolen. The city’s multimillion-dollar system of traffic cameras was disconnected by the cyberattack. The lost application means any time the city wants to change a traffic-light signal timing, a worker needs to physically visit the individual intersection to “manually make the change.” Some services were deemed “unrecoverable" and the city has still not recovered.
Reference: Hamilton cyberattack unplugs system meant to ease traffic chaos
Victim: CIty of Hamilton
CIty of Hamilton, Canada
Reference: CITY OF HAMILTON
Reference: Hamilton has spent $9.6 million battling cyberattack fallout
Incident: China-Linked Cyberattacks Penetrated U.S. Wiretap Systems
A cyberattack tied to the Chinese government penetrated the networks of a swath of U.S. broadband providers, potentially accessing information from systems the federal government uses for court-authorized network wiretapping requests. The hackers might have held access for months or longer, which amounts to a major national security risk.
The hackers, believed to be a part of a group called Salt Typhoon and suspected to be connected to Chinese intelligence, reportedly breached T-Mobile's network as part of their widespread spying campaign.
WSJ and Washington Post News reported AT&T, Verizon, and Lumen Technologies networks were compromised by Chinese cyberattacks and caused a serious security breach. US Government requested more information from the CEOs of said companies in a letter dated October 10, 2024 . No further information available at this time.
Victim: Verizon Communications Inc.
Verizon Communications Inc. is the world's second-largest telecommunications company by revenue and its mobile network is the largest wireless carrier in the United States.
Reference: AT&T, Verizon, and Lumen in Hot Seat After China Cyberattack
Reference: T-Mobile Hacked in Massive Chinese Breach of Telecom Networks
Reference: T-Mobile hack linked to Chinese breaches of telecom networks
Reference: T-Mobile network breached in a massive Chinese cyberattack on telcos
Reference: Cyberattack At Manual Woodworkers And Weavers
Incident: Data Breached at Pallet Logistics of America (PLA)
Dallas, Texas-based Pallet Logistics of America (PLA) suffered a cyberattack where victims’ personal information ended up stolen in the incident. To date, PLA said there were 18,264 victims in the attack.
Victim: Pallet Logistics of America (PLA)
Dallas, Texas-based Pallet Logistics of America (PLA) is a logistics, maker and supplier of pallets for manufacturers across the United States.
Reference: TX-Based Pallet Firm Hit In Cyberattack
Reference: AI company tells SEC that $250,000 stolen in cyberattack
Incident: AI Platform for Learning and Work Automation Loses $250K in Cyber Incident
iLearningEngines, Inc. lost $250,000 in a cybersecurity incident after an attacker gained access to files on its network and misdirected a wire payment. The company has not recovered the wire payment.
Maryland-based iLearningEngines has developed a platform that uses AI to deliver personalized and automated learning, as well as work automation capabilities that organizations can use to custom-design workflows and optimize processes.
Victim: iLearningEngines
iLearningEngines is an applied AI platform for learning and work automation. Serving over 1,000 enterprise end customers, company performs globally in the manufacturing, energy, public sector, healthcare, education, insurance, and retail sectors.
Reference: AI Work Automation Firm Loses $250,000 In Attack
Incident: Italian Home Appliance Manufacturer Smeg Shuts Down Systems after Cyberattack
The Italian home appliance manufacturer Smeg said said on September 17, it was "back up and running" after an "unfortunate cyber attack" that hit Wednesday 12 September.
Company statement on Twitter read: "Unfortunately we have been the victim of a targeted cyber attack and as such have taken immediate steps to totally shut our systems down to protect our customers and ourselves. At this time we have no reason to believe any of our customer information has been exposed. We have a specialist team working around the clock to resolve this issue and get us operational ASAP."
Reference: Smeg UK hit by cyber attack as domestic appliance brand shuts down systems to protect customers
Reference: Oh Smeg! Hacked white goods maker resurfaces after system shutdown
Incident: Production at Standstill at Italian High-end Home Appliances Manufacturer
Smeg, the Italian multinational company known for its high-end home appliances, was hit by a cyberattack last Friday and was forced to suspend its activities due to the interruption of the Sap system. The disruption reportedly affected critical systems managing production processes, logistics, human resources, and accounting functions.
The firm’s headquarters in Guastalla, Reggio Emilia, proactively shut down the affected systems to mitigate potential damage, including the loss of sensitive data. Disruption affected headquarters in Guastalla and some other branches scattered throughout the country. Hundreds of employees were sent home
Victim: Smeg
Smeg (acronym for Smalterie Metallurgiche Emiliane Guastalla) is an Italian market home appliance manufacturer targeting upscale market.
Reference: High-End Appliances Maker Smeg Halts Production After Cyberattack
Reference: Cyberattack on Smeg, the Italian household appliances company
Reference: TX-Based Pallet Firm Hit In Cyberattack
Victim: Pallet Logistics of America (PLA)
Dallas, Texas-based Pallet Logistics of America (PLA) suffered a cyberattack where victims’ personal information ended up stolen in the incident. PLA is a logistics, maker and supplier of pallets for manufacturers across the United States.
Incident: TEAM Software Suffers Cyberattack
Workforce management software provider, TEAM Software, suffered a cyberattack where threat actors made off with personal information of its victims.
On July 26, Holmdel, New Jersey-based TEAM Software detected unusual activity on platforms and quickly launched an investigation, with the assistance of third-party cybersecurity and forensics specialists to determine the nature and scope of the event.
The investigation found an unauthorized actor gained access to certain TEAM Software systems and that information contained in those systems ended up potentially accessed or taken by the unauthorized actor between July 25 and July 26. The company recorded 99,525 victims in the attack
Reference: Security Software Provider Hit In Cyberattack
Victim: TEAM Software
Workforce management software provider, TEAM Software, suffered a cyberattack where threat actors made off with personal information of its victims. TEAM Software develops financial, operations and workforce management solutions for service contractors with distributed workforces, with a focus on the cleaning, security and facilities management industries in North America, Australia and the UK and Ireland.
Incident: IT Systems Disrupted at Vietnamese Gasoline Retailer PVOIL
PVOIL, a subsidiary of state-run giant Petrovietnam, was attacked by hackers at 0:00 on Tuesday, causing its website, email, payment application and electronic invoices to shut down. The firm has about 760 retail gasoline stations across the country. PVOIL said they will continue to sell gasoline, but they will issue delivery notes instead of e-invoices until the system is fixed.
Incident: Paul White Company Tile Firm Hit in Cyberattack
Portland, Maine-based Paul White Company suffered a cyberattack where a threat actor absconded personal information of the tile company’s customers.
“On October 12, 2024, Paul White Company detected unusual activity within its corporate network,” the company said in a letter to victims. “It immediately implemented its response protocols, took measures to contain the activity, and launched an investigation. A cybersecurity firm that has assisted other companies with similar situations was engaged.
In addition, the company also notified law enforcement and is supporting its investigation.
Reference: ME Tile Company Hit In Cyberattack
Victim: Paul White Company
Portland, Maine-based Paul White Company suffered a cyberattack where a threat actor absconded personal information of the tile company’s customers. Paul White creates custom-designed slabs cut in its stone shop, to hardwood flooring, and linoleum.
Victim: PVOIL (Petrovietnam)
PVOIL, a subsidiary of state-run giant Petrovietnam. PVOIL, registered on the Unlisted Public Companies Market (UPCoM) as OIL, is one of 34 gasoline wholesalers in Vietnam, accounting for 17% of the country's market share.
Reference: Gasoline retailer PVOIL hit by ransomware attack
Reference: Tiny Texas City Repels Russia-Tied Hackers Eyeing Water System
Victim: Abernathy Texas Water Facility
Abernathy Texas Water Facility
Reference: Small Texas towns targeted in series of international cyberattacks on water systems
Incident: Cyberattack at PSI Systems, a German Industrial Software Co.
PSI Software SE, a German software developer for complex production and logistics processes, has confirmed that the cyber incident it disclosed last week is a ransomware attack that impacted its internal infrastructure. The IT systems and the extent of the impacts are currently being checked.
The company operates at a global level with a staff of more than 2,000 and specializes in software solutions for major energy suppliers.
Reference: Cyber attack on PSI
Victim: PSI Software SE
PSI Software SE, Germany
PSI Group develops software products for optimizing the flow of energy and materials for utilities and industry.
Reference: EQS-Adhoc: Cyber attack on PSI
Reference: Cyberattack on global plant manufacturer Kreisel in Krauschwitz
Incident: Operations Severely Disrupted at BerlinerLuft manufacturing
On March 16, BerlinerLuft. Technik GmbH, Berlin, fell victim to a cyber attack causing "possible disruptions in the production/manufacturing process and delays in delivery".
Timeline as reported on the company website:
27 March: Production resumed of duct components, louvre dampers and sound insulation baffles at our German and Polish locations.
08 April : Production and operations resumed at all locations.
23 April: IT infrastructure restored, ERP up and running.
Reference: Cyberattack on BerlinerLuft Technik
Reference: Cybersecurity status: Recovery after cyberattack
Victim: BerlinerLuft. Technik GmbH
BerlinerLuft Technik GmbH is one of the leading system suppliers of products for ventilation, air conditioning and process air technology.
Incident: Cyberattack at German Gas Warning Systems manufacturer
Bieler Lang was the victim of a ransomware attack on April 22, 2024. The extortion group 8BASE was able to steal the company's data during the attack. The stolen data includes financial data, employment contracts, confidentiality agreements and other confidential documents.
Victim: Bieler + Lang
Bieler + Lang is a German Gas Warning Systems manufacturer which offers a wide range of gas detectors and controllers especially suited for hazardous areas.
Reference: 8Base Ransomware Group Launches Cyberattack on Bieler Lang GmbH, Threatens Data Leak
Reference: screenshot
Reference: Details of the security incident
Incident: Cyberattack at Max Wild GmbH takes IT Systems Offline
Cyberattack on Max Wild GmbH. The company website reports:
Cyber criminals managed to break through IT security barriers and existing protection systems and penetrate our IT systems. The attack was detected on April 25 and then immediately stopped.
In order to be able to fully examine the IT systems and avert further attacks, many of our IT systems are currently switched off. restrictions in digital communication and telephone accessibility possible
Victim: Max Wild GmbH
Max Wild GmbH is a Construction, Industrial Machinery & Equipment, and Manufacturing company located in Berkheim, Baden-Württemberg
Reference: Update Cyberattack on Max Wild GmbH – Email communication partially restored
Reference: Cyberattack on Max Wild GmbH – restrictions in digital communication and telephone accessibility possible
Incident: 8Base Leaked Data from German Engineering Company
Ringhoffer Verzahnungstechnik was the victim of a ransomware attack on March 25, 2024. The blackmail group 8BASE was able to steal the company's data during the attack. The stolen data includes financial data, employment contracts and other confidential documents. The blackmailers have since published these.
Victim: Ringhoffer Verzahnungstechnik
Ringhoffer Verzahnungstechnik is a mechanical engineering company in Kohlberg, Baden-Württemberg, Germany
Reference: Details of the security incident
Incident: Cyberattack on Municipal Waste Disposal Company in Germany
The waste management company (AWG) in Bassum was unreachable by phone for two weeks at the beginning of May. The company has now announced that this was due to a cyber attack. The disruption meant that all of the company's landlines were unavailable, and bulky waste could no longer be registered online. No customer data was at risk.
In order to resolve the problem, AWG called in a crisis team and took the entire company offline.
Reference: Review of the technical disruption in early May
Reference: AWG Bassum not reachable: disruption was cyber attack
Victim: AbfallWirtschaftsGesellschaft mbH (AWG)
AbfallWirtschaftsGesellschaft mbH (AWG) is a municipal waste disposal company in Germany
Incident: Operations Down at Water & Complex Waste Waste Plant Manufacturer Wehrle
The Emmendingen plant manufacturer Wehrle has fallen victim to hackers.
According to the Badische Zeitung, the attack was carried out on May 11. Since then, the company's production and communication have been severely restricted. The company announced yesterday Tuesday that it was working intensively to restore the affected systems and resume full operations.
Victim: Wehrle-Werk AG
Wehrle-Werk AG a component and plant manufacturer for the treatment of special waste and complex wastewater. The company is divided into three business areas: energy technology, environmental technology and manufacturing.
Reference: cyberattack on Wehrle-Werk AG
Reference: Wehrle-Werk AG restricts production after hacker attack
Incident: German Machinery Manufacturer LEMKEN Halts Production Sites
On Saturday, May 11, 2024, the agricultural technology specialist LEMKEN was attacked by hackers. The criminal attack extends to all locations worldwide. To protect against further access, all IT systems were immediately shut down and external specialists were called in. Production operations are currently stopped, and employees in the office areas can work remotely. Important LEMKEN contacts can still be reached by email or mobile phone.
Victim: Lemken
German Machinery Manufacturer LEMKEN
Reference: Lemken resumes production after cyberattack
Reference: Machinery firm LEMKEN hit by hackers
Reference: LEMKEN affected by cyber attack
Incident: Hamburg Airport Fends Off Hacker Attack
Hamburg Airport was affected by a hacker attack on an IT system used to monitor and document security patrols on May 19. The affected system is hosted separately by a service provider and has no connection to other systems at the airport, according to those responsible.
"The attack by the Killmilk/Just Evil group was repelled and no security-relevant information was intercepted," the airport explained. Other systems were not affected and there were no effects on air traffic.
Threat Actor: Killmilk/Just Evil
Just Evil is a pro-Russian cyber threat group formed in January 2024 by KillMilk. This group emerged following internal changes within KillNet.
Victim: Lockheed Martin
Lockheed Martin
Reference: Russian Hackers Infiltrate US Defense Giant Lockheed Martin
Reference: Just Evil on the wrong track: Hamburg Airport fends off hacker attack
Reference: Hamburg Airport Foils Hacker Attack on Security Monitoring System, No Compromise on Safety
Incident: Cyberattack on European Astronomical Research Institution
Starting on Friday 17 May, several of ESO’s network and communication services were shut down to allow for an important software upgrade to be deployed. The upgrade is being done in response to a cyber security incident. In addition to the shutdown, mitigating this threat included limiting communications regarding the incident to avoid compromising ESO’s cyber security response plan.
As of Tuesday 21 May, email services have been restored and the ESO website is back online. Other services, such as the ESO and ALMA Science Archives, are expected to be restored in the coming days.
ESO’s IT team is working together with a cyber security consultant on detecting and clearing malicious software from all ESO’s machines, as well as on investigating the attack and its consequences. ESO observations have not been affected since our observatories run largely on separate networks. ELT construction remains unaffected.
Reference: ESO network affected by cyber incident
Victim: European Southern Observatory (ESO)
European Southern Observatory (ESO) - Garching, Bavaria, Germany (Landkreis München)
Incident: Online Ticket System Offline for One Day at Hamburger Verkehrsverbund.
A hacker attack has been carried out on the Hamburg transport association. From Tuesday afternoon to Wednesday noon, purchasing tickets via the app was not possible or only possible to a limited extent.
Anyone who tried to buy a ticket via the HVV app or online on Tuesday or Wednesday was confronted with the following message: "Due to a technical problem, registration in the hvv app is currently not possible. Please use the anonymous ticket purchase in the hvv app or the hvv switch app."
Then on Wednesday afternoon the all-clear was given: the app and ticket sales are running as usual.
Victim: Hamburger Verkehrsverbund
Hamburg Transport Association
Reference: HVV: Hacker attack paralyzed online ticket purchasing for almost a day
Incident: BlackBasta Ransomware Attack on German Lambertz Baked Goods
Lambertz recently fell victim to a ransomware attack orchestrated by the BlackBasta ransomware group. The hackers reportedly stole 800 GB of sensitive data, which includes personal information of employees, financial accounting records, human resources details, and other confidential information. The attack was probably possible via a service provider's compromised VPN access.
A press spokesperson for the Lambertz Group confirmed that such an attack had taken place. However, information on the type and extent of the data affected could not yet be shared, as the forensic investigations carried out together with external experts have not yet been completed. As reported on golem.de.
Reference: Lambertz reports hacker attack
Reference: The baked goods manufacturer Lambertz has become the target of a ransomware attack.
Reference: Hackers are getting on Lambertz’s nerves
Victim: Lambertz – officially Aachener Printen- und Schokoladenfabrik Henry Lambertz GmbH & Co
Lambertz, officially known as Aachener Printen- und Schokoladenfabrik Henry Lambertz GmbH & Co. Kg, is a renowned German company specializing in the production of traditional German baked goods. Founded in 1688, Lambertz has a long-standing history and has grown to become one of the leading manufacturers in the European confectionery market. The company is headquartered in Aachen, Germany, and operates several production facilities across the country.
With a significant international presence, Lambertz exports its products to numerous countries around the world.
Incident: Ransomware Attack on German Steel Company
Westfalische Stahlgesellschaft reports on their website they have been the victim of a ransomware attack. Key IT systems were encrypted. We have already been able to restore most systems and data from back-ups and are confident that we will be able to complete this process shortly without any loss of data. Our production has not been disrupted by this incident and we have met and are confident that we will meet all delivery deadlines.
Victim: Westfälische Stahlgesellschaft group
The Westfälische Stahlgesellschaft group of companies comprises trading companies in various regions of Germany and, with the Plettenberg drawing mill, it has its own bright steel production operations for high-quality bar steel products.
Reference: FAQ on the cyber attack of June 9, 2024
Incident: Cyberattack at AKG Group Shuts Down of IT infrastructure and Restricts Production
AKG has become the target of a hacker attack. There has been a "significantly disruptive intrusion into the IT system," reported Jan Pippert. Hofgeismar - head of corporate development at AKG. As a result, AKG shut down its IT infrastructure. Production was also restricted.
AKG can start production again at all locations, says Jan Pippert in an interview with HNA. The company, based in Hofgeismar, has eleven production sites in Europe, North and South America and Asia, and 14 sales companies. In some plants, the attack led to production restrictions of varying degrees. At headquarters an old fax machine was temporarily put back into operation.
Victim: AKG Group
The AKG Group is a global leader in Thermal Management Solutions. Since our founding, we have been designing and manufacturing High-Performance Coolers and Heat Exchangers for a wide range of industries, including automotive, aerospace, rail, renewable energy, and construction and mining equipment.
Reference: AKG-Gruppe’s FB Post
Reference: After cyber attack: Production at AKG is back up and running
Incident: Solar Provider Hanwha Qcells sees Data Leaked Online
A cyberattack occurred at the German location of Hanwha Qcells, which offers solar systems and electricity, among other things. According to a customer letter the attack on the company's IT systems occurred on July 14, 2024. Hanwha QCells has since confirmed the incident. Personal data of customers and business partners was leaked. The company is currently working on restoring the systems. Heise reports that the group "Abyss" is behind the attack.
Reference: After cyber attack: Solar provider “Qcells” informs customers about data leak
Victim: Hanwha Qcells
German Hanwha Qcells offers solar systems and electricity.
Incident: Data Breach at German Waste Disposal Company
The waste disposal company MERB in Achern suffered a cyber attack over the weekend. It is currently unclear how much data was lost in the attack. The garbage collection service was not affected by the attack,
Victim: MERB
MERB is awaste disposal company in Achern, German
Reference: Cyber attack at the company MERB in Achern
Incident: IT Systems Offline, Operations not Affected at Energy Company Stadtwerke Burg
Stadtwerke Burg issued the following statement on their website:
"Stadtwerke Burg can now be reached again via email and online service center. In response to a cyberattack, the energy company immediately deactivated access to all IT services on August 22, 2024 and isolated the affected IT systems. Together with IT service providers and IT forensic experts, the IT systems were thoroughly checked and restored. "Now (almost) all systems are back in operation. The supply of energy to our customers was ensured throughout and personal data is still protected," says Annette Meyer, Managing Director of Stadtwerke Burg.
Reference: Stadtwerke Burg fully accessible again after IT security incident
Victim: Stadtwerke Burg
Energy Company Stadtwerke Burg / operator of critical infrastructure in Germany
Incident: German Timing Belt Manufacturer hit by Cyberattack
Höxter drive belt manufacturer Arntz Optibelt suffers cyberattack. According to the group, the fault was discovered yesterday morning (25 August). Arntz Optibelt has initiated appropriate measures and set up a task force.
"The cyber attack on our group of companies has resulted in restrictions, but with the support of specialists we are working hard to maintain the business capabilities of all our locations worldwide."
Victim: Arntz Optibelt Group
The Arntz Optibelt Group is a German family-run company producing special timing belts made of polyurethane and rubber for the transport and conveyor technology industry. It employs 2,400 people worldwide. From its headquarters in Höxter (North Rhine-Westphalia), the Arntz Optibelt Group manages eight production sites in six countries.
Reference: Hackers attack Optibelt company (Hacker attackieren Mittelständler Optibelt)
Reference: Cyber attack on Arntz Optibelt in Höxter
Incident: German Air Traffic Control (DFS) Suffers Cyberattack
There was a cyber attack at the German Air Traffic Control (DFS). The authority confirmed this upon request to Bayerischer Rundfunk (BR). The security authorities have been informed, and according to media reports, a group with links to the Russian secret service is behind the attack.
The intruders successfully penetrated the "administrative IT infrastructure, i.e. the office communications of DFS GmbH," a DFS spokesman told BR . Defensive measures are being taken and attempts are being made to limit the impact to a minimum. Air traffic is continuing as normal, said a spokesman for the German Press Agency (dpa).
According to information from BR24, the group "APT 28" is involved in the attack.
Victim: German Air Traffic Control (DFS)
German Air Traffic Control (DFS)
Reference: Cyber-Attack on German Air Traffic Control
Incident: German Steel Manufacturer Shuts Down Systems and Cancels Annual Shareholder Meeting
The Aachen-based company is the target of a cyber attack. The systems have been shut down and the annual general meeting of shareholders planned for this Wednesday has also had to be cancelled.
The IT systems of the listed precision parts manufacturer were shut down early on Sunday morning due to the attack, the company announced on Tuesday. The first parts of production were able to start up again outside of the network by Sunday evening. However, for safety reasons, software systems in administration and production control were not put back into operation late on Tuesday afternoon. Security systems and access controls were also affected by the attack.
Reference: Large-scale hacker attack on Schumag AG
Reference: Schumag Aktiengesellschaft: Cyber attack. Cancellation of the Annual General Meeting
Victim: Schumag Aktiengesellschaft
Schumag Aktiengesellschaft produces highly complex precision parts made of steel, which are delivered to customers worldwide in different quantities, sometimes in the millions, according to customer drawings. In the area of standard parts, SCHUMAG manufactures products for mold and tool making.
Incident: Hackers Access Managing Director Email Account at German Municipal Utility Co
The email account of D. Rabeneck, managing director of the Schaumburg-Lippe municipal utility, has been compromised: Cyber criminals have gained access to the account and apparently sent masses of phishing emails to Rabeneck's contacts - This information was confirmed by the municipal utility in a press release
Reference: Cyberattack on Stadtwerke Schaumburg-Lippe
Victim: Schaumburg-Lippe
Schaumburg-Lippe municipal utility company in Germany
Incident: Cyberattack at German Printing Ink Manufacturer Hubergroup
The Hubergroup, a world-leading manufacturer of printing inks, has become the target of a cyber attack. The SAP system, the Internet and also production have been restricted for almost two weeks, as a reader told us. The Hubergroup has now confirmed the incident to CelleHeute, but remains rather vague about the exact effects - including with regard to the site in Celle.
"The hubergroup has become the target of a malware attack that has affected individual, regional IT systems," said Fabian Meyer-Theobaldy . The press spokesman emphasized that the company's security systems had reacted immediately. Thanks to these measures, large parts of the internationally active Hubergroup were not affected by the attack.
Victim: Hubergroup
Hubergroup, a global specialist in printing inks and chemicals
Reference: Cyberattack on Hubergroup: Regional IT systems compromised
Incident: Digital Energy Provider, Tibber Data Leaked Online
Hackers have attacked the electricity provider Tibber and stolen data. Apparently over 50,000 customers are affected, all from Germany. Since November 11, a dataset titled "Tibber Data Breach - Leaked, Download" has been available on a popular darknet forum. Some sample lines contain name, email address, order amount and incomplete address data.
Reference: Data theft at Tibber
Victim: Tibber
Tibber is a Norwegian electricity provider that sells green electricity in Norway, Sweden, Germany and the Netherlands . The business model is based on revenue from a monthly fixed basic fee; according to the company, the actual energy, however, is billed without any additional charge at dynamic rates that follow the hourly electricity exchange price (plus taxes, duties, levies).
Reference: Electricity provider Tibber hacked, 50,000 German customers affected
Incident: Communication Channels Deactivated after Authorities Alert German Tipper Manufacturer
Meiller Kipper, a vehicle manufacturer based in Munich, Bavaria, Germany, has recently been targeted in a cyber attack, according to information disclosed by the company. Authorities alerted the company to specific indicators of the attack, prompting Meiller Kipper to engage security and forensic experts to assess the situation. As a precautionary measure to protect their business partners, Meiller Kipper has opted to deactivate all established Internet-based communication channels, including landline telephony, until the investigation yields concrete results.
Statement on the Meiller Kipper website reads: "Due to a cyber attack, our employees and some services have only been available to a limited extent over the past 14 days. We are pleased to inform you that we have checked our systems and that MEILLER is again available as usual via all channels by phone, email and online."
Victim: Meiller Kipper
Meiller Kipper is a German manufacturer of tippers. The production program includes tippers, trailers, hooklifts and skiploaders.
Reference: Cyberattack Hits German Vehicle Manufacturer
Reference: Important information for our business partners (Wichtige Information für unsere Geschäftspartner)
Incident: Volkswagen Seems Unconcerned after Ransomware Attack
Volkswagen has issued a statement after the 8Base ransomware group claimed to have stolen valuable data from the company’s systems. “This incident is known,” a Volkswagen spokesperson told SecurityWeek, adding, “The IT infrastructure of the Volkswagen Group is not affected. We are continuing to monitor the situation closely.”
The company has not shared any other information on the cyberattack. Its brief statement comes after the ransomware gang 8Base named the carmaker on its leak website. 8Base claims to have stolen invoices, receipts, accounting documents, personal data, certificates, employment contracts, personnel files, and “a huge amount of confidential information”.
Threat Actor: 8Base Ransomware Group
8Base emerged in March 2022, and their activity spiked in June 2023 after they started attacking companies across a broader range of industry verticals and switching to double extortion. The gang launched its data leak site in May 2023, with the extortion group claiming to be "honest and simple" pen testers targeting "companies that have neglected the privacy and importance of the data of their employees and customers."
As of Jun '23 the ransomware group has listed over 350 victims on its site, announcing up to six victims at once on some days. 8Base uses a customized version of Phobos ransomware, a malware that first surfaced in 2019 and shares many code similarities with Dharma ransomware.
Reference: Volkswagen downplays 8Base ransomware attack claims
Reference: Volkswagen Group Data Breach on October 11, 2024
Reference: Hackers Claim They Breached Volkswagen, Carmaker Looks Bored
Reference: Volkswagen Says IT Infrastructure Not Affected After Ransomware Gang Claims Data Theft
Incident: Phishing Attack Dupes Orion Carbon Out of $60M
About $60 million was stolen from one of the leading suppliers of carbon products after an employee was tricked into making several wire transfers to cybercriminals. The funds were stolen from Orion, a Luxembourg-based company that produces carbon black, a material used to make tires, ink, batteries, plastics and more.
A spokesperson declined to explain the situation in detail but the company filed documents with the Securities and Exchange Commission (SEC) about the incident, which it discovered on Saturday.
Reference: Carbon black supplier Orion loses $60 million in business email compromise scam
Reference: SEC Form 8-K
Reference: Orion Engineered Carbons | Fraudsters dupe chemical maker out of $60 million
Victim: Orion Carbon
Orion, a Luxembourg-based company that produces carbon black, a material used to make tires, ink, batteries, plastics and more.
Incident: Payment Services impacted at Rural Indian Banks after Ransomware Attack
recently found itself thrust into the spotlight for all the wrong reasons. A major ransomware attack crippled C-Edge Technologies' systems. The company is a leading provider of IT solutions for the Indian banking and financial sector. The attack caused a ripple effect that disrupted payment services at nearly 300 small banks across India.
The National Payments Corporation of India (NPCI) disconnected all forms of retail payment services offered by C-Edge Technologies after the company allegedly came under a ransomware attack two days ago.
Reference: RansomEXX ransomware strikes Indian banks: CloudSEK
Victim: C-Edge Technologies
C-Edge Technologies is a Mumbai-based technology company that primarily offers payment services to regional rural banks and cooperative banks. C-Edge is a joint venture between software major TCS and the State Bank of India.
Reference: NPCI disconnects C-Edge Tech from retail payments after alleged ransomware attack
Reference: C-Edge Technologies: A deep dive into the Indian fintech powerhouse hit by major cyberattack
Reference: Ransomware strike hits bank services: 200+ cooperatve, rural banks face outage after malware attack
Incident: Covenant Medical Center Diverted Ambulance Traffic
Covenant Medical Center released a statement on Monday regarding ambulance traffic from University Medical Center being diverted to their hospitals last week due to a ransomware attack on September 26.
Victim: Covenant Medical Center
Covenant Medical Center in TX USA
Reference: Covenant releases statement regarding appropriate care following ransomware attack on UMC
Reference: Embargo Ransomware Gang Sets Deadline to Leak Hospital Data
Incident: HHS Settles BCAA HIPAA Cybersecurity Violations Investigation for $90K
The breach at BCAA (Brian County Ambulance Authority), reported to OCR in May 2022, resulted in the encryption of files containing the ePHI of 14,273 patients. OCR’s investigation revealed that BCAA had not conducted a compliant risk analysis to identify potential risks and vulnerabilities to ePHI in its systems, a fundamental requirement under the HIPAA Security Rule.
Under the terms of the resolution agreement, BCAA has agreed to pay $90,000 and adopt a corrective action plan, which will be monitored by OCR over the next three years
Reference: HHS Inks $90K Settlement Linked to Ransomware Hack
Reference: HHS Settles with Bryan County Ambulance Authority Over HIPAA Violations Stemming from Ransomware Attack
Victim: Bryan County Ambulance Authority (BCAA)
Bryan County Emergency Services operates seven (7) ambulances manned by highly trained and certified Paramedics and EMT’s daily, on the North End and on the South End. Each of these units is equipped with specialized equipment for professional pre-hospital emergency medical care to the citizens and visitors of Bryan County.
Bryan County Emergency Services, in addition to responding to medical alarms provides public education, blood pressure and blood glucose screenings.
Reference: Halliburton reports $35 million loss after ransomware attack
Victim: Ahold Delhaize
Ahold Delhaize is a Dutch-Belgian multinational retail and wholesale holding company. Ahold Delhaize's world headquarters is in Zaandam. Other countries with Ahold Delhaize businesses include the Czech Republic, Greece, Luxembourg, Romania, Serbia, and the United States. It also participates in joint ventures in Indonesia and Portugal.
Ahold Delhaize is among the largest food and consumables retailers in the United States operating more than 2,000 stores of multiple brands across 23 states.
Reference: Cyber attack hits Ahold Delhaize’s US branch
Reference: Ahold Delhaize Confirms Cyber Breach – Food Lion, Stop & Shop, Hannaford Among Affected Brands
Incident: Operations Disrupted at US Branch of Grocery Giant Ahold Delhaize
Ahold Delhaize said it had “detected a cybersecurity issue within its U.S. network”. The company said the attack took certain systems offline and affected some pharmacies and e-commerce services.
Hannaford’s e-commerce services remained unavailable Monday morning, continuing an outage that began last week. On Friday, Hannaford posted on Instagram that it had canceled pickup and delivery orders that day “as our associates cannot view orders placed.” The websites for Giant Food, Stop & Shop, The Giant Company and Food Lion each posted an identical note online last Friday saying that customers may experience disruptions and reduced availability for pickup and delivery due to “system outages.” It’s unclear how much the cybersecurity issue has impacted Ahold Delhaize’s e-commerce sales.
UPDATE April 2025 : The company confirmed that data was stolen from its U.S. business systems.
Reference: Grocery giant Ahold Delhaize’s US operations disrupted by cyberattack
Incident: Data breach at Royal Caribbean Group
Attorney General of State of California Department of Justice posted this notification of a datebreach from Royal Caribbean Group: "Between February 6, 2021 and February 18, 2021, your personal data may have been accessed by a third party who gained unauthorized access to a limited number of our employees’ email
accounts. Upon discovery, we immediately secured the email accounts, began an investigation, and
arranged resources to start identifying, informing, and assisting persons whose personal information
may have been involved. During our review, we identified your information as having potentially been accessed, although we are not aware of any attempt to exploit this incident in a malicious way."
Victim: Royal Caribbean Cruise Line
Royal Caribbean Cruise Line
Reference: Submitted Breach Notification Sample
Incident: Colorado Laboratory Faces Action Breach Lawsuits After Medusa Ransomware Hack
Six months after an employee opened a phishing email sent by ransomware gang Medusa, a Colorado-based pathology laboratory is notifying more than 1.8 million patients that their sensitive information was compromised - one of the largest breaches reported by a medical testing lab to U.S. federal regulators to date.
Summit Pathology as of Thursday is already facing eight proposed federal class action lawsuits filed in the past week centering on the breach. The Summit incident ranks among some of the largest breaches reported by medical laboratory testing firms to date.
IT systems affected by the incident contained demographic and healthcare information, including names, addresses, medical billing and insurance information, diagnoses, dates of birth, Social Security numbers, and financial information.
Victim: Summit Pathology Laboratories
Summit Pathology Laboratories in Colorado
Reference: Medusa Ransomware Hack of Pathology Lab Affects 1.8 Million
Incident: City of Columbus Hackers Leak over 3TB Data
A July ransomware attack on the city of Columbus, Ohio, has exposed the personal information of approximately 500,000 residents, marking one of the most substantial cyber incidents involving a U.S. city.
The attack, attributed to the Rhysida ransomware group, has drawn attention due to both the extent of the data stolen and the controversial response from city officials.
Victim: City of Columbus OH
City of Columbus OH
Reference: City of Columbus: Data of 500,000 stolen in July ransomware attack
Reference: 500,000 Ohio Residents Exposed In Data Breach
Incident: Systems and Phones Down at Idaho Weiser Memorial Hospital
"Weiser Memorial Hospital (“WMH”) recently experienced a cybersecurity incident involving our computer systems. Immediately upon learning of this activity, WMH took action to secure our environment and launched an investigation to better understand what information was potentially impacted. The investigation into the incident remains ongoing." as reported on their Facebook page. "Further information will be released should Weiser learn of new developments during the ongoing investigation."
The hospital dealt with weeks of downed computer systems and phone lines. In October 2024 the hospital admitted the outages were caused by a cyberattack and acknowledged that it was investigating the claims made by Embargo operators.
Victim: Weiser Memorial Hospital
Weiser Memorial Hospital (“WMH”) in Idaho
Reference: Weiser Memorial Hospital’s Facebook Post
Incident: Cyberattack at NorthBay Health
NorthBay Health, which operates two hospitals and multiple clinics in Solano County, has been the victim of a systemwide cyberattack. The hospital was forced to turn patients away and cancel appointments following the ransomware attack.
Reference: NorthBay Health falls victim to cyberattack
Incident: Georgia Hospital Under Cyberattack Unable to Access Record System
A ransomware attack on a prominent hospital in southwest Georgia knocked out access to the electronic health record system.
Memorial Hospital and Manor in the town of Bainbridge posted an urgent message on Sunday warning patients that the hospital’s IT team had discovered a ransomware attack the morning before when employees found notifications from the virus protection software.
“This impacts access to our Electronic Health Record system. While we believe this issue will not impact either the level or the quality of care we provide to our patients, we want to be fully transparent regarding this situation,” the hospital said.
The attack was claimed on Tuesday by the Embargo ransomware gang, which is trying to extort a ransom out of the hospital by threatening to leak 1.15 terabytes of purportedly stolen data by November 8.
Victim: Memorial Hospital and Manor, GA
Memorial Hospital and Manor in the town of Bainbridge, GA
Threat Actor: Embargo Ransomware Gang
Embargo is a ransomware operation known for using Rust-based malware and operating under a ransomware-as-a-service (Raas) model. Like many modern ransomware groups, Embargo employs double extortion tactics where they first exfiltrate sensitive data from their victims before encrypting their files. They then threaten to release the stolen data unless a ransom Is paid.
The group was first observed by researchers early 2024. Embargo has claimed attacks on multiple hospitals.
Reference: Georgia hospital unable to access record system after ransomware attack
Reference: Change Healthcare Finally Admits It Paid Ransomware Hackers $22 Million—and Still Faces a Patient Data Leak
Reference: Dealer Losses Due to CDK Cyberattack Reach $1.02 Billion
Reference: US Conducts Cyberattack on Suspected Iranian Spy Ship – Report
Incident: Key Systems Down at Norwegian Cruise Company Hurtigruten After Ransomware rattack
Norwegian cruise company Hurtigruten sustained a cyberattack earlier on Monday and several key systems are currently down, the company said in a statement. The company, which operates ferries along the Norwegian coast as well as cruises in the Arctic and Antarctic in normal times, said it did not expect the attack to lead to a “material financial effect”, it said.
No details have been shared of the strain of ransomware, but the company will be juggling whether to pay its extortionists a handsome fee in order to have its data decrypted or attempt to restore its systems from its own backups.
“This is a serious attack. Hurtigruten’s global IT infrastructure appears to be affected,” Ole-Marius Moe-Helgesen, the company’s head of IT, said in a statement, adding that the company had implemented “comprehensive measures” to limit the damage from the attack.
Victim: Hurtigruten
Hurtigruten operates ferries along the Norwegian coast as well as cruises in the Arctic and Antarctic
Reference: Norwegian cruise liner Hurtigruten sustains cyber attack
Reference: Hurtigruten Struck By Cyberattack
Incident: Tracking in Prison Vans and Courier Vehicles Affected by Microlise Cyberattack
A cyber-attack targeting telematics provider Microlise has disrupted tracking services for key clients like DHL and Serco while exposing some employee data.
According to reports in the Financial Times, Serco - which handles the transport of prisoners for the Ministry of Justice - has seen vehicle tracking, panic alarms, navigation, and notifications related to estimated arrival times disabled. Drivers have been forced to use paper maps and check in with prison bases every 30 minutes.
Other customers believed to be affected by the breach include delivery service DHL Supply Chain and local convenience store chain Nisa, which uses DHL's services.
Third party cyber attacks, such as the one that hit Microlise services last week, present a challenge for all logistics operators.
Victim: Microlise
Microlise is a Nottingham, England-based provider of transport technology solutions to fleet operators
Reference: Serco, DHL among firms affected by Microlise cyber attack
Reference: Cyber attack on Microlise hits operators triggering call for stronger continuity plans
Reference: Microchip Technology reports $21.4M expense from August cyberattack
Reference: HALLIBURTON ANNOUNCES THIRD QUARTER 2024 RESULTS
Reference: Halliburton incurs about $35M in expenses related to August cyberattack
Incident: Ransomware Attack Threatens Disrupting Medicine Supply to Pharmacies in Germany
AEP, a German pharmaceutical wholesaler based in Bavaria, said it was hit by a ransomware attack. Pharmacies are currently only being supplied to a limited extent by AEP.. The Bavarian Pharmacists Association said that affected pharmacies should be able to use supplies from other wholesalers to make up for the disruption, as reported by Bayerischer Rundfunk.
On October 28, AEP fell victim to a targeted cyber attack that led to partial encryption of the company's IT systems. The company is currently not reachable by phone and can only be reached to a very limited extent by email.
Victim: AEP GmbH
AEP GmbH is a German pharmaceutical wholesaler based in Bavaria.
AEP employs around 200 people and supplies more than 6,000 pharmacies across Germany.
Reference: After hacker attack: drug supply not at risk (Nach Hackerangriff: Medikamentenversorgung nicht gefährdet)
Reference: Ransomware attack hits German pharmaceutical wholesaler, disrupts medicine supplies
Incident: Disruptions at Texas Key Oil Field Supplier due to Ransomware Attack
Newpark Resources discovered the ransomware attack on October 29 that affected internal information systems. “The incident has caused disruptions and limitation of access to certain of the Company’s information systems and business applications supporting aspects of the Company’s operations and corporate functions, including financial and operating reporting systems,” the company told the U.S. Securities and Exchange Commission (SEC).
“However, the Company’s manufacturing and field operations have continued in all material respects utilizing established downtime procedures.”
The company has not determined what the costs and financial impacts of the incident will be at this time.
Victim: Newpark Resources
Newpark Resources manufactures, sells, and rents tools for drilling that are used in oilfields and several other energy-related industries like pipelines, renewable energy, petrochemicals and construction.
Reference: Mystery Hackers Target Texas Oilfield Supplier in Ransomware Attack
Reference: Texas-based oilfield supplier faces disruptions following ransomware
Reference: OT Feels Impact Of CrowdStrike Update Outage
Incident: Flooring Manufacturer Congoleum Hit In Cyberattack
Flooring manufacturing giant, Congoleum Acquisition, LLC suffered a data breach where personal information ended up stolen from 1,600 people. Congoleum mailed data breach notification letters to those affected by the cyber incident providing affected individuals with a list of the specific type of sensitive information impacted and complimentary credit monitoring services.
Victim: Congoleum Acquisition, LLC
Mercerville, New Jersey-based Congoleum has been in operation since 1886, and it offers flooring options in an array of styles and colors. The company invented the first groutable resilient tile and the world’s first PVC-free and digitally printed resilient tile and plank. Congoleum has operating manufacturing plants in Maryland, Pennsylvania, and New Jersey, and employs over 500 workers.
Reference: Flooring Manufacturer Hit In Cyberattack
Incident: Medical Device Maker LivaNova Hit In Cyberattack
Medical device manufacturer, LivaNova, suffered a cyberattack on October 26, 2023, which the company said it discovered November 19, 2023.
“The incident resulted in a disruption to portions of our IT systems,” the company said in an advisory. “Promptly after detecting the issue, we began an investigation with assistance from external cybersecurity experts and coordinated with law enforcement. We took action to remediate the issue, such as taking certain systems offline.” As a result of the attack, the company is offering identity protection and credit monitoring for the victims. No further information was available
Victim: LivaNova, plc
LivaNova, plc is an Italian-American medical device manufacturer based in the UK. The company develops devices used for cardiac surgery and neuromodulation. The company formed in 2015 by a $2.7 billion merger between Houston, Texas-based Cyberonics, Inc. and Milan, Italy-based Sorin S.p.a.
Reference: Medical Device Maker Hit In Cyberattack
Incident: Personal Information Exfiltrated at Noritsu America Corporation
On July 31, Buena Park, California-based Noritsu North America said it discovered unusual activity in its network environment that originally started April 29. As soon as Noritsu discovered the incident, the company took action as part of its security plan. As of right now, the company has no evidence any stolen information has ended up used as a result of this incident. No further information was immediately available
Victim: Noritsu
Noritsu is a global manufacturer of professional high-quality digital imaging equipment, and a global provider of photo printing solutions to the retail, professional, law enforcement, specialty and other print-intensive markets
Reference: Imaging Equipment Maker Suffers Cyberattack AUG 9, 2024 | NEWS
Incident: Databreach at Upstream Engineering Firm, Netherland, Sewell & Associates, Inc. (NSAI)
Dallas, Texas-based upstream engineering provider, Netherland, Sewell & Associates, Inc. (NSAI) discovered on or around August 16, 2024 they suffered a ransomware attack in July. Personal information that may have been obtained, the company said. It added there has been no indications attackers are using that information at present. The current count of victims in the attack is at 537, the company said.
Victim: Netherland, Sewell & Associates, Inc. (NSAI)
Dallas, Texas-based upstream engineering provider, Netherland, Sewell & Associates, Inc. (NSAI).
NSAI conducts petroleum property analysis for industry and financial organizations and government agencies. The company delivers fully integrated engineering, operational, geological, geophysical, petrophysical, and economic solutions for all facets of the upstream energy industry.
Reference: TX Engineering Firm Hit In Ransomware Attack SEP 23, 2024 | NEWS
Incident: Composite Material Producer Suffered Cyberattack
Composite material producer, The Gill Corporation (TGC) suffered a cyberattack where threat actors encrypted data in late June and the company is now informing victims personal information ended up stolen.
Victim: The Gill Corporation (TGC)
Composite material producer, The Gill Corporation (TGC)
Reference: Cyberattack Encrypts Composite Material Maker’s Files
Incident: Cyberattack at Oil & Gas Exploration Investor Anderson Feazel
Around July 31, 2024 Anderson Feazel ’s computing system was attacked The hackers accessed and exfiltrated certain unencrypted financial documents that contained individual and employee records, business records, mineral leases, pay records, and other private or personal information. The personal information the attackers stole depended the relationship the victim had with the company. There were 9,222 victims in the incident.
Upon discovery Anderson involved the FBI and state law enforcement.
Victim: Anderson Feazel
Anderson Feazel, a Shreveport, Louisiana-based energy company specializing in oil and gas production.
Reference: LA Energy Company Hit In Cyberattack
Incident: Wafer Equipment Maker Hit In Cyberattack
Mattson Technology Inc. suffered a cyberattack in 2023 and is now letting folks know about the incident.
"Between April 11, 2023 and April 29, 2023, an unauthorized individual accessed our network and accessed and/or removed certain files from it". Mattson did not elaborate on the extent of the information stolen. Upon learning about the event, Mattson moved quickly to respond and investigate the incident, assess the security of its systems, and notified potentially impacted individuals.
Reference: Wafer Equipment Maker Hit In Cyberattack
Victim: Mattson Technology Inc
Mattson Technology is an American technology company founded in 1988 by Brad Mattson and partly state-owned by the municipal government of Beijing. Mattson designs, manufactures, markets and globally supports semiconductor wafer processing equipment used in the fabrication of integrated circuits.
The company also has design centers in the United States and Germany, and manufacturing facilities in the United States, Germany and China.
Reference: Moving Provider’s Cyberattack Leaked Decades-Old Data, Suit Says
Reference: Biotech Leader, Amgen, Affected By Cyberattack
Victim: Sirva Relocation, LLC
Sirva Relocation, LLC (parent company, Sirva, Inc) is an Amgen Inc. service provider –
Incident: Leading Semiconductor Material Manufacturer Falls Victim to Ransomware Attack
MEMC, LLC has recently fallen victim to a ransomware attack orchestrated by the cybercriminal group BlackBasta. The attackers have compromised approximately 1 terabyte of sensitive data from MEMC's systems. The stolen data includes corporate and financial information, non-disclosure agreements (NDAs), confidential documents, human resources and hiring information, research and development (R&D) and engineering data, personal employee documents, and client data.
This breach poses significant risks to MEMC's operations, intellectual property, and the privacy of its employees and clients. Despite the attack, the company's website remains operational.
Reference: Ransomware Attack on MEMC, LLC by BlackBasta: Key Details
Victim: MEMC LLC
MEMC LLC, a provider of advanced semiconductor materials for the electronics industry: specialty silicon-on-insulator (SOI) wafers that support smartphones, gaming systems, and cars. Based in St Peters, Missouri.
Reference: Semiconductor Material Maker Hit In Cyberattack
Incident: Cyberattack on Multiple Rural Texas Water Facilities
Hackers attacked small Texas towns' water systems, causing a tank to overflow in one of them. Then, "There were 37,000 attempts in four days to log into our firewall," said Mike Cypert, city manager of Hale Center. The town is home to about 2,000 residents. "The attempted hack failed as the city "unplugged" the system and operated it manually, he added."
The water facility in Muleshoe, a town of about 5,000 people was also attacked. The hackers broke into a remote login system for industrial software that allows operators to interact with a water tank. City manager Ramon Sanchez said in an email: "The water tank overflowed for about 30 to 45 minutes before Muleshoe officials took the hacked industrial machine offline and switched to manual operations." Muleshoe officials replaced the hacked software system. However, the city's water disinfectant system was not affected, and the public water system nor the public was in any danger.
In nearby Lockney, home to around 1,500 people, hackers unsuccessfully tried to access the town's water system.
The town of Abernathy also experienced cyber incursions. Hackers entered through a virtual network connection, but city staff caught them within 30 seconds. The attackers were cut off as they were trying to change passwords, City Manager Donald Provost told Bloomberg News.
The attacks have been linked to a shadowy Russian hacktivist group. Therefore, the FBI and the US Department of Homeland Security are investigating these breaches.
Reference: Russia-linked hacking group suspected of carrying out cyberattack on Texas water facility, cybersecurity firm says
Victim: Lockney Texas Water Facility
Lockney rural Texas Water Facility
Victim: Hale Center Texas Water Facility
Hale Center rural Texas Water Facility
Victim: Muleshoe Texas Water Facility
Muleshoe rural Texas Water Facility
Reference: Rural Texas towns report cyberattacks that caused one water system to overflow
Reference: Hackers target the Muleshoe, Texas water system – not for ransom, but as a test
Reference: The American Water cyberattack: Explaining how it happened
Incident: Largest US Water Utility Suffers Significant Cyberattack, says Operations Not Impacted.
There was a cyberattack Thursday at American Water. The attack involved unauthorized access to American Water's computer networks and systems. American Water responded to the attack by shutting down some of its systems to prevent further risk to its systems. The precise type of attack was not initially disclosed by American Water, though some early speculation claims that it was a ransomware attack. The company took its customer portal called MyWater offline.
“We currently believe that none of the water or wastewater facilities or operations have been negatively impacted by this incident,” the company said.
Impact of the attack: systems shutdown, customer service disruption, billing suspension, potential data breach, reputational damage.
American Water said the investigation is ongoing and will take time to complete.
Victim: American Water
American Water, which is on the New York Stock Exchange, is the largest regulated water and wastewater utility company in the United States. With a history dating back to 1886, the company provides safe, clean, reliable and affordable drinking water and wastewater services to more than 14 million people with regulated operations in 14 states and on 18 military installations.
Reference: Water Company Attack Shuts Down Some Systems
Incident: Japanese Technology Giant Casio Computer confirmed Cyberattack
High tech manufacturer, Casio Computer Co., Ltd., suffered a cyberattack that caused a “system failure” which did not allow the company to provide services.
The Japanese technology giant confirmed on October 5th of this year that its network had been illegally accessed by a third party. The company stated unauthorized access had caused a system failure, making it impossible to provide some services. On October 5, the attackers leaked the data, which included customer names, email addresses, country of residence, order details, service usage information and payment methods. Attackers did not steal credit card information in the breach, the company said. No further information was immediately available.
Just about one year ago the company said hackers accessed the company’s education web application ClassPad.net, resulting in the leak of customers’ personal information from 148 countries.
Victim: Casio
Casio is a Japanese technology giant which makes among other items calculators, cameras, musical instruments, and digital watches.
Reference: Casio Suffers ‘System Failure’ After Attack
Incident: Atlanta, Georgia-based EPI Breads suffered a Cyberattack
Atlanta, Georgia-based EPI Breads suffered a cyberattack in August and is now letting victims know some of their information ended up exfiltrated by threat actors.
EPI, which has manufacturing facilities in Atlanta and Muskegon, Michigan, issued a letter to victims saying the national bakery suffered a data security incident that may have involved personal information. Additionally, the attack affected 10,853 victims.
Victim: EPI Breads
EPI Breads has manufacturing facilities in Atlanta and Muskegon, Michigan.
EPI Breads started in 1985 as a small Atlanta bakery delivering fresh breads to local establishments. Today it makes a variety of custom breads across foodservice and retail. Each of EPI’s U.S. bakeries can handle major chain capacity orders and ship to all 50 states.
Reference: GA-Based National Bakery Suffers Cyberattack
Incident: Blackinton Manufacturer Suffers Databreach
On August 30, 2024, Blackinton, manufacturer of public safety badges and uniform insignia, suffered a cyberattack. The company immediately secured the network. An investigation confirmed an unauthorized actor accessed its systems. Blackinton launched a comprehensive review and confirmed certain individuals’ personal information may have been involved in the incident. Blackinton has been working to notify all affected individuals of this incident.
Victim: Blackinton
Blackinton is a manufacturer of public safety badges and uniform insignia.
Incident: Databreach at Chemical Manufacturing and Research Company, Ortec.
Ortec, Inc. in Easley, Oregon experienced a network disruption. The investigation determined that certain files may have been acquired without authorization on or about May 28, 2024. A comprehensive review of the affected data determined that personal information was compromised. Everyone has been notified.
Victim: Ortec, Inc.
Ortec, Inc. in Easley, Oregon is a custom chemical manufacturing and research company.
Incident: Databreach at Large North American Natural Stone Manufacturer
Granit Design recently experienced a cybersecurity incident affecting the confidentiality of its employee data. An unauthorized third party accessed the server between July 20, 2024, and August 2, 2024, and acquired a subset of its files. The investigation remains ongoing to determine the extent of data that was acquired, but Granit Design is notifying all individuals whose information was contained on the affected systems.
“.. we took steps to secure our systems and launched an investigation immediately after discovering the Incident. To help prevent similar occurrences in the future, we will continue to monitor our systems for any suspicious activity, and we have implemented additional measures designed to enhance the security of our network, systems, and data. We will continue to evaluate ways to further enhance the security of its systems to minimize the likelihood of similar incidents occurring in the future.”
Victim: Granit Design
Granit Design, Stanstead, Quebec, Canada, is one of the largest North American manufacturers of natural stone, quartz and ultra-compact surface made-to-measure projects.
Incident: Databreach at Stillwater Mining Company
The Sibanye-Stillwater group, part of Stillwater Mining Company, stated a cyber-attack had compromised certain Sibanye-Stillwater information and communications technology (ICT) systems within their global network. "Upon discovery, we initiated the Incident Response plan .. and engaged external cybersecurity experts and forensic firms to help investigate the suspicious activity. The forensic investigation identified indications of unauthorized activity on certain U.S. systems as of mid-June 2024. Impacted past and current employees were notified their employee files were accessed.
The files contain records of personal information, such as: names; contact details; government ID and/or passport number; Social Security number; tax ID number; date of birth certificate; financial information, such as a bank account number (but no passcodes or PINs); and medical information, such as a health plan number.
Victim: Stillwater Mining Company
Stillwater Mining Company in Columbus, Montana is a palladium and platinum mining company with headquarters located at Littleton, Colorado.
Incident: TABASCO Plant Hit by Ransomware Attack
McIlhenny Company discovered a security breach originating from a vulnerability in a third-party’s code. The issue was promptly addressed. The investigation revealed payment details, including name, mailing address, email address, and credit card information were accessed. As of this writing, McIlhenny Company has not received any reports of related identity theft since the date of the incident.
McIlhenny Company manufactures and distributes various food products under the TABASCO brand.
Victim: McIlhenny Company
McIlhenny Company in Avery Island, Louisiana, manufactures and distributes various food products under the TABASCO brand.
Incident: US Medical Device Manufacturing Company, Noble Biomaterials, hit by Ransomware Attack
“On or about August 3, 2024, Noble became aware of suspicious activity on its computer network. An investigation and determined that its network had been infected with malware which prevented access to certain files on its systems. Between July 25, 2024 and August 3, 2024, an unauthorized actor may have had access to information related to certain current and former employees. Although Noble has no evidence of any identity theft or fraud in connection with this incident, they notified those individuals whose information was present within its systems.
Noble notified federal law enforcement regarding the event, and is cooperating with its investigation.
Victim: Noble Biomaterials, Inc.
Noble Biomaterials, Inc. in Scranton, Pennsylvania is a medical device manufacturing company registered with the U.S. Food & Drug Administration (FDA) and Environmental Protection Agency (EPA). It has numerous 510(k) medical device clearances and is a manufacturer of several EPA-approved antimicrobial products.
Incident: Ransomware Attack at US Oldenburg Group, supplier of Performance Engineered Products
Oldenburg Group, a global supplier to the architectural lighting industry worldwide, experienced a ransomware incident between May 4 and May 5. An attacker, appearing to be associated with the Play ransomware group, installed ransomware on the Company’s primary servers and may have had access to personal information located on the servers.
The company secured the servers, launched an investigation and stated that a data breach had occurred.
“The information accessed may have included personal information including, but not limited to your name, email address, address, date of birth, Social Security number, driver’s license number, financial account information, tax information, medical information, and health insurance information"
Reference: Seven Separate Firms Suffer Cyberattacks
Victim: Oldenburg Group
Oldenburg Group is a supplier of performance engineered products used in the architectural lighting industry worldwide.
Reference: Ransomware Group Behind Seattle Airport Attack
Incident: Ransomware Attack at Motorcycle Manufacturer Kawasaki Motors Europe
“At the start of September, Kawasaki Motors Europe, (KME) was the subject of a cyberattack which, although not successful, resulted in the company’s servers being temporarily isolated until a strategic recovery plan was initiated later on the same day,” the company said in an advisory. Over 90 percent of servers was functionality was restored the following week. Before finishing to ensure that each and every server was free of non-authorized information, KME were able to resume business for dealers, business administration and third-party suppliers such as logistics companies.
Victim: Kawasaki Motors Europe
Kawasaki Motors Europe (KME) is a subsidiary of Japan-based Kawasaki Heavy Industries, Ltd. that makes motorcycles, all-terrain vehicles, jet skis, and utility vehicles.
KME is responsible for the distribution, sales, and marketing of Kawasaki’s motorcycle products in the European market, operating a network of authorized dealerships and customer service centers.
Reference: Kawasaki Hit In Ransomware Attack
Incident: Manual Woodworkers And Weavers Suffers Cyberattack
Hendersonville, North Carolina-based Manual Woodworkers and Weavers, Inc., (MWW) fell victim to a cyberattack this past July where threat actors stole personally identifiable information.
“We are writing to advise you of an incident that may have involved some of your personal information,” the company said in a letter to victims. “While we have no evidence that your information has been misused as a result of this incident, this letter provides information about the incident and guidance on what you can do to protect yourself, should you feel it is appropriate to do so.”
Reference: Cyberattack At Manual Woodworkers And Weavers
Victim: Cyberattack At Manual Woodworkers And Weavers
The company built a state-of-the-art warehouse and distribution center. The undertaking included over two miles of smart conveyor systems, a three-story central pick and pack unit, and a million square feet of manufacturing and warehouse distribution space, according to the company’s website.
Incident: CA Footwear Maker, Phoenix Footwear Group, Hit In Cyberattack
Footwear maker, Phoenix Footwear Group, Inc., fell victim to a cyberattack this past August where personally identifiable information of customers fell into the hands of a threat actor.
In a letter to victims, Carlsbad, California-based Phoenix Footwear Group let everyone know about the company’s response and resources available.
“On August 26, 2024, Phoenix became aware of suspicious activity in our network,” the company said in its letter. “We promptly took steps to secure our systems and initiated an investigation into the nature and scope of the event. The investigation determined that certain files on Phoenix’s network were accessed or acquired without authorization on August 26, 2024."
Reference: CA Footwear Maker Hit In Cyberattack
Victim: Phoenix Footwear Group, Inc.,
Phoenix Footwear Group Inc operates in the footwear industry, according to the company’s website. It manufactures and distributes footwear in a range of sizes and widths under the brand’s Trotters, SoftWalk, Pendleton, Los Cabos, and Bueno.
Incident: Fiskars Group Suffers Cyberattack
Global home designer and manufacturer, Fiskars Group fell victim to a cyberattack this past March and is now informing victims of the incident.
Fiskars Group, which has a U.S. headquarters in Middleton, Wisconsin and global headquarters in Fiskars, Finland, said there were 6,306 victims in the attack.
“On April 26, 2024, we discovered unauthorized activity on Fiskars’ network,” the company said in a letter to its victims. “Fiskars immediately began an investigation to assess the nature and scope of the activity. Fiskars engaged third-party cybersecurity experts, and we notified law enforcement."
Reference: Cyberattack At Fiskars Group
Victim: Fiskars Group
Fiskars Group is the global home of design-driven brands for indoor and outdoor living. The company is follows its common purpose: Pioneering design to make the everyday extraordinary, according to the company’s website.
Reference: Ransomware Attack At TX Oilfield Equipment Provider
Incident: Ransomware Attack at Schneider Electric
Schneider Electric suffered a ransomware attack. A threat actor said it stole 40GB of data from a developer platform from the company’s Jira server.
“Schneider Electric is investigating a cybersecurity incident involving unauthorized access to one of our internal project execution tracking platforms which is hosted within an isolated environment,” Schneider said in a statement. “Our Global Incident Response team has been immediately mobilized to respond to the incident. Schneider Electric´s products and services remain unaffected.”
Reference: Schneider Hit In Ransomware Attack
Incident: SelectBlinds, a Custom Wall Covering Provider, Suffers Cyberattack
Maker and retailer of blinds, window shades and other window coverings, SelectBlinds suffered a cyberattack this past January and is now informing victims of the incident.
On October 31, SelectBlinds filed a notice of data breach after discovering the company was the target of a cyberattack back in January. In the notice, SelectBlinds said the incident resulted in an unauthorized party being able to access consumers’ sensitive information.
After learning that sensitive consumer data was accessible to an unauthorized party, SelectBlinds reviewed the compromised files to determine what information leaked and which consumers ended up impacted. SelectBlinds just completed this process, identifying an estimated 206,238 individuals who had information compromised as a result of the incident.
Reference: Custom Wall Covering Provider Suffers Cyberattack
Victim: SelectBlinds
SelectBlinds custom handcrafts every single product and is an Internet retailer of blinds, window shades and other window coverings. The company is is a wholly owned subsidiary of Hunter Douglas, a Dutch company that manufactures window blinds and coverings. SelectBlinds employs more than 140 people and generates approximately $200 million in annual revenue.
Incident: NY Curtain Maker, S. Lichtenberg & Co., Suffers Cyberattack
Great Neck, New York-based S. Lichtenberg & Co., Inc. suffered a cyberattack “to a portion of our network” this past August and it just completed its investigation.
The manufacturer of curtains, draperies, and home fashion products, along with soft window treatments, shower curtains, and bedding to the retail trade, sent letters out to victims last Wednesday after it completed its investigation earlier in October.
“We are writing to inform you of a cyber security event experienced by S. Lichtenberg & Co., Inc. that may have involved your information described below,” the company said in an advisory. “While we have no evidence of attempted or actual misuse of any information, we are providing you with information about the incident, our response, and steps you can take to help protect your information, should you feel it appropriate to do so.
Reference: NY Curtain Maker Suffers Cyberattack
Victim: S. Lichtenberg & Co., Inc.
It is a manufacturer of curtains, draperies, and home fashion products, along with soft window treatments, shower curtains, and bedding to the retail trade.
Incident: Oil Spill Cleanup Equipment Maker, Elastec, Hit In Cyberattack
Carmi, Illinois-based Elastec suffered a cyberattack after it discovered suspicious activity related to an employee’s email account.
In response, the manufacturer of oil spill cleanup and surface water pollution equipment took steps to secure its email environment and conduct a comprehensive investigation, which determined the Elastec employee email account ended up accessed without authorization between June 4 and June 18 by an unknown party.
Elastic, which operates in 155 countries, has three manufacturing facilities in southern Illinois, and Cocoa, Florida, they are a distributor of oil skimmers, oil boom, dispersant application systems, work boats, vacuum systems, portable incinerators, turbidity curtains and custom containment booms for floating trash, debris and aquatic week control.
Reference: Oil Spill Cleanup Equipment Maker Hit In Cyberattack
Victim: Elastec
Elastic, which operates in 155 countries, has three manufacturing facilities in southern Illinois, and Cocoa, Florida, they are a distributor of oil skimmers, oil boom, dispersant application systems, work boats, vacuum systems, portable incinerators, turbidity curtains and custom containment booms for floating trash, debris and aquatic week control.
Incident: Rogers Foam, a Custom Foam Manufacturer, Hit In Cyberattack
Custom engineered foam manufacturer, Rogers Foam Corporation (RFC), suffered a cyberattack last month that included data exfiltration.
“RFC is writing to inform you of a recent data security incident that may have resulted in the potential unauthorized access and acquisition of your sensitive personal information,” the company said in a letter to victims. “We are providing you with details about the incident, steps we are taking in response, and resources available to help you protect against the potential misuse of your data. RFC takes the protection and proper use of your personal information very seriously, and we sincerely apologize for any inconvenience this may cause.
“On September 23, 2024, RFC detected suspicious activity in its network environment. Upon discovery of this incident, RFC promptly took steps to secure its network and engaged a specialized cybersecurity firm to investigate the nature and scope of the incident. RFC’s investigation determined that an unauthorized third-party potentially accessed and acquired certain files and data stored within our network,” the company said.
Reference: Custom Foam Manufacturer Hit In Cyberattack
Victim: Rogers Foam Corporation
Rogers Foam provides custom engineered solutions from product development support, to local production and delivery, according to the company website. The company converts flexible materials for customers in the medical, automotive, consumer goods, industrial, packaging, furniture, and bedding industries.
Incident: Control Room Provider, Activu, Hit In Cyberattack
Control room visualization technology provider, Activu Corporation, suffered a cyberattack this past August and is now informing victims of the attack.
“On or about, August 30, 2024, Activu became aware of suspicious activity on our computer network,” the Rockaway, New Jersey-based company said in an advisory. “We promptly took steps to secure our systems and began an investigation to determine the full nature and scope of the event.
“Our investigation determined that an unknown actor gained accessed certain Activu systems on August 30, 2024, and accessed and/or acquired certain files from those systems."
Victim: Activu Corporation
Founded in 1983, Activu was the first U.S.-based company to develop control room visualization technology. The company is in more than 1,300 control rooms, monitoring, security, and operations centers.
Incident: Well Servicing Contractor, MMI Services, Hit in Cyberattack
Well servicing contractor, MMI Services, Inc., suffered a cyberattack in May and is now letting victims of the attack know about what occurred and what information the threat actors made off with.
“On May 21, 2024, we experienced a network disruption that impacted certain systems,” the Bakersfield, California-based company said in an advisory. “Upon discovery, we took immediate action to address and investigate the event, which included engaging third-party specialists to assist with determining the nature and scope of the incident.
“The investigation determined that limited information maintained on our network may have been acquired by an unauthorized actor between May 20, 2024, and May 21, 2024. We then began a review of the contents of the potentially affected data to determine the type of information contained within and to whom that information related."
Reference: Well Servicing Contractor Suffers Cyberattack
Victim: MMI Services, Inc.
MMI Services is an Independent well wervicing contractor offering oil field services ranging from completions, workovers, abandonments and production, coil tubing, vac truck and crane, BOP and hydro-testing, and transportation and light tower services.
Incident: Arms Maker, Saeilo, Suffers Ransomware Attack
Diversified manufacturer, Saeilo Enterprises Inc., discovered it suffered a ransomware attack this past August and after an investigation, it is now letting victims know about personal information the attackers stole.
“Saeilo Enterprises is writing to inform you of a recent ransomware cyberattack that may have exposed your personal information,” the company said in an advisory. “We take the security of your personal information seriously and want you to know what happened, what data may have been affected, and what you can do to help protect yourself.
“On August 8, 2024, we discovered that files on some of our servers, as well as the servers of our brands and subsidiaries – Kahr Arms, Magnum Research, Tommy Gun, and Thompson/Auto Ordinance – had been subject to a ransomware cyberattack."
Reference: Ransomware Attack At Arms Maker, Saeilo
Victim: Saeilo Enterprises Inc.
Saeilo is a diversified company, offering contract CNC machining, manufacturing of firearms for personal protection and law enforcement, and complete automotive service and used car sales.
Incident: FL Ship Builder, Eastern Shipbuilding Group, Suffers Cyberattack
Panama City, Florida-based Eastern Shipbuilding Group (ESG) discovered in February they fell victim to a cyberattack and they are now letting victims know about the incident. ESG is a key contractor for the US Coast Guard's Offshore Patrol Cutter (OPC) fleet.
The attack was claimed by the LockBit ransomware group. This incident exacerbates existing challenges following a hurricane that had previously forced the company to rebuild its shipyard.
The attack poses significant risks to national security and the USCG's OPC program, potentially impacting the shipbuilding schedule and benefiting other shipyards like Bollinger Shipyards. Eastern Shipbuilding must now address the cybersecurity threat and restore trust with stakeholders, reports Maritime Cybersecurity.
Reference: FL Ship Builder Suffers Cyberattack
Victim: Eastern Shipbuilding Group
ESG’s original shipyard started up in 1976 for the purpose of constructing commercial fishing boats for the company’s founder and president, Brian R. D’Isernia. Furthermore, as the owner of a fleet of commercial fishing vessels, D’Isernia ventured into the world of shipbuilding. Additionally, as he built and developed his own personal fleet of vessels, other professionals in the industry took notice and began to request their own custom-built vessels.
Incident: Ransomware Attack at Kulicke and Soffa Industries
Semiconductror tool maker, Kulicke and Soffa Industries (K&S), suffered a ransomware attack at the hands of “LockBit Black” in May and it now letting victims know about the attack.
In a letter to victims, the company with global headquarters in Singapore and U.S. headquarters in Fort Washington, Pennsylvania, said “Kulicke and Soffa Industries (K&S) writes to inform you about a recent cybersecurity incident that may have involved your personal information. We understand that this can be a stressful situation, and we want to assure you that we are taking this matter very seriously. This letter provides you with information about the nature of the incident and affected data and the immediate and additional corrective measures K&S has taken to guard against future unauthorized disclosure or misuse of your personal data.
“On May 12, 2024, K&S discovered its first indications of a ransomware attack when it (ended up) contacted by an organization that called itself ‘LockBit Black.’” The organization informed K&S it accessed and encrypted specific K&S files and showed certain screenshots to support its claims.”
Reference: Semiconductor Tool Maker Hit By Ransomware
Victim: Kulicke and Soffa Industries (K&S)
K&S principally designs, manufactures, and sells capital equipment and expendable tools used for assembling semiconductor devices. U.S. headquarters is in Fort Washington, Pennsylvania.
Incident: Aero Simulation, Flight Simulator Manufacturer Hit in Attack
Tampa, Florida-based Aero Simulation, Inc., (ASI) a maker of flight simulators for government and military units, suffered a cyberattack this past February that had been ongoing for about a year.
Aero Simulation designs and manufactures flight simulators and provides services for simulator modifications, upgrades, trainer moves, and site support services for customers, primarily in the Department of Defense (DoD), Department of Homeland Security (DHS) and foreign militaries.
“On or around February 27, 2024, ASI became aware of suspicious activity related to an employee email account,” the company said in a letter it sent out to victims in early October. “We immediately took steps to secure the email account, and launched an extensive investigation, with the assistance of third-party forensic specialists, to determine the nature and scope of the event.
“Through our investigation, we determined that an unknown actor gained access to one (1) employee email account and may have viewed and/or downloaded certain data within that account between an estimated period of February 2023 to May 2023."
Reference: Maker Of Flight Simulators Hit In Cyberattack
Victim: Aero Simulation
Aero Simulation, Inc., (ASI) is a maker of flight simulators for government and military units.
Incident: Cyberattack at Apparel Maker Varsity Brands
Farmers Branch, Texas-based Varsity Brands suffered a cyberattack affecting over 65,000 of its customers on May 22 which it discovered two days later, and just sent out a notice Monday to victims of the incident.
“We are writing to inform you that some of your personal information was recently impacted when we experienced a security incident,” said the letter to the victims.
“On May 24, 2024, Varsity Brands identified unusual activity on our systems. Upon detection, we promptly took steps to stop the activity and took certain systems offline. An investigation launched with assistance from external cybersecurity experts. We also notified law enforcement,” the letter said.
Reference: Apparel Maker, Varsity Brands, Hit In Cyberattack
Victim: Varsity Brands
Varsity Brands is an American apparel company owned by the private equity firm Kohlberg Kravis Roberts (KKR). The company primarily focuses on academic apparel and memorabilia, with its operations split among three subsidiaries: Herff Jones, a manufacturer of products such as class rings, graduation caps and gowns, and yearbooks; Varsity Spirit, which produces apparel and competitions for cheerleading; and BSN Sports, a distributor of sports uniforms and equipment.
Incident: Physical Security Giant, ADT, Suffers Attack, Again
For the second time in three months, physical security giant, ADT Inc. reported an “unauthorized activity” on its network, this time gaining access using compromised credentials obtained through a third-party business partner.
The result was the attack forced the Boca Raton, Florida-based company to shut down various components and mitigate the unauthorized access.
The company said it promptly took steps to shut down the unauthorized access, notified the third party its systems suffered compromise, launched an investigation, and implemented counter measures intended to safeguard the company’s information technology assets and operations, the company said in an October 2 8-K advisory to the Securities and Exchange Commission (SEC).
Reference: ADT Hit In Cyberattack, Again
Incident: ADT, Physical Security Giant, Hit in Cyberattack
Physical security giant, ADT Inc., fell victim to a cyberattack where attackers purloined customer data, the company said in an 8-K report to the Securities and Exchange Commission (SEC).
“ADT recently experienced a cybersecurity incident during which unauthorized actors illegally accessed certain databases containing ADT customer order information,” the company said in the report filed with the SEC August 3. “After becoming aware of the incident, the company promptly took steps to shut down the unauthorized access and launched an investigation, partnering with leading third-party cybersecurity industry experts.”
Reference: Physical Security Giant ADT Hit In Cyberattack
Victim: ADT Inc.
Boca Raton, Florida-based ADT is a security company that provides residential and small business electronic security, fire protection, and other related alarm monitoring services throughout the United States.
Reference: Hackers shut down heating in Ukrainian city with malware, researchers say
Incident: Cyberattack against Mobile Guardian Results in Remote Wiping of School Devices.
A cyberattack against mobile device management firm Mobile Guardian has caused disruptions at educational institutions in North America, Europe, and Singapore, the Register reports. The company has halted its services while it responds to the incident. The details of the attack are unclear, but the incident somehow "resulted in a small percentage of devices to be unenrolled from Mobile Guardian and their devices wiped remotely." The company says there's "no evidence to suggest that the perpetrator had access to users’ data."
13,000 student devices were wiped in Singapore, and the country's Ministry of Education (MOE) has severed ties with Mobile Guardian as a result. The MOE says it's "working with schools to support affected students, including deploying additional IT roving teams to schools and providing additional learning resources."
Victim: Mobile Guardian
Mobile Guardian is a powerful, mobile device management (MDM) solution purpose-built for districts and schools, offering device management, web filtering, and classroom management tools.
Reference: MDM vendor Mobile Guardian attacked, leading to remote wiping of 13,000 device
Incident: Epson Korea Cyberattack Affects 350000 Customers
Epson Korea has said hackers breached the personal data of 350,000 registered customers. An official at the South Korean affiliate of Seiko Epson Corp. said personal information, including phone numbers, e-mail addresses, names and coded data of customers registered on its website had been compromised.
Victim: Epson Korea Co., Ltd.
Epson print OEM
Reference: Epson Korea says cyber attack affects 350,000 customers
Reference: Epson admits cyberattack
Incident: Australian Evolution Mining Quickly Contains Ransomware Attack
Australian Evolution Mining became aware of the cybersecurity incident on August 8. In an official statement, Evolution Mining disclosed that the ransomware attack had impacted its IT systems. The company acted swiftly by engaging external cyber forensic experts to investigate and contain the incident. “The Company believes the incident is now contained,”
Evolution Mining reassured stakeholders that it does not foresee any material impact on its operations as a result of the cyberattack.
Reference: Gold producer Evolution Mining confirms ransomware cyber attack, says incident ‘contained’
Victim: Evolution Mining
Evolution Mining is a prominent player in the global gold mining industry, operating a portfolio of high-quality assets across Australia and Canada.
The company manages six mines, including five wholly-owned operations: Cowal in New South Wales, Ernest Henry and Mt Rawdon in Queensland, Mungari in Western Australia, and Red Lake in Ontario, Canada.
Additionally, Evolution holds an 80% stake in the Northparkes mine in New South Wales, further solidifying its position as a leading gold miner.
Reference: Australian Mining Giant Evolution Mining Hit by Ransomware Attack
Incident: Swiss Machine Manufacturer Schlatter Industries Falls Victim to Ransomware Attack
The machine manufacturer Schlatter has fallen victim to a cyber attack, disrupting IT network and communications. The company immediately initiated security measures and involved the relevant authorities, the group announced. The attack was noticed on Friday, August 9. The group was investigating whether data was stolen and experts were working to make all systems available and functional again, Schlatter said.
CEO Werner Schmidli confirmed to 'Netzwoche' that he had received a ransom demand. "We found a blackmail letter on the servers." Schmidli did not say whether Schlatter plans to respond to the demand.
The company is already preparing the market for significantly lower annual results than last year. This is partly due to the necessary postponement of projects in the welding department.
Victim: Schlatter Industries
Schlatter Industries, founded in 1916 and based in Schlieren near Zurich, the company is a globally active plant manufacturer for welding systems and weaving machines. In 2023, the group recorded sales of 120.6 million francs.
Reference: Swiss-based Schlatter says IT network affected by cyberattack
Reference: Swiss manufacturer Schlatter Industries recovered from cyber attack after 10 days
Incident: CRB Engineering Discloses December 2023 Data Breach
CRB Engineering suffered a cyberattack back in December through January and released an update providing a few more details.
The cyberattack affected 1,198 victims. On May 20, the company completed its initial review and it then worked to locate accurate address information in order to inform victims of pertinent information. The company completed its address review May 29. It then sent out letters dated August 21.
Victim: CRB Engineering
CRB Engineering, a full-service facility design, engineering, construction and consulting firm for the life sciences and food & beverage industries.
Reference: CRB Engineering Firm Suffers Attack
Incident: Data Breach at Rubber and Plastic Manufacturer Lavelle Industries
Rubber and plastic product maker, Lavelle Industries Inc. suffered a cyberattack this past March and is now letting victims know what happened.
On March 17, 2024, Lavelle said it became suspicious of unauthorized activity in its systems. In response, the Burlington, Wisconsin- based company quickly took steps to secure its systems and launched an investigation to determine the nature and scope of the incident.
“This investigation determined that between March 10, 2024 and March 17, 2024 an unknown actor gained access to certain systems, and certain information stored within those systems may have been accessed or taken,” the company said in an advisory. Stolen information from the 9,156 victims includes names and Social Security numbers. The company added to date, it does not have any evidence of any misuse or fraud related to the incident.
Reference: Lavelle Industries Suffers Cyberattack
Victim: Lavelle Industries
Lavelle is an OEM rubber manufacturer that designs and manufactures rubber and plastic parts for an extensive array of companies.
Reference: Milk Source Data Breach Investigation
Incident: Milk Source LLC Discloses Data Breach from Last Year
Kaukauna, Wisconsin-based Milk Source LLC suffered a cyberattack last October is now informing victims of the incident.
“On October 10, 2023, Milk Source experienced a network disruption and immediately initiated an investigation of the matter,” the company said in an advisory. “Milk Source also engaged cybersecurity experts to conduct an independent investigation and assist with its response. The investigation revealed that an unauthorized actor may have accessed certain files stored in its systems from October 9, 2023, until October 10, 2023.
Victim: Milk Source LLC
WI based milk producer Milk Source LLC
Reference: WI Milk Producer Hit in Cyberattack
Reference: Dozens of resources of Russian industrial facilities blocked: The Defence Intelligence of Ukraine carried out a large-scale cyberattack
Incident: Mass Cyberattack on Internet Servers and Online Industrial Platforms in Russia
Hackers of Ukraine's military intelligence agency (HUR) carried out on Aug. 24 a mass cyberattack on the servers of Russian Internet providers and blocked "dozens" of online platforms of industrial facilities in Russia, a military intelligence source told the Kyiv Independent. The recent attack affected at least 33 servers and 283 office computers at industrial facilities, took down 21 websites, and destroyed 15 cloud and file storages. Ukrainian hackers also left pro-Ukrainian messages on the affected online platforms, according to the source.
Ukrainian hackers targeted the network infrastructure of factories and companies that produce equipment for Russian law enforcement agencies, aircraft and helicopter components, as well as supply hardware and software, servers, and processors, among other products.
Reference: Ukrainian hackers launch large-scale cyberattack on Russian Internet providers, military-related companies, source says
Threat Actor: Hackers of Ukraine’s military intelligence agency (HUR)
Hackers of Ukraine's military intelligence agency (HUR)
Incident: Data breach at Banham Poultry Plant in UK
Banham Poultry, based in Attleborough, said criminals had remotely accessed its system in the early hours of 18 August.
In an email sent to staff, seen by the BBC, the company said information such as National Insurance numbers, copies of passports and bank details were accessed. The plant immediately shut down its systems and "engaged external forensic specialists" following the cyber attack. "We are not aware of anyone's information being used maliciously, or of any individual suffering any detriment as a result of the incident," the email from the company's HR department said.
Victim: Banham Poultry
Banham Poultry employs about 600 people at its 12-acre (nearly five-hectare) factory, which supplies chicken to major supermarkets.
Reference: Staff details stolen in poultry factory cyber attack
Reference: Banham Poultry workers targeted in cyberattack
Incident: Global Freight Forwarder JAS Confirms Malware Disrupts Operations
Atlanta-based JAS Worldwide, a global freight forwarder, confirmed it was targeted by a ransomware attack . JAS experienced technical disruptions, affecting its ability to operate and service its customers. A week after the attack JAS Worldwide confirmed that most of its systems are operational and that it is actively working through any backlogged requests.
JAS' website posted on Sep 4 that "alll essential systems to our operations have been restored following the recent incident. JAS SmartHub is now functioning, so customers are able to track their shipments in real time. Any backlogged requests continue to be worked through by our dedicated team. Any customers still dealing with specific issues, we are working to resolve those as quickly as possible."
No ransomware group has yet claimed responsibility for the attack.
Reference: JAS Incident Update
Reference: JAS Forwarding recovers from cyber-attack, but saw ‘many stolen credentials’
Victim: JAS Worldwide
Privately owned JAS Worldwide, a global leader in logistics and supply chain solutions, was founded in Milan, Italy, in 1978, before moving its headquarters to Atlanta in 2006. JAS Worldwide has more than 7,000 team members in more than 100 countries, according to its website.
Reference: Global freight forwarder confirms malware attack for ‘technical disruptions’
Incident: Microchip Technology Manufacturing Operations Disrupted After Cyberattack
American chipmaker Microchip Technology Incorporated has disclosed that a cyberattack impacted its systems over the weekend, disrupting operations across multiple manufacturing facilities.
Some Microchip Technology manufacturing facilities operate at reduced capacity, affecting the company's ability to meet orders. Microchip Technology also had to take steps to manage the situation, such as shutting down some systems and isolating the affected ones following the breach. Microchip Technology is currently evaluating the extent and impact of the cyberattack.
The Play ransomware gang added Microchip Technology to its data leak site on Tuesday, according to several cybersecurity researchers.
Reference: Play ransomware hackers claim attack on US manufacturer Microchip Technology
Reference: Microchip Technology discloses cyberattack impacting operations
Victim: Microchip Technology
Microchip Technology Incorporated is a publicly listed American corporation that manufactures microcontroller, mixed-signal, analog, and Flash-IP integrated circuits.
Headquartered in Chandler, Arizona, the company has roughly 123,000 customers across multiple industry sectors, including industrial, automotive, consumer, aerospace and defense, communications, and computing markets.
Reference: Microchip Technology says certain operations disrupted by cyber incident
Incident: German air traffic control (DFS) Operations Unaffected After Cyberattack
The German Air Traffic Control (DFS) has been the target of a hacker attack. "Our office communications have been hacked. We are currently taking defensive measures.," a DFS spokesperson told the German Press Agency. They are trying to keep the impact to a minimum. Air traffic is not affected and is continuing as normal.
According to DFS, the attack happened last week. Whether the hackers were able to obtain data access is still unknown. According to information from Bayerischer Rundfunk, the hacker group “APT 28” is involved in the attack.
Reference: German air traffic control attacked by hackers
Reference: German air traffic control agency confirms cyberattack, says operations unaffected
Victim: Deutsche Flugsicherung (DFS)
German air traffic control corporation Deutsche Flugsicherung (DFS).
Headquarters in Langen close to Frankfurt am Main.
Reference: Pro-Russian hacker organization targeted German air traffic control with a cyberattack
Incident: Systems Breached at Transport for London (TfL) HQ
Transport for London's (TfL) computer systems have been targeted in an ongoing cyber attack. It said there was no evidence customer data had been compromised and there was currently no impact on TfL services. Insiders have told BBC London they have been asked to work at home if possible, and that it is the transport provider's backroom systems at the corporate headquarters that are mainly affected
TfL’s chief technology officer Shashi Verma said, "...there is currently no evidence that any customer data has been compromised. There is currently no impact to TfL services and we are working closely with the National Crime Agency and the National Cyber Security Centre to respond to the incident.”
Reference: TfL faces ‘ongoing cyber security incident’
Victim: Transport for London (TfL)
Transport for London (TfL), the government body responsible for the transport network in Britain’s capital.
Reference: London transport network hit by cyberattack
Reference: Halliburton says hackers removed data in August cyberattack
Incident: Halliburton Takes Systems Offline following Cyberattack
“On August 21, 2024, Halliburton Company became aware that an unauthorized third party gained access to certain of its systems,” the company said in an 8-K report to the SEC. “The Company’s response efforts included proactively taking certain systems offline to help protect them and notifying law enforcement. The Company’s ongoing investigation and response include restoration of its systems and assessment of materiality,” Halliburton vice president Charles Geer said in the report.
Reuters reported on Thursday that some employees were told not to connect to the company’s internal network as a precaution following the cyberattack. The company has not shared many details about the attack, causing other customers to disconnect from Halliburton due to the lack of information being shared. BleepingComputer reports some companies are working with ONG-ISAC—an agency that acts as a central point of coordination and communication for physical and cybersecurity threats against the oil and gas industry—to receive technical information about the attack to determine if they were breached as well.
Victim: Halliburton
Halliburton is the world’s second-largest oil service company, providing oil exploration and drilling management services. Halliburton Company is responsible for most of the world's largest fracking operations.
The energy sector contractor employs over 50,000 people in over 70 countries and reported $23.02 billion in annual revenue in 2023. Company headquarters offices are in Houston, Texas, and Dubai, United Arab Emirates.
Reference: Halliburton cyberattack linked to RansomHub ransomware gang
Reference: Haliburton Hit in Cyberattack.
Incident: Cyberattack Disrupts Seattle Airport for Days, affecting Labor Day Weekend Rush
Seattle-Tacoma International Airport (Sea-Tac) is still suffering from a cyberattack where there have been no mass flight delays or cancellations due to the outages.The outages began early Saturday and took down several systems, including the Port of Seattle websites. Total details of the outage was not immediately available, but email and phone systems were also down Saturday. The attack took down screens in the terminals, baggage systems, crashed websites. The Seattle Times reported that some airlines have been forced to manually sort more than 8,000 bags and hand write boarding passes. The Sea-Tac Airport website and app remained unavailable Monday, and flight information displays only came back online Wednesday.
UPDATE April 2025: This week, the Port of Seattle revealed that the ransomware attack impacted 90,000 people. The Port started notifying impacted individuals after their personal information was compromised.
Reference: Port of Seattle Updates
Victim: Port of Seattle
The Port of Seattle is a United States government agency overseeing the seaport of Seattle, WA, as well as Seattle–Tacoma International Airport.
With a portfolio of properties ranging from parks and waterfront real estate, to one of the largest airports and container terminals on the West Coast, the Port of Seattle is one of the Pacific Northwest's leading economic engines.[2]
Reference: Seattle Airport Working Through Cyber Incident
Incident: Ransomhub Targets SCADA System of Spanish Meat Processing Plant
Ransomhub, claimed an attack on the Spanish Abattoir, Matadero de Gijón. The Ransomhub ransomware group claimed unauthorized access to the plant’s Supervisory Control and Data Acquisition (SCADA) system, which is critical for industrial process control.
La Nueva Espana reports that the alleged "hacking" of the computer that controls the water purification of the Matadero de Gijón plant forced operations to shut down. Workers were sent home and more than 40 cattle stopped being slaughtered. Operations resumed through manual control of the treatment plant.
Reference: El Matadero paralyzed on Monday by the “hacking” of the sewage treatment plant
Incident: Spanish Energy Giant Hit by Cyberattack
On May 7, Iberdrola detected unauthorized access to customer databases through a supplier. Specifically, it affected 850,000 customers in Spain (600,000 from Iberdrola customers and 250,000 from Curenergia), from whom the data of name, surname, ID and contact information were obtained. Iberdrola denies that financial data has been compromised and claims to have notified all those affected.
Reference: Iberdrola suffers a cyber attack that leaves the data of 850,000 customers in Spain exposed
Incident: Large Data Breach at Iberdrola Energy Company affects 1.3 Million Customers
Iberdrola, Spain's largest energy company, suffered a cyberattack on March 15. The attack compromised the personal data of 1.3 million customers, according to Eldiario.es and confirmed by company sources to EL PAÍS. The company denies that users' financial or consumer data has been compromised, although it admits that it did reveal their name, ID, address and telephone number.
Reference: A cyber attack on Iberdrola exposes the data of 1.3 million customers
Victim: Iberdrola
Iberdrola is Spain [and Europe's] largest energy provider. The company has almost 11 million customers in Spain, between electricity (10.4 million) and gas (1.3).
Reference: A cyber attack on Iberdrola exposes the data of 850,000 customers in Spain
Reference: Ransomhub Attacking Industrial Control Systems To Encrypt And Exfiltrate Data
Reference: Ransomware Menace Amplifies for Vulnerable Industrial Control Systems: Heightened Threats to Critical Infrastructure
Victim: Matadero de Gijón
Matadero de Gijón is a Spanish meat processing plant. Also referred to a Biogas energy plant because the plant turned a problem [waste] into an opportunity [energy].
"One of the chapters that has required the most resources has been the installation of a biodigestion system for the waste produced by daily activity, in a clear example of what specialists call the circular economy. This action consists of using the remains to produce biogas, which is then reused in the internal processes of the slaughterhouse, something that once again makes the Gijón slaughterhouse the first in Asturias and one of the first in Spain to reduce waste by producing an ecological fuel."
Incident: Allied Telesis Data Breach Claimed by LockBit
LockBit has claimed an alleged cyberattack on Allied Telesis, Inc., a prominent American telecommunication equipment supplier. The claimed breach, dated May 27, 2024, suggests that the Allied Telesis data breach exposed sensitive data about the organization. However, the claims have not been verified nor is the sample data posted by the threat actor.
The information supposedly exfiltrated includes confidential project details dating back to 2005, passport information, and various product specifications. As a demonstration of their intrusion, the threat actors purportedly disclosed blueprints, passport details, and confidential agreements, issuing a deadline of June 3, 2024, for the full release of the compromised data.
Victim: Allied Telesis
Allied Telesis is a network infrastructure–telecommunications company headquartered in Tokyo, Japan, with other branches in San Jose, California.
The company was established in 1987 as a provider of Ethernet and IP access equipment along with IP triple play networks over copper and fiber access infrastructure.
Reference: Alleged Cyberattack Strikes Allied Telesis: LockBit Ransomware Suspected
Incident: RansomHub Breaches Network of Taiwanese Laptop Manufacturer
Clevo, a leading manufacturer of customizable gaming laptops, was claimed Monday by RansomHub, the cybercriminal gang recently involved in publishing stolen data from UnitedHealth Group’s Change Healthcare hack.
RansomHub claims to have breached the Taiwanese laptop maker by social engineering and phishing an employee.
“All network and backups are fully encrypted. We took care of it. The company has no chance to recover. Only our decryptor will help them to get back to work, nothing else will help them, “ the hacker group posted on their leak site.
Victim: Clevo
Clevo is a public company in Taiwan that manufactures laptop computers for MSI, Gigabyte, System76, and many others. Its list of partners includes prominent tech leaders like Intel, Nvidia, AMD, and Micron.
Reference: RansomHub Claims Attack on Laptop Maker Clevo, Leaks Confidential Docs
Reference: Clevo gaming laptop-maker claimed by RansomHub ransomware gang
Threat Actor: RansomHub RaaS
RansomHub ransomware-as-a-service believe that it has evolved from the currently defunct Knight ransomware project.
RansomHub has a short history and operated mainly as a data theft and extortion group that sells stolen files to the highest bidder. The gang grabbed attention in mid-April when it leaked stolen data from United Health subsidiary Change Healthcare following a BlackCat/ALPHV attack, suggesting some form of collaboration between the two.
Knight ransomware launched in late July 2023 as a re-brand of the Cyclops operation and started breaching Windows, macOS, Linux/ESXi machines to steal data and demand a ransom. One of the peculiarities of Knight was that it also offered affiliates an info-stealer component that could make the attacks more impactful.
In February 2024, the source code for version 3.0 of Knight ransomware put up for sale on hacker forums, the victims extortion portal went offline, and the RaaS operation went silent.
Reference: Frontier warns 750,000 of a data breach after extortion threats
Reference: Frontier Communications shuts down systems after cyberattack
Incident: Data Breach at CA Waste Management Firm
San Francisco, California-based Recology, formerly known as Norcal Waste Systems, suffered a cyberattack this past November and is continuing to inform victims of the attack.
The waste management company that collects and processes municipal solid waste, reclaiming reusable materials said it has no reason to believe any personal information ended up misused “for the purpose of committing fraud or identity theft as a result of the incident.”
Recology previously identified and notified a group of individuals. The company subsequently identified additional individuals whose information may have been accessed and is now sending out another note to victims. (August 2024)
Victim: Recology (formerly Norcal Waste Systems)
Recology, formerly known as Norcal Waste Systems based in San Francisco CA
Reference: Cyberattack At CA Waste Management Firm
Incident: Insulation Manufacturer Discloses Data Breach Nine Months Later
Youngsville, North Carolina insulation materials maker, K-FLEX USA LLC is notifying victims of a November cybersecurity attack, nine months after it happened.
On November 14, 2023, K-FLEX discovered it had fallen victim to a cybersecurity attack. On January 25, the investigation determined certain data suffered compromise in the attack. On July 12, K-FLEX identified current addresses and moved to notify individuals of the incident.
Victim: K-FLEX USA LLC
K-FLEX USA LLC is an Insulation materials maker in Youngsville, North Carolina
Reference: Insulation Materials Maker Hit In Cyberattack
Incident: Blue Ridge Rural Water Company Hit by Cyberattack
Greer, South Carolina-based Blue Ridge Rural Water Company, Inc. suffered a cyberattack on its corporate network late last month which was a separate system from its water management network.
The rural water utility said it suffered the attack July 23 and quickly shifted into defense mode by implementing its security program. While this attack “only” hit the corporate network, it is another indication water systems remain in the sights of threat actors.
Victim: Blue Ridge Rural Water Company, Inc.
Blue Ridge Rural Water Company, Inc based in Greer, South Carolina
Reference: Water Attacks Continue; SC Utility Hit
Reference: Henry Schein cuts annual profit forecast as cyberattack impact lingers
Reference: Henry Schein cuts annual profit forecast as cyberattack impact lingers
Incident: “Significant Blow” to Data Privacy at BMW Hong Kong
BMW Hong Kong has reportedly suffered a data breach affecting approximately 14,000 customers. The leak, which came to light on July 16, 2024, has exposed sensitive personal information, raising concerns about customer privacy and data security.
Initial reports suggest that a threat actor known as “888” may be responsible for the leak.
Reference: BMW Data Breach Exposes 14,000 Hong Kong Customers’ Personal Information
Victim: BMW
BMW is a multinational manufacturer of luxury vehicles and motorcycles headquartered in Munich, Bavaria, Germany.
The company was founded in 1916 as a manufacturer of aircraft engines, which it produced from 1917 to 1918 and again from 1933 to 1945 creating engines for aircraft that were used in the Second World War.
Automobiles are marketed under the brands BMW, Mini and Rolls-Royce, and motorcycles are marketed under the brand BMW Motorrad.
Reference: Nearly 14K hit by BMW Hong Kong breach
Reference: BMW Hong Kong Faces Major Data Breach: 14,000 Customer Records Exposed
Victim: Sibanye-Stillwater
Sibanye-Stillwater is one of the world's largest primary producers of platinum, palladium, and rhodium and is a top tier gold producer.
Incident: Sibanye-Stillwater reports Limited Disruptions in Mining and Metals Processing Operations
Sibanye-Stillwater suffered an ongoing cyberattack that disrupted its IT systems globally.
The South African miner said it took immediate steps to proactively isolate IT systems and safeguard data as soon as it became aware of the incident.
The cyberattack brought down the company’s servers, causing disruptions to certain areas of its global operations. On Wednesday, officials from its Montana operations told local media that the smelter operations in Columbus, Ohio were impacted after its automated systems all went down.
It is unknown at this time who is behind the attack.
Reference: Sibanye-Stillwater hit by cyberattack, says mining business unaffected
Reference: Sibanye-Stillwater delays interim results after cyberattack
Incident: Remote Control Malware Targets South Korean Company’s Large Machine & Equipment Design Files
In April 2024, the North Korean hacking organization Andariel exploited vulnerabilities of the VPN information security software used by targeted construction and machinery companies to replace update files in their systems with malware.
In addition to the VPN products, Andariel also exploited vulnerabilities in server security products. The threat actors were able to distribute remote control malware DoraRAT with the aim of using it to transfer large machine and equipment-related design files to the C2 server, according to South Korean intelligence.
Victim: Unidentified OEM manufacturer
Unidentified OEM manufacturer
Threat Actor: Andariel
North Korean hacking organization Andariel.
Kimsuky and Andariel are some of the North Korean hacker groups whose activities focus on espionage and attacks on the cryptocurrency industry.
Incident: North Korean hackers attack South Korea’s construction sector
The Kimsuky hacker group distributed malware through the website of a professional association in the construction sector, according to the South Korean intelligence.
The malware was hidden in the security authentication software used to log into the website. As a result, the personal computers of local government, public institutions, and construction company staff who accessed the website were infected.
It is believed that the attackers exploited a file upload vulnerability on the professional association's website to alter the security authentication software in a “meticulously” planned operation. “It is presumed that the hackers aimed to use the compromised credentials of officials in the construction sector as a foothold to steal critical information about major construction projects and technical data from companies involved,” the KCIC said.
Reference: North Korean hackers attack South Korea’s construction, machinery sectors
Victim: Unidentified Construction Company Assoc.
Unidentified association in the South Korean construction sector.
Reference: Columbus says it thwarted overseas ransomware attack that caused tech shutdown
Incident: Rhysida Demands $1.9M from Ohio State Government for Sensitive Exfiltrated Data
The government of Columbus, Ohio shut down a large part of its IT systems for >10 days after ransomware attack. The Rhysida ransomware group claimed the attack and is threatening to leak 6.5 terabytes of exfiltrated information. The data allegedly contains emergency services data, access to city cameras and more.
Government email access has been restored after more than a week of outages. 911 as well as 311 have been able to remain operational throughout the recovery process. The city’s department of technology and outside experts are going through each technology system before they are brought back online.
Rhysida demand ransom of 30 BTC — about $1.9 million.
Victim: Ohio State Government
Ohio State Government
Incident: Government Services Disrupted in Kentucky
Jefferson County, Kentucky is dealing with a cybersecurity incident disabling services and closing government offices. All eight branches of the Jefferson County Clerk’s Office in Louisville, Kentucky, remain closed after a ransomware attack on Monday.
The clerk’s office, responsible for issuing vehicle and voter registrations, professional licenses and housing deeds, told Spectrum News 1, which first reported the cyberattack, its data appears not to have been compromised. Its website was inaccessible on Wednesday.
Victim: Kentucky State Government
Kentucky State Government
Reference: Columbus investigating potential data leak after ransomware attack
Reference: Cybersecurity incidents disrupt services in Kentucky, Ohio
Incident: Keytronic takes over $17 Million hit After Cyberatttack
Keytronic detected the incident on May 6 after disruptions at its Mexico and U.S. sites impacted business applications supporting both operations and corporate functions. Keytronic was forced to shut down domestic and Mexico operations for two weeks during the incident response.
"Due to this event, the Company incurred approximately $2.3 million of additional expenses and believes that it lost approximately $15 million of revenue during the fourth quarter," the company said.
Black Basta ransomware gang claimed the attack late May. Keytronic has yet to attribute the attack to a specific threat group.
Reference: Ransomware Attack Shuts Key Tronic Operations
Reference: Key Tronic Lost $17M in Cyberattack
Victim: Keytronic (Key Tronic)
Key Tronic, better known as Keytronic, is an American technology company that initially started as an Original Equipment Manufacturer (OEM) of keyboards and mice but is now one of the largest manufacturers of printed circuit board assembly (PCBA).
Reference: Keytronic reports losses of over $17 million after ransomware attack
Reference: Keytronic confirms data breach after ransomware gang leaks stolen files
Reference: The Ransomware Group Ransomexx Claims Attack on Liteon
Reference: Taiwanese electronics giant allegedly suffers ransomware attack
Incident: Sellafield Nuclear Waste Facility in UK Pleads Guilty; Insists There Never has been a Successful Cyberattack
The state-owned operator of the UK’s largest nuclear waste site has pleaded guilty to criminal charges brought by the industry regulator over IT security breaches. Lawyers acting for Sellafield told a London court on Thursday that they accepted cyber security was “not sufficiently adhered to for a period”, although they insisted there had not been a successful cyber attack and that its systems were now secure.
One of the charges to which Sellafield pleaded guilty was that it failed in March last year to “ensure that there was adequate protection of sensitive nuclear information on its information technology network”. The other two charges related to failures to arrange “annual health checks” for its systems.
Sellafield pleaded guilty to all three charges in the prosecution brought by the Office for Nuclear Regulation under the Nuclear Industries Security Regulations 2003. Sellafield Ltd, which is owned by the UK’s Nuclear Decommissioning Authority, is in charge of cleaning up and looking after the Sellafield nuclear waste facility in Cumbria, north-west England.
Paul Greaney KC, representing Sellafield, told Westminster Magistrates’ Court that the guilty pleas “reflect the fact that while it had in place systems of cyber security, those systems were not sufficiently adhered to for a period”. “However, it is important to emphasize there was not and has never been a successful cyber attack on Sellafield.” He added: “The offenses to which Sellafield has pleaded guilty are historical. They do not reflect the current position.”
Greaney said that Sellafield’s systems were “robust” and added that media reports that its site had been compromised were “false”. The Guardian newspaper previously alleged that Sellafield’s IT systems had been hacked by groups linked to Russia and China.
The Office for Nuclear Regulation said in a statement on Thursday: “We acknowledge that Sellafield Limited has pleaded guilty to all charges . . . These charges relate to historic offences and there is no evidence that any vulnerabilities were exploited." The prosecution is the first the ONR has brought under the 2003 regulations.
Reference: Sellafield nuclear waste site pleads guilty to IT security breaches
Incident: Malware caused Ukranian Energy Company to Disconnect Heating Services
Russian-linked malware was used in a January 2024 cyberattack to cut off the heating of over 600 apartment buildings in Lviv, Ukraine, for two days during sub-zero temperatures. The attack forced district heating company Lvivteploenergo to disconnect heating services on January 23, impacting over 100,000 people across Lviv's Sykhiv residential area.
An investigation into the January 2024 cyberattack in Lviv showed that the attackers may have entered Lvivteploenergo's network almost a year earlier, on 17 April 2023, by exploiting an unidentified vulnerability in an Internet-exposed Mikrotik router. Three days later, they deployed a webshell that allowed them to maintain access and helped them connect to the breached network in November and December to steal user credentials from the Security Account Manager (SAM) registry hive. On the day of the attack, the attackers used L2TP (Layer Two Tunnelling Protocol) connections from Moscow-based IP addresses to access the district energy company's network assets.
FrostyGoop, the Windows malware used in this attack, is designed to target industrial control system (ICS) using the Modbus TCP communications, a standard ICS protocol across all industrial sectors.
Malware: FrostyGoop
FrostyGoop malware is designed to target industrial control system (ICS) using the Modbus TCP communications, a standard ICS protocol across all industrial sectors.
Victim: Lvivteploenergo
Lvivteploenergo is a municipal district energy company in Lviv, Ukraine.
Reference: FrostyGoop malware attack cut off heat in Ukraine during winter
Reference: FrostyGoop malware left 600 Ukrainian households without heat this winter
Reference: 5 ways threat actors are taking advantage of the CrowdStrike outage
Incident: Microsoft Azure Outage Amplified by Fumbled DDoS Defense Strategy Implementation
Microsoft confirmed today that a nine-hour outage on Tuesday, which took down and disrupted multiple Microsoft 365 and Azure services worldwide, was triggered by a distributed denial-of-service (DDoS) attack. The company has yet to link it to a specific threat actor. "While the initial trigger event was a Distributed Denial-of-Service (DDoS) attack... initial investigations suggest that an error in the implementation of our defenses amplified the impact of the attack rather than mitigating it," said an update on the website of the Microsoft Azure cloud computing platform.
It comes less than two weeks after a major global outage left around 8.5 million computers using Microsoft systems inaccessible, impacting healthcare and travel, after a flawed software update by cybersecurity firm CrowdStrike.
Reference: Microsoft says cyber-attack triggered latest outage
Victim: Microsoft
Microsoft Corporation is an American multinational corporation and technology company headquartered in Redmond, WA.
Reference: Microsoft says massive Azure outage was caused by DDoS attack
Reference: ‘Error’ in Microsoft’s DDoS defenses amplified 8-hour Azure outage
Reference: Nearly 10-hour Azure outage caused by DDoS attack, says Microsoft
Incident: Malware Cloaked as Fixes and Updates Exploit Global Crowdstrike Outage
Threat actors are exploiting the massive business disruption from CrowdStrike's glitchy update on Friday to target companies with data wipers and remote access tools. As businesses are looking for assistance to fix affected Windows hosts, researchers and government agencies have spotted an increase in phishing emails trying to take advantage of the situation. CrowdStrike says it "is actively assisting customers" impacted by the recent content update that crashed millions of Windows hosts worldwide. The company advises customers to verify that they communicate with legitimate representatives through official channels since "adversaries and bad actors will try to exploit events like this."
The CrowdStrike crash was caused by human error.
Reference: Fake CrowdStrike fixes target companies with malware, data wipers
Incident: Data Compromised at Mexican Precious Metals Mining Firm Fresnillo
Fresnillo PLC, the world's largest silver producer and a top global producer of gold, copper, and zinc, said attackers gained access to data stored on its systems during a recent cyberattack.
The mining giant revealed in a Tuesday filing with the London Stock Exchange that it was "the subject of a cyber security incident which has resulted in unauthorized access to certain IT systems and data." They also added that the cyberattack didn't affect its operations and said that it doesn't expect financial or material impact.
Victim: Fresnillo
Fresnillo, world leading silver producer, operates eight mines, all of them in Mexico (Fresnillo, Saucito, Juanicipio, Ciénega, Herradura, Soledad-Dipolos1, Noche Buena, and San Julián), four advanced exploration projects (Orisyvo, Rodeo, Guanajuato, and Tajitos), and some other long-term exploration prospects.
Reference: Cyberattack confirmed by Fresnillo
Reference: World leading silver producer Fresnillo discloses cyberattack
Reference: CrowdStrike Incident Affected 8.5M Devices
Reference: Fake CrowdStrike repair manual pushes new infostealer malware
Reference: CrowdStrike update crashes Windows systems, causes outages worldwide
Victim: Crowdstrike
CrowdStrike Holdings, Inc. is an American cybersecurity technology company based in Austin, Texas. It provides endpoint security, threat intelligence, and cyberattack response services.
CrowdStrike is widely used in enterprises, including airports, hospitals, government organizations, the media, and financial firms.
Incident: Plasma Donation Company Octapharma Shuts Down 180 Centers Worldwide
The disruption has impacted more than 150 plasma centers in the US, with possible effects on European factory operations.
The BlackSuit ransomware gang took credit for the attack on Wednesday, claiming to have exfiltrated business and laboratory data as well as the information of both living and deceased donors.
Reference: Ransomware feared as IT ‘issues’ force Octapharma Plasma to close 150+ centers
Victim: Octapharma
Octapharma is based in Switzerland, the company is one of the largest privately-owned, independent plasma companies in the world, using plasma donations to develop and manufacture medicines. It says it has more than 180 donation centers worldwide.
Victim: Octapharma Group
Octapharma US company employs about 3500 people and operates a little over 150 blood plasma donation centers across America.
Octapharma Group, the parent company based in Germany reported revenue of €3.26 billion for 2023, from operations across 118 countries.
Reference: Ransomware feared in Octapharma Plasma’s US-wide shutdown
Reference: Plasma donation company Octapharma slowly reopening as BlackSuit gang claims attack
Incident: Network Shutdown after Ransomware Attack at Synlab Italy
Synlab Italia has suspended all its medical diagnostic and testing services after a ransomware attack forced its IT systems to be taken offline. Although the company has not confirmed, some sensitive medical data may have been exposed to the attackers. As a result of this incident, all laboratory analysis and sample collection services have been suspended until further notice. Customers are advised to use phone to contact Synlab because email communication services are inactive.
No major ransomware gangs has claimed responsibility for the cyberattack on Synlab Italia.
Victim: Synlab Italia
Part of the Synlab group that is present in 30 countries worldwide, the Synlab Italia network operates 380 labs and medical centers across Italy. It has an annual turnover of $426 million and carries out 35 million analyses every year.
Reference: Synlab Italia suspends operations following ransomware attack
Reference: Japan’s space agency reports cyberattacks, possible data leak [Jun24]
Incident: Sandhar Automotive Component Manufacturer Disclosed Cyber Incident
Sandhar Technologies faced a minor setback in its stock performance after disclosing a cyber-incident impacting certain systems. However, the company promptly reacted by mobilizing its technical and cybersecurity teams to address the threat. It assured stakeholders that no confidential data breach occurred and that the incident had minimal impact on its operations.
Victim: Sandhar Technologies Limited
Sandhar Technologies Limited or Sandhar Group or Sandhar is an Indian multinational and a global manufacturer of automotive components primarily catering to automotive OEMs. The company is largely focused on safety and security systems of vehicles with a pan India presence and a growing international footprint.
Reference: Sandhar Technologies shares drop after company reports cyber-incident
Reference: Sandhar Technologies Faces Cyber Incident
Reference: Kadokawa Group’s Niconico targeted in ransomware attack, affecting wider operations
Incident: Panasonic Australia confirms Ransomware Incident
The Akira ransomware gang listed camera and consumer tech giant Panasonic Australia on its darknet leak site overnight, and while the company has confirmed the incident, it has said that no business or customer has been compromised.
Reference: Panasonic Australia confirms cyber incident following Akira ransomware claim
Reference: Senators seek answers from AT&T in massive hacking of US customer call data
Incident: Cyberattack Hits One Of Iceland’s Largest Media Outlets
One of Iceland’s largest media outlets mbl.is and radio station K100 were both down for around three hours yesterday due to a cyberattack on their publisher, Árvakur.
The attack was carried out by a Russian group named Akira, the publisher has confirmed. The attackers seized and encrypted all of the company’s data,leading them to shut down their computer system as they responded.
Both mbl.is and K100 are currently functioning. It is not clear whether Árvakur has recovered all of the data that were seized or whether it will be able to recover them completely.
Reference: Media Company Árvakur Hit By Russian Cyber Attack
Victim: Árvakur
Árvakur hf is a publishing company formed in 1919 to run Morgunblaðið. Árvakur also operates Landsprent hf, Iceland's largest newspaper printing press. In addition to printing Morgunblaðið, it also prints numerous weekly papers and periodicals for various publishers. Arvakur also operates one of Iceland’s largest media outlets mbl.is and radio station K100
Reference: Cyberattack on Morgunblaðið Newspaper’s Publisher
Incident: Nearly All AT&T Customers Exposed in Massive 2022 Data Breach
July 15, 2024: AT&T says calls and text message records for about 109 million of the phone service provider's customers were exposed in a massive data breach two years ago. Nearly all of AT&T's mobile phone customers' information was exposed over the course of months in 2022.
The company said that in April hackers exfiltrated records of customer call and text interactions from May 1, 2022, to October 31, 2022, as well as on January 2, 2023. The data originated from AT&T’s ‘workspace’ on a third-party cloud platform.
AT&T said it learned about an "illegal download" of data from a third-party cloud platform called Snowflake in April.
The hacker reportedly demanded a $1 million ransom from AT&T, but he ultimately settled for far less. The hacker provided AT&T with a video showing that he had deleted the stolen data
Reference: AT&T Breach Linked to American Hacker, Telecom Giant Paid $370k Ransom: Reports
Incident: AT&T Data Breach Exposes >70 Million Accounts
In March 2024, AT&T said it was investigating a possible data breach after personal data from more than 70 million current and former customers was discovered on the dark web.
Based on a preliminary analysis, the company said the data set appeared to be from 2019 or earlier and impacts approximately 7.6 million current AT&T account holders and approximately 65.4 million former account holders.
Reference: AT&T Addresses Recent Data Set Released on the Dark Web
Reference: AT&T Investigating Potential Data Breach Impacting More Than 70M Past And Current Customers
Reference: Major Cyberattacks And Data Breaches In 2024
Victim: AT&T
AT&T is the world's largest telecommunications company (2019). AT&T is also the largest provider of mobile telephone services and the largest provider of fixed telephone (landline) services in the United States.
Reference: Five things to know about the AT&T data breach
Reference: Cyber-attack on Hydro
Incident: Ransomware Attack Shuts Down Large US Furniture Company
Bassett Furniture was forced to shut down its manufacturing facilities following a ransomware attack. Company officials are working to bring impacted systems back online and implement workarounds in order to reduce the disruption.
“As a result of the Company’s containment measures, which included shutting down some systems, the Company has not been, and, as of the date of this Report is not operating its manufacturing facilities,” Bassett Furniture said in an 8-K filing with the Securities and Exchange Commission.
Reference: Bassett Furniture reports significant cyber incident
Victim: Bassett Furniture
Bassett Furniture is one of the largest manufacturers and marketers of furniture in the USA operating nearly 90 stores across the country
Reference: Furniture giant shuts down manufacturing facilities after ransomware attack
Reference: Stellantis Demands $26M In Damages From Chinese Supplier Sparking Lawsuit
Reference: Qilin ransomware claims attack on automotive giant Yanfeng
Incident: Theft of Intellectual Property at Volkswagen Took Place over Several Years.
[Publicly reported April 2024]
Suspected Chinese state hackers breached Volkswagen’s systems and stole sensitive information over several years (2010-2015), including details about gasoline engines, transmission development, fuel cells, and electric vehicle initiatives. At least 19,000 documents related to the company’s research and development were exfiltrated.
ZDF frontal and "Spiegel" were able to view more than 40 documents as part of an international cooperation on Chinese espionage activities in Europe
showing what the data thieves stole.
Reference: Multi-year Volkswagen breach points to Chinese hackers
Reference: The big hack at VW – China in focus
Incident: Major Aircraft Component Manufacturer Scammed out of $50Million
Fischer Advanced Composite Components AG (FACC) was swindled a record 42 million euros (around $47 million) through a spear-phishing attack.
A fake email that impersonated its then CEO Walter Stephan, conned one of FACC’s financial department employee into wiring 50 million euros that was supposedly for one of the company’s acquisition projects.
FACC is a major designer and manufacturer of aircraft components and systems, with a client base that includes Boeing, Airbus, Rolls-Royce, Siemens SAS and Mitsubishi Heavy Industries.
Victim: Fischer Advanced Composite Components AG (FACC)
FACC is a major designer and manufacturer of aircraft components and systems, with a client base that includes Boeing, Airbus, Rolls-Royce, Siemens SAS and Mitsubishi Heavy Industries.
Reference: Austrian Aeronautics Company Loses Over €42 Million to BEC Scam
Incident: Popular Home Electronics Manufacturer, boAt, hit by Ransomware Attack
Popular Indian audio products and smartwatch maker boAt has suffered a massive data breach with personal information of more than 7.5 million customers leaking and selling on the dark web.
Forbes India reports: The leaker's profile (ShopifyGUY) is relatively new and only has this leak under his belt. As the data is genuine, the hacker will gain a good reputation among the forum community
Reference: Hit with massive data breach, boAt loses data of 7.5 million customers
Victim: boAt
boAt, Indian audio products and smartwatch maker.
Founded in 2016 by Shark Tank judge Aman Gupta and Sameer Mehta, boAt has emerged as the second most popular wearable brand in the third quarter of 2023, as per an IDC report. The Gurugram-based company is widely popular among Indian consumers and is known for its reasonable earphones and other audio products. It also makes other products, like smartwatches and speakers.
Reference: Over 7.5 million boAt users personal information leaked in a major data breach
Reference: Name, address, contact number, email ID and other details of 7.5 million Boat customers leaked on Dark Web, claims report
Incident: Ransomware attack at Synnovis Throws >3000 UK Hospitals into Chaos
Synnovis was hit by a ransomware cyber-attack on Monday 3 June 2024. NHS reports that this attack has caused significant disruption in south east London across a range of different treatments. The hackers injected malware into Synnovis’s IT system, which locked the entire computer system until a ransom was paid to regain control and remove the ransomware. Over 3,000 hospital and GP appointments were thrown into chaos as a direct result. Synlab, the parent company of Synnovis, experienced a total of three significant cyber security breaches in the past year.
UPDATE May 2025: More than 11 months after a ransomware attack, the affected patients still have not been informed about what data of theirs was exposed in the incident, with material about sexually transmitted infections and cancer cases being included in the leaks.
Reference: Criminal gang behind London hospitals cyberattack lists victim on darknet site
Reference: NHS confirms patient data stolen in cyber attack
Victim: Synnovis
Synnovis, a pathology partnership between SYNLAB, Guy’s and St Thomas’ NHS Foundation Trust and King’s College Hospitals NHS Trust. Synnovis also provides specialist tests for other hospitals in the country,
Reference: Former NCSC Head: Synnovis Ransomware Cyber Attack Caused by Trilogy of Issues
Reference: Synnovis Ransomware Cyber-Attack
Incident: Wichita City Ransomware Attack Shuts Down Services
The cyberattack at the city of Wichita, Kansas water system targeted water metering, billing and payment processing. All water systems are secure. Other Wichita’s services were also affected and off line.
Hackers copied files from the city’s network, and the city shut down many online services, buying time to minimize the damage. Wichita will temporarily lean on paper records and performing more administrative chores by hand. The City will not shut off any water accounts.
Reference: City of Wichita water bill payment system up after cyberattack
Reference: City of Wichita says cyberattack did not hurt water systems, other FAQs
Victim: City of Wichita
City of Wichita, KS, USA
Reference: Wichita ransomware attack shuts down multiple services. What comes next?
Reference: City of Wichita water bill payment system up after cyberattack
Incident: Illegal App Renders 80% of Bicycles Out of Use in Bologna, Italy
A pirated app caused the bike-sharing service in Bologna to crash putting most of the bikes out of service. The illegal platform compromised the functioning of the bike sharing service, rendering 80% of the available bikes unusable.
The application in question was available online and allowed users to bypass the security systems of the bike sharing service, unlocking bicycles without the need for a regular subscription or payments. This breach created a significant disservice for the many users who rely on bike sharing for their daily travel around the city.
Reference: Hackers Write Illegal App That Paralyzes Bike Sharing. 80% of Bicycles Are Out of Use
Incident: Large Scale Data Breach Disrupts >200 Indonesian Government Agencies
On June 20th, one of the temporary National Data Centers suffered a cyberattack that encrypted the government's servers and disrupted immigration services, passport control, issuing of event permits, and other online services. The government confirmed that a new ransomware operation, Brain Cipher, was behind the attack, disrupting over 200 government agencies.
The Ministry of Communication and Information Semuel Abrijani Pangerapan said "Regarding security, we have succeeded in carrying out quarantine or isolation in the affected areas."
Victim: Indonesian Government
Indonesian Government
Reference: Meet Brain Cipher — The new ransomware behind Indonesia’s data center attack
Threat Actor: Brain Cipher
Brain Cipher is a new ransomware operation launched in June 2024, conducting attacks on organizations worldwide.
Brain Cipher will breach a corporate network and spread laterally to other devices. Once the threat actors gain Windows domain admin credentials, they deploy the ransomware throughout the network.
In latest hack the data encryptor is based on the leaked LockBit 3 encryptor, thoroughly analyzed in the past, unless Brain Cipher tweaked the encryption algorithm, there are no known ways to recover files for free.
Reference: BBSN Says PDNS 2 Disruption Due to Braincipher Ransomware
Incident: Dynamo Software hit by Ransomware Attack
Dynamo detected suspicious activity on its US-based servers which was determined to be a ransomware attack. Dynamo states that it took its systems offline while the
suspicious activity was investigated, and systems were restored.
Victim: Dynamo Software
Dynamo Software
Reference: Notice of Dynamo Software Data Security Incident
Incident: Ransomware Attack at Dutch Eurotrol B.V.
Eurotrol B.V. recently fell victim to a ransomware attack by the BlackSuit group. The ransomware encrypted files on Eurotrol's systems, appending the .blacksuit extension and leaving a ransom note named README.BlackSuit.txt. The note directed Eurotrol to a Tor chat site for further communication with the attackers.
Reference: Eurotrol Data Breach on June 13, 2024
Reference: Eurotrol B.V. Hit by BlackSuit Ransomware, Disrupting Diagnostic Services
Reference: Keytronic confirms data breach after ransomware gang leaks stolen files
Reference: Keytronic Says Personal Information Stolen in Ransomware Attack
Reference: Website of Israeli Oil Refinery Taken Offline by Pro-Iranian Attackers
Reference: BULLETIN CYBERATTAQUE
Incident: Multiple Data Breaches at Maritime Industry Authority (MARINA)
MANILA, Philippines – The Maritime Industry Authority (MARINA) confirmed that a cyberattack compromised at least four of its systems, becoming the latest victim in a growing list of government agencies that have recently faced data breaches.
The attack, which happened on Sunday, June 16, hit four of MARINA’s “web-based systems.” MARINA’s systems manage various types of information, including vessel registrations, seafarers’ information documents, and record books. MARINA said that it aimed to bring systems back online “to receive and process applications on Tuesday, June 18, 2024.”
On July 4, MARINA assured stakeholders its newly launched, blockchain-enabled online certification system has been made more secure. It now employs a two-factor authentication during log-in. Only MARINA clients are allowed to register and use the program.
Reference: MARINA launches ‘safer’ blockchain-enabled portal after data breach
Victim: Maritime Industry Authority (MARINA)
Maritime Industry Authority (MARINA) in the Phillipines
Reference: MARINA assures seafarers’ data safe after cyber attack
Incident: Ransomware Attack at Vietnam Post Takes Systems Offline
The Vietnamese government-owned postal service has restored operation of its services after they were down for several days due to a cyberattack.
Vietnam Post was reportedly hit by ransomware on June 4, affecting the operation of its postal and delivery services. At the time, the company reported that its financial, administrative, and goods distribution services were unaffected by the attack.
Victim: Vietnam Post
Vietnamese government-owned postal service
Reference: Vietnam’s state postal service claims to restore its systems after cyberattack
Incident: Cloud Provider Snowflake Suffers Snowballing Data Breach
The number of alleged hacks targeting the customers of cloud storage firm Snowflake appears to be snowballing into one of the biggest data breaches of all time. The earliest evidence of unauthorized access to Snowflake customer instances occurred on April 14, according to Mandiant's June 10 threat intelligence report on the attacks.
Alleged affected customers are Ticketmaster (560 million records), Santander (30 million records), automotive giant Advance Auto Parts (380 million records/3TB),LendingTree and QuoteWizard (190 million records/2TB). Neither LendingTree nor Advance Auto Parts has filed breach notifications with the Securities and Exchange Commission at this time.
Reference: Overview of the Snowflake Breach: Threat Actor Offers Data of Cloud Company’s Customers
Reference: Snowflake account hacks linked to Santander, Ticketmaster breaches
Reference: Advance Auto Parts stolen data for sale after Snowflake attack
Reference: The Snowflake Attack May Be Turning Into One of the Largest Data Breaches Ever
Victim: Snowflake Inc
Snowflake Inc. is an American cloud computing–based data cloud company based in Bozeman, Montana. It was founded in July 2012 and was publicly launched in October 2014 after two years in stealth mode. The firm offers a cloud-based data storage and analytics service, generally termed "data-as-a-service"
Incident: Threat Actor targets Russia’s Aviation Sector.
A threat actor known as "Sticky Werewolf" is using layered infection chains to compromise organizations involved with Russia's aviation industry. The group has been around since at least April 2023, and seems to be interested in espionage relating to the conflict between Russia and Ukraine.
The group was targeting public organizations in Russia and Belarus, but recent targets have included a pharmaceutical company and a Russian research institute involved in microbiology and vaccine development. In prior campaigns, Sticky Werewolf phishing emails included links to download malicious files. Now, its infections are notably more complex. The final payload will be some sort of commercial remote access Trojan (RAT).
Reference: STICKY WEREWOLF TARGETS THE AVIATION INDUSTRY IN RUSSIA AND BELARUS
Threat Actor: Sticky Werewolf
The group, tracked as “Sticky Werewolf,” is suspected of having geopolitical and/or hacktivist motivations has been linked to cyber campaigns targeting public organizations in Russia and Belarus since at least April 2023.
Victim: Russian Aviation Industry
Russian Aviation Industry
Reference: ‘Sticky Werewolf’ APT Stalks Aviation Sector
Incident: AMD Investigates Potential Cyberattack by IntelBroker
AMD is investigating whether it suffered a cyberattack after a threat actor put allegedly stolen data up for sale on a hacking forum, claiming it contains AMD employee information, financial documents, and confidential information. "We are aware of a cybercriminal organization claiming to be in possession of stolen AMD data," AMD told BleepingComputer in a statement.
The threat actor, IntelBroker, shared screenshots of some of the supposedly stolen AMD credentials but has yet to disclose how much they are selling it for or how it was obtained.
Reference: AMD Hack Won’t Have a Material Impact on Business, Company Says
Incident: Multiple Day Outage at Oahu Transit Services.
Oahu’s bus and transportation services have been suffering from a network outage that may be a ransomware attack originating in Malaysia -Dragonforce is the alleged hacker group . “Oahu Transit Services’ (OTS) online services including the www.thebus.org website, HEA, and related real-time transit and GPS apps are currently unavailable,” the statement said.
Reference: FBI, Police Investigate Possible Ransomware Attack At TheBus, Handi-Van
Reference: AMD investigates breach after data for sale on hacking forum
Reference: AMD Investigates Potential Cyberattack by IntelBroker Hacking Group
Reference: Cactus ransomware hackers say they stole terabytes of Schneider Electric data
Reference: Schneider Business Unit Hit In Ransomware Attack
Incident: Ransomware Attack at Soon Lian Holdings
Soon Lian Holdings announced they suffered a ransomware attack on the evening of July 3. The group said there has been no significant impact to its business operations and that it activated its business continuity plan immediately after.
Victim: Singaporean F&B group YKGI
Singaporean F&B group YKGI - abbreviation for Yew Kee Group International. YKGI Limited is an established home-grown food & beverage (F&B) operator with a track record of more than 30 years. The company owns and operates a diverse portfolio of brands including Yew Kee Duck Rice, XO Minced Meat Noodles, My Kampung Chicken Rice, PastaGo and Victoria Bakery.
Incident: Cyberattack at Singaporean F&B group YKGI
Singaporean F&B group YKGI, which operates brands such as CHICHA San Chen, Yew Kee Duck Rice, and Kampung Kopi House, has been hit with a cyberattack.
The data breach occurred with the company’s customer relationship management (CRM) platform, which is operated by a third-party vendor. The hacker got hold of one of the vendor’s shared servers, and was able to access the CHICHA San Chen membership database stored there.
Reference: Data breach hits F&B operator YKGI
Victim: Soon Lian Holdings Ltd
Soon Lian Holdings is an investment company that distributes aluminum alloy parts for engineering, marine, precision, and semiconductor. The company is based in Singapore,
Reference: Soon Lian Holdings reports ransomware attack
Incident: Databreach at TotalEnergies exposes over 200,000 Customers
TotalEnergies Clientes SAU has reported a significant cyberattack that has compromised the personal data of 210,715 customers. "The company is collaborating with the Police and the Spanish Data Protection Agency "to initiate all relevant legal actions against those responsible for this action."
The incident has raised serious concerns about data security and the integrity of digital infrastructures in the energy sector.
Victim: TotalEnergies SE
TotalEnergies SE is a French multinational integrated energy and petroleum company founded in 1924 and is one of the seven supermajor oil companies.
Reference: Total Energies suffers a cyber attack on the data of 210,715 customers [machine translated]
Reference: TotalEnergies Cyber Attack: Data of 210,715 Customers Exposed
Incident: Ransomware Attack at Engineering and Construction Company Hiap Seng Industries
Hiap Seng Industries, a prominent engineering and construction company, has fallen victim to a ransomware attack that compromised its servers. The company has swiftly taken measures to contain the breach and ensure the continuity of its business operations.
Hiap Seng Industries reported that there has been no material impact on its business operations due to the incident.
Victim: Hiap Seng Engineering Ltd.
Hiap Seng Engineering Ltd. is an industrial building construction company. HQ in Singapore
Reference: Hiap Seng latest victim of cyber attack
Incident: BlackSuit Ransomware Attack at CDK Global Causes Widespread Disruption
On June 19 CDK Global, a major car dealership software company suffered a cyberattack prompting the company to take all systems offline “out of an abundance of caution." Reuters reported CDK took down its dealer management system at more than 15,000 retail locations.
The outage has impacted about half of Volkswagen dealers and around 60% of Audi's dealers and several card retailers also flagged disruptions. Dealers moved back to traditional pen and paper format to conduct operations. As a result new car sales for June are projected to fall.
The hacker group was identified as BlackSuit. As of Wednesday, July 3, the company is still working to get all impacted dealers back online. The date all dealerships using CDK are expected to be back online following the attack is July 4.
COST: A study from the Anderson Economic Group (AEG) estimated losses of over $1 billion for auto dealerships during the outage. The ransomware group reportedly received $25million. CDK agreed to pay $100Million in class action settlement
Threat Actor: BlackSuit
BlackSuit emerged in May 2023 and mainly targets US companies in the education and industrial goods sectors. BlackSuit uses a double-extortion method and other tactics, techniques, and procedures (TTPs) that reflect a maturity atypical of a group that's only been around for a year. This reflects its origin in Royal, which in turn was comprised of members of the formidable and now-defunct Conti ransomware gang.
Reference: Why a hack at CDK Global is casting a shadow on US auto sales
Reference: CDK Global cyberattack: Timeline of the hack, outages and when services could return
Victim: CDK Software
CDK Global Inc. is an American multinational corporation based in Austin, Texas, providing data and technology to the automotive, heavy truck, recreation, and heavy equipment industries.
Incident: Nearly All Systems Offline for Weeks at Global Forklift Manufacturer
Crown Equipment Corporation, the world’s fourth largest forklift manufacturer, has resumed global manufacturing after a cyberattack that took nearly all of its systems offline for several weeks. Since June 8 the company faced significant operational disruption. On July 4 Crown says its 24 global manufacturing plants were back in operation after being suspended on June 10.
Crown confirmed that the multi-week operations disruption resulted from a social engineering attack by an international cybercrime group.
Reference: Crown Equipment Confirms a Cyber Attack by a Cybercrime Group After a Multi-Week Disruption
Victim: Crown Equipment Corporation
Crown Equipment Corporation is the world’s fourth largest forklift manufacturer. Crown was founded in 1945, employs 19,600 people globally and has more than 500 retail locations in 80 countries.
Reference: Crown back in production after cyberattack
Incident: Prolonged effects of Cyberattack on City of Leicester almost Two Months after Initial Attack
The council disabled its phone and computer systems on 7 March after a "cyber incident". The issue lead to prolonged disruption:
-BBC reports on April 3; 25 stolen documents had been posted online but now a "much larger batch" has been released. Council bosses said the attack on its systems was "highly sophisticated".
The council said its IT networks were now back online and that a known ransomware group was responsible.
-BBC reports on April 23 : wider effects of the cyberattack continue to show, including a number of street lights that are staying on during the day. "This means we are currently not able to remotely identify faults in the street lighting system. A number of steps are required to resolve the problem, and we are working through these as quickly as we can." says a city council spokesperson.
INC Ransom claimed responsibility for the attack.
Victim: Leicester City Council.
Leicester City Council, UK
Reference: Stolen data published after Leicester cyber-attack
Reference: Cyber-attack leaves Leicester street lights permanently on
Reference: Leicester City Council’s services back online after ‘cyber incident’
Incident: Northern Minerals Hit in Ransomware Attack
Australian mining company, Northern Minerals, fell victim to a cybersecurity breach back in March that led to data stolen appearing on a publishing site on the dark web, officials said Tuesday.
Northern Minerals mines and develops heavy rare earth elements like dysprosium and terbium. These materials end up used in electronics, batteries, and aircraft.
The miner revealed the threat actors stole data from its systems in late March and then published it on the dark web.
Reference: Aussie Mining Firm Hit In Ransomware Attack
Victim: Northern Minerals
Northern Minerals mines and develops heavy rare earth elements like dysprosium and terbium. These materials end up used in electronics, batteries, and aircraft.
Incident: McKim & Creed Engineering Firm Suffers Cyberattack
Raleigh, North Carolina-based McKim & Creed suffered a cyberattack on its network that disrupted some business aspects.
“On February 11, 2024, McKim & Creed discovered suspicious activity on certain computer systems, resulting in the disruption of certain business functions,” the company said in an advisory last week. “McKim & Creed immediately responded and launched an investigation with outside cybersecurity specialists to confirm the nature and scope of the incident and restore impacted computer systems to full, secure operability.
“Through the investigation, McKim & Creed learned that an unauthorized actor accessed its systems and may have viewed or acquired business data containing certain employee information between December 15, 2023 to February 11, 2024. McKim & Creed conducted a review of the data that was potentially viewed or acquired to determine whether it contained any sensitive information.
“While the review was ongoing, McKim & Creed notified certain impacted individuals of the incident on February 28, 2024. On May 3, 2024, McKim & Creed determined what personal information related to employees and dependents was included in the potentially impacted data set. After determining the scope of information in the potentially impacted files, McKim & Creed undertook efforts to locate address information for the affected individuals, put resources in place to assist, and provide direct notice.”
Reference: NC Engineering Firm Hit In Cyberattack
Victim: McKim & Creed
Raleigh, NC-based engineering services firm. McKim & Creed is an employee-owned firm with more than 800 staff members. It has offices in North, Carolina, South Carolina, Florida, Virginia, Texas, Louisiana and Pennsylvania. The company started up in 1978 and specializes in civil, environmental, mechanical, electrical, plumbing, and structural engineering; industrial design-build services; airborne and mobile Lidar/scanning; unmanned aerial systems; subsurface utility engineering (SUE); and hydrographic and conventional surveying services for the energy, transportation, federal, land development, water and building markets.
Incident: Bimbo Bakeries USA Hit in Cyberattack
Horsham, Pennsylvania-based Bimbo Bakeries USA, Inc. and its affiliate Bimbo Foods Bakeries Distribution, LLC suffered a cyberattack on a server that processes information for the company and its affiliates.
On February 13, 2024, an affiliate of Bimbo Bakeries detected that an unauthorized third party gained remote access to a portion of the network used to process information for Bimbo Bakeries and its affiliates.
An investigation confirmed on February 13, 2024, the unauthorized third party accessed a portion of the network used to process information for Bimbo Bakeries and its affiliates, including one server used to process personal information of employees and vendors of Bimbo Bakeries, and obtained certain files containing personal information.
Reference: Cyberattack At PA Baked Goods Maker
Victim: Bimbo Bakeries USA, Inc. and its affiliate Bimbo Foods Bakeries Distribution, LLC
The largest bakery company in the United States.
Incident: Cyberattack at Tool Maker M.A. Ford Manufacturing
Tool maker, M.A. Ford Manufacturing Company, Inc. suffered a cyberattack over a two-day period at the end of last year, but did not discover it until May.
The incident affected 4,359 with information such as financial account number or credit/debit card number (in combination with security code, access code, password or PIN for the account) falling into the hands of the attackers.
“On December 14, 2023, we discovered unusual activity on our network,” the company said in an advisory. “We immediately began an investigation, which included working with third-party specialists. Our investigation determined an unknown party accessed portions of our network between December 12, 2023 and December 14, 2023. Therefore, we conducted a review of our network to determine the type of information contained therein and to whom the information related."
Reference: Tool Maker Hit In Cyberattack
Victim: M.A. Ford Manufacturing Company, Inc.
Since 1919, Davenport, Iowa-based M.A. Ford has grown from a small midwest maker of rotary files to a manufacturer of standard, high performance and custom cutting tools with manufacturing and distribution facilities all over the world.
Reference: Ransomware Attack Shuts Key Tronic Operations
Victim: Key Tronic Corporation
Contract manufacturer and printed circuit board assembly (PCBA) manufacturing giant.
Incident: Ransomware Attack at Schuette
Metal fabricator, Schuette Inc., fell victim to a ransomware attack in April and is now in the process of notifying its customers.
“On or around April 18, 2024, Schuette became aware of certain unauthorized activity within its computer systems,” the Rothschild, Wisconsin-based company said in a filing. “Upon discovery, we immediately secured the network and swiftly engaged a third-party team of forensic investigators in order to determine the full nature and scope of the incident. On May 14, 2024, following a thorough investigation, we discovered that a limited amount of personal information may have been accessed by an unauthorized third party in connection with this incident.
“At this time, there is no indication that any information has been misused. However, we are providing this notification to you out of an abundance of caution and so that you may take steps to safeguard your information if you feel it is necessary to do so,” the company said.
In the filing, Schuette described the breach as a ransomware attack affecting 1,122 people.
Reference: WI Metal Fabricator Hit In Ransomware Attack
Victim: Schuette Metals Inc.
Schuette Metals is a full-service metal fabricator that manufactures components used in finished products by various OEMs in sectors, including architectural, agricultural, construction, defense, industrial, and access equipment.
Incident: Cyberattack at Cambrex Corporation
Cambrex is a global contract development and manufacturing organization (CDMO) that provides drug substance, drug product, and analytical services across the entire drug lifecycle.
Reference: Cyberattack At NJ Pharma Contract Manufacturer
Victim: Cambrex Corporation
Cambrex is a global contract development and manufacturing organization (CDMO) that provides drug substance, drug product, and analytical services across the entire drug lifecycle.
Incident: Cyberattack at Phillips Screw Company
Amesbury, Massachusetts-based The Phillips Screw Company suffered a “sophisticated” cyberattack that disrupted its day-to-day operations.
The breach occurred December 11 last year, but ended up discovered by the company May 10.
“The Phillips Screw Company detected a sophisticated cybersecurity incident that impacted our network on December 18, 2023,” the company said in a filing. “Due to this incident, we experienced limited disruption to our day-to-day operations and worked as quickly as possible to remediate and resume full business functionality. In doing so, we took immediate steps to mitigate the threat, including taking certain systems offline.”
The company said the threat actor was able to gain access and stayed on the system from Dec. 11 through Dec. 18.
Reference: MA Fastener Firm Suffers Cyberattack
Victim: The Phillips Screw Company
The Phillips Screw Company designs and engineers proprietary fastener technology, including high-performance drive systems for fastening applications in aerospace, automotive, DIY and trade, electronics, industrial, marine, military and header tools and gauging markets.
Incident: Ransomware attack at Lewis Brothers Bakeries
Evansville, Indiana-based Lewis Brothers Bakeries Inc. (LBBI) suffered a ransomware attack in March where files and servers ended up encrypted and threat actors were able to steal information from the network.
The company said in a notice, it discovered on April 18 attackers encrypted certain files on its servers and the attack affected 13,501 victims.
“LBBI immediately launched an investigation into the nature and scope of this activity, with the assistance of third-party forensic specialists,” the company said. “The investigation determined there was unauthorized access to the LBBI network between March 25, 2024, and April 1, 2024, during which time certain files were copied and taken from the network.
“LBBI undertook a comprehensive review of all data that was potentially subject to unauthorized access in order to identify the type of information impacted and to whom the information related. On April 18, 2024, LBBI completed this review.”
Reference: IN Bakery Hit In Ransomware Attack
Victim: Lewis Brothers Bakeries Inc.
Lewis Brothers Bakeries manufactures fresh and frozen bread and bread-type rolls, cakes, pies, and other perishable bakery products.
Incident: Cyberattack at Craft Beer Co.
Craft Beer Company GP, including its subsidiaries Duvel Moortgat USA, Ltd., Boulevard Brewing Company, and Brewery Ommegang, Ltd., fell victim to a cyberattack in March.
The attack led to the release of personal information to a third party for up to 1,584 people, according to a notice the Kansas City, Missouri-based company released May 8.
“On March 5, 2024, we discovered that an unauthorized third party gained access to our network,” the company said in a notice. “Upon becoming aware of the incident, we took immediate action to contain the incident and respond to it. Specifically, we promptly isolated all sites, shut down servers, and disconnected our system from the Internet.
“We also launched an internal investigation, contacted law enforcement, and engaged external cybersecurity forensic experts to conduct an external investigation into this intrusion and help to further secure our systems against any additional potential vulnerabilities."
Reference: Craft Beer Firm Hit In Cyberattack
Victim: Craft Beer Company GP
Beer manufacturer based in Kansas City, MO. Its subsidiaries include: Duvel Moortgat USA, Ltd., Boulevard Brewing Company, and Brewery Ommegang, Ltd.
Incident: Ransomware Attack at Nissan North America
Franklin, Tennessee-based Nissan North America, Inc. (NNA) is just now notifying workers and customers of a ransomware attack against the company this past November which it discovered at the end of February.
The targeted attack on an external VPN shut down some systems and resulted in affecting 53,038 people. It occurred November 7, 2023 and the company discovered it Feb. 28, 2024.
The company said in a report released Wednesday (May 15), “on November 7, 2023, NNA learned it was the victim of a targeted attack against its external VPN when a criminal threat actor deliberately shut down certain NNA systems and demanded a ransom.
“Immediately upon discovering the criminal attack, NNA (working very closely with external cybersecurity professionals experienced in handling these types of complex security incidents) investigated, contained, and successfully terminated the threat."
Reference: Nissan North America Hit In Ransomware Attack
Victim: Nissan North America
A wholly owned subsidiary of Nissan Motor Corporation of Japan.
Incident: Frontier Communications Hit in Attack
Telecom provider, Frontier Communications, suffered an attack from a cybercrime group that was able to get into some of its IT systems which also led to operational disruptions “considered material.” After discovering the incident the company partially shut down some systems to prevent the attackers from moving across the network, which also led to operational disruptions.
The sample of the notice submitted to the Office of the Maine AG has censored the types of data exposed in this incident, but full names and Social Security Numbers (SSNs) were confirmed as breached for 751895 customers.
RansomHub claimed the attack, unless Frontier responds to their demands by June 14 they will sell the data to the highest bidder.
Reference: Frontier Communications Attacked, Suffers ‘Material’ Disruptions
Victim: Frontier Communications
Frontier is a major communications provider which provides gigabit Internet speeds over a fiber-optic network to millions of consumers and businesses across 25 states.
Incident: Cyberattack at Indiana Water Plant
A wastewater treatment plant in Indiana suffered a cyberattack Friday, forcing maintenance personnel to investigate the nature of the incident.
“We were targeted and we have not been compromised,” said Jim Ankrum, general manager of Tipton Municipal Utilities (TMU) in a CNN report. TMU provides electricity, water and wastewater treatment for Tipton, a town of 5,000 people that is about 40 miles north of Indianapolis. “TMU experienced minimal disruption and remained operational at all times.”
A Russia-linked hacking group claimed responsibility, according to the report. The same group claimed credit for a string of hacking incidents against water facilities in Texas earlier this year.
Reference: IN Water Plant Hit In Cyberattack
Victim: Tipton Municipal Utilities
“We were targeted and we have not been compromised,” said Jim Ankrum, general manager of Tipton Municipal Utilities (TMU) in a CNN report. TMU provides electricity, water and wastewater treatment for Tipton, a town of 5,000 people that is about 40 miles north of Indianapolis. “TMU experienced minimal disruption and remained operational at all times.”
A Russia-linked hacking group claimed responsibility, according to the report. The same group claimed credit for a string of hacking incidents against water facilities in Texas earlier this year.
Incident: Nexperia, Chip Maker Suffers Cyberattack
Netherlands-based chip manufacturer, Nexperia, suffered a cyberattack last week and ransomware attackers leaked samples of data it claims it stole from the semiconductor maker’s server.
As a result of the attack, the company said on Friday it shut down IT systems and launch an investigation to determine the scope of impact. It appears the attack came from a ransomware attack group.
In a statement, Nexperia said: “Nexperia has become aware that an unauthorized third party accessed certain Nexperia IT servers in March 2024.
“We promptly took action and disconnected the affected systems from the Internet to contain the incident and implemented extensive mitigation. We also launched an investigation with the support of third-party experts to determine the nature and scope of the incident and took strong measures to terminate the unauthorized access."
Reference: Chipmaker Nexperia confirms breach after ransomware gang leaks data
Reference: Chip Maker Nexperia Hit In Attack
Victim: Nexperia
Nexperia is a global semiconductor company – and a subsidiary of Chinese company Wingtech Technology – with over 15,000 employees across Europe, Asia, and the United States. Nexperia’s components enable the basic functionality of virtually every electronic design in the world, from automotive and industrial to mobile and consumer applications. The company serves a global customer base, shipping more than 100 billion products annually.
Incident: Attack Shuts Down Production at Lens Maker Hoya
Production of several of Hoya Corp.’s products shut down after a system failure, which was most likely the result of “unauthorized access” to its servers, company officials said Thursday.
Japanese lens maker Hoya said the company discovered a system discrepancy in one of its overseas offices Saturday and confirmed the disruption despite its efforts to isolate affected servers.
“The day before yesterday (March 30), we learned that the Group’s head quarter and several of its business divisions have experienced an IT system incident,” the company said in a statement they issued Monday. “The Company will work closely with each of its business divisions and sites, as well as with outside experts, to identify the nature and scope of the incident and to restore the situation as soon as possible.”
Reference: Production Shut Down For Lens Maker After Cyberattack
Victim: Hoya Corp.
Hoya is the world’s second-largest eyeglass lens maker, with 90 percent of its eyewear lens sales earned from outside of Japan, according to its latest annual report. A Hoya spokesperson declined to say whether any of the company’s other optical products, including components for chipmaking equipment and hard disc drives, ended up affected by the disruption.
Editorial: 2024 Threat Report
Reference: Production Shut Down For Lens Maker After Cyberattack
Incident: Acer Confirms Employee Data on Hacker Platform
Acer Philippines confirmed that employee data was stolen in an attack on a third-party vendor who manages the company's employee attendance data. "Earlier today a threat actor known as 'ph1ns' published a link to download a stolen database containing Acer employee data for free on a hacking forum."
Reference: Acer confirms Philippines employee data leaked on hacking forum
Incident: Databreach at Telco Tangerine Impacts 230K Inidviduals
Tangerine suffered a data breach that exposed the personal information of roughly 230,000 individuals. Tangerine management became aware of the incident 2 days after the breach, on Tuesday 20 February 2024.
The telecommunications provider pointed out that no financial information (credit or debit card numbers, banking details) has been compromised. The attack did not affect the availability or operation of their nbn® or mobile services.
Victim: Tangerine
Australian telecommunications provider Tangerine
Reference: Australian telecommunications provider Tangerine disclosed a data breach that impacted roughly 230,000 individuals.
Incident: Operations Impacted at Top Pediatric Hospital in US
Lurie Children’s Hospital in Chicago took IT systems offline after a cyberattack. The security incident severely impacted normal operations also causing the delay of medical care. Lurie confirmed that the attack disrupted the hospital’s access to the internet, email, phone services, and the MyChat platform. “The incident has impacted phones, emails, internet service, some elective surgeries and procedures even had to be canceled.”
Victim: Lurie Children’s Hospital
Lurie Children’s Hospital is one of the top pediatric hospitals in the United States. Formerly known as Children’s Memorial Hospital, it was renamed in recognition of Ann and Robert H. Lurie, who made a significant donation to the hospital.
Reference: A CYBERATTACK IMPACTED OPERATIONS AT LURIE CHILDREN’S HOSPITAL
Reference: MEDUSA RANSOMWARE ATTACK HIT KANSAS CITY AREA TRANSPORTATION AUTHORITY
Incident: Operations Disrupted in Cyberattack at Building Materials Manufacturer Simpson Strong-Tie Co.
Building and structural materials producer, Simpson Strong-Tie Co. Inc., is only now alerting customers in a letter dated March 19, about a cyberattack suffered back in October 2023. From October 9 to October 11 he attackers had access to data that included personal information about certain individuals. Additionally, at the time of the attack the company detected IT problems and application outages, which it soon realized was a cyberattack. In response to the situation, Simpson took all impacted systems offline.
“The incident has caused, and is expected to continue to cause, disruption to parts of the Company’s business operations,” the company said in the report.
Victim: Simpson Strong-Tie Co. Inc.
Building and structural materials producer
Reference: CA Building Products Maker Releases Attack Info
Incident: Data Security Incident at Sierra Lobo (SLI), a US Aerospace Engineering Firm
Despite patching a vulnerability in a remote access tool, Fremont, Ohio-based Sierra Lobo, Inc. (SLI), suffered a data security incident the company feels launched before they applied the mitigation.
"Based upon the forensic investigation, this cybersecurity incident commenced through the exploitation of a vulnerability in our remote access tool, ScreenConnect. Despite the immediate application of a patch addressing the identified vulnerability, subsequent investigations suggest that the system remained compromised, indicating that the initial breach occurred prior to the patch application."
Victim: Sierra Lobo, Inc. (SLI)
Sierra Lobo, Inc. (SLI) is an engineering and technical services company specializing in creating and managing innovative space and aerospace technologies based in Fremont, Ohio, USA
Reference: Aerospace Engineering Firm Hit In Cyberattack
Incident: Southwest Binding & Laminating Hit by Ransomware Attack
Missouri-based Southwest Plastic Binding Company, known as Southwest Binding & Laminating, suffered a ransomware attack at the beginning of February that may have exposed personal information, company officials said.
On February 1, Southwest noticed unusual activity on its internal network from a Southwest domain account with administrator privileges. The company immediately began investigating the incident. “We responded by immediately taking all servers offline. Additionally, on this same day, remediation efforts began, including efforts to restore critical business files and services."
Victim: Southwest Plastic Binding Company
Southwest Plastic Binding Company, MO
Reference: Plastic Binding Maker Hit In Ransomware Attack
Reference: Data Breach Notifications (Fincantieri)
Reference: Ransomware Hits Navy Contractor
Reference: Ransomware attack on US Navy shipbuilder leaked information of nearly 17,000 people
Reference: Ransomware Hits Navy Contractor
Incident: Massive Data Leak after Cyberattack at Kenya Airways
Kenya Airways appears to have been hit by a cyberattack by Ransomexx ransomware group on December 30, 2023 leading to a massive data leak including highly sensitive and confidential data that they uploaded on the dark internet.
The airline now suffers the aftermath of a targeted cyberattack that has exposed sensitive information. Exposed documents encompass a wide array of highly sensitive information, from aircraft accidents and investigations into employee misconduct to confidential agreements, insurance policies, passwords, and customer complaints.Documents leaked cover aircraft accidents, investigation reports into employee misconduct like fraud, theft, policy violations.
Threat Actor: Ransomexx
Ransomexx ransomware group is a Human-Operated Ransomware (HumOR) that has existed since May 2020.
Victim: Kenya Airways
Kenya Airways
Reference: Data Breach: Kenya Airways Hacked, Sensitive And Confidential Files Leaked
Reference: Kenya Airways Faces Ransomware Attack
Incident: Data Security Breach at Alkem Laboratories
Alkem Laboratories, a major pharmaceutical company, acknowledged a cybersecurity incident that resulted in a fraudulent transfer of $6.2M from one of its subsidiaries. The breach involved compromising the business email IDs of some employees at the subsidiary, though the exact details of the security breach were not disclosed by Alkem.
Reference: Alkem Labs Cybersecurity Incident Disclosed
Reference: CYBER CRIMEPharma Giant Alkem Laboratories Faces Security Breach, Rs 52 Crores at Stake
Victim: Alkem Laboratories
Alkem Laboratories, a major pharmaceutical company
Incident: Cyberattack Targets Bazan Group’s Digital Infrastructure
Anonymous Sudan, a notorious hacking group, has claimed responsibility for a substantial cyberattack on Bazan Group, formerly known as Oil Refineries Ltd, Israel’s primary oil refining and petrochemicals company. The attack targeted the digital infrastructure of Bazan Group, raising concerns about potential implications for Israel’s economic powerhouse. While the hacking collective declared a major cyber offensive, Bazan Group confirmed a temporary and minor connectivity slowdown, emphasizing no damage to business or operational processes.
Reference: Anonymous Sudan Targets Bazan Group
Incident: Network Disruptions after Cyberattack on Israel’s Mobile Service Provider, Pelephone
Hacktivist group Anonymous Sudan has claimed responsibility for a cyberattack on Israel’s largest mobile service provider, Pelephone, resulting in disruptions to its network and digital infrastructure. The group declared the attack as part of its ongoing campaign against prominent Israeli targets, specifically mentioning the impact on Pelephone’s critical systems, including SCADA and other infrastructure-based endpoints.
The cyberattack was claimed by Anonymous Sudan to have practically taken Pelephone’s entire digital infrastructure offline through a sophisticated cyberattack.
Victim: Pelephone
Israeli cellphone provider
Reference: Israeli Cellular Provider Pelephone Hacked
Incident: Ukranian Oil and Gas Company Naftogaz Hit by Cyberattack
State-owned critical infrastructure companies in Ukraine fell victim to cyberattacks on Thursday, with the largest oil and gas company, Naftogaz, being among the targets. The cyber assailants targeted Naftogaz’s data center, leading to the complete inactivity of the company’s website and call centers.
As of the latest update, specialists from Naftogaz are actively working to resolve the incident, promising further comments on the nature of the attack. Naftogaz, a cornerstone of Ukraine’s energy industry employing 100,000 people and supplying gas to over 12 million households, faces a critical situation, and the motive and identity of the attackers remain unclear.
Victim: Naftogaz
Naftogaz is a cornerstone of Ukraine’s energy industry employing 100,000 people and supplying gas to over 12 million households
Reference: Naftogaz Operations Halted Amid Cyber Crisis
Reference: Outages due to a cyber attack on the “Parkovy” data center [machine translated]
Incident: Phishing Attack Hits South African Railways
South Africa’s railway agency, PRASA, recently disclosed a significant loss of $1.6 million due to a phishing scam in its annual report. Despite efforts to recover the stolen funds, just over half has been successfully retrieved, leaving the investigation ongoing. While details of the attack remain undisclosed, security experts suspect insider involvement, underscoring the importance of addressing insider threats within organizations.
Victim: Passenger Rail Agency of South Africa [PRASA]
South African Railways
Reference: Passenger Rail Agency of South Africa – annual report
Reference: South African Railways Phishing Scam
Page: Request Access to the 2023 Report
Incident: Hacktivists Claim DDoS Attacks on stateowned airline FlyDubai
United Arab Emirates' government-owned airline Flydubai was claimed to be subjected to several distributed denial-of-service attacks by the self-proclaimed hacktivist operation Anonymous Sudan.
FlyDubai has yet to respond to the claimed compromise by Anonymous Sudan.
Reference: Anonymous Sudan allegedly conducted a cyber attack on FlyDubai and disrupted its network
Reference: Flydubai targeted by Anonymous Sudan DDoS attacks
Reference: A ransomware-type cyber attack affected hospitals in Romania
Incident: SAS Scandinavian Airlines’ App Compromised by a Cyberattack
SAS Scandinavian Airlines was hit by a cyber attack on February 14th, compromising its app. The airline was said to be working on a solution, with reports saying that the problem was fixed to a large extent. Still, SAS warned that the attack may have targeted customer data following the breach.
Reference: Hackers Target SAS Network And Compromise App
Reference: SAS Cyber Attack Chaos
Incident: Lockbit Demands $100K after Ransomware Attack at UAE Telecoms Group
ETISALAT, state-owned Emirates Telecommunications Group Company in the UAE, is reportedly grappling with a ransomware attack attributed to LockBit ransomware group. The hackers are demanding $100,000 for the return of the pilfered data, setting a deadline of April 17th.
The attack has seen sensitive data belonging to Etisalat uploaded onto the Lockbit website, with the cybercriminals demanding a substantial $100,000 ransom for its security. ETISALAT official website remains accessible, raising doubts about the validity of LockBit's claims.
Victim: Etisalat
Etisalat UAE Telecom company
Reference: Etisalat Hit by Lockbit Ransomware
Reference: UAE Telecom Giant ETISALAT Hit by LockBit, $100K Demanded for Data Release
Incident: DDoS Attack Disrupts Copenhagen Airport
The Copenhagen airport experienced a significant cyberattack on a Sunday, causing widespread chaos as Denmark’s largest airport grappled with the aftermath. Identified as a denial of service (DoS) attack, the attack targeted the airport’s digital infrastructure, rendering its official website inoperative and leaving passengers and officials struggling for alternatives.
Airport authorities redirected passengers to a smartphone app for flight updates, highlighting the vulnerability of critical systems and the disruptive potential of cyber threats.
Victim: Copenhagen Airport
Copenhagen Airport
Reference: Cyberattack Hit Copenhagen Airport
Incident: Cyberattack at Macedonian Electricity Transmission Operator (MEPSO)
The Electricity Transmission System Operator of the Republic of North Macedonia (MEPSO) said it is dealing with a cyberattack, but stressed in a press release Thursday that the integrity of the power grid and the supply of electricity have not been threatened.
The state-owned company said its critical energy infrastructure was not the target of the attack and it remains secure and fully functional.
Reference: MEPSO is facing a cyberattack, the network and power supply are not threatened
Victim: MEPSO
Electricity Transmission System Operator of the Republic of North Macedonia (MEPSO)
Reference: MEPSO hit by cyberattack, power grid and electricity supply not threatened
Incident: Belgian Coffee Roaster Suffers Cyberattack
Koffie (coffee) Beyers from the Belgian town of Puurs-Sint-Amands has fallen victim to a cyber attack. Hackers managed to break into the company’s computer systems on Thursday. The coffee roaster itself declined to comment on the events. Police have confirmed that an investigation is underway.
Earlier in the week there was the ransomware attack on Duvel Moortgat, and the pro-Russian hacker group Stormous Group was behind it. It remains to be seen if they are also behind this attack. Cybercriminals are clearly targeting Belgian beverage producers this week.
Victim: Koffie Beyers
Koffie Beyers, Belgium's largest coffee brewery.
Reference: Belgium’s largest coffee roaster falls victim to cyber attack
Reference: Belgian village whose brewery was hit by cyberattack faces another on its coffee roastery
Incident: German Railway Company Transdev Website Access Restricted
An online attack on the railway company Transdev has temporarily led to restrictions on the websites of the Nordwestbahn and the Rhein-Ruhr-Bahn on Monday and Tuesday.
The attackers had directed a spam wave at forms on the Nordwestbahn page on Monday morning, Transdev announced on Tuesday on request. The measures undertaken were gradually reduced the next day. "The Rhein-Ruhr-Bahn, the website is accessible again without problems. Only on the Nordwestbahn website, increased protective measures are currently still ongoing, which are still being readjusted," it was said.
Reference: Spam wave hits Nordwestbahn and Rhein-Ruhr-Bahn
Victim: Transdev
Railway company Transdev
Incident: Hyundai Motor Europe Suffered Black Basta Ransomware Attack
Car maker Hyundai Motor Europe suffered a Black Basta ransomware attack, with the threat actors claiming to have stolen three terabytes of corporate data. Hyundai confirmed to BleepingComputer that they suffered a cyberattack.
BleepingComputer reports learning Black Basta ransomware operation conducted the attack in early January, when they claimed to have stolen 3 TB of data from Hyundai Motor Europe.
Reference: Hyundai Motor Europe hit by Black Basta ransomware attack
Incident: Hackers Attempt Communications Take Over on El Al Flights
At least two planes from Israel's El Al Airlines suffered hacking attempts from "hostile elements," according to several Israeli news outlets. The Jerusalem Post reported that "hostile elements" tried to take over the communications network of an El Al plane flying from Phuket, Thailand, to Ben-Gurion airport in Israel on Saturday night.
During the incident, instructions were given to the crew that were different from their set route, raising concerns that someone was trying to damage the plane or lead it to dangerous areas, maybe even to conduct a kidnapping.
El Al stressed that "the disturbances are not aimed at El Al planes and that this is not a security incident. The disruption did not affect the normal course of the flight
No group has claimed responsibility for the reported hacking attempts.
Reference: Israeli Planes Targeted in Attempted Takeover
Reference: Israeli flight from Thailand faced attack by ‘hostile elements’
Victim: El AL airlines
Israeli airline El Al
Incident: Dozens of Hospitals offline in Romania
Over a hundred Romanian healthcare facilities have been been affected by a ransomware attack, with some doctors forced to resort to pen and paper. Children's and emergency hospitals were among those hit, with other facilities going offline as a precaution. 25 Hospitals were affectec by the attack and 79 other healthcare facilities were taken offline while investigations were carried out to determine if they had been affected.
The cyber extortionists demanded 3.5 Bitcoin, worth over £130,000, to unlock vital files which they had encrypted. But Romanian cyber officials said data had been recently backed up, reducing the impact.
Victim: Hipocrate Information System (HIS)
Romanian Hospital Health information system : Hipocrate Information System (HIS),
Malware: Backmydata ransomware
Backmydata ransomware targets Remote Desktop Protocol (RDP) vulnerabilities, including weak credentials. Upon gaining a foothold, Backmydata establishes persistence, disables firewalls, encrypts, and exfiltrates data. It also deletes backups to prevent victims from restoring their systems without paying the ransom. It was linked to the Romanian hospitals attack in Feb 2024.
Reference: Ransomware attack hits dozens of Romanian hospitals
Reference: Hospitals offline across Romania following ransomware attack on IT platform
Incident: Alamos Gold Mining Company Discloses 2023 Databreach
Alamos Gold (TSX: AGI; NYSE: AGI) fell victim to a cyberattack that saw confidential corporate data get disclosed to the public last year, according to an exclusive scoop by Toronto-based newspaper The Star.
The data breach took place some time in April 2023. The data included sensitive information such as social insurance numbers, payroll reports, financial information, and home addresses and cell numbers for senior executives, all of which were published online by the hackers, the report said.
Victim: Alamos Gold
Mining company
Reference: Alamos Gold fell victim to cyberattack last year – report
Reference: RADIANT LOGISTICS, INC.
Incident: Radiant Logistics Isolates Canadian Operations after Cyberattack
Radiant Logistics, an international freight technology company said it has cut off a portion of its business in Canada after a cyberattack. The Company proactively took measures to isolate its Canadian operations from the rest of its network. The incident has caused service delays for customers in Canada.
Despite the shutdown, the filing says the incident is not “reasonably likely to materially impact the Company's financial conditions.” No ransomware gang has taken credit for the incident.
Victim: Radiant Logistics
Radiant Logistics is an international freight technology company
Reference: International freight tech firm isolates Canada operations after cyberattack
Incident: Cyberattack Affects Communications at KCATA Transit
A ransom cyber-attack hit the KCATA early Tuesday, January 23. The company website notes "The primary customer impact is that regional RideKC call centers cannot receive calls, nor can any KCATA landline. All service is operating, including fixed-route buses, Freedom and Freedom-On-Demand paratransit service. KCATA is working around the clock with our outside cyber professionals and will have systems back up and running as soon as possible."
Victim: KCATA – Kansas City Area Transportation Authority
Kansas City Area Transportation Authority
Reference: Cyber-Attack hits KCATA. Communications affected.
Incident: Weeks of Operational Shutdown at Welch Foods Plant
A cyberattack shut down production at Welch Foods Inc. plant in North East on Feb. 2. The plant restarted jam and jelly production lines end of February.
About 50 or 60 employees, who are members of Teamster's Local 397 in Erie, remained on the job throughout February and over 200 employees were laid off.
Victim: Welch Food
Welch Food
Reference: Welch plant in North East restarts after cyber attack shuts facility down for 3 weeks
Incident: International Paper takes Mill Operations Offline after Cyberattack
International Paper is in the process of starting up its Riegelwood Mill after shutting it down due to a cyberattack, a company spokesperson said Thursday morning.
"Late last week, we experienced a cyberattack event on our operating systems at our mill in Riegelwood, N.C.," IP spokesperson Kimberly Clewis wrote in a statement. "Thankfully, everyone at the mill is safe and there have been no environmental issues."
The statement said that "out of an abundance of caution, we coordinated an orderly shutdown of the mill to resolve the issue and are in the process of starting up the mill."
Clewis said the attacker accessed International Paper's system through a third-party vendor "and did not directly target our company or mill. This event impacted only a limited set of manufacturing systems at the Riegelwood Mill. No other mills, locations or systems were affected."
Reference: International Paper Riegelwood Mill shuts down after ‘cyberattack’
Incident: Continental Aerospace Discloses Cyberattack
Continental Aerospace is under a cyberattack according to its website. The engine manufacturer recently posted a website banner announcing that it is experiencing an ongoing cyberattack which is impacting operations at its Mobile Alabama headquarters.
The important notice posted on the 20 February reads: “Continental US operations were recently impacted by a cyber incident affecting daily operations based in Alabama. Continental is actively engaged with a team of experts who are working to resolve the issues as quickly as possible and expects to resume full operations soon.”
Continental have not elaborated when the cyberattack will end, nor how widely disruptive the event has been to its daily operation. Furthermore, the US engine OEM has not yet said if a data breach has occurred.
Reference: Continental Hacked
Victim: Continental Aerospace
based in Mobile, Alabama
Reference: Continental Aerospace under cyberattack
Incident: Emergency Services Communication System in Kansas down due to cyber incident
Riley County’s P25 public safety agency radio communication system lost connection early this morning as part of a cybersecurity incident. Emergency responders in Riley County are currently using the backup state system for emergency communications. P25 is a solution for intra-agency communication, which allows for interoperable, multi-agency communications during an emergency.
This radio network issue is affecting all first responders in Riley County, including police, fire, and emergency medical services. However, this connection problem does not impact the public or 911 systems. Dispatch operators are able to receive calls, dispatch resources, communicate with emergency responders, and activate outdoor warning sirens.
The Riley County Board of County Commissioners met made a local declaration of a disaster emergency in response to the cybersecurity incident
Reference: Riley County emergency responders using backup radios due to cybersecurity incident
Victim: Kansas, US – Riley County
Kansas, US - Riley County
Reference: Riley County Emergency Responders Using Backup Radio System
Incident: Hackers Attack Alzura, German Tire Trading Company
The online tire and parts retail giant Alzura has fallen victim to a hacker attack. According to the company, dealer accounts on Alzura Tyre24 as well as the white label solutions “Tyre Shopping” and “Alzura Shop” are among those affected by the latest hacker attack.
Reference: Hacker attack on tire trading giant Alzura
Victim: Alzura Tyre24
A large part of the B2B trade in tires takes place via the Alzura Tyre24 platform.
Incident: Cyberattack on Hearing Aid Manufacturer in Germany
The German hearing aid manufacturer Kind has been the target of a hacker attack. In addition to the headquarters near Hanover, communication with more than 600 specialist stores was also affected, said a company spokesperson. There are currently no indications that customer data has been stolen. The systems were shut down immediately and it is hoped that this has averted greater damage.
Victim: Kind, hearing aid manufacturer
German hearing aid manufacturer Kind
Reference: Cyberattack hits German hearing aid manufacturer
Reference: 600 stores affected: Hacker attack paralyzes hearing aid manufacturer Kind
Incident: Data Breach at German Mechanical Engineering Company
Graebener Bipolar Plate Technologies, a pioneer in the development of manufacturing technologies for bipolar plates reported that. between December 1st, 2023 and December 3rd, 2023, their IT systems were attacked. Parts of their databases were accessed. "All of our employees can still be reached via the usual communication channels (email and telephone). Our production processes are not affected and emergency operations have already been successfully resumed. In the coming weeks we will be strengthening some additional security measures to ensure the stability and integrity of our corporate IT.
[machine translated]
Black Basta Group has claimed responsibility for the attack.
Victim: Graebener Bipolar Plate Technologies
Graebener Bipolar Plate Technologies, a pioneer in the development of manufacturing technologies for bipolar plates
Reference: BlackBasta Ransomware Rampage Continues: NALS, Graebener, Among Latest Victims
Reference: Data protection incident at Gräbener Maschinentechnik GmbH & Co. KG
Incident: Cyberatttack at German Automotive Supplier Allgaier
There was a hacker attack on the Uhingen automotive supplier Allgaier in Uhingen. Production is not affected. The company and the insolvency administrator are not yet able to provide any further information.
Victim: Allgaier-Werke
German automotive supplier Allgaier-Werke,
Reference: Allgeier SE: Allgeier clarifies
Reference: Press Release
Reference: UHINGEN: CYBER ATTACK ON AUTOMOTIVE SUPPLIER ALLGAIER
Reference: EQS-Adhoc: Cyber attack on PSI
Reference: Critical infrastructure software maker confirms ransomware attack
Incident: Cyberattack on a mechanical engineering company in Germany
Kampf GmbH reported they were the victim of a targeted and criminal cyber-attack on the morning of 24th February 2024, which partially encrypted their IT systems. "We immediately disconnected all external connections and shut down all IT systems. Currently, we are investigating the extent of the attack with the support of external cybersecurity experts and forensic specialists. We have informed all the relevant authorities and are cooperating with them in all matters."
Reference: Cyber Attack on Kampf GmbH
Victim: Kampf
Mechanical engineering company in Germany
Incident: Yakult Australia Confirmed Australian and New Zealand IT Systems Were Impacted
Iconic probiotic company Yakult Australia has been hit by a significant cyber attack that has seen its company records and sensitive employee documents, such as passports, published on the dark web.
The DragonForce group has claimed responsibility for the breach. A sample of the 95 gigabytes of data leaked, analysed by ABC Investigations, found company records dating back to 2001.
Victim: Yakult
Probiotic company Yakult Australia
Reference: Yakult Australia targeted in cyber attack, employee files published on dark web
Reference: Freight giant Estes confirms data breach, but says it won’t pay ransom
Incident: Massive Ransomware Attack at Tigo, Paraguay’s Largest Telco
A ransomware attack has wreaked havoc inside the network of Tigo, the largest mobile operator and internet service provider in Paraguay. The incident took place on January 4, and impacted the telco's business branch.
Reports stated that over 330 servers were encrypted, and backups were compromised during the attack. At least 300 companies and some government organizations were impacted downstream. The companies lost phone service and files hosted on Tigo servers.
The Tigo attack has been attributed by local media to a ransomware group named BlackHunt.
Victim: Tigo
Tigo is the largest mobile carrier in Paraguay, with its Tigo Business division offering digital solutions to the enterprise, including cybersecurity consulting, cloud and data center hosting, and wide area network (WAN) solutions.
Reference: Paraguay warns of Black Hunt ransomware attacks after Tigo Business breach
Reference: Ransomware wrecks Paraguay’s largest telco
Reference: Australia sanctions Russian national accused of hacking in Medibank data leak
Incident: Black Basta Group Claims Ransomware Attack at UK Water Treatment Company
Southern Water, a water treatment company serving millions across the United Kingdom, was the victim of a ransomware attack claimed by the Black Basta ransomware gang.
"At this point there is no evidence that our customer relationships or financial systems have been affected. Our services are not impacted and are operating normally," Southern Water said today. It's unclear where the root cause of the breach lies. Some documents leaked online are branded with Greensands logos – the parent company of Southern Water.
Black Basta said it stole 750 GB worth of data in total, comprised of personal data and corporate documents, which is consistent with the small sample leaked online.
Reference: UK water giant admits attackers broke into system as gang holds it to ransom
Victim: Southern Water
Southern Water, a water treatment company serving millions across the United Kingdom
Reference: Cyber investigation
Incident: Veolia Municipal Water Division Systems Impacted by Ransomware Attack
Veolia North America’s Municipal Water division reported a ransomware attack. After detecting the attack, Veolia has implemented defensive measures, temporarily taking some systems offline to contain the breach. Veolia is now working with law enforcement and third-party forensics experts to assess the extent of the attack's impact on its operations and systems.
Victim: Veolia group
Veolia North America provides water and wastewater services to roughly 550 communities and industrial water solutions at around 100 industrial facilities, treating over 2.2 billion gallons of water and wastewater daily at 416 facilities across the United States and Canada.
The transnational Veolia group has almost 213,000 employees globally and generated €42.9 billion in revenue in 2022, providing drinking water to around 111 million people and wastewater services to roughly 97 million. The same year, Veolia produced nearly 44 terawatt-hours of energy and treated 61 million metric tons of waste.
Reference: Water services giant Veolia North America hit by ransomware attack
Reference: Veolia North America and Southern Water hit by ransomware attacks, data breach concerns arise
Reference: Veolia Responds to Cyber Incident
Incident: Aviation Leasing Company Aercap Reports Ransomware Attack
AerCap, a global company that leases aircraft, engines and helicopters, reported this week that it was responding to a ransomware attack. In a filing on Monday with the U.S. Securities and Exchange Commission, the Ireland-based company said the impact of the January 17 incident was limited. “We have full control of all of our IT systems and to date, we have suffered no financial loss related to this incident,” AerCap said.
Victim: Aercap
Aviation leasing company AerCap has more than $72 billion in aviation assets on hand, including 1,700 aircraft, approximately 1,000 engines and over 300 helicopters.
Reference: Aviation leasing company AerCap investigates ransomware incident
Incident: Ransomware Attack at Iowa Water & Electric Utility Company
Iowa Electric, Water Utility confirmed that a January ransomware attack at Muscatine Power and Water — providing the Muscatine and Fruitland area with internet, TV, phone, water, and electric services for more than 50,000 people —led to the exposure of sensitive information from nearly all local residents.
The company said internet services on the night of the attack were down for eight hours and business systems were restored over several days. “Additionally, at no time were critical controls systems at the power plant or in the field at risk,” the company explained.
Victim: Muscatine Power and Water
Iowa electric water utility
Reference: Iowa electric, water utility says info of nearly 37,000 leaked in January ransomware attack
Incident: Global Pharmaceutical Co. Cencora Data Breach
Global pharmaceutical corporation Cencora discovered that intruders had stolen data from its networks. The company said in a regulatory filing that data from IT systems “had been exfiltrated” in an incident that came to light on February 21.
UPDATE: 11 drug companies that partner with Cencora have disclosed data breaches of their own. According to data breach notifications published by the California Attorney General’s office from the affected companies, the Cencora cyber incident was the catalyst.
“The company has not yet determined whether the incident is reasonably likely to materially impact the company’s financial condition or results of operations.”
Victim: Cencora
Global pharmaceutical corporation Cencora (formerly known as AmerisourceBergen) is a Pennsylvania-based corporation with 46,000 employees and reported revenue of $262.2 billion for fiscal 2023.
Reference: Pharmaceutical giant Cencora reports cyberattack
Incident: Crinetics Pharmaceuticals Investigating Cyberattack
Crinetics , a San Diego pharmaceutical development company, said it is investigating a cybersecurity incident following claims from the LockBit ransomware gang that data was stolen.
The Lockbit gang demanded a $4 million ransom and set a deadline for Mar. 23. Crinetics did not respond to questions about whether they were dealing with a ransomware attack.
Reference: Pharmaceutical development company investigating cyberattack after LockBit posting
Victim: Crinetics
Crinetics , a San Diego pharmaceutical development company
Incident: Ransomware Attack at Bira 91, Indian Craft Beer brand.
On March 22, Indian craft beer brand Bira 91 was attacked by ransomware group BianLian.
Despite absence of an official statement from the company, reports indicate potential data exposure encompassing sensitive information concerning finance, human resources and proprietary recipes.
The absence of stringent disclosure laws in India, particularly in non-regulated industries such as manufacturing and healthcare, leaves customers vulnerable to data breaches without adequate notification or recourse.
Victim: Bira 91
Indian craft beer brand
Reference: Story of Ransomware Attacks on Indian Listed Companies
Incident: Ransomware Attack at India’s largest Wire and Cable Maker.
On March 17, Polycab India was targeted by LockBit ransomware group. According to Polycab, the incident did not impact the core systems and operations of India’s largest wire and cable maker. There was no mention of any ransom paid in the filing.
Victim: Polycab India
Polycab is India’s largest wire and cable maker.
Reference: Polycab, Motilal Oswal, Bira91 among latest companies to be hit by ransomware attacks
Victim: Carolina Foods
Carolina Foods, creator of the baked goods Duchess brand, a family owned business for 80 years. Duchess is a pastry manufacturer and their products include a variety of individually wrapped items including honey buns, baked pies, fried pies, and gem donuts.
Reference: Bittersweet: Charlotte honey bun maker hit with ransomware attack
Reference: North Carolina Honey Bun Maker Hit With Ransomware Attack
Incident: Fujitsu Caught in Cyberattack
Japanese multinational information and communications technology giant, Fujitsu Limited suffered a cyberattack. The company reported the incident March 15 when officials said they found malware on multiple computers within the organization.
“We confirmed the presence of malware on multiple work computers at our company, and as a result of an internal investigation, we discovered that files containing personal information and customer information could be illegally taken out,” the company said in a statement. Fujitsu is the world’s sixth largest IT services provider, with 124,000 employees and had revenues of $23.9 billion.
Reference: Fujitsu Suffers Cyberattack
Victim: Fujitsu
Fujitsu is the world’s sixth largest IT services provider, with 124,000 employees and had revenues of $23.9 billion.
Incident: FL Boat Builder, MarineMax, Hit in Cyberattack
One of the world’s largest recreational boat, yacht, and superyacht builders discovered they suffered a cyberattack earlier this week, but the company’s operations remained up and running.
Clearwater, Florida-based MarineMax Inc. discovered the attack March 10, 2024, saying a third party gained unauthorized access to portions of its information environment and filed an 8-K document with the Securities and Exchange Commission (SEC).
“MarineMax, Inc. determined on March 10, 2024, that it experienced a ‘cybersecurity incident,’ as defined in applicable Securities and Exchange Commission rules, whereby a third party gained unauthorized access to portions of its information environment,” the company said in the filing.
Reference: Boat Dealer MarineMax Hit by Cyberattack
Reference: MarineMax Boat Builder Hit In Cyberattack
Victim: MarineMax
One of the world’s largest recreational boat, yacht, and superyacht builders. MarineMax has over 130 locations worldwide, including about 80 retail dealership locations, some of which include marinas.
Incident: Switserland: Federal Passwords and Classified Information Stolen
On May 23, the Play ransomware group claimed it attacked Xplain – a Swiss IT firm providing services to several federal agencies in the country. The ransomware group leaked the files it stole from the company on June 1, which it claimed included 907 GB of financial and other data.
In March, 2024 SWI news reports that federal passwords and classified information were stolen in the >2023 cyberattack
Victim: Xplain
Xplain – a Swiss IT firm providing services to several federal agencies in the country
Reference: Swiss Administration Hit By Cyber Attack
Reference: Cybercrime News Government News News Get more insights with the Recorded Future Intelligence Cloud. Learn more. Switzerland warns that a ransomware gang may have accessed government data
Reference: Federal passwords and classified information stolen in 2023 cyberattack
Incident: Biggest Data Breach to-date in France Affects 50% of the Population
Two French service providers for medical insurance companies were targeted by a cyberattack. The hack has been determined to impact over 33 million people in the country. The "tiers payant," a payment system in which the patient doesn't have to pay the full cost of medical services upfront, may be unavailable for certain health professionals but still available for the patients.
While the exposed data does not include financial info, it is still enough to raise the risk of phishing scams, social engineering, identity theft, and insurance fraud for the exposed individuals.
Victim: Almerys
Almerys provide healthcare and insurance services in France with technological and administrative solutions to facilitate transactions
Victim: Viamedis
Viamedis provide healthcare and insurance services in France with technological and administrative solutions to facilitate transactions.
Reference: Data breaches at Viamedis and Almerys impact 33 million in France
Reference: Data of half the population of France stolen in its largest ever cyberattack. This is what we know
Incident: Belgian Duvel Brewery Halts Production after Ransomware Attack.
Duvel Moortgat Brewery is currently experiencing problems as a result of a cyber attack. The brewery confirms this. Production has been at least partially halted, this concerns all servers of the brewery, including those of their other Belgian beers such as De Koninck and La Chouffe.
A forensic investigation is underway into who might be behind the hacking.
Victim: Duvel Brewery
Duvel is a Belgian beer brand best known for its strong and fruity golden pale ale bearing the same name. The brewery also makes other popular abbey beers such as Vedett, Maredsous, and La Chouffe.
Reference: Duvel says it has ‘more than enough’ beer after ransomware attack
Reference: Duvel Moortgat Brewery victim of cyber attack: production and business shut down
Incident: Taiwan Semiconductor Manufacturer Hit by Lockbit Ransomware Gang
One of Taiwan's biggest semiconductor manufacturers has fallen victim to a cyberattack, supposedly carried out by the notorious LockBit ransomware gang. The hackers posted a threatening message on Foxsemicon’s website, stating that they had stolen its customers' personal data and would publish it on their darknet website if the company refused to pay. The company’s website, however, could not be accessed as of Wednesday afternoon Eastern U.S. time, while Google search results still display the hackers’ message
The tactic used in the attack on Foxsemicon is atypical for LockBit: Usually, they post the names of the victims on their extortion website rather than deface the company’s web page.
Reference: Foxsemicon Hit by LockBit Ransomware
Victim: Foxsemicon (FITI)
Foxsemicon Integrated Technology, Inc. (FITI) engages in the research, development, manufacture, and sale of semiconductor equipment and components
Reference: Steel Giant Hit In Cyberattack
Reference: Taiwanese semiconductor company hit by ransomware attack
Victim: Simpson Manufacturing Company
Simpson Manufacturing Company is an engineering firm and building materials producer in the United States that produces structural connectors, anchors, and products for new construction and retrofitting.
Incident: Schneider Electric Sustainability Business Hit by Cactus Ransomware Gang
Schneider Electric confirmed a ransomware attack that affected its Sustainability Business division. The attack disrupted some of Schneider Electric's EcoStruxure Resource Advisor cloud platform. The Cactus ransomware gang claims they stole 1.5TB of data. 25MB of allegedly stolen were also leaked on the operation's dark web leak site today as proof of the threat actor's claims. It is not known if Schneider Electric will be paying a ransom demand.
At a recent PASA Connect roundtable event, three of the 13 Chief Product Officers in attendance confirmed minor issues related to the incident.
Threat Actor: Cactus ransomware gang
The Cactus ransomware operation launched in March 2023 and has since amassed numerous companies that they claim were breached in cyberattacks.
Like all ransomware operations, they breach corporate networks through purchased credentials, partnerships with malware distributors, phishing attacks, or by exploiting vulnerabilities.
Reference: Supply chain disruption caused by Schneider Electric ransomware attack
Reference: Cactus ransomware claim to steal 1.5TB of Schneider Electric data
Reference: Schneider Business Unit Hit In Ransomware Attack
Reference: Schneider Electric, in ransomware recovery, faces claims of stolen data trove
Reference: Thyssenkrupp Auto Unit Hit by Cyberattack
Reference: Zurich Policyholder Dispute Highlights Danger of Calling Out Cyber Attackers: Opinion
Reference: Tietoevry ransomware attack causes outages for Swedish firms, cities
Incident: Natanz and Fordo Facilities closed down “Automation Network” after New Worm Targeted Iran’s Nuclear Program
Two of Iran’s uranium-enrichment plants were struck by a cyberattack earlier this week that shut down computers and blared AC/DC songs, according to reports from Bloomberg News and others. The virus closed down the automation network at the Natanz and Fordow facilities, according to an e-mail received by F-Secure, a Finnish cybersecurity Web site, from Iran’s Atomic Energy Organization.
F-Secure Security Labs said that while it was unable to verify the details of the attack described, it had confirmed that the scientist who reported them was sending and receiving the e-mails from within Iran’s Atomic Energy Organization.
Victim: Fordow Fuel Enrichment Plant
Fordow Fuel Enrichment Plant is an Iranian underground uranium enrichment facility located 20 miles northeast of the Iranian city of Qom, near Fordow village, at a former Islamic Revolutionary Guard Corps base. The site is under the control of the Atomic Energy Organization of Iran.
Reference: Iran Nuclear Plants Hit By Virus Playing AC/DC
Reference: Iranian nuclear facilities are hit by AC/DC virus
Incident: Change Healthcare Cyberattack Causes Widespread Disruptions at US Pharmacies
Ransomware attack impacts more than 100 Change Healthcare services, including benefits verification, claims submission, and prior authorization. As soon as the breach was detected, Change Healthcare took the drastic step of disconnecting its systems to prevent further damage. Retail pharmacies, some now forced to revert to manual processing, face delays, sparking concerns among patients relying on timely medication.
The AHA (American Hospital Association) has advised health systems to disconnect from Change Healthcare and Optum services. This breach, reportedly due to hackers exploiting vulnerabilities in the ConnectWise ScreenConnect remote IT platform and using LockBit malware, underscores the vulnerability of consolidated healthcare data systems.
Update: "RansomHub leaked stolen data from United Health subsidiary Change Healthcare following a BlackCat/ALPHV attack, suggesting some form of collaboration between the two." Change Healthcare paid $22 million in hopes of securing the stolen data
Victim: UnitedHealth Group Inc.
UnitedHealth Group Incorporated is an American multinational health insurance and services company based in Minnetonka, Minnesota
Reference: The Change Healthcare cyberattack is still impacting pharmacies. It’s a bigger deal than you think
Victim: Change Healthcare
Change Healthcare is a provider of revenue and payment cycle management that connects payers, providers, and patients within the U.S. healthcare system.
Reference: US pharmacy outage triggered by ‘Blackcat’ ransomware at UnitedHealth unit, sources say
Reference: Exclusive: US pharmacy outage triggered by ransomware at unit of UnitedHealth, sources say
Reference: Cyber Siege: The Attack on Change Healthcare Echoes the Colonial Pipeline Crisis, Shaking the U.S. Healthcare Sector
Incident: Trans-Northern Pipelines (TNPI) Says Able to Contain Ransomware Attack
Trans-Northern Pipelines (TNPI) has confirmed its internal network was breached in November 2023 and that it's now investigating claims of data theft made by the ALPHV/BlackCat ransomware gang.
"Trans-Northern Pipelines Inc. experienced a cybersecurity incident in November 2023 impacting a limited number of internal computer systems," TNPI Communications Team Lead Lisa Dornan told BleepingComputer. "We have worked with third-party, cybersecurity experts and the incident was quickly contained. We continue to safely operate our pipeline systems.
Victim: Trans-Northern Pipelines (TNPI)
TNPI operates 850 kilometers (528 miles) of pipeline in Ontario-Quebec and 320 kilometers (198 miles) in Alberta, transporting 221,300 barrels (35.200m3) of refined petroleum products daily.
Reference: Trans-Northern Pipelines investigating ALPHV ransomware attack claims
Reference: Canadian Oil Pipeline Hit With Ransomware
Incident: Hackers Breach Systems at Steel giant ThyssenKrupp
Steel giant ThyssenKrupp confirms that hackers breached systems in its Automotive division, forcing them to shut down IT systems as part of its response and containment effort. “The threat situation is under control, and we are working on a gradual return to normal operations,” a spokeswoman for the company said. While the shutdown halted production, she said, the company was still able to supply customers.
ThyssenKrupp has clarified that no other business units or segments have been impacted by the cyberattack, which was contained in the automotive division. They are working on gradually returning to normal operations.
Reference: Hacker attack on Thyssenkrupp – factory with 1,000 employees in Saarland affected
Reference: Steel giant ThyssenKrupp confirms cyberattack on automotive division
Reference: Flame And SCADA Security
Reference: Iranian oil terminal ‘offline’ after ‘malware attack’
Reference: Attacks on Iranian oil industry led to Flame malware find
Threat Actor: WIZARD SPIDER
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Reference: Timeline: Israeli Attacks on Iran
Incident: Virun Infection in turbo Control System at US Electric Utility
In early October 2012 a power company contacte ICS-CERT to report a virus infection in a turbine control system which impacted approximately ten computers on its control system network. 10 plant PCs were infected by Mariposa malware variant, transmitted through a USB stick. Occurred during scheduled shutdown for maintenance.
Reference: ICS CERT Monitor – December 2012
Reference: German Steel Mill Attack: Inside Job
Incident: Attack on Kyiv Power Substation Shut Down Remote Terminals
The attack on the Pivnichna transmission facility shut down the remote terminal units that control circuit breakers. Oleksii Yasynskyi, head of research for Information Systems Security Partners in Ukraine, said the attackers belonged to several different groups that worked together. Among other things, they gathered passwords for targeted servers and workstations and created custom malware for their targets. Sandworm suspected in deploying Industroyer (also: CrashOverride) malware, by exploiting a vulnerability in Siemens SIPROTEC relays.
The hack was less severe than the one used in the 2015 attack, which rendered the devices inoperable and prevented engineers from remotely restoring power.
Victim: Pivnichna Power Transmission Facility
Pivnichna transmission facility, Kyiv, Ukraine
Reference: Hackers trigger yet another power outage in Ukraine
Reference: Found: “Crash Override” malware that triggered Ukrainian power outage
Incident: Wannacry Affects Operations at Several Renault Plants
Global cyberattack caused widespread disruption including stoppages at several of Renault-Nissan sites. Renault and its Japanese partner are the only major car manufacturers so far to have reported production problems resulting from Friday's WannaCry ransomware worm attack that spread to more than 150 countries.
The cyber attack halted or reduced the output of at least five Renault sites over the weekend. Besides Douai, they included a van plant in Sandouville, France; a small-car plant in Slovenia; the no-frills Dacia plant in Pitesti, Romania; and a factory shared with Nissan in Chennai, India.
Victim: Renault-Nissan
Renault-Nissan
Reference: Renault-Nissan is resuming production after a global cyberattack caused stoppages at 5 plants
Reference: Throwback Attack: WannaCry ransomware takes Renault-Nissan plants offline
Incident: Petya Ransomware Attack Affects Operations at Terminal of India’s Largest Container Port JNPT
Operations at one of the three terminals of India's largest container port JNPT (Jawaharlal Nehru Port Trust) were impacted on Tuesday night as a fallout of the global ransomware attack, which crippled some central banks and many large corporations in Europe. AP Moller-Maersk, one of the affected entities globally, operates the Gateway Terminals India (GTI) at JNPT, which has a capacity to handle 1.8 million standard container units.
Reference: Maersk Ransomware Attack
Reference: India’s largest container port JNPT hit by ransomware
Reference: TRITON Malware Used in Attacks Against Industrial Safety Equipment
Reference: Russia Behind Triton Attack: Report
Reference: TUG: Safety System Attack ‘Slow Burn’
Victim: Rabigh Refining & Petrochemical Company
Rabigh Refining & Petrochemical Company is a Saudi Arabia–based company which produces and markets refined hydrocarbon and petrochemicals. It was founded in 2005 as a joint venture between Saudi Aramco and Japan’s Sumitomo Chemical. The company was a joint venture between and which is now publicly held
Reference: AW North Carolina Hit in Ransomware Attack
Incident: Ransomware Attack at AW North Carolina Shuts down Operations for 4 Hours
The attack against AWNC started on Aug. 16, 2017, when the company’s information technology (IT) systems were infiltrated by a newer strain of ransomware. This malicious software encrypted the company’s critical data and demanded a ransom to restore access to the affected files. It ultimately shut down production lines for four hours at the 2,200-worker plant. The disruption affected not only AWNC, but also its customers as delays in the delivery of transmission components led to a ripple effect throughout the automotive supply chain.
Reference: Take down: Hackers looking to shut down factories for pay
Reference: Throwback Attack: AW North Carolina attack shows dangers of ransomware and just-in-time manufacturing
Incident: TSMC Hit by WannaCry Variant
The cyber attack on iPhone supplier TSMC was apparently caused by a WannaCry variant, the company has revealed. The severity of the attack caused the company to shut down some of its factories while the issue was fixed, which meant some plants were out of action for days. Although the problem has mostly been rectified now, it says it's still expecting shipments to be delayed for some time.
The virus was injected into TSMC's systems when a supplier reportedly installed infected software onto some of its machines, without running an antivirus scan. The infection then spread to other locations within the company's network in Tainan, Hsinchu and Taichung, which caused the majority of its facilities to close down temporarily.
The attack may have cost the iPhone component manufacturer up to 3% of revenues and could cost Apple over $255M
Reference: TSMC cyber attack was apparently caused by WannaCry
Incident: US Natural Gas Compression Facility Shut Down Entire Pipeline for 2 Days
Attackers used spear phishing to gain initial access to the IT network, then pivoted into the OT network due to poor segmentation. Then, they planted ransomware.
The attack did not impact any programmable logic controllers (PLCs) and at no point did the victim lose control of operations. Although the victim’s emergency response plan did not specifically consider cyberattacks, the decision was made to implement a deliberate and controlled shutdown to operations.
Victim: Unidentified Natural Gas Facility
Unidentified Natural Gas Facility
Reference: Ransomware Impacting Pipeline Operations
Reference: Operations at U.S. Natural Gas Facilities Disrupted by Ransomware Attack
Incident: Malware Attack Disrupts Multiple Sites of Rheinmetal AG Causing Shares to Drop
German arms and car parts maker Rheinmetall said it had been hit by a malware attack affecting production at some sites in the United States, Mexico and Brazil, sending shares down in early trade on Friday. "Normal production processes at these locations are currently experiencing significant disruption," Rheinmetall said in a statement late on Thursday.
Rheinmetall shares, which have risen around 50% since the start of this year, were indicated to open 2.9% lower in early Frankfurt trade on Friday.
Reference: Shares in Rheinmetall drop after company discloses malware attack
Reference: https://drivesncontrols.com/news/fullstory.php/aid/6191/Pilz_is_recovering_from_a__91major_92_ransomware_attack.html
Reference: Oddly specific ‘cyber attack’ hits Alaskan airline RavnAir and one plane type
Reference: oll Group shuts down IT systems in response to ‘cybersecurity incident’
Reference: Deliveries stranded across Australia as Toll confirms ransomware attack
Reference: Toyota to suspend packaging line after cyberattack on Japan port
Reference: Nagoya Port cyberattack may become security wake-up call
Incident: KHS Bicycle Shipments Delayed for 2 Days after Cyberattack
KHS Bicycles suffered an IT system hack over the weekend. KHS' vice president, Wayne D. Gray, told BRAIN Tuesday afternoon; "Our B2B site is back up and we are shipping from California today," and that the company would resume shipping from its Kentucky distribution center on Wednesday.
The company was unable to accept or ship dealer orders Monday and early Tuesday. The company was able to restore its email systems Tuesday and is working with security specialists to restore other systems as soon as possible.
Victim: KHS Bicycles
California-based distributor KHS Bicycles
Reference: KHS Bicycles resumes some shipments after system hack
Reference: Cyber attack shuts down Evraz IT systems across North America,
Incident: Large Amount of Data Leaked after at New Zealand Manufacturer Refused to Pay
Fisher & Paykel Appliances has confirmed it has fallen victim to a damaging ransomware attack. The Auckland-based whiteware manufacturer, which is owned by China's Haier, was targeted by a malware program called Nefilim. They refused to pay and they suffered a large data leak.
Victim: Fisher & Paykel Appliances
Fisher & Paykel Appliances manufacturer in New Zealand
Reference: Fisher & Paykel Appliances a victim of ransomware scourge
Incident: X-FAB Group Targeted by Cyberattack
X-FAB Group was the target of a cyber security attack. Following the advice of leading security experts engaged by X-FAB, all IT systems have been immediately halted. As an additional preventive measure, production at all six manufacturing sites has been stopped. At this stage it cannot be estimated for how long and to which degree X-FAB's operations will be disrupted. It is also too early to assess if there will be any financial impact stated company press release.
Victim: X-FAB
X-FAB manufactures slicon wafers for automotive, industrial, consumer, medical and other applications.
Reference: X-FAB Affected by Cyber Attack
Incident: Cyberattack at Israeli Tower Semiconductor Manufacturer
Cyberattack at Tower Semiconductor forced certain operations to a complete halt. Company authorities said that specific measures were taken to prevent the spread of the cyberattack, however, there was no immediate factual assessment report available that would state the real effect of the damages done.
Victim: Tower Semiconductor
Tower Semiconductor mainly manufactures integrated circuits (ICs) and provides a host of technology solutions for growing markets such as consumer, industrial, automotive, mobile, infrastructure, medical, aerospace, and defense.
It has operations spread across three different locations around the globe – two in Israel (Migdal Haemek); two in the U.S. (Newport Beach, California and San Antonio, Texas); and at three in Japan where it has partnered with Panasonic Semiconductor Solutions Co. Ltd.
It
Reference: Israel’s Tower Semiconductor Hit by a Cyberattack
Reference: Australian Steel Maker BlueScope Hit by Cyberattack
Reference: BlueScope Steel hit by cyber attack causing worldwide system shutdown of operations
Incident: Montreal’s Transit Service Hit by RansomExx Ransomware
Montreal's transit service was hit by RansomExx ransomware, and they refused to pay the $2.8 mil demanded. The Société de transport de Montréal (STM) says the attack targeted 1,000 of its 1,600 servers.
624 operationally sensitive servers were affected by the attack — but more than three-quarters of them are back within a week, except the website was still down.
The agency said the attack did not affect bus or Metro service, and that employees were able to receive their pay "almost normally." The attack did, however, stop the STM from providing adapted transit for nearly a week. That was reestablished on Sunday, a week after the attack. .
Victim: Société de transport de Montréal (STM)
Société de transport de Montréal (STM) - transit agency
Reference: The STM completes cyber attack investigation
Reference: STM says it refused hackers’ $2.8M demand in ransomware attack
Incident: Canadian Stelco Temporarily Suspended Operations
Stelco – one of Canada’s oldest and largest steelmakers – has issued a statement revealing that it was the target of a “criminal attack” on its information systems. When the cyberattack first hit, Stelco said that certain operations, which included steel production, were temporarily suspended as a precaution.
Victim: Stelco
Stelco – one of Canada’s oldest and largest steelmakers.
Reference: Stelco reveals information systems were subjected to a “criminal attack”
Incident: German Flavor Manufacturer Symrise Preventively Shut Down Operations
Flavor and fragrance developer Symrise has suffered a Clop ransomware attack where the attackers allegedly stole 500 GB of unencrypted files and encrypted close to 1,000 devices.
The cyberattack forced shut down of systems to prevent the spread of the attack.
Victim: Symrise
Symrise is a major developer of flavors and fragrances used in over 30,000 products worldwide, including those from Nestle, Coca-Cola, and Unilever. Symrise generated €3.4 billion in revenue for 2019 and employs over 10,000 people.
Reference: Hackers paralyze Symrise – why the case is particularly serious
Reference: Flavors designer Symrise halts production after Clop ransomware attack
Incident: Ransomware Attack at Forward Air
Ransomware Attack at Forward Air claimed by Hades ransomware gang impacted data exchange with customers, leading to delivery delays which impacted financial results. The company shutdown operations and delayed shipments for a week.
Threat Actor: The Hades ransomware gang
The Hades ransomware gang began operating in 2020. When encrypting a victim, it will create a ransom note named 'HOW-TO-DECRYPT-[extension].txt' that resembles notes used by the REvil ransomware group.
Victim: Forward Air
Trucking company Forward Air
Reference: News Alert: Forward Air’s systems coming back online
Reference: Trucking company Forward Air said its ransomware incident cost it $7.5 million
Reference: Forward Air reveals ransomware attack, warns of revenue hit
Reference: Palfinger attack highlights escalation in cyber crimes
Incident: JBI Bicycle Retailer Halts Shipments due to Cyberattack
Global wholesale distributor JBI back online 1 week after a ransomware attack shut down its website.
A spokesperson said on Wednesday afternoon that JBI was taking orders again in limited but shipping delays might occur because of backlogged orders. JBI has 11 warehouses and not all of them have resumed full operations. The Miami warehouse is among those operating again.JBI said then that none of its customers' business information was affected.
Victim: JBI.bike
JBI.bike, a family-owned, Florida based bike and parts distributor with a bicycle division.
Reference: JBI back online in limited capacity after ransomware attack
Incident: Swiss Drug Manufacturer Siegfried Shuts Down Production after Cyberattack
The Siegfried Group suFfered a cyber attack shortly before Pentecost. THe Swiss company shut down production at multiple sites, cut off network connections, and scoured its information technology systems. Among other things, Siegfried packages the Pfizer-BioNTech COVID-19 vaccine.
As a result of the attack, there will be certain volume and revenue shortfalls in the first half of the year. Based on the results of the forensic investigations, which are well advanced, the Siegfried Group continues to assume that no sensitive customer data were affected by the incident.
Victim: The Siegfried Group
The Siegfried Group is a global life sciences company with sites in Switzerland, Germany, Spain, France, Malta, the USA and China. In 2020, the Siegfried group achieved sales of CHF 845.1 million and currently employs approximately 3’500 people at eleven sites on three continents.
Siegfried is active in manufacturing pharmaceutical APIs (and their intermediates) as well as drug products (tablets, capsules, sterile vials, ampoules, cartridges and ointments) for the pharmaceutical industry and provides development services.
Reference: Siegfried restarts production after cyber attack
Reference: Siegfried, Brenntag, and Symrise hit by cyberattacks
Reference: Schreiber Foods hit with cyberattack; plants closed
Reference: Costa Rica: Costa Rica Customs Delays Affect Imports
Reference: Foxconn: Mexico factory operations ‘gradually returning to normal’ after ransomware attack
Victim: Hipp
German baby food manufacturer Hipp
Incident: German Battery Maker, VARTA Group, Hit in Cyberattack
Ellwangen, Germany-based VARTA Group suffered a cyber attack Monday that shut down its production plants and its administrative areas, company officials said in an advisory released Tuesday.
“Last night, February 12th 2024, the VARTA Group was the target of a cyberattack on parts of its IT systems,” the company said in an advisory.
“This affects the five production plants and the administration. The IT systems and thus also production were proactively shut down temporarily for security reasons and disconnected from the Internet. The IT systems and the extent of the impact are currently being reviewed. The utmost care is being taken to ensure data integrity,” the company said.
Reference: German Battery Maker Shut By Cyberattack
Victim: VARTA Group
VARTA manufactures batteries for global automotive, industrial, and consumer markets and Energizer Holdings owns a piece of the company. The company traces its roots back to 1887. VARTA’s annual revenue exceeds $875 million.
Incident: City of Mayen, Germany, Reports Street Light Outage Due to Cyberattack on Control Partner
Due to a cyber attack on the city of Mayen's control partner, there may be irregularities in the switch-on and switch-off times of the street lighting in the coming days. The partner is working hard on a solution.
Victim: Unidentified
unidentified
Reference: Street lighting failures in Mayen’s city center and the districts
Reference: Sellafield site compromised by foreign hackers and leaks covered up – investigation
Reference: Sellafield: Minister wants answers on alleged cyber hack
Reference: Britain says no evidence of Sellafield nuclear site hacking
Reference: Sellafield boss hits back at safety failure claims
Victim: Sellafield
Sellafield Nuclear facility is mainly used for the treatment and storage of nuclear waste. It employs 11,000 people - many of whom are engaged in maintaining or decommissioning redundant buildings and equipment.
Home to the UK's civil plutonium stockpile, with 140 tonnes of the material stored there. Security is extremely tight.
Reference: Sellafield nuclear site hacked by groups linked to Russia and China
Incident: Cyberattack at Private Company Providing Services to Canadian Military Personnel Exposes PII
A private company that assists members of the Canadian military and foreign service when they move across the country or around the world was hacked. The breach involves the personal information of Canadian government employees held by Brookfield Global Relocation Services (BGRS), whose company website has been offline since Sept. 29.
Victim: Brookfield Global Relocation Services (BGRS)
Brookfield Global Relocation Services (BGRS) is a private company that assists members of the Canadian military and foreign service when they move across the country or around the world.
Reference: Company that arranges military moves has been hacked, defense department confirms
Incident: Estonian National Rail Company Experiences Largest Operational Disruption To-date
September 20 cyber incident on Elron, Estonia's national train company, orchestrated by a pro-Russia hacker group, inflicted substantial disruptions. Targeting Ridango-managed systems, a Distributed Denial of Service (DDoS) attack paralyzed ticketing services, impacting online platforms and physical stations.
The cyberattack that began on Wednesday had a major impact on Elron ticket sales. The company has never experienced a system outage of this scale before.
By Thursday noon, the situation had returned to normal.
Reference: RIA on Elron cyberattack: It is likely that it will happen again
Reference: Elron ticket service back online after DDoS attacks from Russia supporters
Victim: Elron
Elron, Estonia's national train company
Reference: Cyber attack brought Elron ticketing system down Wednesday
Incident: Ransomware Attack at Unidentified Bavarian Wood Processing Manufacturer
A wood processing company in Deggendorf, Germany, encountered a ransomware attack. Unknown perpetrators managed to encrypt several of the company's servers by installing malware. This meant that working in emergency mode was only possible for a short period of time. Since the company did not contact the perpetrators, no demands for money have been reported so far. A swift law enforcement response and deployment of backups facilitated system recovery.
Reference: Hacker attack on company in Deggendorf district: malware installed [machine translated]
Reference: Lower Bavaria: Digital attack on company [machine translated]
Incident: Ransomware attack at Unidentified Bavarian Manufacturer
Deployment of a quick reaction team from the Deggendorf Police Department was necessary because a company in the digital manufacturing sector fell victim to a cyber attack.
Ransomware (malicious software) had been installed on one of the company computers. A possible decryption was promised after a ransom was paid in the form of Bitcoins. No contact was made. The affected company was able to rely on existing data backups. The company suffered no financial damage. It is unknown if there were any operational consequences as further details were not disclosed.
Victim: Undisclosed – manufacturing sector
Undisclosed - manufacturing sector
Reference: Lower Bavaria: Malware installed on company computers – deployment of a quick reaction team
Incident: NoName DDoS Attacks on Port Authorities Throughout Canada
NoName is targeting key port authorities throughout Canada: the Port of Nanaimo, Port de Saguenay, Trois-Rivières Port Authority, and the Port of Belledune.Port of Nanaimo, Port de Saguenay, Trois-Rivières Port Authority, and the Port of Belledune. The incident has raised serious concerns about the potential impact on operations and security of sensitive information as all are essential gateways to Canadian transportation and shipping routes.
In April 2023, the Port of Halifax in Nova Scotia and the Ports of Montreal and Québec were targeted by a ‘denial-of-service attack’ that flooded their websites with traffic, causing them to crash.
Victim: Port of Nanaimo
Port of Nanaimo, located on Vancouver Island in British Columbia, is a vital Canadian regional transportation hub.
Victim: Port of Belledune
an essential gateway for international trade in New Brunswick Canada
Victim: Trois-Rivières Port Authority
Trois-Rivières Port Authority in Canada is an important port facility connecting the Saint Lawrence River to major shipping routes.
Victim: Port de Saguenay
Port de Saguenay in Quebec is crucial in facilitating Canadian international trade and transportation.
Reference: NoName Targets Canada, Port Authorities Under Cyber Attack
Incident: Ransomware Attack at Billstein, German Car Parts Manufacturing, Group.
The BianLian ransomware gang has added the Bilstein Group to its list of victims. At the end of April, 60 GB of internal company data appeared on the dark web, as can be seen on the monitoring site ransomware.live . This includes human resources, accounting and financial data. The auto parts specialist confirmed to CSO that there had been a recent cyber attack. “However, this was quickly discovered by our systems and IT specialists, so the impact was marginal,” explained a spokesman. The company did not want to release any further information about the case. It is not known whether there was a blackmail letter demanding a ransom.
Victim: Billstein Group
Billstein Group is a supplier and manufacturer of car and commercial vehicle replacement parts.
Reference: German car spare parts specialist Bilstein hacked
Reference: Data from Lux Automation on the Darknet
Victim: Lux Automation
Safety technology for machines and plants
Incident: Ransomware Attack at Pierce Transit System
A ransomware "incident" hit Pierce Transit. A Pierce Transit spokesperson stated the agency "experienced a ransomware incident that temporarily disrupted some agency systems. Upon discovering the incident, our team immediately took action to contain and isolate the threat. Third party forensic experts were engaged to conduct a thorough investigation into the nature and scope of the incident, and law enforcement has been notified.” They claim that transit operations and rider safety were not impacted because of the incident.
The Pierce Transit spokesperson went on to say that an "unauthorized actor" has claimed responsibility and that the investigation into the disruption is ongoing.
Reference: Pierce County agencies investigating potential ransomware attacks
Incident: Cyberattack at Canadian Engineering Giant Contracted for Government Military, Power and Transportation Projects.
A Canadian engineering giant whose work involves critical military, power and transportation infrastructure across the country has been hit with a ransomware attack. Details about the ransomware attack are scarce, with Black & McDonald refusing even to confirm it happened.
Canada’s defense department confirmed Thursday that its systems were not affected by a ransomware attack on engineering giant Black & McDonald. "Once DCC was informed of the incident, it blocked all incoming emails from Black & McDonald out of an abundance of caution and conducted business by phone or in person," Department of National Defense spokeswoman Jessica Lamirande said in a statement. "Once the contractor restored its email system and informed DCC, email communication resumed."
Black & McDonald also has contracts with the Toronto Transit Commission and Ontario Power Generation — both of which told The Canadian Press they were informed by the company about the ransomware incident.
Victim: Black & McDonald
Black & McDonald is the parent company of Canadian Base Operators, which holds several contracts with the Department of National Defense for facilities management and logistical support services.
Reference: Canadian military: Ransomware attack on contractor didn’t touch defense systems
Reference: Cyber attack hits engineering giant with contracts for military bases, power plants
Malware: CryptoLocker
CryptoLocker is a Trojan horse that infects your computer and then searches for files to encrypt. This includes anything on your hard drives and all connected media — for example, USB memory sticks or any shared network drives. In addition, the malware seeks out files and folders you store in the cloud. Only computers running a version of Windows are susceptible to Cryptolocker; the Trojan does not target Macs.
Incident: Ransomware Attack at Black and White Taxi Service in Australia
A cyber attack on Black and White Cabs has shut down the company's phone and online booking system. Suspicious activity was detected by staff and a "serious threat" to the company was determined in the afternoon. Black and White Cabs has confirmed that a CryptoLocker virus has infiltrated its network security, and it has reported the attack to the Australian Cyber Security Centre. The company was unable to computer dispatch bookings and took all booking portals down in the interest of protecting our passengers, drivers and staff. Drivers were still completing street work (hail & rank) and private bookings.
Reference: Passenger Information
Victim: Black and White Cabs
Black and White Cabs
Reference: Black and White Cabs booking service offline after cyber attack
Incident: Cyberattack Distrupts Costa Rica Transportation Systems
Costa Rica’s Ministry of Public Works and Transport (MOPT) called in Cybersecurity experts from the National Security Directorate and the Ministry of Science, Innovation, Technology and Telecommunications to address the situation that 12 servers were encrypted and all of MOPT’s computer systems were knocked offline. The government did not respond to request for more information but stated that international organizations were brought in for support.
Driving tests are still being conducted in person and while license issuance services were briefly disrupted, they are now being resumed.
Victim: Costa Rica’s Ministry of Public Works and Transport (MOPT)
Costa Rica’s Ministry of Public Works and Transport (MOPT)
Reference: Costa Rica’s Ministry of Public Works and Transport crippled by ransomware attack
Incident: Data Breach at Fresh Del Monte Produce Exposed Employee Data
On May 16, 2023, Fresh Del Monte Produce, Inc. filed a notice of data breach with the Attorney General of Massachusetts after learning that confidential employee information was subject to unauthorized access following a cyberattack. According to the filing, an unauthorized user gained access to the company’s computer network. The breach exposed confidential employee information containing consumer information including names, Social Security numbers, driver’s license numbers, passport numbers, financial account information, and protected health information.
Fresh del Monte believes that no consumer data was leaked as a result of the incident. The company launched an investigation and took its systems offline in an effort to limit further access.
Victim: Fresh Del Monte Produce, Inc.
Fresh Del Monte Produce, Inc. is a global fruit and vegetable company based in Coral Gables, Florida. The company produces, markets and distributes fresh fruits and vegetables, as well as a line of as well as prepared fruit & vegetables, juices, beverages, snacks, and desserts. Fresh Del Monte Produce employs more than 40,000 people and generates approximately $4.4 billion in annual revenue.
Reference: Data breach affected Fresh del Monte’s employees’ information
Reference: Electronic health record giant NextGen dealing with cyberattack
Reference: Fresh Del Monte Produce Notifies Employees of Recent Data Breach
Incident: Japanese Manufacturer Fujikura Global Hacked by Lockbit Gang.
The hacker group LockBit 3.0 has claimed Fujikura Global, the Japanese manufacturer of electrical and electronic products company, as its victim. A company issued press release confirms the attack: "We have confirmed that our group company in the Kingdom of Thailand received unauthorized access to its network by a third party on January 12, 2023."
The threat actor claimed to have breached the corporate headquarters of the Japanese company and infiltrated each of its far-flung outposts around the world. The hacker group claims that the compromised data consists of a staggering 718GB of confidential and critical information pilfered from the company’s digital infrastructure. The purloined data encompasses a vast array of valuable assets, such as financial records, internal reports, certificates, correspondence, extensive internal documentation, tables, employee personal information, and much more.
Victim: Fujikura Global
Fujikura Global is a Japanese manufacturer of electrical and electronic products.
Reference: LockBit Group Lists Japanese Company Fujikura Global as Latest Victim
Reference: Unauthorized Access to our Group Company in the Kingdom of Thailand [machine translated]
Incident: Significant Electrical Malfunctions at Draguignan Prison Center
Since Wednesday January 11, the remand center has been plagued by computer difficulties which have caused significant electrical malfunctions. A computer virus is expected to have sowed discord and caused numerous malfunctions. To monitor the inmates, management called on intervention teams while waiting for the cameras to be put back into operation. [machine translated].
Reference: Draguignan prison victim of a computer virus
Victim: Centre pénitentiaire de Draguignan
Centre pénitentiaire de Draguignan, - prison facility in France
Incident: Czech Railways Website and App Hacked
The website and application of the state railway carrier České dráhy were attacked by hackers. The website and the booking application may therefore be unavailable according to the carrier. Passengers will be checked in without surcharge. The spokeswoman did not want to give details about the beginning of the attack and the type of attack for security reasons. [machine translated].
Victim: České dráhy – Czech Railways
Czech state railway carrier České dráhy
Reference: Czech Railways is facing a hacker attack. The My Train website and app are down
Incident: Crystal Manufacturer Baccarat S.A Experienced Cyberattack on Undisclosed Data
Baccarat S.A., the renowned crystal manufacturer, experienced a cyberattack on an undisclosed date, causing partial operational disruption. While the impact on production remains uncertain, Baccarat reassured clients of no compromised personal data. The company, proactive in communication, urged clients to report suspicious messages.
Victim: Baccarat S.A
Baccarat S.A., the renowned crystal manufacturer in France
Reference: BACCARAT VICTIM OF CYBER ATTACK
Reference: Meurthe-et-Moselle: the Baccarat crystal factory victim of a cyberattack
Reference: GO train, UP Express service resumes with ‘minimal disruptions’ after major outage
Incident: Phishing Incident at Major Mexican Airport
The Querétaro Intercontinental Airport is responding to a cyberattack. The airport is one of the highest-traffic airports in Mexico, situated about three hours from Mexico City. Reports confirm that it had been attacked by hackers. A notice on social media sites states it had called in experts to help address the issue. On Monday, the LockBit ransomware gang took credit for the attack, threatening to leak the data on November 27.
“We reported that we had a cyberattack incident and are working with experts to address this situation. AIQ systems are operating normally. The safety of our passengers and operations remains our top priority,” the airport said, according to a translation of the notice, posted Tuesday.
Officials said the cyberattack was traced back to an employee downloading a file containing malware.
Victim: Querétaro Intercontinental Airport
Querétaro Intercontinental Airport, Mexico. Over the last decade, Querétaro Intercontinental has become one of the busiest airports in Mexico, serving more than 1.1 million passengers in 2022 and becoming a hub for cargo flights within Mexico and to the U.S. and Europe.
Reference: Major Mexican airport confirms experts are working to address cyberattack
Reference: Japan space agency hit with cyberattack, no sensitive info accessed
Incident: Japan’s Space Agency (JAXA) Hit by Cyberattack
Japan's space agency was hit by cyberattacks even as hackers failed to access sensitive information about rockets and satellite operations, a spokesperson revealed Wednesday (Nov 29). “There was a possibility of unauthorized access by exploiting the vulnerability of network equipment,” the spokesperson at Japan Aerospace Exploration Agency (JAXA) was quoted as saying by Reuters. However, the official declined to elaborate on details, such as when did the attack take place.
JAXA got to know about the attack after an external organisation conducted an internal audit, as per the spokesperson.
In August, China-backed hackers were held responsible by Japan for a months-long cyberattack campaign, in which Japan’s National Center of Incident Readiness and Strategy for Cybersecurity (NISC) was targeted.
A spokesperson for the JAXA said a detailed investigation is going on into the hacking attempt and it was not revealed who could be orchestrating this.
Reference: Japanese space agency JAXA hit by cyberattack amid hacking spree by China
Reference: Japanese space agency JAXA hit with cyberattack
Victim: Japan Aerospace Exploration Agency (JAXA)
Japan Aerospace Exploration Agency (JAXA)
Reference: Cyberattack Hits German Battery Maker Varta, Halts Production
Reference: German battery maker Varta says five plants hit by cyberattack
Reference: “Take any vulnerability very seriously”: Car manufacturers are on the alert after Conti data theft
Incident: Ransomware Attack at Large Indian Paint Manufacturer, Kansai Nerolac.
Kansai Nerolac Ltd., among India's largest paint manufacturing companies, reported a ransomware incident. In a statement to exchanges, Kansai Nerolac informed that a cyberattack occurred on Sunday, wherein the company’s IT infrastructure was targeted by a ransomware attack. “This has affected a few systems. We would like to assure you that the technical team of the company along with a specialised team of cybersecurity experts and the management responded promptly and initiated necessary precautions and protocols to mitigate the impact of this incident,” the statement read.
Victim: Kansai Nerolac Ltd.
Kansai Nerolac Ltd. is among India's largest paint manufacturing companies
Reference: Kansai Nerolac Reports Ransomware Incident on Sunday
Reference: Kansai Nerolac reports ransomware indicent on Sunday, financial impact undisclosed
Reference: ROBOVIC Dataleak
Reference: Ransomware Victim ROBOVIC
Victim: Nobiskrug
Nobiskrug is a shipyard located on the Eider River in Rendsburg, Germany, specialized in building innovative, custom-made luxury superyachts.
Victim: Flensburger Schiffbau-Gesellschaft (FSG)
Flensburger Schiffbau-Gesellschaft is a German shipbuilding company located in Flensburg. The company trades as Flensburger and is commonly abbreviated FSG.
Reference: Cyber attack on the Flensburger Schiffbau-Gesellschaft and Nobiskrug shipyard
Reference: Cyber attack on FSG and Nobiskrug shipyards
Reference: Cyber attack on the Flensburg shipbuilding company
Reference: Claim a Canadian energy company was target of Russian cyberattack highlights our vulnerability, but could just be fake
Reference: Leaked Pentagon Document Claims Russian Hacktivists Breached Canadian Gas Pipeline Company
Incident: Websits of 7 German Airports simultaneously Hit by Cyberattack
The websites of seven airports were hit by a suspected cyberattack. Among the airports affected by a “large-scale DDoS [distributed denial-of-service] attack” on Thursday were Dusseldorf, Nuremberg, Erfurt-Weimar and Dortmund, according to Ralph Beisel, chief executive of the ADV airport association.
A group calling itself “Anonymous Russia” took responsibility for cyberattacks on German airports. “Germany has non-flying weather again,” the hackers said on Telegram alongside a list of their alleged victims.
Reference: Scandinavian Airlines hit by cyberattack, ‘Anonymous Sudan’ claims responsibility
Reference: German airports hit by DDoS attack, ‘Anonymous Russia’ claims responsibility
Incident: Cyberattack at Leading Building Management Co. GEZE Raises Product Integrity Concerns
GEZE, a leading building management company, cyberattack targeted core offerings, including automatic door and window solutions, raising concerns about product integrity and safety features.
The company website statement [sinds removed] stated : "Our systems were exposed to a cyber attack. We have decided to shut down our system landscape preventively and to start a controlled, step-by-step reconstruction. Therefore, we are unfortunately not available at the moment and ask for your understanding. We are making every effort to restore our systems as quickly and securely as possible."
Reference: GEZE IT Security statement [web.archive.org]
Victim: GEZE
a leading building management company headquartered in Germany
Reference: 35 years and counting for GEZE [mentions the cyberattack]
Reference: Cyber Incident Victim: Geze (GEZE)
Reference: Colipays: after the cyberattack, reimbursement of injured customers will take longe
Reference: Colipays victim of a cyberattack, customers never received their package
Incident: Sandworm Linked Group Sabotages Major Ukrainian Communications Provider Affecting Millions of Customers
A hacker group calling itself Solntsepek—previously linked to Russia’s notorious Sandworm hackers - is responsible for sabotaging Kyivstar, a major Ukrainian mobile and internet provider, cutting off communications for millions and even temporarily sabotaging the air raid warning system in the capital of Kyiv.
Victim: Kyivstar
Kyivstar, one of Ukraine's largest mobile and internet providers
Reference: Hacker Group Linked to Russian Military Claims Credit for Cyberattack on Ukrainian Telecom
Reference: Staples Confirmes Cybersecurity Risk Disrupting Online Stores
Incident: Cyberattack at Staples Disrupts Internal Operations.
American office supply retailer Staples took some of its systems down to contain impact of a cybersecurity attack and protect customer data. Staples confirmed that it was forced to take protective action to mitigate what it described as a "cybersecurity risk." The response measures disrupted backend processing and product delivery.
In March 2023, Staples-owned distributor Essendant also experienced a multi-day outage that prevented customers and suppliers from placing or fulfilling online orders.
Victim: Staples
American office supply retailer Staples operates 994 stores in the US and Canada, along with 40 fulfillment centers for nationwide product storage and dispatch.
Reference: Staples confirms cyberattack behind service outages, delivery issues
Incident: Japanese Global Lingerie Producer, Wacoal, Hit by Cyberattack
The European arm of the Japanese lingerie business Wacoal had been hit by a cyber attack affecting ordering systems, websites and phone systems.
Its websites being taken offline and indie stockists being unable to place orders.
Reference: Wacoal hit by cyber attack
Victim: Lingerie group Wacoal
Japanese Lingerie group Wacoal (includes brands Fantasie, Freya and Elomi)
Incident: Ransomware Attack at Canadian Weather Network
Ransomware hit the Weather Network’s parent company Pelmorex Corp. taking out many of its website and app services. Many critical functions were impaired or shutdown, impacting English, French and Spanish services in North America. Ransomware was not paid.
Victim: Perlmorex Corp
Perlmorex Corp operates Canada's Alert Ready emergency warning system, the Weather Network app and website, as well as the French-language version Méteomédia
Reference: The Weather Network working on restoring service after cybersecurity incident
Reference: Weather Network says ransomware attack caused website and app outages in September
Incident: DDoS Attack Severely Distrupts Norwegian Data Protection Authority Datatilsynet
In September 2023, Norwegian Data Protection Authority Datatilsynet suffered a severe disruption when their website fell victim to a Distributed Denial of Service (DDoS) attack. Attributed to the Russian group NoName057(16), the incident caused physical damage, stressing hardware to the point of failure, emphasizing an unusual level of attack sophistication.
Victim: Datatilsynet
Norwegian Data Protection Authority Datatilsynet
Reference: Cyber Incident Victim: Datatilsynet
Reference: The Norwegian Data Protection Authority’s website shut down by a Russian hacker attack: Several authorities affected
Incident: Two Major NY Hospitals Struggle to Recover from Lockbit Cyberattack
Two major hospitals serving thousands in upstate New York are struggling to recover from cyberattacks that were announced last week.
The two facilities, Carthage Area Hospital and Claxton-Hepburn Medical Center, serve an area with more than 200,000 people in Jefferson, Lewis and St. Lawrence Counties. For two weeks, the hospitals have been dealing with a cybersecurity incident that forced them to divert ambulances to other local hospitals and reschedule most appointments.
Richard Duvall, chief executive officer of both hospitals, said "no demand for a ransom has been made."
Victim: NY’s Carthage Area Hospital & Claxton-Hepburn Medical Center
Carthage Area Hospital and Claxton-Hepburn Medical Center, serve an area with more than 200,000 people in Jefferson, Lewis and St. Lawrence Counties.
Reference: Carthage, Claxton-Hepburn hospitals target of cyber attack
Reference: Upstate New York nonprofit hospitals still facing issues after LockBit ransomware attack
Incident: Ransomware Attack at Russian Medical Laboratory
Customers of the Russian medical laboratory Helix have been unable to receive their test results for several days due to a “serious” cyberattack that crippled the company's systems over the weekend. According to a statement the lab issued Monday, hackers attempted to infect the company's systems with ransomware.
Victim: Helix, Russian medical laboratory
Russian medical laboratory Helix
Reference: Russian medical lab suspends some services after ransomware attack
Incident: USA’s ASPR issues Alert as Ransomware Gang Attacks Cancer Centers.
An attack against a US cancer center in June 2023 rendered digital services unavailable, limiting the center’s patient care capabilities.The group calling itself TimisoaraHackerTeam (THT), is not widely known but it has a history of attacking medical facilities by exploiting known vulnerabilities and using a living-off-the-land approach to minimize detection.
ASPR Healthcare and Public Health Sector issued a Cybersecurity Notification and warning on June 16, 2023: “Even among hackers, there is often a code of conduct not to attack hospitals or other HPH organizations that could cause physical harm,” HHS stated. “However, in their purposeful targeting of the healthcare sector, groups like THT abstain from that moral code.”
Threat Actor: TimisoaraHackerTeam (THT)
THT is named after a Romanian town, and its source code also appears to have been produced by Romanian speakers. Researchers have not yet determined which overarching family the THT ransomware group belongs to.
Researchers discovered the group in July 2018, when it surfaced with its characteristic tactic of abusing legitimate tools such as Microsoft Bitlocker, rather than developing its own tools to encrypt victim files. What is known, however, is that the group is not against targeting hospitals.
Reference: ASPR Healthcare and Public Health Sector Cybersecurity Notification June 16, 2023
Reference: Ransomware gang preys on cancer centers, triggers alert
Reference: TimisoaraHackerTeam Ransomware Attacks US Cancer Center
Incident: Cyberattack Takes German University IT Systems Offline
The Kaiserslautern University of Applied Sciences (HS Kaiserslautern) was hit by a ransomware attack, following incidents affecting at least half a dozen similar institutions in recent months. The incident was confirmed on Friday, with the university using an emergency website to announce its “entire IT infrastructure” had been taken offline, including university email accounts and the telephone system.
Almost every facility and service available to the institution’s more than 6,200 students has been affected. Computer pools and even the library will “remain closed until further notice,” the university stated.
Victim: Kaiserslautern University of Applied Sciences
Kaiserslautern University of Applied Sciences (HS Kaiserslautern), Germany
Reference: Cyberattack on German university takes ‘entire IT infrastructure’ offline
Incident: Ransomware Attack Shuts Down 14 Canadian Gateway Casinos for Two Weeks
Canada’s Gateway Casinos & Entertainment Ltd. has officially confirmed that the company has been the subject of a cyberattack. All 14 of the company’s casinos in the province of Ontario were shut down. The casinos were hit with a ransomware attack that reportedly created an IT outage. Gateway Casinos started reopening on April 29.
Reference: Cyberattack – 14 Canadian Casinos Shut Down Since April 16
Reference: Gateway Casinos ransomware attack highlights need for better cybersecurity, says analyst
Incident: Server Outage at Telecom DOCOMO Pacific
The largest provider of mobile, television, internet and telephone services to the U.S. territories of Guam and the Northern Mariana Islands is slowly recovering from a cyberattack that brought down many of its services. The outages started on Thursday evening, and by Friday Docomo Pacific CEO Roderick Boss confirmed that the company’s servers were attacked “Early this morning, a cyber security incident occurred and some of our servers were attacked ... affected servers shut down to isolate the intrusion,” Boss explained in a statement.
“DOCOMO PACIFIC's customer data, mobile network services, and fiber services remain unaffected, protected, and secure at this time. We are working to restore service as soon as possible.
Reference: DOCOMO PACIFIC responds to multiple service outage
Reference: Largest telecom in Guam starts restoring services after cyberattack
Victim: DOCOMO PACIFIC
DOCOMO PACIFIC, Guam based regional leader in innovation, telecommunications, & entertainment. DOCOMO PACIFIC is a wholly owned subsidiary of NTT DOCOMO, Japan's leading mobile operator.
Incident: Ransomhouse Extortion Group Paralyzes Barcelona Hospital Operations.
A cyberattack has targeted one of Barcelona’s leading hospitals, shutting down its computer system and forcing the cancellation of 150 non-urgent operations and up to 3000 patient checkups. The hospital's SAP system wasn't impacted, but all applications and communications remain broken as work to restore critical systems continues. This means that patient information for physicians is out of reach, and the situation impacts care services.
In addition to the cancellations mentioned above, the hospital delayed 800 urgent cases and diverted patients to other hospitals.
Victim: Hospital Clínic de Barcelona
Hospital Clínic de Barcelona is a 819-bed hospital is based in Barcelona, Spain, and serves over half a million people seeking medical attention and healthcare services.
Reference: Ransomware Attack Against Barcelona Hospital Disrupts Operations
Reference: Hospital Clínic de Barcelona severely impacted by ransomware attack
Incident: Lockbit Ransomware Attack at Office Supply Distributor Essendant
A systems outage at Essendant is preventing the placement or fulfillment of online orders, thereby impacting both the company's customers and suppliers. Freight carriers have also been told to hold off on any pick-ups until further notice. Essendant continues to make its recovery efforts. During this time, customers will not be able to place orders or contact Essendant's customer care. The company’s statement acknowledges a threat actor publicly claimed responsibility for the cyberattack, but the validity of these claims has not been officially confirmed yet.
Essendant stocks over 160,000 types BleepingComputer reached out to Staples and Essendant with questions but we were not provided with any additional information of items serving approximately 30,000 reseller customers. The systems outage is therefore likely to have a widespread impact on the supply chain.
Victim: Essendant
Essendant, a wholesale distributor of stationery and office supplies is a Staples-owned company, formerly known as United Stationers.
Essendant generates over $5.4 billion in annual revenue and employs more than 6,400 people. Headquartered in Deerfield, Illinois, Essendant also operates in Dubai, UAE.
Reference: Office Supplies Giant Essendant Was Hit by Ransomware
Reference: LockBit ransomware attacks Essendant
Reference: Staples-owned Essendant facing multi-day “outage,” orders frozen
Incident: Ransomware Attack on Thousands of VMware ESXi Servers
A vast ransomware infection campaign hits VMware ESXi servers around the world on February 3. The scale suggests an automated operation.
Admins, hosting providers, and the French Computer Emergency Response Team (CERT-FR) warn that attackers actively target VMware ESXi servers unpatched against a two-year-old remote code execution vulnerability to deploy a new ESXiArgs ransomware. Tracked as CVE-2021-21974, the security flaw is caused by a heap overflow issue in the OpenSLP service that can be exploited by unauthenticated threat actors in low-complexity attacks.
While the threat actors behind this attack claim to have stolen data, one victim reported in the BleepingComputer forums that it was not the case in their incident. Victims have also found ransom notes named "ransom.html" and "How to Restore Your Files.html" on locked systems. Others said that their notes are plaintext files.
Threat Actor: Nevada Ransomware Operation
(Feb'23): A relatively new ransomware operation known as Nevada seems to grow its capabilities quickly as security researchers noticed improved functionality for the locker targeting Windows and VMware ESXi systems.
Nevada ransomware started to be promoted on the RAMP darknet forums on December 10, 2022, inviting Russian and Chinese-speaking cybercriminals to join it for an 85% cut from paid ransoms. For those affiliates who bring in a lot of victims, Nevada say they will increase their revenue share to 90%.
RAMP has been previously reported as a space where Russian and Chinese hackers promote their cybercrime operations or to communicate with peers.
Reference: Ransomware: thousands of VMware ESXi servers caught in vast campaign
Reference: Massive ESXiArgs ransomware attack targets VMware ESXi servers worldwide
Reference: Caribbean island of Martinique dealing with cyberattack that disrupted government services
Incident: Cyberattack Upended New Flag Voting Process in Martinique
A quest to select the first official flag and hymn for the French Caribbean island of Martinique was interrupted Wednesday by a cyberattack. The attack on government servers upended a nearly two-week online voting window that began on Jan. 2. Officials said the attack was not successful but forced them to temporarily shut down the system. They did not say when voting would resume.
Reference: Flag and anthem: the CTM suspended votes due to a security breach
Reference: Cyberattack halts Martinique’s search for new flag, hymn
Incident: Ransomware Attack at Slovenian Power Company HSE
Slovenian power company Holding Slovenske Elektrarne (HSE) has suffered a ransomware attack that compromised its systems and encrypted files, yet the company says the incident did not disrupt electric power production. HSE is Slovenia's largest power generation company, accounting for roughly 60% of domestic production, and it is considered critical infrastructure in the country. No ransom demand has been received.
The attack did affect the company’s communication and information infrastructure and, according to Slovenian news outlet 24ur, the websites of some of the power plants were temporarily inaccessible. Unofficial information shared with local media attributes the attack to the Rhysida ransomware gang. If Rhysida is behind the attack, it would also explain why HSE is stating they did not receive a ransom demand, as Rhysida ransom notes only contain an email address to contact the threat actors without specifying any monetary demands.
Reference: Slovenian power company hit by ransomware
Victim: Holding Slovenske Elektrarne (HSE)
Slovenian power generation company Holding Slovenske Elektrarne (HSE)
Reference: Slovenia’s largest power provider HSE hit by ransomware attack
Incident: Targeted Cyberattack on Ukranian Critical Energy Infrastructure Facility
The Computer Emergency Response Team of Ukraine (CERT-UA) recorded on Tuesday a targeted cyber attack against a critical energy infrastructure facility in the country. The advisory added that the described activity is carried out by the Russian state-sponsored APT28 hacker group. The agency confirmed that they were able to prevent any intrusion.
Threat Actor: APT28
APT28 does not appear to conduct widespread intellectual property theft for economic gain. Instead, APT28 focuses on collecting intelligence that would be most useful to a government. Specifically, FireEye found that since at least 2007, APT28 has been targeting privileged information related to governments, militaries, and security organizations that would likely benefit the Russian government.
Reference: APT28 cyberattack: msedge as a bootloader, TOR and mockbin.org/website.hook services as a control center (CERT-UA#7469)
Reference: Ukraine’s CERT discloses cyberattack on critical energy infrastructure by APT28 hacker group
Incident: Russian Cyberattack Targets Water and Gas Utility Meter Manufacturer in Ukraine
Illia Vitiuk, head of the cyber department at the Security Service of Ukraine (SBU), when asked in an interview for a recent example of attacks Russia has carried out during the war, gave a previously undisclosed real-world example. He said Russia targeted a water and gas utility meter manufacturer in a supply chain attack. The Security Service of Ukraine (SBU) was able to stop the supply chain attack from real-world consequences.
SBU went on to explain this was targeted at telemetry equipment that could see and measure the consumption of water or gas. They penetrated the company as a new update was about to come out. With this update, they wanted to penetrate these systems [a kind of supply chain hack similar to the SolarWinds hack in 2019].
Reference: Exclusive: How a defend-forward operation gave Ukraine’s SBU an edge over Russia
Incident: Ukrainian Online Surveillance Cameras Allegedly Hacked by Russia to Carry Out Deadly Drone Attacks
Ukraine’s security officers said they took down two online surveillance cameras that were allegedly hacked by Russia to spy on air defense forces and critical infrastructure in Ukraine’s capital, Kyiv.
The cameras were installed on residential buildings in Kyiv and were initially used by residents to monitor the surrounding area and parking lot. After hacking them, the Russian intelligence services supposedly gained remote access to the cameras, changed their viewing angles, and connected them to YouTube to stream sensitive footage.
According to Ukraine’s security service, SBU, this footage likely helped Russians direct drones and missiles toward Kyiv during a large-scale missile strike against Ukraine on Tuesday. During the attack, Russia fired almost 100 drones and missiles, primarily targeting Kyiv and Kharkiv, Ukraine’s second-largest city. At least 5 people were killed, and 129 were injured.
Since Russia invaded Ukraine in February 2022, the SBU said it has blocked about 10,000 digital security cameras that Moscow might have used to prepare for missile strikes on Ukraine.
Victim: Ukraine’s security service, SBU
Ukraine’s security service, SBU
Reference: Ukraine says Russia hacked web cameras to spy on targets in Kyiv
Incident: Cyberattack at Yusen Logistics, partner of Big Kitchen Manufacturers, Spells Delays for Applicance Retailers
BlackCat/ALPHV posted Yusen Logistics to its data leak site on September 25th, claiming to have stolen 90GB of company information. Yusen has confirmed that on Sunday, September 17 it was the victim of a malicious attack and is working all relevant stakeholder to keep them informed. Home appliance retailer BSH, a Yusen partner in the UK, also confirmed they were impacted.
BlackCat made no mention of leaking the data, suggesting a ransom could have been paid.
Reference: Appliance supplier confirms delays due to cyber-attack
Reference: Appliance delivery woes return for big brands as tech glitch hits logistics partner
Victim: Yusen Logistics
Founded in 1955, Yusen Logistics is a global supply chain logistics company that provides ocean and air freight forwarding, warehousing, distribution services, and supply chain management – a seamlessly connected suite of supply chain solutions that delivers superior value, reliability, and expertise.
Incident: Iranian Petrol Stations Hit by Cyberattack
Iran has accused a hacking group with alleged ties to Israel of carrying out a cyber attack that resulted in service disruptions at petrol stations throughout the country on Monday. The Israeli hacker group Gonjeshke Darande or Predatory Sparrow also claimed responsibility for hacking Iran’s gas stations. Iran’s oil minister, Javad Owji, confirmed that a cyberattack was responsible for the widespread disruption of petrol stations nationwide, and that services had been disrupted at about 70% of Iran’s petrol stations.
Incident: Snatch Claims it Breached Hemeria Group, partner of the French Space Agency CNES
The Snatch ransomware group has claimed in a post on February 17, 2023, that it has breached the systems of Hemeria Group, a partner of defense and space systems maker of the French Space Agency CNES in 2022. According to the leak site post, the operators of Snatch state they initiated talks with the Palace of Versailles to maintain caution because the company data is considered a state secret.
Cybersecurity researchers have posted about the Hemeria Group data breach with screenshots from the ransomware group’s post.
Hemeria management replied by denying having anything to do with the data that Snatch had. The firm also did not seem to be affected by the data breach news.
Reference: Reactions to cyberattack on Iran’s fuel system
Reference: Iranian petrol stations hit by cyber attack allegedly linked to Israeli hacker group
Reference: Iran petrol stations hit by cyberattack, oil minister says
Reference: Israel-linked group claims cyberattack that shut down 70% of Iran’s gas stations
Incident: Large Canadian Book Distributor Suspends Operations after Cyberattack
Socadis, one of the largest book distributors in Quebec, was forced to suspend “all of its activities” due to a cybersecurity problem that occurred last Sunday.
The problem affects all of its communication systems, rendered “inaccessible”. “We cannot take any orders,” the company said. “The business is temporarily closed,” she posted on her Facebook page on Tuesday. In an update Wednesday, it said its "operations are still at a standstill" and that the business would remain closed "until further notice."
Victim: Socadis
Socadis, one of the largest book distributors in Quebec distributes in particular the works of the publishing houses Flammarion, Fides and La Pastèque.
Reference: A cyberattack would paralyze an important link in Quebec books
Reference: The activities of the book distributor Socadis on pause
Incident: Polish Train Builder Denies Sabotaging PLC Code to Lock In Repair Services, Claims Being Hacked.
After a rail maintenance service provider won a contract to maintain rolling stock manufactured by Newag, they soon discovered that the rolling stock would stop operating for no apparent reason. After hiring a third party consulting group, they discovered deliberate code in the firmware designed to "brick" or disable rolling stock if it had been maintained in certain locations or conditions not under the supervision of the original manufacturer.
Dieselgate? Newag denied this, suggesting they were the victim of a cyber attack. However, there is no evidence to back up that claim, and instead all evidence points to the vendor deliberately sabotaging their own firmware code in manufactured products to enforce vendor maintenance and repair lock-in and unfairly disadvantage their competition.
"We found that the PLC [programmable logic controller] code actually contained logic that would lock up the train with bogus error codes after some date, or if the train wasn't running for a given time," Bazański wrote. "One version of the controller actually contained GPS coordinates to contain the behavior to third-party workshops."
Reference: Dieselgate, but for trains – some heavyweight hardware hacking
Reference: Polish train maker denies claims its software bricked rolling stock maintained by competitor
Incident: Pro-Iran Hackers Cut Water Supply for 2 Days in Remote Irish Town
Cyberattack on Irish water utility, Erris, leaves 180 homeowners without water for 2 days after the extraordinary incident impacted the Eurotronics Israeli-made water pumping system. The hackers stated the equipment was targeted due to the fact it originated in Israel.
Erris Water stated they did not have the budget for firewalls and were unable to recover operations, struggling to bypass the pump to run manually, leading to the two day outage.
Victim: Private Water Services serving Erris, Ireland
Private Water Services serving Erris, Ireland
Reference: Two-day water outage in remote Irish region caused by pro-Iran hackers
Reference: Cyberattack on Irish Utility Cuts Off Water Supply for Two Days
Reference: Hackers hit Erris water in stance over Israel
Incident: Wide concern over GPS spoofing incidents, previously thought to be impossible, in Middle East,
OPSGroup reports: since first discovered, additional distinct spoofing scenarios have been reported by flight crews:
= A Gulfstream G650 experienced full nav failure on departure from LLBG/Tel Aviv (25 Oct). The crew reports, “ATC advised we were off course and provided vectors. Within a few minutes our EPU was 99.0, FMS, IRS, and GPS position were unreliable. The navigation system thought it was 225nm south of our present position.”
=A Bombardier Global Express was spoofed on departure from LLBG/Tel Aviv (16 Oct). A false GPS position showed position as overhead OLBA/Beirut. Crew advises “The controller warned us that we are flying towards a forbidden area”.
=A Boeing 777 experienced a 30 miute GPS spoofing encounter in the Cairo FIR (16 Oct). A false GPS position showed the aircraft as stationary overhead LLBG for 30 minutes.
=A Bombardier Global 7500 was spoofed 3 separate times in the Cairo FIR (16 Oct 2023). Crew advises: “The first took out one GPS, the second took out a GPS and all 3 IRS’s, and the third time took both GPS’s and all 3 IRS’s.” The distance from LLBG was roughly 220-250 miles, and the spoofing stopped once we were approx 250nm west of LLBG.
= An Embraer Legacy 650 enroute from Europe to Dubai. They tell us, “In Baghdad airspace, we lost both GPS in the aircraft and on both iPads. Further, the IRS didn’t work anymore. We only realized there was an issue because the autopilot started turning to the left and right, so it it was obvious that something was wrong. After couple of minutes we got error messages on our FMS regarding GPS, etc. So we had to request radar vectors. We were showing about 80 nm off track. During the event, we nearly entered Iran airspace (OIIX/Tehran FIR) with no clearance.
= A Bombardier Challenger 604 experienced spoofing in the Baghdad FIR and required vectors all the way to Doha. “Nearing north of Baghdad something happened where we must have been spoofed. We lost anything related to Nav and the IRS suggested we had drifted by 70-90 miles. We had a ground speed of zero and the aircraft calculated 250kts of wind. The FMS’s reverted to DR (Dead Reckoning) and had no idea where they were. We initially took vectors to get around the corner at SISIN. Nav capability was never restored, so we required vectors all the way from Iraq to Doha for an ILS. We never got our GPS sensors back until we fired up the plane and went back to home base two days later.
Reference: GPS Spoofing Update: Map, Scenarios And Guidance
Victim: Aircraft in route crossing Middle East airspace
Aircraft in route crossing Middle East airspace
Reference: Flights Misled Over Position, Navigation Failure Follows
Incident: Fake GPS Signals in Middle East lead Multiple Aircrafts Astray
GPS spoofing from an unknown source in the Iraq-Iran area is causing complete aircraft navigational system failures in some overflying airliners and business jets. GPS spoofing is “the surreptitious replacement of a true satellite signal that can cause a GPS receiver to output an erroneous position and time”
This novel type of GPS and IRS signal spoofing attack caused over 20 aircraft to suffer complete loss navigation capability over restricted airspace, and caused unintended divergences in flight paths, in the corridor between Iran and the UM686 airway in NW Iraq. As a result, one bizjet almost strayed into Iranian airspace without clearance. This jeopardized the safety of hundreds of lives. GNSS comms are unencrypted and were never expected or designed to cope with this threat.
Reference: Someone In the Middle East is Leading Aircraft Astray by Spoofing GPS Signals
Reference: DGCA cautions airlines against fake navigational signals
Incident: Operational Slowdown after Hack at French BBQ Manufacturer
French BBQ manufacturer Somagic was infected over the weekend by MedusaLocker ransomware, halting production. Employees were surprised when they showed up at work on Monday morning only to discover all their IT systems were rendered unusable as all files were encrypted and left with a ".medusa" file extension.
Reference: The Bressan company Somagic victim of a large-scale cyber attack
Victim: Somagic
French BBQ manufacturer Somagic
Incident: Data Breach at French Trèves Group Claimed by Lockbit Ransomware Gang
LockBit #ransomware group added Trèves Group, a supplier of acoustic and thermal solutions based in #France, to their victim list. They claim to have access to 250 GB of company data.
Victim: Trèves Group
Trèves Group is a global, family-owned automotive supplier, designer and manufacturer of acoustic and thermal insulation solutions for the automotive industry,
Reference: Logistics, a sector of choice for cyberattacks?
Reference: FalconFeed on X: Treves Group Data Breach
Incident: Complicated Situation for Management at French Prison as CyberAttack cuts Power
Since Wednesday January 11, the remand center has been plagued by computer difficulties which have caused significant electrical malfunctions. "A virus was installed in the system via a USB key used by a teacher who was giving a lesson to inmates that day,” confirms Julien André, CGT staff representative within the establishment. prison. The computer system was shut down.
The prison was without power last weekend. “Friday evening, the pellets blew, cutting off all the electricity supply to the jail (sic), says Julien André, on duty that day. No more light, no more surveillance cameras.” A complicated situation for the management of the establishment, which had to call in numerous reinforcements.
Victim: Draguignan prison (Maison d’arrêt de Draguignan)
The new Draguignan prison (Maison d'arrêt de Draguignan)
Reference: Draguignan prison victim of a computer virus
Incident: Bay & Bay Transport, MN Hit by Ransomware Attack a 2nd Time
Bay & Bay Transport was targeted by a ransomware gang called Conti. Wade Anderson, Bay & Bay’s chief information officer, chief technology officer and head of marketing said that ransomware only impacted some of its systems and “a small minority” of desktop computers, but that everything was shut down as a precaution. The company, he said, had measures in place to minimize the impacts and was able to return to “90% functionality” within about a day in a half, he said.
In contrast to its response to the attack in 2018, Bay & Bay refused to pay. Anderson said the company was in a better position to recover on its own instead of paying the criminals for the key to decrypt its data
Threat Actor: Conti group
Conti group — a so-called ransomware as a service provider — provides malware, an extortion platform and support to affiliates, who get a percentage of the payments made by victims. Conti has been linked to hundreds of attacks, including multiple U.S. transportation and logistics companies.
Reference: Minnesota trucking company hit in 2nd ransomware attack
Reference: Black Basta Ransomware Victim Gates Corporation
Reference: Ransomware gang Lockbit attacks Zalando’s logistics service provider
Reference: Staff at security firm G4S on alert after tax numbers and bank details posted online following hack
Incident: Operational Impact at Electronics Company Alps Alpine Group
ALPS' North American production operations and delivery was impacted by a ransomware incident on their systems. ALP promptly shut off the network connection of servers and other devices infected and reported they "are still working to restore equipment and production functions. At present, with the exception of our production bases in Mexico, we have resumed production and delivery with alternative methods for system failures."
North American employee data was reportedly leaked.
This follows on the heels of a separate attack on July 6, 2023, where an attack exfiltrated data on 16,000 employees.
Reference: Cyber Incident Victim: Alps Alpine Group
Victim: Alps Alpine Group
Alps Alpine Group (Alpine Electronics, Inc., Alps Electric Co., Ltd.) is a Japanese multinational corporation, headquartered in Tokyo, a leading manufacturer of electronic components and automotive infotainment systems.
Reference: Cyber attack on our group companies
Reference: Press Release 2nd Update: Cyber attack on our group companies
Reference: PRESS RELEASE: Cyberattacks on Our Group Companies
Incident: Operations Disrupted at Montpellier Airport after Weekend Cyberattack
Montpellier airport suffered a major cyberattack during the night from Saturday to Sunday, which disrupted its activities. All flights on Sunday were operated, even if they experienced delays. Expectation was for all flight to be "back to normal between this Sunday evening and tomorrow Monday.” With internal operating systems of the various services to return to their usual functioning “during the week”.
Victim: Montpellier Airport
Montpellier Airport
Reference: “Our systems were out of order for several hours”: a “very violent” cyberattack against Montpellier airport
Incident: Giant North American Freight Forwarder Livingstone hit by Ransomware Attack
Giant North American freight forwarder and customs broker Livingston, stopped operating at the US-CAN border for 2 business days after being breached by Royal ransomware. Operations resumed operations after 2 days, but the Royal gang was able to exfiltrate both customer and employee data. A post from Royal on social media claimed to have information of 3,200 employees, 30,000 customers, and 125 key border entry points.
Victim: Livingston International
Livingston International provides customs brokerage, trade consulting and international freight forwarding services to importers and exporters
Reference: Royal Ransomware Group Adds Livingston International to Leak Site
Incident: French Cosmetics Factory at Standstill after Cyberattack
A premiere European maker of cosmetic aerosols reported that Russian cybercriminals attacked their centralized servers in Germany, According to the company's general manager Ramdane Mansoura, production was shutdown for at least 13 days and 300 employees have been temporarily laid off. Costs are €250K per day of lost production.
Victim: Elysée Cosmétiques
leading European cosmetics manufacturing company in France
Reference: Hacked servers: the Élysée Cosmétiques factory shut down
Incident: Cyberattack at Drug Distributor Alliance Healthcare Impacts Pharmacies in Spain.
A cyberattack on one of the main distributors of Catalan pharmacies, Alliance Healthcare, is disrupting medicines supplies, according to the Spanish daily 'El País.' A week later, the company’s website is still completely inaccessible. Alliance Healthcare’s billing systems and ordering processes are also in utter chaos, El País’ sources said. Outages led to supply delays, with pharmacies across the northeastern Catalonia region seeing the biggest impact.
While the affected company is one of the leading distributors to Catalan pharmacies, the industry has been able to cope with medicines supplies as they work with different distribution companies.
Victim: Alliance Healthcare
Alliance Healthcare is the fourth largest pharmaceutical distributor in Spain, with a market share of more than 10%.
Reference: Cyberattack on main distributor of pharmacies disrupts medicines supplies
Reference: Cyberattack hits Spanish pharmaceutical company Alliance Healthcare
Reference: Cyberattack cripples Spanish drug giant Alliance Healthcare
Incident: Weekend DDoS Attack on 400 Nepal Government Sites, Airport Most Affected
More than 400 Nepal government websites went down for hours on Saturday, disrupting services and inconveniencing thousands of passengers at Kathmandu airport, exposing the vulnerability to hacking of the gov.np domain.
Hackers appear to have targeted the government’s only central data bank at the Government Integrated Data Centre (GIDC) with a ‘Distributed-Denial of Service’ attack, possibly from abroad, and knocked out most government ministry websites, including the database of the Department of Immigration as well as Passports.
The greatest disruption was at the airport where chaotic queues began forming at the immigration desks both at the arrival and departure areas.
Many international flights, including those to Delhi, Mumbai, Bangalore, Kuala Lumpur and Doha were delayed by up to three hours. There were serpentine queues at the arrival concourse as the visa machines and consoles at the immigration desk went out of action.
Victim: Nepal Government Sites
Nepal Government Sites
Reference: Open season on hacking into gov.np
Incident: Operations Disrupted at Italian Clothing Giant Benetton
Renowned Italian clothing company the Benetton Group reportedly faced a cyberattack from an unknown threat group. The hackers behind the operation attacked Benetton’s online sale platform as well as the automated system of the newly opened Castrette di Villorba warehouse.
Workers were sent home and logistical operations impaired.
Victim: United Colors of Benetton’
Italian clothing manufacturer - globally distrituted
Reference: United Colors of Benetton’s Italy Nerve Centre Suffers Cyber Attack
Reference: United Colors of Benetton’s Italy Nerve Centre Suffers Cyber Attack
Incident: Iranian Oil Terminals Offline after Malware Attack
Iran has been forced to disconnect key oil facilities after suffering a malware attack on Sunday, say reports.
The computer virus is believed to have hit the internal computer systems at Iran's oil ministry and its national oil company. Equipment on the Kharg island and at other Iranian oil plants has been disconnected from the net as a precaution. Oil production had not been affected by the attack, said the Mehr news agency. However, the attack is believed to have been responsible for knocking offline the websites of the Iranian oil ministry and national oil company.
Victim: Kharg Island, Iranian Oil Terminal
Kharg Island, Iranian Oil Terminal
Malware: Flame
Flame, also known as Flamer, sKyWIper, and Skywiper, is modular computer malware discovered in 2012 that attacks computers running the Microsoft Windows operating system. The program is used for targeted cyber espionage in Middle Eastern countries.
Reference: Attacks on Iranian oil industry led to Flame malware find
Reference: Iranian oil terminal ‘offline’ after ‘malware attack’
Incident: MGM Shuts Down Operations for 10 Days Across Las Vegas Properties
A major cyberattack disrupted operations of MGM Resort in Las Vegas. The cyberattack forced MGM to shut down significant portions of its internal networks, affecting various aspects of its services. Guests at MGM’s hotels and casinos, including renowned establishments like the Bellagio, Aria, and Cosmopolitan, have reported widespread disruptions.
The hackers spear phished an MGM employee through social media. MGM did not pay the ransom.
Victim: MGM Hotels and Casinos
Casino resort of Metro-Goldwyn-Mayer Studios, Inc., an American media company specializing in film and television production and distribution.
Threat Actor: Scattered Spider
Scattered Spider threat actors, per trusted third parties, have typically engaged in data theft for extortion. Known to utilize BlackCat/ALPHV ransomware alongside their usual TTPs.
This loose-knit group of predominantly teenage, native English-speaking hackers has carried out some of the most disastrous cyberattacks in history, such as MGM Hotels and Transport for London.
Reference: MGM Resorts breached by ‘Scattered Spider’ hackers
Reference: Hackers Behind MGM Cyberattack Thrash The Casino Incident Response
Incident: Contractor inserts Cyber “Time Bomb Attack” in Firmware of Orqa Drone Goggle
A contractor named Swarg maliciously planted a time-bomb in the firmware of Orqa's FPV.One V1 first person view (FPV) drone goggles, causing product failures. The malicious code was designed to brick devices after a timestamp is reached. Later, Swarg posted a paid and unauthorized binary firmware fix online as a "license extension and renewal" that would unbrick devices. Orqa's stated this is effectively a case of a ransomware attack by a malcious insider deploying a wiper payload. Analysis shows that both Orqa and Swarg have done business together and operate from the same location, suggesting they share offices.
Victim: Orqa
Drone manufacturer
Reference: Drone goggles maker claims firmware sabotaged to ‘brick’ devices
Reference: Drone Goggles Maker Orqa Hit with ‘Time-bomb’ Ransomware Attack
Incident: Disruption at Israel Postal Company after Cyberattack Last for 6+ Days
The Israel Postal Company detected several services including the sending of international mail and courier services were interrupted and proactively shut down part of its computer systems. The attack and shutdown did not affect Israel Post's banking services. Attack was part of the #OPIsrael hacktivist campaign.
Reference: Cyberattacks strike Israel Post, irrigation systems
Reference: Cyber attack shutters Galilee farm water controllers
Victim: Israel Postal Company
Israel Postal Company
Incident: Vice Society Disrupts Operations at CommScope and Publishes Employee PII
CommScope suffered a ransomware incident that resulted in "several days of widespread disruption, including plant production," according to employees. Employee PII data was breached on the dark web by the ransomware gang Vice Society.
Reference: Network infrastructure provider CommScope investigating data leak following ransomware attack
Reference: Hackers publish sensitive employee data stolen during CommScope ransomware attack
Reference: CommScope employees left in the dark after ransomware attack
Victim: CommScope
CommScope Holding Company, Inc. designs and manufactures network infrastructure products. Based in Hickory, North Carolina. CommScope employs over 30,000 employees.
CommScope has four business segments: home networks, broadband networks, venue and campus Networks, and outdoor wireless networks.
Reference: RansomEXX claims ransomware attack on Sea-Doo, Ski-Doo maker
Incident: Ricardo Defense Suffers Cyberattack
Multi-industry technology provider, Troy, Michigan-based Ricardo Defense Inc., suffered a cyberattack this past October where personally identified information ended up stolen.
“On October 23, 2023, Ricardo discovered suspicious activity on its network,” the company said in a notice. “Ricardo immediately took steps to secure its systems and initiated an investigation into the nature and scope of the event with the assistance of third-party forensic specialists.
“The investigation determined that Ricardo’s network was subject to unauthorized access between October 16, 2023 and October 23, 2023, and that certain files were acquired by an unknown actor while on the network,” the statement said.
Reference: Cyberattack Strikes Technology Provider
Victim: Ricardo Defense
Ricardo works across eight market sectors: Aerospace & defense; automotive; energy utilities and waste; financial services; government and public sector; industrial and manufacturing; maritime; rail and mass transit. The company provides technological solutions that ensure access to clean air and water; cross-sector engineering solutions to accelerate decarbonized transportation; support for global net zero and industry agendas; and comprehensive expertise in safety, assurance and certification.
Incident: Clothing Provider, V.F. Corp., Hack Hits 35.5M Customers
After suffering a cyberattack December 13, V.F. Corporation, the global apparel and footwear company founded in 1899, released further details on the assault that led to shutting down some systems and losing personal information of 35.5 million customers.
On December 13, V.F. detected unauthorized occurrences on a portion of its information technology (IT) systems, according to an 8-K document filed with the Securities and Exchange Commission (SEC).
Upon detecting the unauthorized occurrences, V.F., which brought in $11.6 billion in revenue, immediately began taking steps to contain, assess and remediate the cyber incident, including beginning an investigation with leading external cybersecurity experts, activating its incident response plan, and shutting down some systems.
As a result of these and other measures, and while V.F.’s investigation and remediation efforts remain ongoing, the Denver, Colorado-based company believes it “ejected” the threat actor was ejected from its IT systems on December 15. V.F. said it notified, is cooperating with, and will continue to cooperate with and notify, federal law enforcement and the relevant regulatory authorities as required under applicable law.
Reference: Clothing Brand, V.F. Corp., Hack Hits 35.5M Customers
Victim: V.F. Corporation
V.F. operated retail stores, brand e-commerce sites and distribution centers are operating with minimal issues. The company’s brands include: Vans, North Face, Timberland, Dickies, Jansport, and Kipling to name a few.
Incident: Framework Laptop Maker Suffers Cyberattack
San Francisco, California-based Framework, the repairable laptop maker, said hackers phished a worker Tuesday at its accounting service provider and were able to purloin customer data.
Framework sent an email to affected customers explaining what happened during the incident at San Mateo, California-based Keating Consulting, its primary external accounting partner. In the attack, an accountant fell victim to a social engineering attack that resulted in thieves stealing customers’ personal information related to outstanding balances.
The letter from Framework to its customers said:
“Keating Consulting, Framework’s primary external accounting partner, brought to our attention at 8:13am PST on January 11th, 2024, that one of their accountants fell victim to a phishing email that utilized social engineering tactics to obtain customer PII (Personal Identifiable Information) associated with outstanding balances for Framework purchases."
Reference: Laptop Maker Framework Says Customer Data Stolen in Third-Party Breach
Reference: Laptop Maker Hit In Attack
Victim: Framework
Framework is a San Francisco, California-based repairable laptop maker.
Incident: OR Luxury Recreational Vehicle Maker Hit In Cyberattack
Luxury recreational vehicle maker, Marathon Coach, Inc. suffered a cyberattack affecting personal information of some of its customers.
The incident occurred June 22, but the Coburg, Oregon-based company did not discover it until November 21 and it sent out letter to some of its 704 victims January 3. Marathon Coach, Inc. began operations in September 1983 converting new commercial bus shells into luxury recreational vehicles and corporate coaches.
“On July 7, 2023, Marathon Coach became aware of unusual activity involving certain systems within our network,” the company said in a letter to its victims. “We promptly isolated the systems and commenced a comprehensive investigation into the nature and scope of the activity.
“The investigation determined that an unauthorized actor was able to intermittently access certain systems between June 22 and July 7, 2023. We undertook a review of the files within the systems in order to identify what specific information was present and to whom it related,” the company said.
Reference: Luxury OR RV Maker Hit In Cyberattack
Victim: Marathon Coach, Inc.
Marathon Coach, Inc. began operations in September 1983 converting new commercial bus shells into luxury recreational vehicles and corporate coaches.
Reference: Shipbuilder Hit In Ransomware Attack
Victim: Fincantieri Marine Group (FMG), LLC
FMG is a medium-sized shipbuilder in the United States that works for civil and government clients, such as the U.S. Navy and the U.S. Coast Guard.
Incident: Cyberattack at Missouri Window Maker
Freeburg, Missouri-based Quaker Window Products, Co. suffered a cyberattack where an unauthorized attacker gained access to personal data stored on the network.
Total amount of victims in the November 25 attack amounted to 10,988.
“On November 25, 2023, Quaker experienced a network disruption and immediately initiated an investigation of the matter,” the company said in a notice sent out to customers. “Quaker engaged cybersecurity experts to assist with the process. The investigation revealed that an unauthorized actor had access to certain files from the Quaker network on or about November 25, 2023."
Reference: MO Window Maker Hit In Attack
Victim: Quaker Window Products, Co.
Headquartered in Freeburg, MO, Quaker Windows & Doors is a manufacturer of residential and commercial window and door products in the United States.
Incident: Hackers Accessed Customer Information at Toyota Kreditbank Germany
Toyota Financial Services (TFS) is warning customers it suffered a data breach, stating that sensitive personal and financial data was exposed in the attack. Earlier this month, Toyota Kreditbank GmbH in Germany admitted that hackers gained access to customers' personal data.
German news outlet Heise received a sample of the notices sent by Toyota to German customers, informing that personal information, including leasing and bank account information has been compromised. However, the internal investigation isn't complete yet, and Toyota promises to promptly update affected customers should the internal investigation reveal further data exposure.
Reference: Toyota warns customers of data breach exposing personal, financial info
Reference: BLACKCAT RANSOMWARE GANG STOLE SECRET MILITARY DATA FROM AN INDUSTRIAL EXPLOSIVES MANUFACTURER
Victim: Solar Industries Limited India
Explosives manufacturer Solar Group and top private Indian defense contractor
Incident: Hackers Target Indian Defense Explosives Manufacturing Contractor, Solar Industries Limited India.
The parent company of a private defence ministry contractor manufacturing explosives, Solar Industries Limited India, has been the target of a ransomware attack, a government official said, in an incident that experts said could pose a threat to security if documents were leaked. “The government is investigating the extent of the data compromised and the source of the attack.” an official familiar with the matter said, asking not to be named. The official could not confirm if a ransom demand had been made so far, or whether data was stolen by the attackers.
A listing on the dark web by a group that calls itself Black Cat (Alphv) claimed to have stolen two terabytes of data. BlackCat published images of the stolen documents and pictures taken from the company’s security cameras as proof of the hack. The claims, however, could not be independently verified by HT.
Reference: CBI may probe ransomware attack on Nagpur’s ammo maker
Reference: Defence ministry contractor’s parent firm faces ransomware attack
Incident: Haynes International Cyberattack Estimated Cost is $18-$20 Million
On June 10, 2023, the Company began experiencing a network outage indicative of a cybersecurity incident.
Various aspects of the Company’s networks were down.
On June 21, 2023, less than 2 weeks after the incident began, the Company announced that all manufacturing operations were running and that it had substantially restored administrative, sales, financial and customer service functions. Nevertheless, during those 11 days many aspects of the Company’s production were substantially disrupted.
Victim: Haynes International, Inc
Haynes International, Inc. is a leading developer, manufacturer and marketer of technologically advanced, high performance alloys, primarily for use in the aerospace, industrial gas turbine and chemical processing industries.
Reference: Haynes International Provides Cybersecurity Update and Estimated Third Quarter Financial Impact
Reference: UNITED STATES SECURITIES AND EXCHANGE COMMISSION Form
Incident: Cyberattack hits Multiple Sites of Pharmaceutical Vibrac Group
The Virbac Group was the target of a cyber attack on several of its sites worldwide during the night of June 19-20. "As soon as we became aware of the attack, we immediately took steps to contain it. At the same time, we set up a crisis unit including dedicated cybersecurity experts to assess the impact on our systems and organize remediation operations."
"As a result of this attack, we are currently experiencing a slowdown or temporary interruption of some of our services."
Reference: Cyber attack on several sites
Reference: Virbac : Cyber attack on several sites
Victim: Vibrac
French animal health pharmaceutical company Vibrac
Incident: German Milk Producer Affected by Cyberattack
A statement from SCHWÄLBCHEN MOLKEREI AG says the company is affected by a cyber attack in some areas of the IT infrastructure. Due to the attack, the company's accessibility is currently impaired. Current production and logistics are not affected. Work is underway to fully restore the systems.
It is unclear to what extent company data was obtained by unauthorized third parties.
Reference: Cyber attack on Schwäbchen
Victim: SCHWÄLBCHEN
German Milk Producer
Reference: Schwälbchen Molkerei Jakob Berz AG: IT security incident
Incident: Cyber Incident at Coca Cola Mexico
In a Statement the Coca Cola FEMSA states the company is working with experts on measures to prevent an adverse impact on its information technology applications. While such measures are being implemented, the Company expects to continue its operations through back-up procedures and will prioritize the protection of the integrity, confidentiality and availability of its information.
A forensic assessment is currently underway to determine the scope of the cyber incident.
Reference: Coca Cola Cybersecurity incident
Incident: Cyberattack at Super Bock Brewery Affects Operations
The Super Bock Group has been the target of a cyber-attack that is causing disruption to its IT services, with constraints on regular operations, particularly service levels.
The situation is causing major restrictions in its operation to supply the market with some of its products, in the different sales channels.
The company immediately activated the necessary security protocols and informed the competent authorities, and also put in place a contingency plan to restore normal market supply conditions.
The Super Bock Group regrets the possible inconvenience caused to all its customers and suppliers, and thanks its partners for their expressions of solidarity and support on this date.
Reference: Super Bock Group targeted by cyber attack
Victim: Super Bock Group
Super Bock Group, a brewery based in Portugal
Incident: Lockbit Group Demands Ransom of Colombian Grupo Nutresa
Through a press release, Grupo Nutresa informed that this Thursday a possible ransomware or cyber attack event was identified, which so far has not compromised the integrity of the organization's data, nor the information of its customers, suppliers, consumers and other related groups.
Victim: Grupo Nutresa
Grupo Nutresa, formerly Grupo Nacional de Chocolates S.A. is a food-processing conglomerate headquartered in Medellín, Colombia. The group's principal activities are producing, distributing, and selling cold cuts, biscuits, chocolates, coffee, ice cream and pasta
Reference: LockBit #ransomware group added Nutresa
Reference: Nutresa confirms that it is the victim of a possible cyber attack.
Incident: Royal Vopak’s Malaysian Oil Storage Complex Hit by Ransomware Attack
Vopak has fallen victim to a ransomware attack in Malaysia by what appears to be the ALPHV Blackcat ransomware group. Vopak informed that its business operations in the Netherlands are not in danger.
“We can confirm that an IT incident has occurred at Pengerang Independent Terminals (PTSB) in Malaysia,” a Vopak spokesperson said. "Unauthorized persons have gained access to our data," Vopak confirms. “The incident is under investigation and we apologize for any inconvenience caused.” The company remains operational. Critical business information was allegedly stolen, including about the company's fuel infrastructure and systems.
Reference: Ransomware attack on tank storage company Vopak limited to one location
Reference: Dataleak Vopak
Reference: Vopak hit by ransomware
Victim: Royal Vopak N.V.
Dutch tank storage company Royal Vopak N.V.
Incident: Ransomware Attack at Fiege Logistik Italian sites
Fiege Logistik has fallen victim to a hacker attack. With the Lockbit 3.0 ransomware, criminals stole 259 GB of internal data and published some of it on the dark web. The target was Italy and the affected IT systems there were immediately isolated.
“The Fiege Cyber Defense Center recognized a hacker attack on Fiege Italy early on and responded quickly to the attack. The attack impacts a small part of our logistics centers in Italy. Around 15 percent of Italian business is affected," said Fiege According to Fiege, three locations in Italy were affected by the hacker attack. Two of them have now been able to resume work. The third affected location will also start operations again in the next few days.
Victim: Fiege Logistik
modular solutions for logistics, digital services, real estate and ventures - all driven by one integrated system.
Reference: Hackers attack Fiege Logistik
Reference: Hackers attack Fiege Logistik
Incident: Cyberattack at Puerto Rico’s Water Supply Agency did not Affect Critical Infrastructure
The agency that manages Puerto Rico’s water supply has called in the FBI to investigate a cyberattack that occurred last week. The investigation into the attack on the Puerto Rico Aqueduct and Sewer Authority (PRASA), which was announced on March 19, found that customer and employee information was compromised in the incident. But officials noted that the authority’s critical infrastructure was not affected by the incident due to network segmentation.
The Vice ransomware gang leaked the passports, driver’s licenses and other documents of the impacted individuals.
Reference: VICE SOCIETY CLAIMS ATTACK ON PUERTO RICO AQUEDUCT AND SEWER AUTHORITY
Victim: Puerto Rico Aqueduct and Sewer Authority (PRASA)
Puerto Rico Aqueduct and Sewer Authority (PRASA)
Reference: FBI, CISA investigating cyberattack on Puerto Rico’s water authority
Incident: ALPHV/Blackcat Reportedly Demands ‘8 figure’ Ransom from Western Digital
On March 26 hackers breached Western Digital's
Hackers breached data storage giant Western Digital internal network and stole company data. They claim to have stolen around 10 terabytes of data from the company, including reams of customer information. The extortionists are pushing the company to negotiate a ransom — of a “minimum 8 figures” — in exchange for not publishing the stolen data.
The ALPHV ransomware operation, aka BlackCat, has published screenshots of internal emails and video conferences stolen from Western Digital, indicating they likely had continued access to the company's systems even as the company responded to the breach Western Digital declined to comment regarding the leaked screenshots and claims by the threat actors.
Victim: Western Digital
Western Digital, leaders in digital storage solutions compatible with Mac and PC.
Reference: Hackers leak images to taunt Western Digital’s cyberattack response
Reference: Hackers claim vast access to Western Digital systems
Reference: Western Digital Provides Update on Network Security Incident
Incident: Renewable Energy Company hep global Target of Cyberattack
hep global GmbH recently became the target of a cyber attack. This was detected immediately. Cooperating closely with authorities and external IT security experts, hep was able to ensure business continuity. The investigation into the cyber attack is still ongoing.
Darkrace ransomware group has claimed responsibility for the hep Global data breach, listing the German renewable energy company as its latest victim
Reference: Hep Global Data Breach: Darkrace Ransomware Group Strikes Renewable Energy Sector
Reference: hep ensures business continuity after cyber attack
Incident: Cyberattack at Electricity Supply Company in Peru
The electricity supply company Sociedad Eléctrica del Sur Oeste (SEAL), in Arequipa, suffered a cyber attack this Monday, April 17. In response to this, the entity reported that the customer service area, virtual channels, collections and parts table; They were suspended until further notice.
SEAL general manager Paul Rodríguez indicated that those who carried out the attack sought to capture and retain information. However, the security system in place did not allow this.
Victim: Sociedad Eléctrica del Sur Oeste (SEAL
electricity supply company Sociedad Eléctrica del Sur Oeste (SEAL), in Arequipa, Peru
Reference: SEAL suffered a cyber attack and suspended all its virtual services
Incident: Ransomware Attack at Indian MPPMC Power Company
Madhya Pradesh Power Management Company (MPPMC) which oversees the management of electricity in the state has been hit by ransomware attack. The state-run entity said on Sunday that it has approached police after a ransomware attack on May 22 that crippled its internal information technology system used for communication among its different functionaries.
A source familiar with the incident told PTI that those behind the ransomware attack had not sought money as yet but had provided email IDs to contact them.
Victim: Madhya Pradesh Power Management Company (MPPMC)
Madhya Pradesh Power Management Company (MPPMC) - oversees the management of electricity in the state Madhya Pradesh, India
Reference: MP power mgmt co hit by ransomware
Reference: Madhya Pradesh power management co’s IT system hit by ransomware attack
Incident: Databreach at German Manufacturer Laremo GmbH
Laremo GmbH was hit by ransomware attack on February 5. A company issued statement on their website states that customer database and financial accounting data were compromised.
The LockBit ransomware group claimed responsibility for the attack and uploaded the company’s data on their dark web site on February 19.
Reference: LockBit 3.0 Ransomware Victim: laremo[.]de
Reference: Laremo Cyber Incident Notice
Victim: Laremo GmbH
German steel special vehicle equipment producer
Reference: Just received an email from @Hyundai_Italia
Incident: Databreach Impacts Italian and French Hyundai Car Owners
Hyundai has disclosed a data breach impacting Italian and French car owners and those who booked a test drive, warning that hackers gained access to personal data. It is unclear how many Hyundai customers this incident impacts, how long the network intrusion lasted, and what other countries might be affected.
BleepingComputer has contacted Hyundai to learn more about the security incident
Victim: Hyundai
Hyundai is a multinational automotive manufacturer selling over half a million vehicles per year in Europe, with a market share of roughly 3% in France and Italy.
Reference: Hyundai data breach exposes owner details in France and Italy
Incident: All Rosenbauer Group Locations Affected by Ransomware Attack claimed by Lockbit
The Rosenbauer Group is currently the target of a cyber attack. As a precautionary measure, parts of the IT infrastructure were switched off. The measures affect all Rosenbauer locations. The Rosenbauer Group is one of the world’s three largest manufacturers of fire-service vehicles and firefighting equipment.
The exact extent and duration of the attack as well as its consequences cannot yet be estimated. An immediately established task force is working with external cybersecurity experts and data forensics to restore system operations safely and as quickly as possible. According to current knowledge, neither customer nor company data was stolen or encrypted. The responsible authorities were called in.
The LockBit 3.0 ransomware group listed the company as one of its victims.
Victim: Rosenbauer Group
The Rosenbauer Group is one of the world’s three largest manufacturers of fire-service vehicles and firefighting equipment, based in Leonding, Austria. Rosenbauer supplies the fire fighting sector in over 100 countries with a wide range of custom fire and rescue apparatus and services
Reference: LockBit 3.0 Ransomware Victim: rosenbauer[.]com
Reference: Cyber attack on Rosenbauer Group
Reference: Suspected ABB hackers are also behind the attack on Bobst
Incident: Operations Disrupted at Machine Manufacturer, Bobst.
Bobst, the Vaud-based machine manufacturer, suffered two targeted cyberattacks over Easter weekend, Emergency measures had to be taken to protect critical IT systems by isolating them. This resulted in production, customer service and research and development operating in degraded mode.
Work gradually resumed at the group's various global sites between April 12 and 18, while the systems were reconnected. The calmer holiday period helped smooth out the impact.
Victim: Bobst Machine Manufacturer
Swiss manufacturer of packaging machines with 6,100 employees around the world
Reference: Bobst resists two computer hacks
Reference: CONTRARY TO WHAT THEY CLAIMED, BOBST HAD HIS DATA STOLEN
Reference: ‘Total system shutdown’ as Ghana hit by countrywide power blackout
Victim: Porsche
Porsche
Reference: Porsche South Africa suffers ransomware attack
Incident: Cyberattack at German Packaging Manufacturer Storopack
German packaging manufacturer Storopack recorded a cyberattack on March 21. The company was not reachable by email and limited by phone. Its website was unaffected, but its online store was unavailable.
Although there may have been some delays in delivery, Storopack worked at full speed to maintain its ability to deliver. Production and delivery capability were not interrupted at any time.
Reference: Notice of Business Ransomware Attack
Reference: CYBERATTACK ON STOROPACK
Victim: Storopack
German packaging manufacturer Storopack
Incident: Hahn Group Shuts down Network and Systems after Cyberattack
The HAHN Group was attacked by hackers last week. Therefore, all systems were switched off as a precautionary measure.
"As you are aware, on March 17 2023, we suffered a cyber incident affection on our networks and systems. Our IT team responded to this attack quickly and was able to stop it. Among other things, this meant that all systems had to be shut down for security and containment purposes. Since Monday, March 27 2023, we are able to start to ramp-up our operations again. This included re-installation of our infrastructure in a clean environment and leveraging our back-up systems. ....getting everything back online and operational will, we anticipate, continue throughout April."
Reference: Automation specialist affected by cyber attack
Reference: Update | Cyber Attack | 2023/04/06
Victim: HAHN Group,
HAHN Group, an industrial automation and robotics headquartered in Germany,
Incident: Cyberattack at French Manufacturer Groupe SEB
Groupe SEB's IT teams detected an attempt to exploit a vulnerability. After investigations, an intrusion in the Information System has been confirmed. The necessary measures have been taken to limit the effects of this intrusion.
To date, and after extensive research, Groupe SEB has not identified any data leakage or damage to information systems. The incident is currently undergoing a detailed analysis to investigate its origins allowing to reinforce existing security measures.
Reference: A security incident has been detected on one of Groupe SEB’s IT networks, without any material impact on operations.
Victim: Groupe SEB
Groupe SEB, a French manufacturer of household appliances
Incident: Gates Industrial Corporation Temporarily Takes Systems Offline
On February 11, Gates Industrial Corporation plc, a US manufacturer of fluid power and power transmission technology, determined that it was the target of a malware attack. The attack affected certain of the company’s IT systems, and as part of its containment efforts, the company suspended the affected systems and elected to temporarily suspend additional systems. These suspensions resulted in the temporary inability of most of the facilities to produce and ship products.
"Anytime you shut down the majority of operations at a global company, it’s a big deal," an executive says.
Reference: Gates Corporation hit by ransomware
Reference: Gates Corp. recovers from cyberattack that shut down most of its systems
Reference: UNITED STATES SECURITIES AND EXCHANGE COMMISSION
Victim: Gates Industrial Corporation plc
Gates Industrial Corporation plc, a US manufacturer of fluid power and power transmission technology
Reference: Cyber Security Incident
Reference: Press Release
Incident: ALPHV Group Hacks Belgian Secure Access Control Manufacturer, Automation Systems
On June 3, 2023, Belgium’s Automatic Systems uncovered a ransomware attack, which has now been claimed by the notorious ALPHV group. The cybercriminals specifically targeted a segment of the company’s servers, as confirmed by a notification prominently displayed on the company’s homepage.
ALPHV cybercriminals claimed they stole sales data, and logistics information. Moreover, that they had access to confidential documents pertaining to NATO and the procurement of equipment for military companies which had installation schemes, and data about security equipment.
Victim: Automation Systems
Belgium-based Security system supplier
Reference: ALPHV Claims the Automatic Systems Ransomware Attack
Incident: Austrian Laboratory Instruments Manufacturer Hacked via Phishing Emails
The Austrian manufacturer of laboratory instruments and process measuring systems fell victim to a ransomware attack initiated via phishing emails received on April 6.
The website states: "On April 19, the attackers encrypted approximately 10% of the company’s internal PCs and servers. The company immediately took most of its systems and services offline worldwide and worked with the highest priority to get its IT systems up and running again. The cybersecurity incident resulted in the unauthorized disclosure of personal data in some instances. "
The Black Basta ransomware group added Anton Paar to the victim list on its dark web site.
Reference: Information about the April 2023 cybersecurity incident
Malware: Phishing Attack
Phishing Attack
Victim: Anton Paar Group
Austrian manufacturer of laboratory instruments and process measuring systems
Reference: BERNINA International hacked: ALPHV Ransomware Group Strikes the Sewing Machine Manufacturer
Incident: Swiss-based Bernina International Reports Cyberattack
Swiss-based Bernina International AG, a leading manufacturer of sewing and embroidery machines, reported that it fell victim to a cyberattack after being added to the victim list of the ALPHV ransomware group.
The group claim to have gained access to vast data, including customer, client, and employee data, NDA contracts, and drawings.
The attack’s impact has been felt in the company’s offices in Switzerland and Thailand, with tapes and NAS wiped clean. Additionally, the attackers successfully encrypted seven Hyper-V.
Reference: Cyber attack on BERNINA International AG
Victim: Bernina International AG
Swiss-based Bernina International AG, a leading manufacturer of sewing and embroidery machines
Incident: Lighting Manufacturer, Lumila, Announces ‘Massive Ransomware Attack’
French lighting manufacturer Lumila was one of the victims of a ransomware attack on February 3 that targeted several French hosting companies, including Scaleway and OVHCloud. Lumila provides services to the French railways. All services were restored and operational at the time of the announcement [Feb 8].
Victim: Lumila
French lighting manufacturer Lumila, provides services to the French railways
Reference: Press release: Lumila hit by massive ransomware attack
Incident: Sites Down Worldwide after Cyberattack at Stamp Manufacturer
TroGroup, based in Wels, has become the target of a cyber attack. A large part of the Group’s central IT services was temporarily unavailable at numerous locations worldwide. Emergency operations were activated immediately after the incident became known and it was possible to ensure continued service and to avoid any disadvantages for our customers and suppliers in the best possible way. After the immediate preventive shutdown of the system landscape and thorough forensic system analyses, a controlled reconstruction is now underway.
Reference: TroGroup has become the target of a cyber attack
Victim: Trodat, Inc.
Trodat, Inc. is an Austrian multinational company which claims to be the world's largest manufacturer of rubber stamps. Trodat has its company headquarters in Wels, Austria.
Incident: Bartec Top Holding Announces Data Breach
Bartec TOP HOLDING Gmbh disclosed cyber incident on their website: "In the past days, an unauthorized data access attempt was undertaken on parts of BARTEC's IT infrastructure. This attempt was largely prevented by our own security systems. We immediately checked our existing IT infrastructure and have not identified any new attempts at unauthorized data access since then."
The attack was claimed by Hunters International Ransomware Group.
Victim: BARTEC Top Holding GmbH
BARTEC Top Holding GmbH operates as holding company. The Company, through its subsidiaries, provides explosion-resistant switching and signaling gear including stainless steel enclosures and controls, as well as gas detection systems. BARTEC Top Holding serves chemical, petrochemical, and pharmaceutical companies worldwide.
Reference: Information about possible data access
Reference: Hunters International Ransomware Victim: Austal USA
Incident: US DoD Contracted Shipbuilding Company Austal USA Confirms Ransomware Attack
Austal USA confirmed that it suffered a cyberattack and is currently investigating the impact of the incident. a Austal USA is a shipbuilding company and a contractor for the U.S. Department of Defense (DoD) and Department of Homeland Security (DHS). Hunters International ransomware and data extortion group claimed to have breached Austal USA and leaked some information as proof of the intrusion. Austal USA did not share if the threat actor was able to access data about engineering schematics or other proprietary U.S. Navy technology.
Hunters International emerged recently as a ransomware-as-a-service (RaaS) operation. The group is believed to be a rebrand of the Hive ransomware gang, a theory based on overlaps in the malware code.
Threat Actor: World Leaks, formerly Hunters International
Hunters International was launched in late 2023 as a ransomware operation and was flagged as a possible rebrand of Hive due to code similarities. Since then, the threat actors have claimed over 280 attacks against organizations worldwide. In January 2025, Hunters International rebranded as World Leaks, citing concerns that ransomware is no longer profitable and risky. World Leaks shifted its focus away from file encryption toward pure data extortion.
Reference: Navy contractor Austal USA confirms cyberattack after data leak
Incident: Florida Water Agency Confirms it Responded to Cyberattack
A regulatory agency in Florida that oversees the long-term supply of drinking water confirmed that it responded to a cyberattack over the last week as the top cybersecurity agencies in the U.S. warned of foreign attacks on water utilities.
A spokesperson for the St. Johns River Water Management District, which works closely with utilities on water supply issues, confirmed that it “identified suspicious activity in its information technology environment” and that “containment measures have been successfully implemented.”
Victim: St. Johns River Water Management District, Florida
St. Johns River Water Management District, Florida.
Most of the work by the St. Johns River Water Management District is centered around educating the public about water conservation, setting rules for water use, conducting research, collecting data, restoring and protecting water above and below the ground, and preserving natural areas.
Reference: Florida water agency latest to confirm cyber incident as feds warn of nation-state attacks
Incident: Phishing Attack at Hershey Company Compromised PI of 2,214 people
A cyberattack that targeted The Hershey Company may have compromised the personal data of 2,214 people, the company revealed in December. The data breach was the result of an email phishing attack. The data that may have been compromised includes first and last names, health and medical information, dates of birth, financial account information, debit and credit card data and related access codes.
Reference: Cyberattack on Hershey Company left hackers with access to personal data
Incident: Ransomware Attack at Central Virginia Transit System
The organization that runs the transit system for central Virginia dealt with a computer network disruption due to a cyberattack around the Thanksgiving holiday. A spokesperson told Recorded Future News that around Thanksgiving they experienced a network disruption that “temporarily impacted certain applications and parts of the GRTC network.”
The Play ransomware gang took credit for the attack and gave GRTC until December 13 to pay an undisclosed ransom.
Victim: Greater Richmond Transit Company (GRTC)
The Greater Richmond Transit Company (GRTC) provides bus and specialized transportation services for millions of people across Richmond, Chesterfield and Henrico Counties.
Reference: Central Virginia transit system affected by cyber incident
Incident: Cyberattack and Potentional Data Breach at Nissan Oceania
Japanese automobile manufacturer Nissan announced that its Australia and New Zealand arm suffered a significant cyber security incident that affected the company’ daily operations. The company informed customers of its Nissan Oceania division of a potential data breach, warning them that there is a risk of scams in the upcoming days. The company did not share details about the attack or its scope. The problems suffered by the company suggest that its systems were infected with ransomware.
The carmaker warned that some dealer systems will be impacted despite local dealerships continue to operate.
Reference: A CYBER ATTACK HIT NISSAN OCEANIA
Reference: Nissan is investigating cyberattack and potential data breach
Victim: Nissan Oceania
Nissan Oceania is a regional division of the famous Japanese automaker that covers distribution, marketing, sales, and services in Australia and New Zealand.
Reference: IMPORTANT UPDATE FROM NISSAN OCEANIA
Reference: Guard against cyber-attacks warning, as UK haulier data appears on ‘dark web’
Incident: Lockbit Ransomware Attack Significantly Impacts Owens Group Operations.
British logistics company Owens Group has reportedly suffered a significant data security incident. Confidential company data and the sensitive personal information of its drivers, employees, and clients was compromised. LockBit ransomware infiltrated its systems. The ransomware attack has had a significant impact on Owens Group’s day-to-day operations. The encryption of critical files and systems has led to disruptions in logistics planning, supply chain management, and communication channels.
LockBit group says it stole over 700 GB of data. Owens’ data included finance information, such as budget, cash flow, balance sheets, tax returns, project calculations and bank statements, as well as client details including addresses, phone numbers, payment information and contracts, and employees’ personal information like passport scans and contracts.
Owens Group has engaged cybersecurity experts to assess the extent of the breach and work towards a resolution. The company is actively involved in restoring its systems and implementing enhanced cybersecurity measures to prevent future incidents.
Reference: Welsh logistic Owens Group impacted by LockBit ransomware
Reference: LockBit group says it stole over 700 GB of data from British logistics company Owens Group
Victim: Owens Group
British logistics company Owens Group
Reference: Most WSF, WSDOT websites back online after cyber attack
Incident: Online Transportation Information Widely Disrupted at WSDOT
A cybersecurity incident on Tuesday has made key parts, including real-time information, of the transportation department’s website inaccessible, causing major disruptions. While some services have been restored, maps and permits are still down.
While the department's basic website and app are still accessible, most real-time information is not. As a result, the outage has caused major disruptions for anyone trying to track the chronically late ferries or navigate mountain passes as winter approaches. Statewide traffic cameras were restored Thursday morning, but the state's travel map, mobile app, ferry vessel watch and online freight permits remain out of service.
Reference: Cyberattack shuts down WA transportation website, bringing confusion, disruptions
Reference: Cyber Attack Downs Washington State’s Transportation Website
Victim: Washington State Department of Transportation
Washington State DOT
Reference: Chinese hackers allegedly target US infrastructure as ‘Volt Typhoon’
Threat Actor: Volt Typhoon
According to Microsoft, a group known as "Volt Typhoon" has been engaged in espionage and collecting information on behalf of the People's Republic of China for at least two years. To avoid detection, the hackers rely on tools that are already installed or integrated into compromised devices, which they manually operate rather than automate. This approach is commonly referred to as "living off the land." Volt Typhoon's targets include communications, energy, transportation systems, and water and wastewater systems.
Incident: Chinese Identified Hackers Targeting Hawaii Water Utilities and unidentified Oil & Gas Pipeline in US
Chinese hackers are positioning themselves inside critical US infrastructure by targeting careless office workers in a bid to cause 'societal chaos' from within should war break out.
Beijing's military have burrowed into more than 20 major suppliers in the last year alone including a water utility in Hawaii, a major West Coast port and at least one oil and gas pipeline, analysts have revealed. They have bypassed elaborate cyber security systems by intercepting passwords and log-ins unguarded by junior employees, leaving China 'sitting on a stockpile of strategic' vulnerabilities.
"It is very clear that Chinese attempts to compromise critical infrastructure are in part to pre-position themselves to be able to disrupt or destroy that critical infrastructure in the event of a conflict" stated Brandon Wales, executive director of the Department of Homeland Security's Cybersecurity and Infrastructure Security Agency (CISA).
As a result of these cyber concerns, the Biden administration introduced mandatory regulations for industries in the oil and gas pipeline sector in summer 2021. Additionally, the Environmental Protection Agency introduced a directive for states to disclose cyber threats within their public water system evaluations in March. After that, three states filed lawsuits against the administration, alleging excessive regulatory control.
Victim: Unidentified Oil & Gas Pipeline
Unidentified Oil & Gas Pipeline
Victim: Hawaii Water Utility
Hawaii Water Utility
Reference: China’s cyber army is invading critical U.S. services
Reference: Chinese-affiliated hacking groups infiltrated critical American infrastructure, including Hawaii water utility and at least one oil and gas pipeline, US officials say
Incident: No Databreach from Cyberattack at Fulcrum Utility Services in UK
Fulcrum Utility Services Ltd - Sheffield-based multi-utility infrastructure and services provider - Says it has recently managed a cyber security incident, after detecting unauthorized activity on its network. The activity has now ceased and the company's IT systems have been securely reinstated. Adds that the "majority" of its operations were able to continue, however access to managerial and system information has been limited and work is still ongoing to correct this. No data was breached during the cyber attack, Fulcrum notes.
"The Board will provide a further update as and when appropriate," the company says.
Reference: NewsFulcrum Utility Services hit by cyber attack but no data breached
Victim: Fulcrum Utility Services Ltd
Fulcrum Utility Services Ltd - Sheffield-based multi-utility infrastructure and services provider -
Incident: Data Breach at Compass Group Italia
A ransomware-type attack recently hit Compass Group Italia. The company manages numerous canteen services in schools throughout Italy. The data that may have been stolen can be sensitive depending on the company branch involved. Compass Group Italia said the company's operations were not compromised. However, the focus of attention is now on data security, with the company working diligently to ensure that any sensitive information is protected.
The Akira group is suspected to be behind the attack.
Reference: Cyber attack on Compass Group Italia: the data of many school canteens also at risk
Victim: Compass Group
Compass Group plc is a British multinational contract foodservice company headquartered in Chertsey, England.[3] It is the largest contract foodservice company in Europe, ahead of Sodexo, employing over 500,000 people
Incident: Data Breach at Aqualectric Utilities in Curaçao
Aqualectra Utilities witnessed a breach of its digital infrastructure. With data soon to be available for download, the Akira ransomware attack on Aqualectra Utility compromised operational files, business documents, and a plethora of payment records. The breach threatens the security and privacy of over 80,000 households and companies relying on Aqualectra’s water and electricity services.
Reference: Detected: Aqualectra Utility falls victim to Akira Ransomware
Reference: Akira Ransomware Strikes Again: Compass Group Italia and Aqualectra Utility Hit by Data Breach
Victim: Aqualectra Utility
government-owned utility provider in Curacao
Reference: Medical test company’s ‘serious and systemic failures’ led to cyber-attack, watchdog says
Incident: Town Mayor Criticizes Bluewater Health Hospital on Public Dissemination of Ransomware Attack Information.
Bluewater Health appears to be the hardest hit of a group of southwestern Ontario hospitals targeted in the cyber-attack. The affected hospitals said restoration is not expected to be complete until mid-December. Patient records dating back more than 30 years, affecting 267,000 patients, were stolen by last month by hackers. All patients treated at its Sarnia Lambton Hospitals from 1992 onward were affected by the breach. In addition, the social insurance numbers of about 20,000 people were taken.
Bluewater Health has refused to answer questions about the ransomware attack, instead issuing updated statements on its recovery progress.
Reference: Bluewater Health says 250K patients compromised by cyber attack
Reference: ‘This affected everyone’: Sarnia mayor critical of lack of transparency in Bluewater Health cyber-attack
Victim: Bluewater Health
Bluewater Health is a hospital in Sarnia, Ontario. It was opened October 3, 1896 as Sarnia General Hospital and was the community's first public hospital. In 2010, with extensive renovations to the two existing buildings and construction of a third, it was renamed Bluewater Health.
Incident: Blue Waters Bottling Company Operations Affected by Ransomware Attack
Blue Waters Products Limited is the latest local company to fall victim to a cyberattack. Officials of the company, located at Orange Grove Estate, Trincity, confirmed that their operations had been affected by a ransomware attack. They have not yet determined whether the hacker gained access to data and other sensitive company information.
A screenshot of one of the company’s computers shows a ransom notice warning that Blue Waters’ data will be released on the dark web. Blue Waters CEO Dominic Hadeed said company officials are still assessing the cyberattack and have taken the necessary actions. Lockbit3 claimed responsibility for the attack
“Our automated ordering and delivery capabilities are now back to normal,” he said. “Once we know more about how it happened, we will be communicating internally and with our business partners accordingly.”
Reference: LockBit3 takes responsibility for data breach of BlueWaters bottled water and drinks
Victim: Blue Waters Products Limited
Blue Waters Products Limited established in the year 1999 in Trinidad and Tobago is the preferred brand of bottled purified drinking water in the Caribbean.
Reference: Cybercriminals attack Blue Waters
Incident: Data Breach at B&G Foods in January 2023
On Sunday, February 5, 2023, B&G Foods became aware of a systems instrusion by "an unauthorized third party that was conducting indiscriminate cyber-attacks on
businesses world-wide". Employee records were accessed between Jan 23 and Feb 7 : name, address, social security number and/or date of birth. "After we shut down the unauthorized access, we implemented additional security measures designed to prevent a recurrence of such an attack and to protect the privacy of B&G Foods’ valued employees and former employees."
Reference: B&G notice of data breach
Victim: B&G Foods
B&G Foods is an American branded foods holding company based in Parsippany, New Jersey. The company was formed in 1996 to acquire Bloch & Guggenheimer, a Manhattan-based producer of pickles, relish and condiments which had been founded in 1889
Reference: Atlassian urges customers to take ‘immediate action’ to protect against data-loss security bug
Incident: Hackers Exploits Critical Security Hole in Atlassian Software
Software company Atlassian is now saying that a recently disclosed issue is being exploited by hackers using the Cerber ransomware — a ransomware brand thought to be long-defunct. Atlassian CISO Bala Sathiamurthy warned the public on November 3 about the bug, which he said could lead to “significant data loss if exploited.” The company escalated this on November 6, 2023 following evidence of malicious activity, including ransomware attacks.”
The Cerber ransomware operation was active between 2016 and 2019. Several ransomware experts said they had not seen the Cerber ransomware used in years.
Threat Actor: Cerber ransomware operation
The Cerber ransomware operation was active between 2016 and 2019 but was seen in 2021 targeting Confluence instances vulnerable to another bug, CVE-2021-26084. At the time, the hackers behind the 2021 campaign targeted victims in China, Germany, and the U.S., demanding 0.04 bitcoin in exchange for the decryptor.
Several ransomware experts said they had not seen the Cerber ransomware used in years.
Victim: Atlassian Corporation
Atlassian Corporation is an Australian software company that develops products for software developers, and project managers among other groups. The company is domiciled in Delaware, with global headquarters in Sydney, Australia, and US headquarters in San Francisco
Reference: Atlassian confirms ransomware is exploiting latest Confluence bug
Reference: Atlassian hit by Chinese state-linked hackers
Reference: Hacker attack on German energy service provider Ista
Incident: Hamburg Airport Website Disabled by DDoS Attack
Hamburg Airport fell victim to a hacker attack on Wednesday . The company confirmed this in response to an inquiry from the Abendblatt. The website hamburg-airport.de was “not always accessible during the day yesterday,” said airport spokeswoman Janet Niemeyer on Thursday. The reason for this was a massive so-called Distributed Denial-of-Service (DDoS) attack. Websites are usually loaded with so many visits that the servers crash. Only the accessibility of the website was affected, said Niemeyer. She did not say how long the outage lasted. No other airport services or systems were affected.
Victim: Hamburg Airport
Hamburg Airport, Germany
Reference: Hackers paralize the website of Hamburg Airport
Incident: Karlsruhe Public Utility Company Claims to Successfully Fend Off Cyberattack.
Hackers have managed to break into the Karlsruhe public utilities network. The perpetrators are said to have read passwords and spied out other data. The Karlsruhe public utility company claims to have successfully fended off the cyber attack.
The attackers successfully broke into the computer of a high-ranking municipal utility employee on February 1st and searched the system for hours. This was apparently preparations for a ransomware attack, as the criminals left a note mentioning a three-digit million sum. The Karlsruhe public utility company confirms the attack to Spiegel, but claims that its supply-related IT was not affected. According to a company spokesman, the malware was unable to spread. The separate systems of the critical infrastructure were also not infiltrated. There was no encryption by ransomware.
Victim: Karlsruhe Public Utility Company
Karlsruhe Public Utility Company
Reference: Hacker attack on Karlsruhe public utilities
Incident: Filstal Energy Supply (EVF) Affected by DDoS Attack on IT Supplier
The Filstal energy supply (EVF) has been struggling with IT problems for several days. The cause is said to be DDoS attacks on their IT service provider imos. “Unfortunately, since March 13th, there have been recurring temporary restrictions and even outages of our services,” says the Göppingen IT service on March 27..
Reference: Network attack on IT service provider of the Filstal energy supply
Victim: Filstal energy supply (EVF)
Germany
Incident: German Cloud Service Provider Hacked
The hosted exchange of the German provider United Hoster suffered a ransomware attack on Saturday (May 20th). "As part of an internal investigation, it was determined that an attacker exploited an unknown vulnerability in Microsoft Exchange to gain access to the Exchange Server," a company spokesman told heise online
United Hoster is building a new Microsoft Exchange environment into which customers will eventually be migrated so that they can receive the full range of functions again. The company does not provide information about the number of affected customers or mailboxes, as this is a business secret. It is also unclear when United Hoster expects to restore services in the new structure. The company spokesman did not specify which Exchange security gap the attackers were able to abuse.
Victim: United Hoster
United Hoster German cloud service provider
Reference: Ransomware attack: Hosted Exchange by United Hoster offline [translated]
Reference: Ransomware attack on United Hoster
Incident: German Biogas Register Offline Due to Cyberattack
The hosting service provider of the German Energy Agency Dena has fallen victim to a ransomware attack. This led to a failure of the biogas register. All systems were immediately switched off.
Dena has decided to set up the biogas register system on the servers of another external data center operator. “This serves as a safeguard in case the existing server structure could no longer be used,” it says.
Reference: German biogas register offline due to cyber attack
Victim: Deutschen Energie Agentur, Dena
The Biogas Register Germany is a platform for standardised and simple documentation of evidence of biogas quantities and qualities in the natural gas grid.
Incident: Dutch Electromagnet Manufacturer Kendrion hit by Cyberattack
The control technology manufacturer Kendrion was hacked. An unauthorized third party gained access to the company's network. The company took all of its systems offline and to keep operations running, relies on an emergency plan. Based on the current status of the investigation, it cannot be ruled out that the perpetrator also obtained company data.
Kendrion location in Malente was also affected by the attack. Development and sales are currently at a standstill, production could continue. Kendrion has sent home most of the 300 employees in Malente.
Kendrion issued a statement on September it had "fully resumed all operations. The incident has had no significant impact on our customer deliveries and is not expected to have a material impact on the company’s financial results."
Reference: Dutch Magnet Manufacturer Kendrion Hit by LockBit Ransomware Attack
Reference: Kendrion fully resumed operations after cyber security incident
Reference: Hacker attack on Kendrion [translated]
Incident: German Hochsauerland Water and Energy Utilities Ward off Consequences of Cyberattack
The utilities HochsauerlandWasser and HochsauerlandEnergie were hit by a hacker attack. Customer service “out of operation” for several days. The monthly payments for drinking water, electricity and natural gas deliveries due in October will be collected at a later date.
Neither the supply of drinking water nor the supply of electricity and gas were affected or endangered by the hacker attack at any time.
Victim: HochsauerlandWasser and HochsauerlandEnergie utilities
The utilities HochsauerlandWasser and HochsauerlandEnergie
Reference: HSW AND HE: SERVICES LIMITED
Reference: Hacker attack on water and energy suppliers
Incident: Cities and Municipalities in North Rhine-Westphalia Offline after Cyberattack
The municipal service provider Südwestfalen IT (SIT) said it was hit by a ransomware attack on the night from Sunday to Monday (October 30). In order to contain the attack, all connections to the data center were severed. This affects 72 member municipalities in South Westphalia. As the regional newspaper Sauerland Kurier reports, it is assumed in the Hochsauerland district that the IT failure will last several days. Most administrations can only be reached by telephone because email traffic is also affected, the report says.
Reference: Hacker attack causes administrative failure in NRW
Victim: Südwestfalen IT
German municipal service provider Südwestfalen IT
Incident: Cyberattack paralyzes systems at Bauer Group AG
The Bavaria-based civil engineering specialist, Bauer Group, was the victim of a cyber attack. Various systems were shut down or switched off as a precautionary measure. The websites were still down on Wednesday. This results in restrictions for the business partners of Bauer companies worldwide.
Update 10 Nov:
Following the attack on the IT infrastructure, the Group’s business can continue in most areas, even with restrictions in one place or another. “Our construction sites in the Geotechnical Solutions and Resources segments are continuing to operate, we can also deliver equipment and Sales and Materials Management can also continue to work. To this end, we have switched many digital processes back to manual processes over the past week. Our solvency has also not been affected by the attack,” says Peter Hingott, Executive Board member of BAUER AG.
However, as there are individual areas of the company that are severely restricted, such as machine production and associated teams, the response in these areas is to reduce working hours and bring forward vacations. There are also plans to use short-time working for these areas where necessary. “What we have achieved in the last two weeks is a great achievement." "We continue to ask our business partners for understanding and patience if there are currently delays or problems in our cooperation,” says Peter Hingott.
Reference: BAUER Group became target of an attack on IT infrastructure
Reference: Hacker attack on Bauer AG [translated]
Victim: Bauer AG
The BAUER Group is a leading provider of services, equipment and products related to ground and groundwater. The Group operates a worldwide network on all continents. The operations are divided into three future-oriented segments with a high potential for synergy: Geotechnical Solutions, Equipment and Resources.
Incident: Cyberattack Disrupt Operations at North Texas Water Utility
A water utility in North Texas is dealing with a cybersecurity incident that caused operational issues. North Texas Municipal Water District (NTMWD) provides wholesale water, wastewater and solid waste management services to more than 13 cities in the state. Alex Johnson, director of communications for NTMWD, told Recorded Future News that they recently detected a cyberattack affecting their business computer network.
“Most of our business network has been restored. Our core water, wastewater, and solid waste services to our Member Cities and Customers have not been impacted by this incident. We continue to provide those services as usual,” Johnson said. “Our phone system was also affected by this incident, and we hope to have it back online this week.
Victim: North Texas Municipal Water District (NTMWD)
With more than 850 employees, North Texas Municipal Water District (NTMWD) provides wholesale water, wastewater and solid waste management services to more than 13 cities in the state, including Plano and Frisco.
Reference: One of North Texas Largest Water Suppliers is Latest Victim of Cyberattack
Reference: North Texas water utility serving 2 million hit with cyberattack
Incident: Killnet Launches DDoS Attacks on EUROCONTROL Website
EUROCONTROL has confirmed that its website has been under attack since April 19 when pro-Russian hackers claimed responsibility for the disruption. This attack has since caused interruptions to the website and web availability. The cyberattack did not disrupt any flight operation.
Russia’s KillNet group claimed to be behind the last weekend a DdoS attack targeting Eurocontrol, the European air traffic control organization. A DDoS attack on EUROCONTROL's website could have serious repercussions, with the potential to disrupt air traffic control across Europe.
Victim: EUROCONTROL
EUROCONTROL is a European organization responsible for managing air traffic control across the continent. Coordinating commercial traffic between 41 states, which include the EU and their national air-traffic control systems. Based in Brussels, Belgium
Reference: EUROCONTROL’s Website Attack And Ongoing Cybersecurity Implications
Reference: Eurocontrol hit by a cyberattack
Incident: Toyota T-Connect Source Code Exposed on Github for 5 Years
Toyota Motor Corporation customers' personal information may have been exposed after an access key was publicly available on GitHub for almost five years. The T-Connect site source code was mistakenly published on GitHub. The code contained an access key to the data server that stored customer email addresses and management numbers.
Toyota T-Connect is the automaker's official connectivity app that allows owners of Toyota cars to link their smartphone with the vehicle's infotainment system.
Reference: Toyota discloses data leak after access key exposed on GitHub
Incident: Toyota Databreach for Ten Years Exposes Car Location Data of over 2M Customers
Toyota Motor Corporation disclosed a data breach on its cloud environment that exposed the car-location information of 2,150,000 customers for ten years, between November 6, 2013, and April 17, 2023. "It was discovered that part of the data that Toyota Motor Corporation entrusted to Toyota Connected Corporation to manage had been made public due to misconfiguration of the cloud environment," reads the notice (machine translated). No customers are believed to be at risk of criminals tracking down a user’s car, as they would be difficult to track without knowing a target vehicle’s VIN.
This incident exposed the information of customers who used Toyota's in-car smart service T-Connect for voice assistance, customer service support, car status and management, and on-road emergency help between January 2, 2012, and April 17, 2023.
Victim: Toyota Motor Corporation
Toyota Motor Corporation
Reference: Toyota: Car location data of 2 million customers exposed for ten years
Reference: Toyota data breach exposes 10 years’ worth of data for over 2m customers
Reference: Honolulu Handi-Van Servers Hit By A Cyberattack, Forcing Passengers To Rebook Rides
Victim: Port Authority of Groningen
Groningen The Netherlands
Victim: Port Authorities in The Netherlands
Port Authority Rotterdam, Groningen, Amsterdam, and Den Helder
Reference: Dutch ports’ websites offline for hours, days due to pro-Russian cyber attacks
Incident: DDoS Attack Took Down the North Sea Port Website
A DDoS attack took down the North Sea Port website, the company that operates the ports of Vlissingen and Terneuzen in Zeeland, and the Gent port in Belgium. The website was inaccessible for several hours, starting at 8:30 a.m. on Tuesday.
By early afternoon, the attack had been repelled, and the site was up and running again. Work in the port continued as usual, those systems were not affected.
Victim: North Sea Port
North Sea Port operates the ports of Vlissingen and Terneuzen in Zeeland, Netherlands and the Gent port in Belgium.
Reference: Zeeland port website hit by DDOS attack, possibly by Russian hackers
Incident: Dutch Port Authority Websites Bombarded With a DDoS Attack
The Port of Rotterdam, the largest seaport in Europe, reportedly suffered a major cyberattack that knocked off its official website for hours. According to Dutch news agency RTL Nieuws, a group of pro-Russian hackers targeted the Port of Rotterdam’s website and bombarded it with a DDoS attack. The websites of several other Dutch ports, including Groningen, Amsterdam, and Den Helder were also targeted by the threat actors.
While the official websites of the port authorities in Rotterdam, Amsterdam, and Den Helder were offline for several hours, the Groningen Seaport website was offline for the entire weekend. “For us, the website is important because we can inform the public, but we are not dependent on the website,” a spokesperson for the Port of Rotterdam said.
Port authorities also said that no other internal systems were affected by the attack and systems used for handling shipping were not impacted.
The Dutch National Cyber Security Centre repo
Reference: Pro-Russia Hacker Group Claims Major DDoS Attack On The Port Of Rotterdam
Reference: Pro-Russia Hacker Group Claims Major DDoS Attack On The Port Of Rotterdam
Incident: Former Employee Indicted for Water Treatment Plant Attack in CA
A former employee of Discovery Bay Water Treatment Facility in California was indicted by a federal grand jury for intentionally attempting to cause malfunction to the facility’s safety and protection systems. Rambler Gallo, 53, was a full-time employee of a private Massachusetts company under contract with Discovery Bay to operate the town’s water treatment facility. He had an “instrumentation and control tech” role, which he fulfilled between July 2016 and December 2020.
The indictment alleges that Gallo had installed remote control software on his employer’s systems and also his personal computer, which enabled him to monitor instrumentation readings and control the electromechanical processes of the facility.
Victim: Discovery Bay Water Treatment Facility
Discovery Bay Water Treatment Facility in California
Reference: Former employee charged for attacking water treatment plant
Incident: Attack on Swedish medical technology provider disrupts municipal British ambulance services.
Attack on Swedish medical technology provider disrupts municipal British ambulance services.
Swedish healthcare and medical technology provider Ortivus disclosed a cyber incident that took place on July 18, which affected UK customers using their cloud-hosted MobiMed ePR electronic patient record system. The UK National Health Service (NHS) confirmed the intrusion impacted the ambulance services in several parts of the country, preventing access to patient medical histories by ambulance crews.
Victim: Ortivus
Swedish healthcare and medical technology provider Ortivus
Reference: Cyber attack affects two south England ambulance services
Reference: British ambulances unable to access patient records system following cyberattack
Incident: Cyberattack Affects Platform used by 12 Government Ministries in Norway
The Norwegian government is warning that its ICT platform used by 12 ministries has suffered a cyberattack after hackers exploited a zero-day vulnerability in third-party software.
This platform is used by twelve ministries in the country, except for the Prime Minister's Office, the Ministry of Defense, the Ministry of Justice, and the Ministry of Foreign Affairs. The hackers might have accessed and/or exfiltrated sensitive data from the ICT system, leading to a data breach.
Despite the compromised platform's critical role in the government's daily operations, the recent cyberattack will not necessitate a halt in work activities.
Victim: Norwegian Government
Norwegian Government
Reference: Norwegian government IT systems hacked using zero-day flaw
Incident: Widespread System Outages after Cyberattack at Bermuda Government
A major cyberattack has hobbled government operations in Bermuda, with officials struggling to restore service. “It is clear that this was a sophisticated and deliberate attack that has resulted in unprecedented stress on basic government systems,” Premier David Burt said. The resulting widespread internet outages affected all government agencies and more.
"After the attack that the government is slowly restoring operations after being hit by a “very sophisticated” cyberattack a week ago. An in-depth forensic audit is underway to determine how the attack occurred, and so far, experts have not uncovered evidence that sensitive data was stolen:", Premier David Burt said. He declined to say whether it was a ransomware attack.
All systems were immediately taken offline, and network use was strategically abandoned. The Government’s focus has been on safely restoring system functionality, particularly those systems that support providing services to the public.
Victim: Government of Bermuda
Government of Bermuda
Reference: Cyber-Attack Update from Premier David Burt JP, MP
Reference: Bermuda’s premier attributes system outages to ‘Russia-based’ attackers
Reference: Bermuda premier says ‘sophisticated and deliberate’ cyberattack hobbles government services
Reference: ‘Redfly’ hackers infiltrated power supplier’s network for 6 months
Incident: Databreach at European Telecommunications Standards Institute (ETSI)
On 27 September 2023 the European Telecommunications Standards Institute (ETSI) reported that hackers have stolen a database identifying its users.
It is not yet clear whether the attack was financially motivated or if the hackers had intended to acquire the list of users for espionage purposes.
Following the incident, ETSI, which is based in the Sophia Antipolis technology park in the French Riviera, said it brought in France’s cybersecurity agency ANSSI “to investigate and repair the information systems.” The nonprofit said the “vulnerability on which the attack was based has been fixed,” although it did not identify the vulnerability.
Victim: European Telecommunications Standards Institute (ETSI)
European Telecommunications Standards Institute (ETSI) based in the Sophia Antipolis technology park in the French Riviera
Reference: Hackers steal user database from European telecommunications standards body
Reference: Cyber attack on ETSI
Incident: Spanish Aerospace Company targeted by North Korean Lazarus Gang
Hackers connected to a notorious group within the North Korean government launched an attack against an aerospace company in Spain, according to researchers at security company ESET. In a report on Friday, researchers said they discovered a campaign by hackers connected to Lazarus — an infamous group that has stolen billions from cryptocurrency firms over the last two years.
The North Korean 'Lazarus' hacking group targeted employees of an aerospace company located in Spain with fake job opportunities to hack into the corporate network using a previously unknown 'LightlessCan' backdoor. The hackers utilized their ongoing "Operation Dreamjob" campaign, which entails approaching a target over LinkedIn and engaging in a fake employee recruitment process that, at some point, required the victim to download a file.
Employees of the unnamed company were sent messages on LinkedIn from a fake Meta recruiter and tricked into opening malicious files that purported to be coding quizzes or challenges. When opened, the files infect a victim’s device with a backdoor that would allow the hackers to conduct espionage, according to ESET.
Malware: LightlessCan malware
The LightlessCan backdoor: ESET says LightlessCan is a successor to BlindingCan, based on source code and command ordering similarities, featuring a more sophisticated code structure, different indexing, and enhanced functionality.
The malware replicates many native Windows commands like ping, ipconfig, netstant, mkdir, schstasks, systeminfo, etc., so it can execute them without appearing in the system console for better stealthiness against real-time monitoring tools. Since those commands are closed-source, ESET comments that Lazarus has either managed to reverse engineer the code or drew inspiration from the open-source versions. Another interesting aspect reported by ESET is that one of the LightlessCan payloads they sampled was encrypted and could only be decrypted using a key dependent on the target's environment.
This is an active protection measure to prevent outside access to the victim's computer, for example, by security researchers or analysts.
This discovery underscores that Lazarus' Operation Dreamjob is not solely driven by financial objectives, such as cryptocurrency theft, but also encompasses espionage goals.
Victim: Unidentified Spanish Aerospace company
Unidentified Spanish Aerospace company
Reference: Lazarus hackers breach aerospace firm with new LightlessCan malware
Reference: North Korean gov’t hackers targeted aerospace company in Spain
Incident: Iranian Linked Cyber Gang Shut down Aliquippa Drinking Water Supply Line Pump
The Municipal Water Authority of Aliquippa said on Saturday that one of their booster stations had been hacked by an Iranian-backed cyber group.
Matthew Mottes, the chairman of the board of directors for the Municipal Water Authority of Aliquippa, confirmed to KDKA-TV that the cyber group, known as Cyber Av3ngers, took control of one of the stations. An alarm went off as soon as the hack had occurred. Mottes added that the station, located on the outskirts of town, monitors and regulates pressure for Raccoon and Potter Townships. He stressed that there is no known risk to the drinking water or water supply. The machine that was hacked uses a system called Unitronics, which is software or has components that are Israeli-owned.
Aliquippa workers disabled the affected equipment and are currently working on back up methods of maintaining water pressure to the communities.
Threat Actor: Cyber Av3ngers
Iranian-backed Cyber Av3ngers Hacktivist group has been active since at least 2020.
Victim: Municipal Water Authority of Aliquippa, PA
The Municipal Water Authority of Aliquippa, PA
Reference: Iranian Linked Cyber Army Had Partial Control of Aliquippa Water System
Reference: Municipal Water Authority of Aliquippa hacked by Iranian-backed cyber group
Incident: Employee of Taiwanese D-Link Falls for Phishing Leading to Data Breach
D-Link Corporation, a Taiwanese networking equipment, confirmed a data breach linked to information stolen from its network and put up for sale on BreachForums earlier this month.
The intrusion vector was likely an employee who unintentionally fell victim to phishing. The attacker claims to have stolen source code for D-Link's D-View network management software, along with millions of entries containing personal information of customers and employees, including details on the company's CEO.
Victim: D-Link
Taiwanese networking equipment manufacturer D-Link
Reference: D-Link confirms data breach after employee phishing attack
Reference: NoName Hacker Group Goes on Rampage, Targets German Government and Ministries
Victim: Geneva Airport
Geneva Airport, Switserland
Reference: Pro-Russian hackers step up attacks against Swiss targets, authorities say
Incident: DDoS Attack Caused Brief Disruption at German weapons manufacturer Rheinmetall
The Russian hacker group has today targeted the German weapons manufacturer Rheinmetall with a DDoS attack. Rheinmetall’s website was briefly unavailable on the morning of 28 March. Access was later restored.
Rheinmetall is expected to provide Ukraine with ammunition and weapons, such as tanks, which prompted the Russia-affiliated hackers to target the company.
Reference: NoName Hacker Group Targets German Weapons Manufacturer Rheinmetall with DDoS Attack
Incident: Ukrainian Hacktivists Temporarily Disabled Internet Services in some Russia Occupied Territories
Ukrainian hackers have temporarily disabled internet services in parts of the country’s territories that have been occupied by Russia. The group of cyber activists known as the IT Army said on Telegram that their distributed denial-of-service (DDoS) attack took down three Russian internet providers — Miranda-media, Krimtelekom, and MirTelekom — operating in the territories.
Early on Friday, Russian internet operators confirmed that they had experienced an “unprecedented level of DDoS attacks from Ukrainian hacker groups,” temporarily disrupting their operations. The attack affected services such as cellular networks, phone calls, and internet connections.
Victim: Russian internet providers — Miranda-media, Krimtelekom, and MirTelekom
Russian internet providers — Miranda-media, Krimtelekom, and MirTelekom
Reference: IT Army Ukrainian Hacktivist Group Hit ISPs in Occupied Territories
Reference: Ukrainian hackers disrupt internet providers in Russia-occupied territories
Incident: Cyberattack Causes Widespread Disruption for Lyca Mobile Customers
Lyca Mobile, a British telecom company, faced a network disruption due to a cyber attack over the weekend of September 30 - October 1.
“The issues affected all Lyca Mobile markets apart from the United States, Australia, Ukraine and Tunisia,” the company said. The attack prevented customers and retailers from accessing top-ups. National and international calling was impacted and it raised concerns about potential customer data compromise.
Reference: Lyca Mobile blames cyberattack for network disruption
Victim: Lyca Mobile
Lyca calls itself the world's largest international mobile virtual network operator with over 16 million customers. They offer pay-as-you-go SIM cards across 23 countries in Europe, Africa and Asia. Based in UK
Reference: Lyca Mobile Services Significantly Disrupted by Cyberattack
Reference: Cyberattack on British telecom Lyca prevented customers from making calls, topping up
Reference: Bangladesh hacktivists target critical infrastructure in India, Israel, and Australia
Reference: Bangladesh hacktivists target critical infrastructure in India, Israel, and Australia
Incident: Large Scale DDoS Attacks at Italian Airports
Mysterious team Bangladesh , a criminal hacker group that has attracted attention in the past for attacks especially against Indian and Israeli sites, targeted three Italian airports: those of Valle d'Aosta, Calabria and Puglia .
The attacks are of the DDoS (Distributed denial of service) type and have caused slowdowns on the sites. The Italian Cybersecurity Agency, as far as we know, has alerted the subjects potentially affected by the offensive: airports and, more generally, providers of essential services.
“Aeroporti di Puglia communicates that the analyzes carried out did not reveal any compromises to the functioning of the web services which are still regularly online”. Nor was there any damage to the computer systems of the various airports, so everything is proceeding regularly both in Bari Palese, Foggia and Brindisi.
Since the beginning of the Hamas-Israel crisis, there is also an increase in activity on the web, with the participation - among others - of hacktivists such as those of the Mysterious team Bangladesh appear to be: groups who carry forward a political message with their actions.
Threat Actor: Mysterious Team Bangladesh
Research by the cyber security firm Group-IB shows that the gang is actively targeting critical infrastructure in countries outside Bangladesh. It has already carried out over 750 Distributed Denial of Service (DDoS) and more than 70 website defacements in 2023.
Mysterious Team Bangladesh was founded by a threat actor with the nickname D4RK TSN in 2020 and is associated with Bangladesh. The motivations behind most of the gang’s attacks are religious and political. The group’s activity peaked in May 2023 when it announced a large-scale campaign against India.
Reference: Mysterious team Bangladesh attacks Italy, alert issued by ACN and 007 towards 3 Italian airports
Incident: BlackCat Allegedly Attacked Drone Systems Partner of NASA, Airbus
Unmanned drone systems maker, Autonomous Flight Technologies (AFT), has allegedly fallen victim to a cyberattack orchestrated by the notorious BlackCat ransomware group. The attackers claimed the Autonomous Flight Technologies data breach and purportedly sold exfiltrated data to an undisclosed foreign entity.
AFT, recognized for its cutting-edge unmanned drone technology, boasts prominent partnerships with industry giants such as Airbus, NASA, NBC, and Northrop Grumman. As the Autonomous Flight Technologies data breach remains unconfirmed, the industry awaits an official response from AFT while grappling with the broader implications of cybersecurity vulnerabilities in the rapidly advancing field of unmanned autonomous systems.
Victim: Autonomous Flight Technologies (AFT)
AFT, recognized for its cutting-edge unmanned drone technology, boasts prominent partnerships with industry giants such as Airbus, NASA, NBC, and Northrop Grumman.
Reference: NASA, Airbus Partner Autonomous Flight Technologies Targeted by BlackCat
Reference: Drone Systems Maker Autonomous Flight Technologies Targeted by BlackCat Ransomware
Incident: Cyberattack Disrupts Paris Wastewater Operations
The organization that manages wastewater for nine million people in and around Paris was hit with a cyberattack on Friday. Service public de l'assainissement francilien – known by its acronym SIAAP — manages nearly 275 miles of pipes throughout four French departments. IT teams have worked since Wednesday to secure industrial systems and close off all external connections in order to prevent the attack from spreading.
Officials said they have prioritized measures that allow them to “maintain the continuity of the public sanitation service for Ile-de-France residents.”
“The SIAAP crisis unit remains mobilized to manage the aftermath of this attack and support the continuity of the work of all of its agents from this week in a working environment largely degraded by the current situation,” they said, according to a machine translation of the statement.
“This mobilization will continue until a return to normal can be ensured.”
The organization has set up local systems to answer any questions from the public and said they are in constant communication with various government agencies about the situation.
Reference: Cyberattack targets Paris wastewater management organization
Victim: Service public de l’assainissement francilien – SIAAP
Paris wastewater agency: Service public de l'assainissement francilien – known by its acronym SIAAP — manages nearly 275 miles of pipes throughout four French departments.
Reference: Greater Paris wastewater agency dealing with cyberattack
Reference: Simpson Manufacturing Takes Systems Offline Following Cyberattack
Incident: Cyberattack cripples Operations at Ace Hardware in US
Cyberattack cripples Ace Hardware’s internal systems, resulting in shipment delays, suspended online orders.
According to a notice that Ace President and CEO John Venhuizen sent to retailers and customers on Sunday evening, the incident occurred on the morning of October 29 and affected most of the organization’s operating systems.
“ACENET, our Warehouse Management Systems, the Ace Retailer Mobile Assistant (ARMA), Hot Sheets, Invoices, Ace Rewards and the Care Center’s phone system have been interrupted or suspended,” reads a copy of the notice, shared on Reddit.
The company informed Ace members that shipments were disrupted and that deliveries were delayed, urging customers to refrain from placing further orders.
Victim: Ace Hardware
Ace Hardware has more than 5,600 locally owned and operated hardware stores across roughly 70 countries.
Reference: Cyberattack Disrupts Ace Hardware’s Operations
Incident: Japanese Bicycle Manufacturer Shimano hit by Lockbit Gang
World-leading bicycle part manufacturer Shimano has suffered a major cyber attack. 4.5 terabytes of sensitive data breached including employee passport data, financial documents and confidential diagrams.
LockBit gave Shimano a 5 November deadline to pay ransom, to which it appears Shimano refused to pay, as the hacking group has listed the company’s data as published. Shimano is yet to issue a statement on the breach, but responding to media inquiries, the company said: “This is an internal matter at Shimano, and we cannot comment on anything at this time.”
Reference: Shimano hit by ransomware attack
Reference: Shimano faces threat of massive data breach by LockBit ransomware group
Victim: Shimano
World-leading bicycle part manufacturer Shimano in Japan
Reference: LockBit strikes at bicycle giant Shimano, steals 4.5TB of data
Reference: Boeing Confirms Cyber Incident Following Ransomware Attack Report
Reference: Infy subsidiary in US hit by ransomware
Incident: Cyberattack Disrupts Systems at Infosys McCamish Systems
Infosys McCamish Systems, a subsidiary of India-based IT services giant Infosys Ltd. (NYSE: INFY), experienced a cyberattack. The company reported the incident in a regulatory filing on 3 November.
“Infosys McCamish Systems (IMS), a subsidiary of Infosys BPM Limited (a wholly owned subsidiary of Infosys Limited), has become aware of a cybersecurity event resulting in non-availability of certain applications and systems in IMS,” according to the filing.
“Data protection and cybersecurity are of utmost importance to us,” the statement continued. “We are working with a leading cybersecurity products provider to resolve this at the earliest and have also launched an independent investigation with them to identify potential impact on systems and data.”
Reference: INFOSYS MCCAMISH SYSTEMS SUBSIDIARY HIT BY CYBERATTACK
Victim: Infosys McCamish Systems
Infosys McCamish Systemsprovides business process outsourcing in the insurance space.
Incident: Yanfeng cyberattack disrupts production at Stellantis
A cyberattack that hit automotive parts production at Yanfeng International Automotive Technology in the US this week has had a knock-on effect at Stellantis, with the carmaker forced to halt assembly on certain lines.
In a short statement Stellantis said: “Due to an issue with an external supplier, production at some North America assembly plants has been disrupted. We are monitoring the situation and working with the supplier to mitigate any further impact to our operations.”
The carmaker said it would not provide information on affected plants or any other details. There has been no comment from Yanfeng.
Yangfeng manufactures key parts like seats, interiors, and electronics, among other components. Yanfeng also supplies General Motors but the carmaker has not yet said if it will have any impact on its current production schedule.
Reference: Yanfeng cyberattack disrupts production at Stellantis
Victim: Yanfeng Automotive Interiors
Yanfeng Automotive Interiors, Chinese global supplier to automanufacturing industry
Victim: Stellantis N.V
Stellantis, Dutch automotive company
Stellantis N.V. is a multinational automotive manufacturing corporation formed from the merger of the Italian–American conglomerate Fiat Chrysler Automobiles and the French PSA Group. The company is headquartered in Amsterdam.
Reference: Stellantis Production Stalled Over Cyberattack
Incident: Hacktivists Attack on Israel’s Rail Network
The Cyber Avengers hacker group reveals information showing that it targeted the Israeli railroad system's electrical infrastructure. Israeli media reported that "Israel's" railroad network has been targeted by a cyberattack. The Cyber Avengers hacker group has revealed information showing that it targeted the Israeli railroad system's electrical infrastructure.
Since 2020, the Cyber Avengers has hacked into and carried out numerous cyberattacks against the Israeli railroad systems, as per their Telegram channel. The group warned that if the Israeli occupation continues to pursue its crimes, it would deliver dreadful blows to Israeli infrastructure.
Victim: Israel Rail System
Israel Rail System
Reference: Israeli Rail System Comes Under Cyberattack
Reference: ‘Israel’s’ railroad network targeted by cyberattack: Israeli media
Incident: NoName Hits Swiss Governments and Rail sites with DDoS Attack
Swiss federal government websites and the online portal of the Swiss Federal Railways have been victims of malicious online attacks. Several websites of the federal administration are currently unavailable, Swiss public radio, SRF, reported on Monday.
According to the finance ministry, the sites were hit by a so-called DDoS attack, which aims to overload websites and applications with targeted requests so that they are no longer accessible. No data is lost in a DDoS attack.
The pro-Russian hacker group “NoName” has claimed responsibility for the attack on the federal government on its own Telegram channel, Tages-Anzeiger newspaper said. This group was also behind the attack on the Swiss parliament website (www.parlament.chExternal link) last week.
Victim: Swiss federal government
Swiss federal government
Victim: Swiss Federal Railways
Swiss Federal Railways
Malware: DDoS Attack
DDoS Attack
Reference: Swiss government and Federal Railways hit by cyberattacks
Victim: Canadian National Railway
Canadian National Railway
Incident: German Pump Manufacturer Down for 7 Days after Cyberattack
In February 2022, Kracht GmbH was attacked by unknown perpetrators, and important systems were brought to a halt. Systems were up and running again in seven days. The entire IT system was reorganized so the workforce could quickly return to day-to-day business.
"It was a worst case scenario, as unknown offenders managed to override our sophisticated security systems. We decided not to negotiate with the offenders." states Peter Schilg, Head of IT, Kracht GmbH
.
Reference: Kracht – Bechtle forensics restores the IT.
Reference: Cyber attack on pump manufacturers: unknown people blackmail company in MK
Victim: Kracht GmbH
Kracht GmbH in Werdohl is a leading German technology provider for pumps, fluid measurement, valves, hydraulic drives and customized system solutions. About 450 employees worldwide design, produce and sell the products.
Incident: Medusa Ransomware Gang Demands $8M Ransom from Toyota
Toyota Financial Services (TFS) has confirmed that it detected unauthorized access on some of its systems in Europe and Africa after Medusa ransomware claimed an attack on the company. The Medusa ransomware gang listed TFS to its data leak site on the dark web, demanding a payment of $8,000,000 to delete data allegedly stolen from the Japanese company. The threat actors gave Toyota 10 days to respond, with the option to extend the deadline for $10,000 per day. While Toyota Finance did not confirm if data was stolen in the attack, the threat actors claim to have exfiltrated files and threatened that the data will be leaked if a ransom is not paid.
Reference: Toyota confirms breach after Medusa ransomware threatens to leak data
Victim: Toyota Financial Services, subs. of Toyota Motor Corp
Toyota Financial Services, a subsidiary of Toyota Motor Corporation, is a global entity with a presence in 90% of the markets where Toyota sells its cars, providing auto financing to its customers.
Reference: Toyota Confirms Breach After Medusa Ransomware Threatens to Leak Data
Incident: Longbeach, CA Declares State of Emergency after Cyberattack
The City of Long Beach in the US state of California suffered a significant network security incident. The attack forced officials to take several of its systems offline and announce a state of emergency.
All public safety systems, including the Emergency Communications Centre and emergency response from Police and Fire haven’t been impacted by the cyber attack. Systems connected to the network were taken offline out of an abundance of caution to mitigate the impact of the cyber attack.
Victim: CIty of Longbeach, CA
CIty of Longbeach, CA
Reference: California’s City of Long Beach declares a state of emergency to respond to a major cyber attack
Reference: Estes commits to more technology spending after October cyberattack
Reference: Rhysida ransomware gang claims British Library cyberattack
Incident: British Library Systems Disrupted for Weeks after Ransomware Attack
In late October, the British Library first disclosed it was experiencing an unspecified cybersecurity incident that caused a “major technology outage” across its sites in London and Yorkshire, which downed its website, phone lines, and on-site services, such as visitor Wi-Fi and electronic payments.
Two weeks on, and the British Library outage is still ongoing. However, the organization has now confirmed the disruption is the result of a ransomware attack launched “by a group known for such criminal activity.” The British Library said that some internal data has leaked online, which “appears to be from our internal HR files.”
The British Library said in its latest statement that it could take weeks, or possibly even longer, for it to recover from the ransomware attack.
Victim: British Library
Great Britain's National Library
Reference: British Library confirms data stolen during ransomware attack
Reference: Yamaha Subsidiary Hit In Ransomware Attack
Reference: Yamaha Motor Confirms Data Breach Following Ransomware Attack
Incident: Data Breach at Idaho National Labs
Federal research center, Idaho National Laboratory (INL), experienced a massive data breach Sunday night, leading to the leak of employee addresses, Social Security numbers, and bank account information.
The breach is under investigation and federal law enforcement is involved, said INL media spokesperson Lori McNamara. INL is part of the United States Department of Energy (DoE). Historically, the lab has been involved with nuclear research, although the laboratory does other research as well. Battelle Energy Alliance for the DoE’s Office of Nuclear Energy manages INL.
Reference: Idaho National Labs Suffers Data Breach
Victim: Idaho National Laboratory
INL is part of the United States Department of Energy (DoE). Historically, the lab has been involved with nuclear research, although the laboratory does other research as well. Battelle Energy Alliance for the DoE’s Office of Nuclear Energy manages INL.
Incident: Ransomware Attack at Kyocera
Kyocera AVX (KAVX) Components Corporation suffered a ransomware attack in March on servers in its Greenville and Myrtle Beach, South Carolina locations that temporarily disrupted operations and resulted a breach of over 39,000 people, company officials said.
Upon learning of the incident, the company launched an investigation into the attack and hired an outside third party cybersecurity expert and notified law enforcement. KAVX is an American manufacturer of advanced electronic components and a subsidiary of the Japanese semiconductor giant Kyocera. Kyocera Corporation is a Japanese multinational ceramics and electronics manufacturer headquartered in Kyoto, Japan.
Reference: Kyocera AVX says ransomware attack impacted 39,000 individuals
Reference: Kyocera Suffers Ransomware Attack
Victim: Kyocera AVX (KAVX) Components Corporation
KAVX is an American manufacturer of advanced electronic components and a subsidiary of the Japanese semiconductor giant Kyocera. Kyocera Corporation is a Japanese multinational ceramics and electronics manufacturer headquartered in Kyoto, Japan.
Incident: Ransomware Attack at Yamaha Subsidiary
Yamaha Motor Co., Ltd. said one of the servers managed by its motorcycle manufacturing and sales subsidiary in the Philippines, Yamaha Motor Philippines, Inc. (YMPH), was hit by a ransomware attack, and a partial leakage of employees’ personal information.
Upon learning of the attack, the IT Center at Yamaha Motor headquarters in Japan and YMPH immediately set up a countermeasures team and have been working to prevent further damage while investigating the scope of the impacts, the company said in a statement.
In addition, the company said it is working on a recovery together with an external Internet security company, but it thinks it will take time until the full extent of the damage can be confirmed.
Reference: Yamaha Motor confirms ransomware attack on Philippines subsidiary
Reference: Yamaha Subsidiary Hit In Ransomware Attack
Threat Actor: INC Ransom
INC Ransom came about in August this year and targeted organizations spanning various sectors such as healthcare, education, and government in double extortion attacks.After gaining access, they move laterally through the network, first harvesting and downloading sensitive files for ransom leverage and then deploying ransomware payloads to encrypt compromised systems.
Victim: Yamaha Motor Co., Ltd.
A motorcycle manufacturing and sales subsidiary in the Philippines, Yamaha Motor Philippines, Inc. (YMPH).
Incident: 40% of Australians Without Internet or Phone for One Day
An outage at No.2 Australian telco Optus left nearly half the population without internet or phone on Wednesday, throwing payment, transport and health systems into chaos and raising questions about the fragility of the country's core infrastructure. The outage was first reported about 4 a.m. local time (1700 GMT on Tuesday) and it was not until almost 5.30 p.m. that Optus said services had been restored.
Some 10 million Australians, 40% of the population, are Optus customers and could not use smartphones, broadband internet or landlines for much of the day. Hospitals couldn't take phone calls, small businesses were unable to process electronic payments and train networks and ride share services were down simultaneously in some cities. The incident sparked criticism about the robustness of Australia's telecommunications network and in particular about Optus, which is owned by Singapore Telecommunications
Reference: Optus outage causes chaos in Australia before services restored
Reference: BianLian extortion group claims recent Air Canada breach
Incident: Customers’ Credit Card details Stolen at Spanish Airline: Air Europa
Spanish airline Air Europa, the country's third-largest airline and a member of the SkyTeam alliance, warned customers on Monday 9 October to cancel their credit cards after attackers accessed their card information in a recent data breach. "We inform you that a cybersecurity incident was recently detected in one of our systems consisting of possible unauthorized access to your bank card data," Air Europa said in emails sent to affected individuals and seen by BleepingComputer.
The credit card details exposed in the breach include card numbers, expiration dates, and the 3-digit CVV (Card Verification Value) code on the back of the payment cards. Air Europa warned affected customers to ask their banks to cancel their cards used on the airline's website due to "the risk of card spoofing and fraud" and "to prevent possible fraudulent use."
Victim: Air Europa
Spanish airline Air Europa is the country's third-largest airline and a member of the SkyTeam alliance.
Reference: Air Europa data breach: Customers warned to cancel credit cards
Incident: Cyberincident at American Airlines Pilot Union
The American Airlines pilot union – Allied Pilots Association- representing 15,00 pilots has suffered a data breached in an apparent cyber-incident. The organisation is based throughout the U.S.
Looking into the ramifications of this for Digital Journal is Kevin Kirkwood, Deputy CISO at LogRhythm.
Kirkwood begins by assessing the actual breach and the significance on the trade union: 2The American Airlines pilot union, representing 15,00 pilots, was hit with a ransomware attack late last week. Founded in 1963, it is the largest independent pilots’ union in the world.”
With the specific risk factors, Kirkwood says: “The organization is seeking outside experts to restore their systems and is still assessing what personally identifiable information (PII) was breached, only announcing that some systems were encrypted.”
Victim: Allied Pilots Association (American Airlines)
Allied Pilots Association is American Airlines' pilot union
Reference: Wings clipped: Aviation group caught out in cyberattack
Incident: Tri-City Medical Center in CA Operations Affected for Days
Tri-City Medical Center is diverting ambulance traffic to other hospitals Thursday as it copes with a cybersecurity attack that has forced it to declare “an internal disaster” as workers scramble to contain the damage and protect patient records. The Oceanside facility’s management confirmed the situation in a brief statement, indicating that the hospital’s emergency department remains “prepared to manage emergency cases” that may arrive in private vehicles and is “working with our other health system partners to ensure the provision of health care for our community.”
On Monday, 13 November, ambulance deliveries remain diverted from its emergency department and elective procedures remain canceled as the medical provider deals with the fallout of an attack on its digital assets and continues to operate in a state of “internal disaster.”
Victim: Tri-City Medical Center
Tri-City Medical Center in Oceanside, CA, USA
Reference: Four days in, cyber attack continues to impact Tri-City Medical Center in Oceanside
Reference: Tri-City Medical Center Announces Cyber Attack Causing an “Internal Disaster,” Leading Some to Raise Data Breach Concerns
Reference: Healthcare giant McLaren reveals data on 2.2 million patients stolen during ransomware attack
Incident: Boeing Hacked – Lockbit Gang Leaks almost 45 GB of Data Reportedly Stolen.
Boeing Co. is assessing a claim made by the Lockbit cybercrime gang it had “a tremendous amount” of sensitive data it would publish online if Boeing didn’t pay a ransom by November 2.
The hacking group posted a countdown clock on its data leak website with a message saying, “Sensitive data was exfiltrated and ready to be published if Boeing do not contact within the deadline! For now we will not send lists or samples to protect the company BUT we will not keep it like that until the deadline.”
Two weeks after the claimed attack, Lockbit leaked almost 45 gigabytes of data reportedly stolen.
Reference: Weeks after Boeing attack, ransomware group leaks allegedly stolen files
Reference: Boeing ‘Assessing’ Ransomware Claim
Reference: Shares in Rheinmetall drop after company discloses malware attack
Reference: Ventia Systems Affected By Cyber Incident
Reference: Augustans still seeing higher water bills after cyberattack
Reference: Dole incurs $10.5M in direct costs from February ransomware attack
Victim: Wildeboer
Wildeboer Bauteile GmbH develops, manufactures and markets products for fire protection, noise protection, air distribution an building control system
Reference: Hacker attack on the Stade drinking water association
Incident: Cyberattack at India’s National Institute of Ocean Technology
Medusa Ransomware group claims to have infiltrated NIOT's systems and encrypt critical data, including plans, CAD drawings, and other sensitive information. The website was down while reporting the incident.
Victim: National Institute of Ocean Technology (NIOT)
National Institute of Ocean Technology - NIOT - is a premier research institution in India dedicated to developing sustainable ocean exploration and conservation technologies.
The organization’s work is vital for understanding and protecting the ocean ecosystem and supporting the country’s economic growth through offshore activities such as fishing, oil and gas exploration, and shipping.
Reference: Medusa Ransomware Group Targets National Institute of Ocean Technology
Incident: Cyberattack Reported at Institute of Science and Technology Austria (ISTA)
On Nov 2, 2022 a targeted attack caused Institute of Science and Technology Austria (ISTA) to take down the entire research facility offline in an abundance of caution. Details about the extent of the attack are still under investigation.
Reference: Institute of Science and Technology Austria (ISTA) is victim of a targeted cyberattack
Victim: Institute of Science and Technology Austria (ISTA)
Research Institute of Science and Technology in Austria
Incident: Cyberattack at American Meterological Institute
On Monday, 24 April 2023, we discovered that some of our systems has been impacted by an encryption/ransomware attack. The perpetrator encrypted AMS servers, making them inaccessible.
The Cactus Blog leak site reported the attack on July 20.
Reference: AMS notification letter to customers
Victim: American Meteorological Society
American Meteorological Society
Incident: Cyberattack Crippled Facilities of Large Australia Port Operator
A cyber incident shut down Australia’s second largest port operator, which is now having an impact on moving goods in and out of the country. DP World Australia, which operates ports in Melbourne, Sydney, Brisbane and Fremantle, is responsible for 40 percent of maritime freight said it began responding to a cybersecurity incident this past Friday, according to an ABC News report. While ships remain able to unload freight, the freight cannot then leave the port site. The operator said it took immediate action which included disconnecting Internet connectivity, which stopped any ongoing unauthorized access.
Operations at container terminals in Melbourne, Sydney, Brisbane and Perth were disrupted from Friday to Monday morning. DP World Australia said its ports resumed operations at 09:00 local time "following successful tests of key systems overnight" - reports BBC.
There was no further word on what type of attack the port operator suffered and who was behind the assault.
Victim: DP World Australia
DP World is an Emirati multinational logistics company based in Dubai, United Arab Emirates. It specialises in cargo logistics, port terminal operations, maritime services and free trade zones. Formed in 2005 by the merger of Dubai Ports Authority and Dubai Ports International, DP World handles 70 million containers that are brought in by around 70,000 vessels annually. This equates to roughly 10% of global container traffic accounted for by their 82 marine and inland terminals present in over 40 countries. Until 2016, DP World was primarily a global port operator, and since then, it has acquired other companies up and down the value chain.
Reference: Cyberattack Shuts Down Aussie Ports
Reference: DP World shuts down ports after hack
Reference: Australian Ports Impacted by ‘Significant Cyber Security Incident’
Reference: Anatomy Of A Series Of Cyber Attacks
Incident: Largest Recorded Cyberattacks at Danish Energy Infrastructure
This past May, Danish critical infrastructure suffered the most extensive cyber-related attack it ever experienced in Denmark to date. In all, 22 companies that operate parts of the Danish energy infrastructure ended up compromised in a coordinated attack, according to a report by SektorCERT. The result was the attackers gained access to some of the companies’ industrial control systems and several companies had to go into island mode operation.
The attacks began on May 11, followed by 10 days of inactivity. A second wave of attacks began on May 22 when SektorCERT received an alert that one of its members had downloaded new firewall software over an insecure connection. Whether the attack came from servers associated with a unit of Russian military hackers popularly known as Sandworm cannot be said with certainty. Individual indicators of this have been observed, but we have no opportunity to neither confirm nor deny it, states the SektorCERT report.
Threat Actor: Unconfirmed
Unconfirmed at time of publishing
Victim: Danish Energy Infrastructure
National energy infrastructure in Denmark
Reference: SektorCERT The-attack-against-Danish-critical-infrastructure (PDF)
Reference: Denmark Hit With Largest Cyberattack on Record
Reference: Inside Denmark’s hell week as critical infrastructure orgs faced cyberattacks
Incident: Russian Sandworm Behind Operational Disruption of Ukraine Energy Facility in October 2022
According to Google-owned US cybersecurity firm Mandiant, Russia-linked hacking group Sandworm were behind hacks on Ukraine energy infrastructure during the October 2022 blackouts. The attack is a rare example of a cyber incident disrupting the physical operation of a targeted facility, according to Mandiant. There was potentially a two-month time period from when the attacker gained initial access to the SCADA system to when they developed the OT capability. Two days after the OT event, Sandworm deployed a new variant of CADDYWIPER in the victim’s IT environment to cause further disruption and potentially to remove forensic artifacts.
The techniques used during the attack show a growing maturity of Russia’s operational technology-oriented offensive cyber capabilities and overall approach to attacking such systems, Mandiant said.
Reference: Ukraine energy facility took unique Sandworm hit on day of missile strikes, report says
Reference: Russian spies behind cyber attack on Ukraine power grid in 2022 – researchers
Reference: Sandworm Disrupts Power in Ukraine Using a Novel Attack Against Operational Technology
Reference: Russia’s Sandworm hacking unit targets Ukrainian telecom providers
Incident: ‘Sandworm’ Attack Interrupts Service at 11 Telcom Providers in Ukraine
The state-sponsored Russian hacking group tracked as 'Sandworm' has compromised eleven telecommunication service providers in Ukraine between May and September 2023.
That is based on a new report by Ukraine's Computer Emergency Response Team (CERT-UA) citing 'public resources' and information retrieved from some breached providers. The agency states that the Russian hackers "interfered" with the communication systems of 11 telcos in the country, leading to service interruptions and potential data breaches.
Threat Actor: Sandworm
Sandworm is a very active espionage threat group linked to Russia's GRU (armed forces). The attackers have focused on Ukraine throughout 2023, using phishing lures, Android malware, and data-wipers.
Reference: Russian Sandworm hackers breached 11 Ukrainian telcos since May
Incident: Ransomware Hits Rea Magnet Wire Company
One of the world’s largest manufacturers of magnet and nonferrous wire products, Rea Magnet Wire Company, Inc. suffered a ransomware attack.
On October 4, Rea, a privately held company, sent a letter out to its customers saying they suffered a ransomware attack on September 9. The company said in the letter:
“On September 9, 2023, the Company was victimized by a ransomware attack. Fortunately, the attack did not affect all of the Company’s internal systems, and, through the quick and thoughtful work of our IT team and our external partners and advisors, we were able to restore substantially all of our systems within days. At present, the Company is operating normally, and we do not expect that the attack will have a material effect on the business going forward.
“In the course of the ransomware attack, the perpetrators stole information from the Company’s systems that may have included your name, mailing address, email address, phone number, date of birth, and social security number and/or tax identification number."
Reference: Rea Magnet Wire Company Hit In Ransomware Attack
Victim: Rea Magnet Wire Company
Fort Wayne, Indiana-based Rea produces copper, aluminum and brass-insulated magnet wire and bare wire used in the making of motors, transformers and coils. Rea also manufactures a number of specialty wire products.
Incident: Cyber Incident at Healthcare Solutions giant Henry Schein
On October 14, 2023, Henry Schein determined that some of its manufacturing and distribution businesses had been the target of a cyberattack. In response, Henry Schein reported the incident to law enforcement and took steps to contain the incident, including taking down portions of its computer system. Henry Schein also enlisted the help of third-party cybersecurity and forensic information technology experts to determine if any confidential information stored on its computer network was subject to unauthorized access.
The company has not shared any other details on the cyberattack, but its brief description suggests that it may have involved ransomware.
UPDATE 6 August 2024: The cyberattack disrupted its manufacturing and distribution businesses and had a residual impact on the company’s financial performance in 2024. ,
Victim: Henry Schein
Henry Schein is a retail company based out of Melville, New York. Henry Schein provides healthcare products and services to dental, medical and animal healthcare practices in 32 countries. The company is publicly traded on the NASDAQ under the symbol “HSIC.” Henry Schein, Inc. employs more than 22,000 people and generates approximately $12.7 billion in annual revenue.
Reference: Operations of Healthcare Solutions Giant Henry Schein Disrupted by Cyberattack
Reference: Henry Schein, Inc. Confirms Recent Cyberattack, Raising Data Breach Concerns
Incident: Simpson Manufacturing, a Building Materials Maker, Attacked
Engineering and building material provider, Pleasanton, California-based Simpson Manufacturing Co. Inc., fell victim to a cyberattack Tuesday.
The company said it experienced disruptions in its Information Technology area Tuesday and took some systems offline. The Company is working diligently to respond to and address this issue. The incident has caused, and is expected to continue to cause, disruption to parts of the Company’s business operations.
Reference: Building Materials Maker Simpson Manufacturing Attacked
Incident: Major Canadian Institutions Targeted in Cyberattacks.
Major Canadian institutions, including military and Parliament websites, have been targeted in recent cyberattacks. The Indian Cyber Force hacker group claims responsibility, causing disruption in various government-operated web platforms. However, Canada’s signals-intelligence agency reassures that these “nuisance” attacks probably haven’t compromised private data.
Canadian Armed Forces acknowledged that its website was temporarily inaccessible for mobile users after a DoDDS attack. The issue was resolved.
House of Commons website also suffered from a DDoS attack, resulting in slow loading or incomplete page displays starting Mondaywithin hours. Elections Canada faced a denial-of-service attack for about an hour early Wednesday.
Threat Actor: Indian Cyber Force (ICF)
Indian Cyber Force (ICF)
Reference: Cyberattacks hit military, Parliament websites as India-based group targets Canada
Victim: Canadian Government services
Canadian Government Services
Reference: CYBERATTACKS FROM INDIAN HACKER GROUP IMPACT CANADIAN GOVERNMENT WEBSITES
Reference: Canadian Air Force and government sites hacked by Indian threat actor
Reference: Kenya cyber-attack: Why is eCitizen down? Published
Incident: Cyberattack Causes Widespread Disruption in Kenya
Kenya endured a huge cyber attack that has affected services on a key government online platform. The BBC reported the attack against the region’s eCitizen portal. The portal is used by the public to access over 5,000 government services. Impacted were passport applications and renewal, e-visas for non-citizens visiting Kenya, as well as driving licenses, ID cards and health records from being issued.
Anonymous Sudan claim responsibility for an extensive cyberattack in Kenya which saw multiple government services impacted and raised digital concerns.
Mobile-money banking services M-Pesa were also affected by the attack. People were unable to make payments at shops. Public transport vehicles, hotels and other platforms also experienced difficulties. Millions of people across Kenya use Mobile-money to receive and spend money and the platform is seen as widely convenient for those who do not have access to essential banking services.
Victim: M-PESA
M-PESA is a mobile phone-based money transfer service, payments and micro-financing service, launched in 2007 by Vodafone and Safaricom, the largest mobile network operator in Kenya.
Victim: Kenya Government Services
Kenya Government
Reference: Cyberattack in Kenya impacts online government platforms
Reference: Lessons learned from Rio Tinto’s massive cyber-attack
Incident: Employee Data of Rio Tinto Group Uploaded to Dark Web
Personal data of Rio Tinto Ltd's former and current Australian employees were stolen by Cl0p. On April 6 the files were uploaded on the dark web. Ransom group Cl0p claims responsibility for the alleged data hack.
Rio Tinto confirmed that stolen employee data have been uploaded on the dark web, ABC News reported.
Victim: Rio Tinto Group
Rio Tinto Group is a British-Australian multinational company that is the world's second-largest metals and mining corporation. It was founded in 1873 when a group of investors purchased a mine complex on the Rio Tinto, in Huelva, Spain, from the Spanish government.
Reference: Stolen Rio Tinto employee data from cyber-attack uploaded on dark web: reports
Reference: Global mining group Rio Tinto Australian staff hit by cyberattack
Victim: Eskom
Eskom transforms coal, nuclear, fuel, diesel, water, and wind into more than 90% of the energy supplied to a wide range of customers in South Africa and the Southern African Development Community (SADC) region.
Eskom is one of the few remaining vertically integrated utilities connected to the Southern African Power Pool (SAPP) through an interconnected grid.
Incident: Reportedly Disruptive Cyberattack at Porsche South Africa’s Headquarters
Porsche South Africa’s headquarters in Johannesburg suffered a disruptive ransomware attack over the weekend, taking down several of the company’s systems and at least some backups.
MyBroadband news outlet in SA understands the attackers used a relatively new ransomware strain called Faust to encrypt the company’s files and lock it out of corporate systems. The news outlet contacted Porsche South Africa for further details about the incident, but it declined to comment — neither confirming nor denying the attack.
Reference: Porsche South Africa suffers ransomware attack
Incident: Cyberattack at LTL Specialist Estes Express
Estes Express confirmed that its IT systems were the target of an ongoing cyberattack, but said terminals and drivers were still picking up and delivering freight while the IT infrastructure was out of action.
“We’re working as quickly as possible to resolve this issue and to return to business as usual,” the Richmond, Va.-based company wrote on X, the platform formerly known as Twitter, noting that it was “unable to share specific details at this time.”
The disruption caused by the cyberattack at Estes will tighten LTL capacity further, even though it is likely a short-term event.
Victim: Estes Express (LTL)
Estes Express had 9,694 company-owned tractors and 37,032 trailers as of the end of 2022, according to TT data. The carrier currently has in excess of 280 freight terminals.
Estes ranks No. 14 on the Transport Topics Top 100 list of the largest for-hire carriers in North America. It ranks No. 5 on the LTL sector list.
Reference: Estes Express says widespread system outage caused by cyberattack
Reference: Cyberattack Hits Estes Express Lines’ IT Systems
Incident: Golf Gear Giant Callaway Data Breach Exposes 1.1 Million Accounts
Topgolf Callaway (Callaway) suffered a data breach at the start of August, which exposed the sensitive personal and account data of more than a million customers. This impacts customers of Callaway and its sub-brands Odyssey, Ogio, and Callaway Gold Preowned sites. According to the data breach notification, the incident affected 1,114,954 individuals in the United States.
Callaway has forced a password reset for all customer accounts to prevent unauthorized access.
Victim: Callaway
Callaway is an American sports equipment maker and seller specializing in golf equipment and accessories such as clubs, balls, bags, gloves, and caps. The company is present in more than 70 countries worldwide and has an annual revenue of over $1.2 billion. It employs roughly 25,000 people.
Callaway sub-brands operating under the same business umbrella: Odyssey, Ogio, and Callaway Gold Preowned sites.
Reference: document: Topgolf Callaway-ME App & Sample
Reference: Golf gear giant Callaway data breach exposes info of 1.1 million
Incident: Cyberattack Shuts Down 14 Facilities at Largest Healthcare System in MI
McLaren Healthcare in Michigan reported outages affecting billing and electronic health record systems. According to the Detroit Free Press, McLaren had to shut down the computer network at 14 different facilities — a situation that got so bad that employees had to communicate through their personal phones. The Black Cat/AlphV ransomware gang claimed to have stolen 6 TB of data.
UPDATE: 13 November: McLaren reports Black Cat stole data on 2.2 million patients.
Victim: McLaren Healthcare
McLaren operates 13 hospitals across Michigan, as well as other medical services such as infusion centers, cancer centers, primary and specialty care offices and a clinical laboratory network. The company has more than 28,000 employees and also has a wholly owned medical malpractice insurance company.
Reference: Large Michigan healthcare provider confirms ransomware attack
Incident: Ransomware Attack Suspends All Services at Seville City Council – $1.5M Ransom Demanded
The Seville City Council has returned to paper notes and in-person procedures after suffering the hijacking of its computer systems by a group of cybercriminals, as confirmed by the City Council. The pirates demand a ransom of more than one million euros and the City Council refuses to pay or agree “with cybercriminals”
The hackers have claimed up to one and a half million dollars (1,396,642 euros) from the municipal government, although it has assured that "in no case will it negotiate with cybercriminals." It is the second successful attack on the municipal website in three years.
All services have been affected.
Victim: Seville City Council
Seville City Council - Spain
Reference: The Seville City Council suspends all telematic services due to a computer hijacking: “It will not be negotiated”
Incident: Russian Railways Website Suffers DoDDS Cyberattacks
The Russian Railways website has suffered serious cyber attacks. The portal may experience disruptions, the company’s press service warned about this on February 26. “Our website is subject to regular, serious DDoS attacks. <…> The official mobile application of Russian Railways works normally. We are also increasing the number of operating ticket offices at stations so that all our passengers have the opportunity to buy tickets,” says a message published by Russian Railways on Telegram.
Reference: Russian Railways reported DDoS attacks on the site
Incident: Russian RZD Railway Cyberattack Disrupts Online Ticket Sales
The Russian state-owned railway company RZD said Wednesday that its website and mobile app were down for several hours due to a “massive” cyberattack, forcing passengers to only buy tickets at railway stations. RZD’s system was down for at least six hours, but the company said later on Wednesday that it had restored its operation despite ongoing attacks. Some of the company's online services are still unavailable due to the increased load, RZD said.
Victim: RZD railway company
Russian state-owned railway company RZD
Reference: Russian railway site allegedly taken down by Ukrainian hackers
Reference: Israel’s largest oil refinery website offline after DDoS attack
Incident: Wuhan Earthquake Monitoring Center Suspects Cyberattack comes from US.
Wuhan Earthquake Monitoring Center suffered a cyberattack. The Wuhan public security bureau Jianghan sub-bureau confirmed the discovery of a Trojan horse program originating from abroad at the Wuhan Earthquake Monitoring Center. According to the public security bureau, this Trojan horse program can illegally control and steal seismic intensity data collected by the front-end stations. This act poses a serious threat to national security. The center has immediately sealed off the equipment that was affected and reported the attack to the public security authorities, in order to investigate the case and handle the hacker organization and criminals according to law, said the statement.
Victim: Wuhan Earthquake Monitoring Center
Wuhan Earthquake Monitoring Center, China
Reference: Wuhan Earthquake Monitoring Center suffers cyberattack from the US; investigation underway
Incident: Akira Ransomware Attacks Cisco VPN Network in Attempt to Breach Corporate Networks
Bleepingcomputer reports there's mounting evidence that Akira ransomware targets Cisco VPN (virtual private network) products as an attack vector to breach corporate networks, steal, and eventually encrypt data. Reportedly, Akira has been using compromised Cisco VPN accounts to breach corporate networks without needing to drop additional backdoors or set up persistence mechanisms that could give them away.
Cisco VPN solutions are widely adopted across many industries to provide secure, encrypted data transmission between users and corporate networks, typically used by remotely working employees.
Reference: Akira ransomware targets Cisco VPNs to breach organizations
Victim: Augusta Utilities
Augusta Utilities, TN
Incident: Augusta Utilities Cyberattack Disables Water Meter Readers causing Extended Billing Chaos
Cyberattack at Augusta Utilities disabled electric readers for five weeks, causing customer bills to almost double. The readers are used to measure customer water usage. Separate parts inside the device were all affected during the cyber shutdown. There’s a backorder on water meters because of high demand during COVID. A total of 75,000 meters are installed in Richmond County. With 15 employees, each employee has to check 5000 meters.
On Sep 26, 4 months after the hack, local WRDW/WAGT reports that customers still claim inaccurate billing. Augusta says that 30% of the 75,000 water meters active in Richmond County still have to be read in person. The company is aware some meters may need to be replaced entirely. Since 2021, Augusta Utilities has been working on deciding a trial replacement model to replace all 75,000, it will take five years to complete replacing them all.
Reference: DHL investigating MOVEit breach as number of victims surpasses 20 million
Incident: Akira and Blackbyte both claim Cyberattack at Yamaha Music Equipment Manufacturer
Yamaha’s Canadian music division confirmed that it recently dealt with a cyberattack after two different ransomware groups claimed to have attacked the company. On June 14, the company was posted on the Black Byte ransomware gang’s list of victims, according to cybersecurity expert Dominic Alvieri. But on Friday, Yamaha appeared on the leak site of the Akira ransomware group.
Yamaha Canada Music said the attack “led to unauthorized access and data theft.” “In response, we swiftly implemented measures to contain the attack .. to prevent significant damage or malware infiltration into our network.” The company did not respond to requests for comment about whether the incident involved ransomware.
“Yamaha Canada has been notifying affected individuals, and we are offering credit monitoring services to those at risk of potential harm
Victim: The Yamaha Corporation [musical equipment]
The Yamaha Corporation — different from the spun-off motorcycle division — is a Japanese manufacturing giant producing musical instruments and audio equipment. It is considered the world’s largest producer of musical equipment.
Reference: Yamaha confirms cyberattack after multiple ransomware gangs claim attacks
Incident: Russian Medical Lab Helix Hit by Ransomware Attack
Customers of the Russian medical laboratory Helix have been unable to receive their test results for several days due to a “serious” cyberattack that crippled the company's systems over the weekend. Hackers attempted to infect the company's systems with ransomware. The company told Russian state-owned news agency Tass that its tech team partially restored the functionality of its website, mobile app and other e-health services without paying a ransom.
No customer personal data was leaked. Service disruptions prevented the company from delivering medical test results to its customers on time. Helix did not respond to a request for comment. It is unclear which group is responsible.
Victim: Helix Laboratory
Russian medical laboratory Helix
Reference: Russian medical lab suspends some services after ransomware attack
Incident: <9000 American Airlines and Southwest Airlines Pilots Affected by Data Breach at 3rd Party Vendor
American Airlines and Southwest Airlines disclosed data breaches. The cause was the hack of Pilot Credentials, a third-party vendor that manages multiple airlines' pilot applications and recruitment portals. Documents containing information provided by certain applicants in the pilot and cadet hiring process were stolen. American Airlines said the data breach affected 5745 pilots and applicants, while Southwest reported a total of 3009.
Victim: Pilot Credentials
Pilot Credentials, a third-party vendor that manages multiple airlines' pilot applications and recruitment portals
Victim: Southwest Airlines
US low cost airline
Reference: American Airlines, Southwest Airlines disclose data breaches affecting pilots
Incident: Phishing Campaign Accessed Data for 15 Months at Multinational Shipping Company UPS
Multinational shipping company UPS is alerting Canadian customers that some of their personal information might have been exposed via its online package look-up tools and abused in phishing attacks. "UPS is aware that some package recipients have received fraudulent text messages demanding payment before a package can be delivered," UPS said in a letter shared by Emsisoft threat analyst Brett Callow.
Following an internal review, UPS found that the attackers behind this ongoing SMS phishing campaign were using its package look-up tools to access delivery details, including the recipients' personal contact information, between February 2022 and April 2023.
Victim: UPS
Multinational shipping company UPS in USA
Reference: UPS discloses data breach after exposed customer info used in SMS phishing
Incident: MOVEit Transfer Hack Affects Aer Lingus
A spokesperson for Aer Lingus has confirmed that around 5,000 of its employees have been affected by a cyber attack that has compromised personal information. Aer Lingus also said that a "significant but lesser number of former employees" have also been affected.
The incident relates to a flaw in a piece of software called MOVEit Transfer, used by thousands of companies globally to transfer files, which could be exploited by cyber criminals.
Reference: Around 5,000 Aer Lingus employees affected by cyber attack
Incident: Lockbit Attacks US Networks of Largest Zipper Manufacturer in Japan
Japanese zipper giant YKK confirmed that its U.S. operations were targeted by hackers in recent weeks but said it was able to contain the threat before damage was caused. The Tokyo-based corporation would not say if it was hit with ransomware, but a spokesperson told Recorded Future News that once YKK discovered that its U.S.-based networks were targeted, the cybersecurity team “contained the threat before significant damage was done or sensitive information was exfiltrated.”
“The incident did not have a material impact on our operations or our ability to continue to serve our customers,” said Jessica Kennett Cork, vice president of corporate communications at YKK Corporation of America.
Reference: June 7th, 2023 Industry Briefs Cybercrime Get more insights with the Recorded Future Intelligence Cloud. Learn more. Zipper giant YKK confirms cyberattack targeted U.S. networks
Victim: YKK Group
YKK Group is a Japanese manufacturing conglomerate best known for manufacturing zippers. However, the company also produces industrial machinery and hardware. YKK Group controls over 100 companies worldwide, employs over 44,000 people, and boasts a revenue exceeding $6 billion last year.
Reference: Zipper manufacturer YKK Group allegedly breached by LockBit
Incident: MOVEit Hack affects US Waste Isolation Plant in NM
The Department of Energy “took immediate steps” to mitigate the impact of the hack after learning that records from two department “entities” had been compromised, the department spokesperson said. “The Department has notified Congress and is working with law enforcement, CISA, and the affected entities to investigate the incident and mitigate impacts from the breach,” the spokesperson said in a statement.
One of the Department of Energy victims is a contractor affiliated with the department’s Waste Isolation Pilot Plant in New Mexico, which disposes waste associated with atomic energy. The other victim is Oak Ridge Associated Universities, a not-for-profit research center, a department spokesperson told CNN.
Incident: MOVEit hits US Department of Energy Research Universities in TN
The Department of Energy “took immediate steps” to mitigate the impact of the hack after learning that records from two department “entities” had been compromised, the department spokesperson said.
“The Department has notified Congress and is working with law enforcement, CISA, and the affected entities to investigate the incident and mitigate impacts from the breach,” the spokesperson said in a statement.
One of the Department of Energy victims is Oak Ridge Associated Universities, a not-for-profit research center, a department spokesperson told CNN. The other victim is a contractor affiliated with the department’s Waste Isolation Pilot Plant in New Mexico, which disposes waste associated with atomic energy, the spokesperson said.
Victim: Oak Ridge Associated Universities, TN
Oak Ridge Associated Universities, a not-for-profit research center for US Department of Energy
Victim: US Waste Isolation Pilot Plant – NM
Waste Isolation Pilot Plant - the New Mexico-based facility for disposal of defense-related nuclear waste.
Reference: Exclusive: US government agencies hit in global cyberattack
Reference: Cyberattack Hits US Lab Contractor, Nuclear Waste Site
Reference: EDS Automotive Data Breach on January 02, 2023
Incident: Data Breach at Nigerian Oil and Gas Sector
An unknown threat actor has targeted the Nigerian Oil & Gas Industry Content Joint Qualification System (NOGIC JQS) and posted its data on the hacker forum with sample images revealing lists of files, including backups and MySQL data. The NOGIC JQS website offers services such as registration of contractors in the Nigerian oil and gas industry, marine vessel registration, verification, databases for national skill development, categorization of marine support vendors, expatriate quota application management, tenders management, etc. This points towards the severity of the hacking and leaking of sensitive and critical data.
Currently, the Nigerian Oil & Gas Industry Content Joint Qualification System (NOGIC) JQS portal is inaccessible and “under maintenance”. The website (nogicjqs.gov.ng) states that the application is undergoing updates.
The Nigerian oil and gas industry has been in the news over the oil theft controversy, price increase, and discovery of oil slicks in the Escravos river. As per reports, Nigeria is Africa’s primary oil provider and adds 1.2 million barrels of oil daily.
Victim: Nigerian Oil & Gas Industry Content Joint Qualification System (NOGIC JQS)
Nigerian Oil & Gas Industry Content Joint Qualification System (NOGIC JQS) offers services such as registration of contractors in the Nigerian oil and gas industry, marine vessel registration, verification, databases for national skill development, categorization of marine support vendors, expatriate quota application management, tenders management, etc.
Reference: Nigerian Oil and Gas Sector Under Attack, Hackers Leak NOGIC Data
Incident: Campbell Soup Shuts Down OH Site After Cyberattack
Campbell Soup disclosed an “IT-related complication” at a factory in Napoleon, Ohio. The company told station WTOL that impacted systems had been restored and operations would be back to normal. The Toledo Blade reported the plant was offline for three days and employees were temporarily sent home.
The attack had a limited impact on the company’s business and the company considers the disruption nonmaterial.
Victim: Campbell Soup Co.
The US company product line includes a variety of soups, beverages and snacks, including Campbell’s soup, Pepperidge Farm cookies, Pop Secret popcorn, V8 juices and other foods.
Reference: Three-day Campbell’s Napoleon plant outage due to IT problems, company says
Reference: Campbell Soup says summer cyberattack caused limited business impact
Incident: German Mechanical Engineering Firm Dürr successfully Wards off Cyberattack
Dürr's security experts were able to fend off a hacker attack. The subsidiary was also attacked. The attempt to break into the IT system of the Bietigheim-Bissingen mechanical engineering company was repelled. The hackers neither encrypted any data nor took control of the system. The employees at Dürr were informed about the attack. Everyone had to change their password.
There was also a hacker attack at an American company in the Homag Group, which belongs to Dürr AG, says Christen. The attackers got a little further in the company than in Bietigheim-Bissingen. The spokesman emphasizes that data was not lost there either. To prevent this, the computer systems were shut down. IT security checks are currently ongoing. (see cross link to Stiles Machinery)
Reference: Systems Shut Down at Stiles Machinery (HOMAG) after Cyberattack
Victim: Dürr
Mechanical Engineering Firm in Germany
Reference: Hackers are taking a look at Dürr
Reference: Dürr fends off cyberattacks
Reference: Hacker attack on Baden steelworks in Kehl
Reference: Cyber attack on Baden steelworks
Incident: Edinburgh Trams’ Website offline after Cyberattack
Edinburgh Trams said on Thursday it was the victim of a “cyber crime” making the company's website "inaccessible" to its user base.. The matter was reported to police on Thursday, 28 September, 2023 and enquiries are ongoing.”
Threat intelligence platform FalconFeeds said that international ransomware group NoName was behind the attack, and also targeted Swiftcard and Mersey Ferries Limited.
Victim: Edinburgh Trams
Edinburgh Trams, Scotland, UK
Reference: Edinburgh Trams website offline following ‘cyber- attack’
Reference: Edinburgh trams targeted by ‘cyber attack’ as fears grow over Russian hackers
Threat Actor: BianLian Ransomware Group
BianLian is a ransomware group that was first observed in 2022. According to a report from cybersecurity firm Redacted, the gang has evolved its tactics. The hackers now no longer aim to encrypt their victims' files. Instead, they threaten to publish the stolen data on the dark web if the ransom is not paid.
BianLian informs about stolen data on its blackmail site after just 48 hours. The victims then have around ten days to pay the ransom. According to the research report, as of March 13, 2023, the ransomware gang has listed a total of 118 victim organizations on its extortion portal, with the vast majority (71 percent) being US-based companies.
Reference: German car spare parts specialist Bilstein hacked
Incident: SoftProject GmbH Reports Ransomware Attack
SoftProject GmbH was the target of a ransomware attack on its data center. According to available findings, part of SoftProject GmbH's application landscape was encrypted. The forensic audits to date have revealed no evidence of a data leak. The detected malware “CryTox” is only used for encryption. The office domain of SoftProject GmbH's administrative location was not part of the attack. According to current knowledge, there was no data leakage here either. SoftProject GmbH is working on putting the systems back into operation and carrying out further forensic analyses.
The incident was immediately and properly reported. SoftProject offers products and services for digitizing and automating business processes in all industries
Reference: SoftProject GmbH reports ransomware attack
Victim: SoftProject
SoftProject offers products and services for digitizing and automating business processes in all industries since 2000.
Incident: Ransomware Attack Shuts Down Operations at German Manufacturer Wildeboer
Hackers paralyzed Wildeboer's IT on July 14 and encrypted the company data. Production has been at a standstill since then, and a large proportion of the 350 employees have been on short-time work since. The company produces, among other things, fire and sound insulation components for office complexes and stadiums. The perpetrators left instructions, however instead of responding to the ransom demand, the company filed a police report.
The company issued a statement on their website: "After weeks of hard work, Wildeboer will resume production on Monday, August 14. In connection with the restart of production, we will provide you very promptly with the necessary documents from our order processing department. The restart was made possible by many very intensive and dedicated colleagues from all divisions. "
Reference: German construction producer Wildeboer affected by hacker attack
Reference: Attack on Wildeboer IT Systems
Incident: Ransomware Attack German Drinking Water Association Paralyzed IT Systems
Hackers have paralyzed the IT systems of the Stader Land Drinking Water Association (TWV) resulting in technical disruptions. The company website states (translated in EN): At the end of July we fell victim to a ransomware attack. The aim of this was to encrypt our systems. The encryption could be prevented and we have now largely completed the secure reconstruction of our IT. We are supported by external experts and work closely with the relevant data protection and police authorities. The drinking water supply was never affected by the IT security incident and is operating at the usual high level.
With an attack of this type, there is always a risk that the perpetrators will steal data such as address or account details and other sensitive information. Unfortunately, this is now also the case with us. The criminals stole customer data in the context of meter changes and, according to our experts, published it on the darknet. A large number of our customers are affected by this.
Reference: Trinkwasserverband Stader Land website homepage
Victim: Trinkwasserverband Stader Land (TWV)
Trinkwasserverband Stader Land (TWV) - drinking water association in Germany
Reference: Hacker attack on the Stade drinking water association
Incident: Ransomware Strikes Progressive Computing entire Client Base
On July 2, 2021, REvil ransomware group launched a cyberattack on Kaseya’s VSA. The attack affected approximately 50 managed service providers (MSPs). Progressive Computing was one of the victims and hackers installed ransomware across their entire client base. The hack simultaneously affected 500 endpoints across 80 clients with 200 physical sites in four different time zones.
Victim: Progressive Computing
Progressive Computing, a manufacturer and supplier of equipment for wide area networks.
Reference: How Progressive Computing Combated a Large-Scale Cyberattack
Reference: Hackers strike Aker Solutions’ Brazil M&M operation
Incident: 2020 Phishing Email Cost UK Interserve more than £11M
Hackers stole sensitive details on 100,000 people from an outsourcing company named Interserve. The Phishing campaign attackers are unknown and the company offered no additional information. The data stolen is sensitive, including employee names and their addresses, bank details, payroll information, HR records, pension information and much more.
Update August 2023: The Information Commissioner fined Interserve £4.4m in autumn 2022. Interserve was once a FTSE 250 firm but has largely been broken up after collapsing into administration four years ago. Its latest accounts reveal that it spent £7m on ‘professional adviser fees’ following the attack.
Reference: Interserve Hit by Data Breach; 100,000 Employee Records Stolen
Reference: Cyber attack cost Interserve more than £11m
Incident: Norwegian Energy Company Investigating Cyberattack at Brazil Subsidiary
Norwegian energy services company Aker Solutions said a subsidiary company in Brazil has been subjected to a cyber attack on its IT systems.Aker Solutions said it does not yet know the full extent of the situation, and that a dialogue is being established with the authorities in Brazil about the incident.
In addition, its global IT organisation is working to resolve the situation with external expertise. "The attack is currently directed at CSE, and the attackers claim that they have entered the IT systems, encrypted digital files and locked access to data," said the company, led by chief executive Kjetel Digre.
CSE is a fully-owned Aker Solutions subsidiary with 450 employees in Brazil. Its main business is providing maintenance and modifications services to oil and gas installations offshore Brazil.
Victim: Aker Solutions / CSE
Norwegian energy services company Aker Solutions.
CSE is a fully-owned Aker Solutions subsidiary with 450 employees in Brazil. Its main business is providing maintenance and modifications services to oil and gas installations offshore Brazil. Aker Solutions also has a subsea manufacturing plant and service base in Brazil.
Reference: Aker Solutions working to solve cyber attack at its Brazil subsidiary
Incident: Encino Energy Says Operations Not impacted by Cyberattack
Major U.S. private natural gas and oil producer Encino Energy has disclosed that its operations were not impacted by a cyberattack, which it has already remediated, days after it was added by the ALPHV ransomware operation, also known as BlackCat, to its data leak site, reports The Record. Encino Energy spokesperson Jackie Stewart would not say if the cyberattack was a ransomware incident, if the company paid a ransom or if it had examined the 400GB of data on ALPHV's site. The post by the cybercrime group does not mention a dollar figure or a deadline for payment.
ALPHV had exposed 400 GB of data claimed to be stolen from Encino Energy, which is Ohio's primary oil producer, but company spokesperson Jackie Stewart refused to confirm the nature of the cyberattack and whether the demanded ransom was paid, as well as the veracity of the data leaked by the ransomware group.
Such an attack against Encino Energy comes after the ransomware gang's intrusions against two Luxembourg-based energy firms, as well as German oil companies Mabanaft and Oiltanking.
Victim: Encino Energy
Encino Energy, OH, is one of the largest private natural gas and oil producers in the U.S.
Reference: Ohio’s largest oil producer says ‘no impact’ seen after cyberattack
Reference: Encino Energy claims ‘no impact’ from ALPHV ransomware attack
Reference: ‘Israel’s’ railroad network targeted by cyberattack: Israeli media
Incident: DDoS attack at Israel’s Largest Oil Refinery
The website of Israel’s largest oil refinery operator, BAZAN Group, became inaccessible to most parts of the world on Sunday due to a potential cyber attack. The website remained accessible from within Israel, possibly after imposition of a geo-block by BAZAN in an attempt to thwart an ongoing cyber attack. In a Telegram channel, Iranian hacktivist group Cyber Avengers has claimed responsibility and leaked what appear to be screenshots of BAZAN’s SCADA systems. The group states that it breached the petrochemicals giant via an exploit targeting a Check Point firewall at the company.
In a statement to BleepingComputer, a spokesperson for BAZAN has dismissed the leaked materials as "entirely fabricated." An Iranian hacktivist group called Cyber Avengers, also known as CyberAv3ngers, claim to have compromised BAZAN Group
Victim: BAZAN Group
The Haifa Bay-based BAZAN Group, formerly Oil Refineries Ltd., is Israel's largest oil refinery operator and generates over $13.5 billion in annual revenue and employs more than 1,800 people.
Reference: Israel’s largest oil refinery website offline after DDoS attack
Incident: Australian Infrastructure Services Provider Takes Down Systems
The Australian infrastructure services provider Ventia says a cyberattack on the weekend of July 8 and 9 is contained. The attack on the Sydney-headquartered essential infrastructure services provider caused it to take key systems offline. However, in a July 12 statement, Ventia says its key internal systems have been safely re-enabled and external-facing networks are systematically being restored. Ventia is giving little away about the nature of the cyberattack, but the company’s decision to shut down its systems is a characteristic response to a ransomware-style attack.
An APAC Analyst Technical Director at DarkTrace says some of Ventia’s systems were offline for at least three days and switching off services would significantly impact customers. “Ventia are an important pillar in the management of critical infrastructure. They operate sites across Australia and New Zealand on behalf of defence, electricity, gas, and water companies,”
Victim: Ventia
Ventia provides a range of services at 400-plus locations across Australia, including waste management, asset management, telecommunications, engineering services and environmental management services.
One of its biggest clients is the Western Australian government.
Reference: Ventia says Recent Cyberattack Contained, but Questions Unanswered
Reference: Cyber Incident
Reference: Australian infrastructure company Ventia hit with cyberattack
Incident: Unknown Actor Targets South African Power Generator
Researchers have uncovered a suspected cyberattack targeting a power generator in southern Africa with a new variant of the SystemBC malware. The attack was carried out by an unknown hacker group in March of this year, according to a report by cybersecurity firm Kaspersky. The hackers used a Cobalt Strike tool and DroxiDat — a new variant of the SystemBC payload — to profile compromised systems and establish remote connections on the electric utility.
No ransomware was delivered to the organization, however.
Reference: Unknown Actor Targets Power Generator with DroxiDat and Cobalt Strike
Reference: Southern African power generator targeted with DroxiDat malware
Incident: China linked-Hackers Breach Power Grid in undisclosed Asian country
Symantec revealed that a Chinese hacker group with connections to APT41, which Symantec is calling RedFly, breached the computer network of a national power grid in an Asian country—though Symantec has declined to name which country was targeted. The breach began in February of this year and persisted for at least six months as the hackers expanded their foothold throughout the IT network of the country's national electric utility, though it's not clear how close the hackers came to gaining the ability to disrupt power generation or transmission.
Signs suggest the culprits worked within a notorious Chinese hacker group that may have also hacked Indian electric utilities years earlier.
Victim: Undisclosed – Energy sector
Undisclosed - Energy sector
Reference: China-Linked Hackers Breached a Power Grid—Again
Incident: Cyberattack Suspends Clinical Activity in Madeira Health Service
Cyberattack forces suspension of clinical activity in the Madeira Health Service. Non-urgent clinical activity will be suspended on Monday.
The Madeira Health Service (SESARAM) was the target of a cyber attack that caused a “dysfunction in its computer network”, said the institution, informing that non-urgent clinical activity will be suspended on Monday 7 August. The institution stated: "All non-urgent clinical activity will be suspended for the day tomorrow [Monday, August 7]." This includes consultations, scheduled surgeries and clinical analyzes and complementary means of diagnosis.
The attack compromised compromised the personal data of more than 250,000 Madeirans and 10,000 foreigners. Although there is no ransom demand for the information, the attack has already been claimed by the Rhysida group.
Victim: Madeira Health Service (SESARAM)
Island of Madeira, Portugal Health Service organization
Reference: Cyberattack forces suspension of clinical activity in the Madeira Health Service
Incident: 16 Hospitals of Prospect Medical Holdings Impacted by Ransomware Attack
The 16 hospitals run by Prospect Medical Holdings are still recovering from a ransomware attack announced last Thursday that caused severe outages at facilities in four states. Several of the hospitals were forced to divert ambulances to other healthcare facilities, cancel appointments and close smaller clinics while the parent company dealt with the attack. The incident has drawn national headlines due to how widespread it is, covering healthcare facilities in multiple states.
While the FBI and the U.S. Department of Health and Human Services (HHS) declined to comment on the perpetrators, HHS published a warning to all hospitals on Friday about Rhysida, noting that it was a relatively new ransomware-as-a-service (RaaS) group that emerged in May.
Victim: Prospect Medical Holdings, Inc
Prospect owns and operates 16 hospitals and more than 165 clinics and outpatient centers, with primary operations in California, Connecticut, Pennsylvania, Rhode Island and Texas.
Reference: Prospect Medical hospitals still recovering from ransomware attack
Incident: Italtel Cyberattack Claimed by Medusa
On Monday 25 September, the Italian company Italtel was the victim of a cyber attack. The cyber attack impacted Italtel's IT infrastructure, limiting access and use of some company systems. The situation continues to evolve. The Italtel affair adds to the many IT incidents involving large Italian companies.
Italtel has already started communicating with its customers and suppliers about the cyber attack. Any subsequent interactions will be managed by the competent figures within the company.
The Medusa ransomware criminal gang claims the ransomware attack, Italtel has as of today not confirmed the attack. Italtel's target markets are Telco & Media, Industry & Manufacturing, Energy & Transportation, Banking & Insurance, Healthcare and Public Administration.
Reference: Italtel Suffers a Cyber Attack: What We Know So Far
Victim: Italtel Ltd
Italtel Ltd. is an Italian telecommunications equipment and ICT company founded in 1921, originally as a branch of Siemens AG.
Reference: Johnson Controls Hit In Cyberattack
Incident: DoDDS Attack at Russian Flight Booking System, Leonardo, Disrupts Airport Operations
A Russian flight booking system was hit by a cyberattack on Thursday, causing delays at airports. The incident lasted about an hour and affected the operation of several Leonardo customers, including Russian air carriers Rossiya Airlines, Pobeda and flagship airline Aeroflot. DDoS attacks overwhelm websites with a flood of traffic, making them temporarily unavailable to users.
Leonardo is used by more than 50 Russian carriers and serves around 45 million passengers annually, according to the Russian news agency Interfax.
Victim: Leonardo
Russian flight booking system used by more than 50 Russian carriers, serving around 45 million passengers annually. Customers include including Russian air carriers Rossiya Airlines, Pobeda and flagship airline Aeroflot.
Threat Actor: IT Army of Ukraine
Ukrainian hacktivist group
Reference: Russian flight booking system suffers ‘massive’ cyberattack
Incident: Network Monitoring Company Users Affected by Hacking Campaign
Network monitoring company LogicMonitor confirmed today that some users of its SaaS platform have fallen victim to cyberattacks.
The company says that the hacking campaign has hit what it describes as a "small number" of users and is working with those affected to mitigate the attacks' impact.
While LogicMonitor did not confirm that ransomware attacks hit its affected customers, anonymous sources familiar with the incidents told BleepingComputer that the threat actors hacked customer accounts and "were able to create local accounts and deploy ransomware."
Victim: LogicMonitor
LogicMonitor / LM Envision is a SaaS-based cloud platform
Reference: LogicMonitor customers hacked in reported ransomware attacks
Incident: Travel Booking Giant Sabre Investigating Claims of a 1.3TB Data Breach
Travel booking giant Sabre said it was investigating claims of a cyberattack after a tranche of files purportedly stolen from the company appeared on an extortion group’s leak site. The Dunghill Leak group claimed responsibility for the apparent cyberattack in a listing on its dark web leak site, alleging it took about 1.3 terabytes of data, including databases on ticket sales and passenger turnover, employees’ personal data and corporate financial information.
Sabre is a travel reservation system and major provider of air passenger and booking data. Many U.S. airlines and hotel chains rely on the company’s technology.
Victim: Sabre
Sabre is a travel reservation system and major provider of air passenger and booking data, whose software and data is used to power airline and hotel bookings, check-ins and apps. Many U.S. airlines and hotel chains rely on the company’s technology.
Reference: Ransomware gang claims credit for Sabre data breach
Incident: Paralyzing Cyberattack Hits Danish Cloud Service Companies
CloudNordic has told customers to consider all of their data lost following a ransomware infection that encrypted the large Danish cloud provider's servers and "paralyzed CloudNordic completely," according to the IT outfit's online confession. The hackers shut down all of CloudNordic's systems, wiping both company and customers' websites and email systems, even the backups and production data were trashed. CloudNordic isn't prepared, nor able, to pay a ransom, presumably to restore the information and systems. CloudNordic says its "best estimate" is that the infection happened as servers were being moved from one datacenter to another.
Customers with Azero are also affected. CloudNordic and Azero are owned by Denmark-registered Certiqa Holding, which also owns Netquest, a provider of threat intelligence for telcos and governments.
Reference: Devastating ransomware attack hits Danish cloud hosting companies CloudNordic and AzeroCloud
Victim: CloudNordic & Azero owned by Certiqa
CloudNordic and Azero are owned by Denmark-registered Certiqa Holding, which also owns Netquest, a provider of threat intelligence for telcos and governments. CloudNordic offers Resellers a complete Cloud Computing platform and portfolio
Reference: Criminals go full Viking on CloudNordic, wipe all servers and customer data
Incident: Medusa Ransom Group Hacks into Gujarat Mining Company Demanding $500K Ransom
A ransomware gang breached the Gujarat Mineral Development Corporation (GMDC) data network on April 1. The ransomware gang called ‘Medusa’, first published on its blog, ‘Medusa Blog’ on March 23, privy to hacker networks, that they were in possession of several GBs of sensitive data belonging to GMDC’s office in Ahmedabad and had compromised the ‘admin’ of the network. Medusa ransomware demanded $500,000 as ransom by April 1, from GMDC to decrypt the documents.
The Medusa ransomware gang took control of administrator rights, and allegedly had access to Office365 users’ emails including the attached documents. There were lists of corporate business clients with whom GMDC is in business, maintenance contracts for a power plant, several tender documents, infrastructure evaluation report conducted by Schneider Electric for GMDC, several IP addresses of employees and their devices, employees’ personal details.
Victim: Gujarat Mineral Development Corporation – GMDC
Indian government operated mining company.
Reference: Notorious Medusa ransomware: Gang seeks $500,000 from GMDC
Incident: $1M Ransom Demanded of Auckland Transport
The Auckland Transport (AT) transportation authority in New Zealand is dealing with a widespread outage caused by a cyber incident, impacting a wide range of customer services. The company announced that it is experiencing issues with its HOP services (integrated ticketing and fares system).
Auckland Transport dismissed a claim by Medusa hacker group, that it will release data at 8pm Tuesday from the agency’s ticketing system. AT said it would not be engaging, and believed no financial data had been lost.
Threat Actor: Medusa
This ransomware gang launched in 2021 but saw a significant spike in malicious activity in 2023.
Reference: Auckland transport authority hit by suspected ransomware attack
Victim: Auckland Transport
Auckland Transport is responsible for Auckland's transport services excluding state highways. From roads and footpaths to cycling parking and public roads.
Reference: Hackers offer stolen Auckland Transport data for sale on dark web
Incident: UK based KNP Logistics Business Shuts Down: 700 Jobs lost
KNP Logistics Group will be forced to make over 700 employees redundant. According to the administrators, a “major ransomware attack … affected key systems, processes and financial information. This adversely impacted on the financial position of the Group and ultimately, its ability to secure additional investment and funding.” The incident is a rare public example of the existential threat that experts warn ransomware can pose to businesses.
Only the group’s Nelson Distribution business will survive after being sold, saving 170 jobs. KNP was formed out of a 2016 merger between Nelson Distribution and Knights of Old, a haulage business that dated back to 1865. The group was originally compromised in June 2023 by the Akira ransomware collective. However, it’s unclear whether it was able to access a decryptor for the ransomware released by Avast in July.
Victim: KNP Logistics Group
KNP Logistics Group is one of the UK’s largest privately owned logistics firms. KNP was formed out of a 2016 merger between Nelson Distribution and Knights of Old, a haulage business that dated back to 1865.
Reference: UK logistics firm blames ransomware attack for insolvency, 730 redundancies
Reference: UK Logistics Firm Forced to Close After Ransomware Breach
Incident: Massive Ransomware Attack at Johnson Controls
Johnson Controls International suffered a massive ransomware attack. The attack encrypted many of the company devices, including VMware ESXi servers, impacting the company’s and its subsidiaries’ operations. Johnson Controls shut down portions of its IT systems over the weekend. After which many of its subsidiaries, including York, Simplex, and Ruskin, begun to display technical outage messages on website login pages and customer portals.
Cost of the attack to the company was $27 million.
Customers of York report that they are told the company’s systems are down. "Their computer system crashed over the weekend. Manufacturing and everything is down," a York customer posted to Reddit. "I talked to our rep and he said someone hacked them," posted another customer. This morning, Nextron Systems threat researcher Gameel Ali tweeted a sample of a Dark Angels VMw. BleepingComputer reports the ransom note links to a negotiation chat where the ransomware gang demands $51 million to provide a decryptor and to delete stolen data. The threat actors also claim to have stolen over 27 TB of corporate data and encrypted the company's VMWare ESXi virtual machines during the attack.
BleepingComputer reports that the Linux encryptor used in the Johnson Controls attack is the same as ones used by Ragnar Locker since 2021. They contacted Johnson Controls with questions regarding the attack but has not received a response.
Victim: Johnson Controls
Johnson Controls is a multinational conglomerate that develops and manufactures industrial control systems, security equipment, air conditioners, and fire safety equipment. The company employs 100,000 people through its corporate operations and subsidiaries, including York, Tyco, Luxaire, Coleman, Ruskin, Grinnel, and Simplex.
Threat Actor: Dark Angels
Dark Angels is a ransomware operation launched in May 2022 when it began targeting organizations worldwide. Like almost all human-operated ransomware gangs, Dark Angels breaches corporate networks and then spreads laterally through the network. During this time, the threat actors steal data from file servers to be used in double-extortion attacks.
When they gain access to the Windows domain controller, the threat actors deploy the ransomware to encrypt all devices on the network. The threat actors initially used Windows and VMware ESXi encryptors based on the source code leak for the Babuk ransomware. However, cybersecurity researcher MalwareHunterTeam tells BleepingComputer that the Linux encryptor used in the Johnson Controls attack is the same as ones used by Ragnar Locker since 2021.
Reference: Building automation giant Johnson Controls hit by ransomware attack
Incident: National Science Foundation Shuts down Telescopes in Hawai’i and Chile
A U.S. national center for astronomy was struck with a cyberattack this week that hindered the operations of an observatory in Hawai'i and Chile.
The National Science Foundation’s National Optical-Infrared Astronomy Research Laboratory – also known as NOIRLab – published a notice on Tuesday night explaining that the lab had discovered an attempted cyberattack on its systems that morning. The attack forced the “suspension of astronomical observations at Gemini North in Hawai'i.” Located in Maunakea, Gemini North is one of the Gemini Observatory's two telescopes, with the other in Chile, and is an international science partnership between the U.S., Canada, Chile, Brazil, Argentina and South Korea.
“Quick reactions by the NOIRLab cyber security team and observing teams prevented damage to the observatory. Out of an abundance of caution we have decided to isolate the Gemini Observatory computer systems by shutting them down,” the organization said. Both the telescopes in Hawai'i and in Cerro Pachón, Chile have been shut down as the IT team investigates the incident and “develops the recovery plan in consultation with NSF’s cyber specialists.”
The lab did not say if the incident was a ransomware attack but said it had no impact on the infrastructure of other NOIRLab centers.
Victim: NOIRL National Optical-Infrared Astronomy Research Laboratory
National Science Foundation’s National Optical-Infrared Astronomy Research Laboratory
Reference: Hawai’i’s Gemini North observatory suspends operations following cyberattack
Incident: Belt Railway Company Investigates Data Theft
The largest switching and terminal railroad in the U.S. is investigating the theft of data by a ransomware group. Operating about 28 miles of railroads, the company allows its owners to bring their trains to the headquarters where they are separated and reorganized. They also provide services to more than 100 local manufacturing companies that ship products across North America.
On Thursday evening, the Akira ransomware gang added the company to its leak site, claiming to have stolen 85 GB of data.
Christopher Steinway, general counsel of Belt Railway, told Recorded Future News that it recently became aware that “a threat actor group posted on its website that it had obtained certain company information.”
“The event did not impact our operations. We have engaged a leading cybersecurity firm to investigate the incident and are working with federal law enforcement,” Steinway said.
“Our investigation remains ongoing.”
Threat Actor: Akira Ransomware Gang
The Akira ransomware gang emerged in March 2023 and has since compromised at least 63 victims, including the government of Nassau Bay in Texas; Bluefield University; a state-owned bank in South Africa; major foreign exchange broker London Capital Group; and Yamaha’s Canadian music division.
Victim: Belt Railway Company of Chicago
The Belt Railway Company of Chicago — based in Bedford Park, Illinois — is co-owned by six railroad companies in the U.S. and Canada, each of which uses the company’s switching and interchange facilities.
Reference: Largest switching and terminal railroad in US investigating ransomware data theft
Incident: Unnamed US Energy Company Targeted with QR code Phishing Campaign
Cybersecurity researchers uncovered a large phishing campaign using malicious QR codes with the hopes of acquiring Microsoft credentials at several targets, including a major U.S. energy company.
QR codes have become widely adopted since the onset of the COVID-19 pandemic, with thousands of restaurants and businesses replacing physical menus and guides with the machine-readable images that pull up webpages containing the same information. But hackers have been quick to exploit the trend, launching campaigns that spread fake QR codes to steal user information.
Cybersecurity firm Cofense released a new report on Wednesday identifying a campaign that began in May targeting a wide array of industries. The hackers sent thousands of emails containing malicious QR codes to companies, which took users to a Microsoft credential phishing page. The author of the report declined to name the energy company that was attacked but said that about 29% of the emails they tracked as part of the campaign were sent to the energy company.
Reference: Phishing campaign used QR codes to target large energy company
Incident: Data Breach at Medical Food Home Delivery Service Affects 1.2M people.
PurFoods, a U.S. producer of medically-tailored home-delivered meals, disclosed a data breach affecting over 1.2 million people. The incident occurred in January but was not discovered until February, the company said. Customers were notified late last week that their data had been compromised. PurFoods also notified federal law enforcement about the incident.
During the investigation, which is still ongoing, the company found out that certain files in its network were encrypted. It also identified the presence of tools that could be used for data exfiltration, adding that it’s possible that data was stolen from one of its file servers.
Victim: PurFoods
PurFoods partners with health plans, managed care organizations, and government agencies to offer meals to people enrolled in Medicare and Medicaid health programs, as well as those who pay for the service themselves. PurFoods customers include seniors, high-risk patients and people who are permanently or temporarily disabled.
Reference: US food delivery service PurFoods discloses data breach
Incident: Polish Railways Hack Paralyzed Freight and Passenger Trains
Poland's national railway’s communications network attack halted 20 trains across the country and paralyzed traffic for hours over the weekend, according to Poland’s railway infrastructure operator. The suspects, who are Polish citizens aged 24 and 29, were arrested near the border with Belarus. RMF radio reported that one of the suspects is allegedly a police officer in Bialystok. On Tuesday, Polish police announced the suspension of one of its officers in the area, but gave few additional details.
The saboteurs were able to paralyze the trains — both freight and passenger — across the country by simply sending “stop” commands via radio frequency to the trains they targeted. The attackers also played the Russian national anthem and parts of a speech by Russian president Vladimir Putin on the railway’s radio. Polish trains use a radio system that lacks encryption or authentication, making them vulnerable to such hacks.
Victim: Poland Railway System
Polish Railways
Reference: Two suspects arrested following Poland railway hack
Incident: Ransomware Attack at Sri Lanka Government Wipes Months of Data
Sri Lanka’s government email network was hit by a ransomware attack that wiped months of data from thousands of email accounts, including ones belonging to top government officials, authorities confirmed on Monday. The attack, which started at the end of August, affected nearly 5,000 email addresses using the gov.lk email domain. The victims include Sri Lanka’s council of ministers which forms the central government of the country.
The targeted system, Lanka Government Cloud (LGC), was encrypted along with backups of the system. Although officials were able to restore LGC within 12 hours of the attack, they didn’t have backups from May 17 to August 26, so all affected accounts lost data from that period, according to Mahesh Perera, the head of Sri Lanka’s Information and Communication Technology Agency (ICTA).
Perera told media outlets that the Sri Lankan government doesn’t plan to negotiate with the attackers or pay any ransom to retrieve the lost data. The agency did not respond to a request for comment.
Victim: Sri Lanka Goverment
Sri Lanka Government
Reference: Sri Lankan government loses months of data following ransomware attack
Incident: Airbus IT System Breach Exposes Data from Thousands of Airbus Vendors
The European aerospace giant Airbus said on Tuesday that it is investigating a cybersecurity incident following reports that a hacker posted information on 3,200 of the company’s vendors to the dark web. A threat actor using the moniker "USDoD" posted Monday on BreachForums that they obtained access to an Airbus web portal after compromising the account of a Turkish airline employee. The hacker claimed to have details on thousands of Airbus vendors, including names, addresses, phone numbers and emails, according to a report from Hudson Rock.
Airbus spokesperson Philippe Gmerek confirmed to Recorded Future News that hackers breached an “IT account associated with an Airbus customer” and that the company was investigating the incident. This account was used to download business documents dedicated to this customer from an Airbus web portal, the company said.
According to the Hudson Rock, the threat actor posted the leaked information publicly without making any demands. Few details are known about the threat actor or their motivations, but they have said they are a member of the relatively new ransomware group known as “Ransomed.”
Victim: Airbus
Airbus is the world's largest manufacturer of airliners as well as the leading helicopter manufacturer
Reference: Airbus investigates data leak allegedly involving thousands of suppliers
Incident: Ransomware Attack at US-Canada Water Management Organization.
International Joint Commission (IJC), the organization tasked with managing the lake and river systems along the border between the U.S. and Canada for the last hundred years, announced Wednesday that it experienced a cyberattack following reports that ransomware hackers claimed to have stolen reams of data.
The NoEscape ransomware gang claimed it attacked the organization — which has offices in Washington, D.C., Ottawa and Windsor — and stole 80 GB of contracts, geological files, conflict of interest forms and more. The gang gave the IJC 10 days to respond to their demand for a ransom. The group did not say how much money it was demanding to unlock the files. IJC did not respond to requests for comment about whether a ransom would be paid.
This week, the Cybersecurity and Infrastructure Security Agency (CISA) announced that it would be offering drinking water and wastewater systems free vulnerability scanning services. Water systems can get weekly automated scans that will provide a report on known vulnerabilities found on internet-accessible assets, week-to-week comparisons, and mitigations.
Reference: US-Canada water org confirms ‘cybersecurity incident’ after ransomware crew threatens leak
Threat Actor: NoEscape ransomware gang
NoEscape is a ransomware-as-a-service operation that appeared in May 2023 and takes a double-extortion approach. That means instead of simply infecting victims' machines with malware, encrypting their files and demanding a ransom to release the data, the crooks first steal the files before locking them up. They threaten to leak the information, as well as withhold the decryption keys, if the victims don't pay the ransom.
NoEscape operators do not target organizations based in the former Soviet Union. This is a similar MO to other ransomware groups, such as the now-defunct Conti and Black Basta, which also avoid infecting Russian companies and government agencies. The gang is believed to be a rebrand of Avaddon – another ransomware crew that shut down and released its decryption keys in 2021, according to Bleeping Computer.
NoEscape hackers have taken credit for attacks on Germany’s bar association and Hawaiʻi Community College as well as Australian companies, a hospital in Belgium, a manufacturing company in the US and another manufacturing company in the Netherlands.
Victim: International Joint Commission (IJC)
The International Joint Commission (IJC) — guided by the 1909 Boundary Waters Treaty signed by both countries — approves projects that affect the water levels and flows across the border, investigates transboundary issues and offers solutions (Canada/USA)
Reference: US-Canada water commission investigating cyberattack
Incident: Operations Impacted at Americold after Network Breach
Atlanta-based Cold storage giant Americold was hit with a cyberattack according to filings with the Securities and Exchange Commission. On April 26, the company “began to receive evidence that its computer network was affected by a cybersecurity incident,” it wrote in the SEC filing. “The Company immediately implemented containment measures and took operations offline to secure its systems and reduce disruption to its business and customers.”
“The Company is taking action to resume normal operations at impacted facilities so that it can continue to support customers,” it wrote. “The Company will continue to take appropriate measures to further safeguard the integrity of its information technology infrastructure, data and customer information.”
Reference: Cold storage giant Americold outage caused by network breach
Reference: Cold storage company Americold reports cyberattack to SEC
Incident: US Largest Freight Transportation Companies Impacted by ORBCOMM Software Outage
New Jersey-based ORBCOMM, one of the biggest providers of software for the trucking industry, acknowledged a ransomware attack after reports emerged of issues that customers had with its products.
An ORBCOMM executive confirmed the attack to Recorded Future News but would not say which ransomware group was behind the incident or whether a ransom would be paid.Trucking and fleet management solutions provider ORBCOMM has confirmed that a ransomware attack is behind recent service outages preventing trucking companies from managing their fleets.
ORBCOMM is a solutions provider for freight companies to manage fleets and track transported assets. The company also provides Electronic Logging Devices (ELD) that truckers use to log their hours to adhere to federal safety regulations. The department granted an extension to all carriers using ELD models from ORBCOMM, allowing drivers to use paper logs while the system is down. Outage has impacted some of the country's largest freight transportation companies as they cannot track their fleets and inventory.
Reference: ORBCOMM ransomware attack causes trucking fleet management outage
Victim: ORBCOMM
An American company that offers industrial internet and machine to machine (M2M) communications hardware, software and services designed to track, monitor, and control fixed and mobile assets in markets including transportation, heavy equipment, maritime, oil and gas, utilities and government.
American company that offers industrial internet and machine to machine (M2M)[1] communications hardware, software and services designed to track, monitor, and control fixed and mobile assets in markets including transportation, heavy equipment, maritime, oil and gas, utilities and government.
The company provides hardware devices, modems, web applications, and data services delivered over multiple satellite and cellular networks.
Reference: Major trucking software provider confirms ransomware incident
Reference: Alert – Distributed Denial of Service campaign targeting multiple Canadian sectors
Incident: DDoS Attack at Bordercheck Point in Canada
A cyberattack suspected to be carried out by a pro-Russia hacking group reportedly resulted in widespread service disruptions at several Canadian airports. The Canada Border Services Agency (CBSA) confirmed to Recorded Future News that the connectivity issues that affected check-in kiosks and electronic gates at airports last week are the result of a distributed denial of service (DDoS) attack. Such attacks work by flooding systems with junk traffic, disrupting their operations. CBSA's spokesperson said that they had restored all systems within a few hours. The Montreal Airport Authority (ADM) told the Canadian newspaper La Presse that a computer outage at check-in kiosks caused significant delays in the processing of arrivals for over an hour at border checkpoints throughout the country, including Montreal-Trudeau International Airport.
CBSA has not disclosed how a DDoS attack managed to breach the computer system used by check-in kiosks at airports. This system is supposed to be on a closed circuit, meaning it should not be connected to the internet, La Presse reported. CBSA did not respond to request to comment.
Victim: Canada Border Services Agency (CBSA)
Canada Border Services Agency (CBSA)
Reference: Canada blames border checkpoint outages on cyberattack
Incident: Data Breach at Air Canada Involved Employee Information
Canada’s largest airline announced a data breach this week that involved the information of employees, but said its operations and customer data was not impacted. “An unauthorized group briefly obtained limited access to an internal Air Canada system related to limited personal information of some employees and certain records. Flight operations systems and customer facing systems were not affected,” the company said.
“No customer information was accessed. We have contacted parties whose information has been involved as appropriate, as well as the relevant authorities. All our systems are fully operational.”
The company added that it worked with cybersecurity experts to further lockdown its systems following the incident. (The announcement came on the same day that a cyberattack suspected to be carried out by a pro-Russia hacking group reportedly resulted in widespread service disruptions at several Canadian airports.)
UPDATE: October: BianLian extortion group claims recent Air Canada breach
Reference: Air Canada says hackers accessed limited employee records during cyberattack
Victim: Air Canada
Air Canada, Canada’s largest airline.
Reference: Marine industry giant Brunswick Corporation lost $85 million in cyberattack, CEO confirms
Reference: Clorox reports production issues after August cyberattack
Incident: MOVEit Campaign Continues Affecting <900 Schools in Almost Every US State.
U.S. educational nonprofit National Student Clearinghouse (NSC) has disclosed a data breach affecting 890 schools using its services across the United States. Attackers gained access to its MOVEit managed file transfer (MFT) server on May 30 and stole files from nearly 900 colleges and universities across the U.S. The stolen information includes personally identifiable information such as Social Security numbers and dates of birth.
The attack on NSC was one of several involving MOVEit that had wide-ranging downstream effects.
Victim: National Student Clearinghouse (NSC)
U.S. educational nonprofit National Student Clearinghouse (NSC)
Reference: National Student Clearinghouse data breach impacts 890 schools
Reference: September 25th, 2023 News Cybercrime Industry Get more insights with the Recorded Future Intelligence Cloud. Learn more. MOVEit fallout continues as National Student Clearinghouse says nearly 900 schools affected
Incident: KIA Motors GA Plant Hit in Cyber Incident
A cybersecurity incident shut down manufacturing at the KIA Motors West Point, Georgia facility earlier this month.
While KIA addressed the problem in a day, manufacturing ground to a halt September 6 when shifts, and deliveries ended up disrupted. A KIA spokesperson confirmed some details related to the cybersecurity issue.
“Kia Georgia was alerted by a supplier of a cybersecurity issue that has resulted in a disruption to our regular production schedule. Kia Georgia is working closely with the supplier to minimize impact and anticipates a prompt return to normal operations,” said Patrick Sands, a spokesperson with KIA.
It appears the auto manufacturer and other auto suppliers, who operate on the same software system, ended up hacked by cyber pirates who demanded a ransom to restore data and service.
Reference: Cyber Incident Disrupts KIA Manufacturing
Incident: Zaun, a Fencing Supplier, Suffers Ransomware Attack
Fencing products maker, UK-based Zaun, suffered a ransomware attack by the LockBit attack group which started leaking information it purloined from the hack.
The West Midlands, UK company supplies some of the UK’s key military installations.
LockBit’s data release included sales orders relating to Porton Down research unit in Wiltshire and the Faslane nuclear submarine base in Scotland. It also mentions details of equipment used at GCHQ’s Bude satellite ground station and network monitoring site.
Reference: UK Fencing Supplier Hit In Ransomware Attack
Victim: Zaun
Fencing products maker, West Midlands, UK-based Zaun, supplies some of the UK’s key military installations.
Incident: Inside Job: Tesla Suffers Data Breach
Two former Tesla workers released confidential information regarding over 75,000 people to a German media outlet this past May.
The breach occurred May 10 and Tesla took immediate action to quell the breach and make sure information did not release.
The auto giant said in a statement to its customers:
“At Tesla, we take data privacy and security seriously— so we are writing to tell you about a data incident that involved your information. While we have not identified evidence of misuse of the data in a manner that may cause harm to you, we are nonetheless providing you with this notice to ensure that you are aware of what happened and the measures we have taken."
Reference: Tesla Suffers Data Breach From Disgruntled Ex-Workers
Victim: Tesla
Tesla, Inc. is an American multinational automotive and clean energy company headquartered in Austin, Texas. Tesla designs and manufactures electric vehicles, stationary battery energy storage devices from home to grid-scale, solar panels and solar shingles, and related products and services.
Incident: Ransomware Attack Against Montreal Utility
A 100-year-old municipal organization that manages electrical infrastructure in the city of Montreal suffered a ransomware attack at the hands of the Lockbit criminal group.
Commission des services electriques de Montréal (CSEM) suffered the attack at the hands of the ransomware gang called Lockbit this past Wednesday which said it “added Commission des services electriques de Montreal to their victim list.”
The electric provider said in an advisory it was hit with ransomware on August 3 but refused to pay the ransom.
Reference: Montreal Utility Hit In Ransomware Attack
Victim: Commission des services electriques de Montréal (CSEM)
A 100-year-old municipal organization that manages electrical infrastructure in the city of Montreal.
Incident: Limited Operational Impact after Cyberattack at Copper Mining Company FCX
Copper mining company Freeport-McMoRan (FCX) suffered a cyber attack that hit its information technology systems and caused limited impact to its operations. Phoenix, Arizona-based FCX said “the company is assessing the impact and proactive measures are being taken to address the situation. The company is working closely with third-party experts and law enforcement.
“To date, there has been limited impact on production. Transitional solutions are being planned and implemented to secure information systems as quickly as possible.
Victim: FCX (Freeport-McMoRan)
Arizona based mining company Freeport-McMoRan (FCX) operates large, long-lived, geographically diverse assets with significant proven and probable reserves of copper, gold and molybdenum.
FCX is one of the world’s largest publicly traded copper producers.
Reference: Copper Mining Firm Hit In Attack
Reference: Rapattoni reportedly restores service to its NorCal MLS network
Incident: Rapattoni Cyber Attack has Significant Financial Impact on Real Estate Sector
August 8 Rapattoni cyberattack on NorCal MLS provider drags on for > 14th days. Rapattoni says “certain essential components” missing to restore service. This is said to be the longest-running cyberattack on an MLS.
Real estate agents are unable to track property online as the information on listing websites was not updated, and buyers could not discover new houses. Subsequently, fewer buyers showed up for open houses, reducing competition for available houses and affecting their prices. Some realtors resorted to manual systems and old-school real estate marketing tactics like cold-calling buyers or passing flyers, while others started sharing property information on social media.
Rapattoni did not confirm if a ransom was paid.
Victim: Rapattoni
Northern California MLS provider (Real Estate)
Reference: Cyberattack on NorCal MLS provider drags on for 14th day
Reference: Real estate agents resort to manual systems after the Rapattoni cyber attack
Incident: Independent Businesses Suffer Big Hit as Result of Cyberattack on Swan Retail IT Firm
Up to 300 independent retailers have been left unable to process stock after being hit by a cyber attack at fullfilment software supplier Swan Retail. The attack took place on Sunday (13 August).
Independents told Drapers that their businesses have taken a big hit since the attack as they struggled to replenish stock in-store or fulfill online orders. Some have also had to delay bringing in new autumn/winter collections as a result.
Victim: Swan Retail
IT supplier Swan Retail works with around 300 independents retailers in sectors including fashion, homeware, sports, catering and garden centres in the UK
Reference: Indies ‘in standstill’ after cyber attack hits IT supplier
Reference: Exclusive: 300 independent retailers affected by cyber attack
Incident: Wide-ranging Ransomware Attack Takes Down Local County Government in Alabama
The local government of George County, Alabama was thrown into chaos this weekend when ransomware actors used a discrete phishing email to gain deep access to the county’s systems. The ransomware attack took down nearly all of the government’s in-office computers.
The attack is the latest in a string of incidents affecting counties across the U.S., including ones in Delaware, California, South Carolina, New Jersey and Oregon as well as major metropolitan areas like Oakland and Dallas. Ransomware groups have shown little preference, targeting both small counties and large ones alike. The second quarter of 2023 saw 59 attacks, far above the 51 seen in the second quarter of 2022.
Victim: George County, Alabama
Local government of George County, Alabama
Reference: ‘It feels like a digital hurricane’: Coastal Mississippi county recovering from ransomware attack
Incident: MOVEit Transfer data breach at Zellis affect
UK payroll and HR solutions provider Zellis suffered a data breach due to MOVEit attacks. "A large number of companies around the world have been affected by a zero-day vulnerability in Progress Software's MOVEit Transfer product," Zellis told BleepingComputer in a statement on June 7. "We confirm that a small number of our customers have been impacted and we are actively working to support them. Zellis-owned software is unaffected and there are no associated incidents or compromises to any other part of our IT estate. We have also notified the ICO, DPC, and the NCSC in both the UK and Ireland."
Additional information, 23AUG23:
On June 6th, 2023, the notorious Russian-affiliated ransomware group, Clop, claimed responsibility for an attack that targeted Progress Software’s MOVEit transfer tool. This corporate file-sharing solution has an extensive customer base in the United States. Organizations use MOVEit for secure file transfers; it’s essentially a more jazzed-up, professional version of popular file-sharing tools like Dropbox. In May 2023, cybercriminals at Clop uncovered a previously unknown vulnerability in MOVEit, which they began exploiting. Up to 130 organizations suffered from downstream impacts when the vulnerability in MOVEit enabled Clop hackers to gain access to their IT environment and steal sensitive data.
Reference: The MOVEit hack and what it taught us about application security
Reference: Clop ransomware claims responsibility for MOVEit extortion attacks
Victim: Zellis
Payroll service provider
Incident: BBC Victim of MOVEit Software Hack at Payroll Service Provider Zellis
British Airways (BA), the BBC, Ofcom and Boots were among a number of organisations that were reportedly victims of a major recent cyber-attack, resulting in the breach of numerous staff details. The stolen data is said to include staff names, staff ID numbers and national insurance numbers (although, importantly, not banking details). The recent attack was against a piece of software called Moveit, which is used to transfer computer files from one location to another. It involved what’s called a “zero-day exploit”, a piece of computer code that takes advantage of a previously unknown vulnerability. This allowed hackers to compromise Zellis, a trusted supplier of services to BA, the BBC, Boots and others. Zellis confirmed a “small number” of customers had been affected, adding that it had disconnected the server using Moveit as soon as it became aware of the incident.
Since Zellis is the main payroll service provider to these organisations, it is easy to trace how this incident started. Responsibility for the attack was claimed by the Russia-linked “cl0p” group, which has since issued an ultimatum to the affected organisations – asking for money unless they want the stolen data to be released on the dark web.
Reference: BBC, British Airways among big-name victims in MOVEit software hack
Incident: Boots also Victim MOVEit Software Hack at Zellis
British Airways (BA), the BBC, Ofcom and Boots were among a number of organisations that were reportedly victims of a major recent cyber-attack, resulting in the breach of numerous staff details.
The stolen data is said to include staff names, staff ID numbers and national insurance numbers (although, importantly, not banking details). But, other than for those personally affected, the real issue is what this attack reveals about the evolution of cybercrime.
Incident: British Airways also Breached by MOVEit Software Hack (Zellis)
British Airways (BA), the BBC, Ofcom and Boots were among a number of organisations that were reportedly victims of a major recent cyber-attack, resulting in the breach of numerous staff details. The stolen data is said to include staff names, staff ID numbers and national insurance numbers (although, importantly, not banking details).
The recent attack was against a piece of software called Moveit, which is used to transfer computer files from one location to another. It involved what’s called a “zero-day exploit”, a piece of computer code that takes advantage of a previously unknown vulnerability.
This allowed hackers to compromise Zellis, a trusted supplier of services to BA, the BBC, Boots and others. Zellis confirmed a “small number” of customers had been affected, adding that it had disconnected the server using Moveit as soon as it became aware of the incident.
Since Zellis is the main payroll service provider to these organisations, it is easy to trace how this incident started. Responsibility for the attack was claimed by the Russia-linked “cl0p” group, which has since issued an ultimatum to the affected organisations – asking for money unless they want the stolen data to be released on the dark web.
Reference: Update: Boots issued ultimatum by Russian hackers who stole employee data
Reference: (Zellis) Press statement on MOVEit Transfer data breach
Victim: Boots
Boots, a British health and beauty retailer and pharmacy chain in the United Kingdom and operates also internationally including Ireland, Italy, Norway, the Netherlands, Malta, Thailand and Indonesia.
Victim: BBC
BBC - The British Broadcasting Corporation is a British public service broadcaster headquartered at the Broadcasting House in London
Reference: BBC, British Airways among big-name victims in MOVEit software hack
Victim: British Airways
British Airways (BA) is the flag carrier of the United Kingdom. It is headquartered in London, England, near its main hub at Heathrow Airport.
Reference: Moveit hack: attack on BBC and BA offers glimpse into the future of cybercrime
Reference: MOVEit Data Incident: What You Need to Know
Incident: First Merchant Bank also Confirmed Databreach as Result of MOVEit Hacks
Indiana-based banking giant First Merchants Bank, also confirmed a data breach affecting sensitive customer information resulting from the MOVEit hacks.
First Merchants said that hackers accessed data including customers’ addresses, Social Security numbers, online banking usernames, payee information and financial account information. “Online or mobile banking passwords were not captured or compromised and remain unaffected by this incident.” First Merchants Bank also has not yet said whether the company has the ability to determine the number of affected customers. A spokesperson did not return a request for comment.
Clop has not yet listed First Merchants Bank on its dark web leak site.
Reference: More organizations confirm MOVEit-related breaches as hackers claim to publish stolen data
Victim: First Merchants Bank
First Merchants Bank, an Indiana-based banking giant with more than $18 billion in assets
Incident: Seiko Suffers Ransomware Attack
Seiko Group Corporation confirmed it suffered a data breach July 28 and is apparently a victim of a ransomware attack, according to a Monday post on an attack group’s website.
Seiko, a watchmaker with 12,000 employees and an annual revenue over $1.5 billion, said in an advisory: “It appears that some as-yet-unidentified party or parties gained unauthorized access to at least one of our servers. Subsequently, on August 2nd, we commissioned a team of external cybersecurity experts to investigate and assess the situation.
“As a result, we are now reasonably certain that there was a breach and that some information stored by our company and/or our group companies may have been compromised.
Reference: Japanese watchmaker Seiko breached by BlackCat ransomware gang
Reference: Seiko Hit In Data Breach
Victim: Seiko Group Corporation
A watchmaking giant with 12,000 employees and an annual revenue over $1.5 billion.
Incident: Energy One Suffers Attack
Wholesale energy software provider Energy One suffered a cyberattack last week that hit systems in Australia and the United Kingdom.
The 15-year-old business provides software and services to Australia, New Zealand and other Pacific islands and European companies.
Once Energy One detected the attack August 18 and it took “immediate steps to limit the impact of the incident, engaged cyber security specialists, CyberCX, and alerted the Australian Cyber Security Centre and certain UK authorities,” the company said in a statement to the Australian Securities Exchange dated Monday.
Reference: Energy One Hit In Cyber Attack
Victim: Energy One
The 15-year-old business provides software and services to Australia, New Zealand and other Pacific islands and European companies.
Incident: Cleaning Products Maker, Clorox, Suffers Attack
Clorox Company took down systems effecting business operations after a cyberattack hit the Oakland, California-based cleaning products manufacturer, company officials said.
The company said in a 10-Q report in February 2024 expenses to handle the hack were $49 million for the six-month period. They were $25 million for the first three months.
“The Clorox Company has identified unauthorized activity on some of its Information Technology (IT) systems,” The company said in an 8-K filing with the Security and Exchange Commission (SEC). “After becoming aware of the activity, the company began taking steps to stop and remediate the activity, including taking certain systems offline. “The Company is working diligently to respond to and address this issue, and is also coordinating with law enforcement. To the extent possible, and in line with its business continuity plans, Clorox has implemented workarounds for certain offline operations in order to continue servicing its customers."
In September, the company said some products were in short supply. Production remained an issue as operations have been slow to get back up to full speed. The company said it had been fulfilling and processing orders manually. The company said it expects to return to normal operations next week. “Clorox is still evaluating the extent of the financial and business impact. Due to the order processing delays and elevated level of product outages, the Company now believes the impact will be material on Q1 financial results."
In regulatory filings with the SEC, the company said the cyberattack “damaged portions of the Company’s IT infrastructure, which caused widescale disruption of Clorox’s operations.”
Reference: Clorox Hit In Cyberattack
Victim: Clorox Company
Clorox makes and sells consumer and professional cleaning products, including Brita, Glad, Green Works Cleaning Products, Kingsford, Liquid-Plumr, Pine-Sol, and Tilex. The company has locations in 25 countries and has a market presence in over 100 countries.
Incident: Tempur Sealy International Suffers Cyberattack
Mattress and bedding products maker, Tempur Sealy International, Inc. suffered a “temporary interruption of the company’s operations” is in the process of recovering from a cyberattack last week. “On July 23, 2023, Tempur Sealy International, Inc. identified a cybersecurity event involving certain of the Company’s information technology systems.
Upon discovery of the event, the Company activated its incident response and business continuity plans designed to contain the incident. “This included proactively shutting down certain of the Company’s IT systems, resulting in the temporary interruption of the Company’s operations. Legal counsel, a cybersecurity forensic firm and other incident response professionals have been engaged to advise on the matter. The Company has also notified law enforcement authorities,” the company said in an 8-K notice to the Security and Exchange Commission (SEC).
AlphV/Black Cat ransomware group took credit for the attack on the company, claiming to have sensitive documents from senior officials.
Reference: Mattress Maker Hit In Cyberattack
Victim: Tempur Sealy International
Mattress and bedding products maker.
Reference: Japanese Port Reopens After Russian Ransomware Group Attack
Incident: BlackCat Ransomware Attack at Lehigh Valley Health Network
Lehigh Valley Health Network has confirmed that its Jan. 8 cyberattack was conducted by Russian ransomware gang BlackCat. On June 29, 2023 the health system notified patients that the breach from BlackCat occurred on Jan. 8, with the health system detecting the ransomware on its IT system on Feb. 6.
BlackCat was able to obtain some patients' protected health information including email addresses, banking information, medical information, Social Security numbers and more.
In addition the cybercriminals may have stolen the sensitive photographs of as many as 2,760 patients, officials said Thursday. Some of those images were posted on the dark web. According to the court filing the health care provider suggested a class-action lawsuit over the data breach. That would likely involve more than 100 people and could cost about $55 million.
LVHN also revealed that the hackers responsible for the breach demanded a ransom of over $5 million in February, which officials refused to pay.
Victim: Lehigh Valley Health Network
Lehigh Valley Health Network, PA, USA
Reference: Lehigh Valley Health Network confirms it was attacked by ransomware gang BlackCat
Reference: Cybercriminals stole sensitive photos of nearly 3K patients in LVHN data breach: Officials
Incident: 300 KFC, Pizzahut, Taco Bell restaurants Shut Down after Ransomware Attack on Parent Company
KFC, Pizza Hut, and Taco Bell parent company Yum! Brands confirmed a ransomware attack that leaked company data and shut down restaurants in the United Kingdom.
Yum! quickly mitigated the ransomware attack, and all outlets resumed operations within 24 hours.
“With the ransomware being contained to a third of Yum! Brands UK outlets and the downtime being limited to 1 day – Yum! Brands have done relatively well recovering,” said Morten Gammelgard EVP, EMEA at BullWall. “The average amount of downtime for organizations when hit by Ransomware is approximately 24 days.”
Breach notification letters were sent to affected people starting Thursday 6 April. Yum! Brands revealed that it has "now found out the attackers stole some individuals' personal information, including names, driver's license numbers, and other ID card numbers."
Reference: KFC, Pizza Hut owner discloses data breach after ransomware attack
Reference: Yum! Brands January 18, 2023 Statement
Victim: Yum! (KFC, Pizza Hut, and Taco Bell parent company)
Yum, KFC, Pizza Hut, and Taco Bell parent company, operates 53,000 restaurants in 155 territories, with 1,000 restaurants in the United Kingdom. The company owns assets worth over $5 billion and records about $1.3 billion in annual profits.
Reference: KFC, Pizza Hut, and Taco Bell Ransomware Attack Shuts Down 300 Restaurants in the UK
Incident: 14 Ontario Gateway Casinos Close for Two Weeks after Ransomware Attack
Canada’s Gateway Casinos & Entertainment Ltd. confirmed on Friday ,22 April that all 14 of the company’s casinos in the province of Ontario were shut down after being hit with a ransomware attack on 16 April.
On Saturday April 29, Gateway Casinos confirmed it was starting to re-open its Ontario operations. 15 other casinos in different provinces were not affected and remained open.
Victim: Canada’s Gateway Casinos & Entertainment Ltd
Canada’s Gateway Casinos & Entertainment Ltd
Reference: Cyberattack – 14 Canadian Casinos Shut Down Since April 16
Reference: Ontario casino ransomware attack ‘as bad as it gets,’ expert says
Reference: Gateway Casinos ransomware attack highlights need for better cybersecurity, says analyst
Incident: Secret Network of US Marshall Infiltrated by Hackers
On February 17 the U.S. Marshals Service "discovered a ransomware and data exfiltration event affecting a stand-alone USMS system." The unidentified hackers infiltrated a network used by the Technical Operations Group (TOG) to track fugitives, reports the Washington Post. The precise activities of the service are kept secret.
US Marshals Service spokesperson Drew Wade said no one in the witness protection program is in danger because of the breach. Nevertheless, the official said, the incident is significant, affecting law enforcement sensitive information pertaining to the subjects of Marshals Service investigations.
The agency developed a workaround enabling the unit to continue operations and efforts to track down fugitives. “Most critical tools” related to the affected computer network “were restored within 30 days of the breach discovery” in February, Wade told CNN, declining to explain what those critical tools were. The network remains compromised nearly 3 months after being hit.
The Technical Operations Group (TOG) network provides surveillance capabilities to track fugitives. The group operates 29 field offices in the US and Mexico and uses high-tech methods to track fugitives.
Victim: United States Marshals Service
The United States Marshals Service is a federal law enforcement agency in the United States. The USMS is a bureau within the U.S. Department of Justice.
Reference: US Marshals Service still recovering from February ransomware attack affecting system used by fugitive hunters
Reference: Computer system used to hunt fugitives is still down 10 weeks after attacks
Incident: Emergency Shut Down at Medical Clinic in TN after Cyberattack
A cyberattack on Murfreesboro Medical Clinic & SurgiCenter (MMC) in Tennessee shut down operations for around two weeks.
On April 22, 2023 the network was rapidly shut down to contain the attack. MMC said the action taken limited the damage caused. MMC has been working with cybersecurity experts and law enforcement to investigate the incident and determine the extent of the attack. While those processes were completed, the decision was taken to close all operations.
MMC planned to reopen on a limited basis on May 3, 2023, then restore full operations shortly thereafter. However, the recovery process took longer than planned.
Victim: Murfreesboro Medical Clinic & SurgiCenter (MMC)
Murfreesboro Medical Clinic & SurgiCenter (MMC) in Tennessee
Reference: Ransomware Attack Results in 2 Week Shutdown of Operations at TN Medical Clinic
Incident: Recycling, Mining Provider, Tomra, Hit in ‘Extensive’ Attack
Norwegian recycling and mining corporation Tomra suffered an “extensive cyberattack” Sunday which affected some of its data systems, company officials said.
“Tomra has been targeted by an extensive cyberattack directly affecting some of the company’s data systems,” the company said in a statement. “Relevant authorities have been informed, and all available internal and external resources have been mobilized to contain and neutralize the incident.
“The attack was discovered in the morning of July 16th (CET), and immediate actions were taken to stop it and mitigate consequences. We immediately disconnected some systems to contain the attack, and Tomra is currently assessing whether customers and employees might experience reduced stability in our services. Our primary focus now is to get all systems up and running again as fast as possible."
Reference: Norwegian Giant Tomra Suffers “Extensive” Attack
Reference: Recycling, Mining Provider Suffers ‘Extensive’ Attack
Victim: Tomra
Tomra builds automated tools for a range of industries but is makes machines that collect metal, plastic, and glass beverage packages for recycling. The company is also in the waste and metal recycling, mining and food production sectors.
Incident: Cosmetic’s Giant Estée Lauder Suffers Breach
Cosmetics giant Estée Lauder admitted Tuesday a hacker stole some data from its systems, with the cyber incident causing disruption in its business operations.
The cosmetics maker is continuing to work on restoring the affected systems and implemented measures to secure its operations, including taking down some of its systems to mitigate the incident, the company said in a statement.
As a part of the incident two ransomware actors, ALPHV/BlackCat and Clop, listed Estée Lauder on their data leak sites as a victim of separate attacks. In a message to the company, the BlackCat gang said they were still present on the network, according to a published report.
In a Security Exchange Commission (SEC) filing Tuesday, Estée Lauder confirmed one of the attacks saying the threat actor gained access to some of its systems and may have stolen data.
Further information on the attack was not immediately available. But the company did say it took down some systems to prevent attackers from expanding on the network.
Reference: Estée Lauder beauty giant breached by two ransomware gangs
Reference: Estée Lauder Hit In Data Breach
Victim: Estee Lauder
Maker of skin care and cosmetics.
Reference: Ventia Systems Affected By Cyber Incident
Incident: 225K Customers Without Power in Ukraine Power Grid Hack
On the evening of December 23, 2015, the cursor on the grid operator's computer screen started to move on its own. Hackers had struck the power distributor company Prykarpattyaoblenergo in Ukraine, disabling one circuit breaker after another. It was one of a kind cyberattack on a power grid executed successfully. Soon after, half of the population of Ukraine's Ivano-Frankivsk region were in the dark without power for up to six hours. While the power was restored in a few hours, it took months for all the control centers to become fully operational again.
The hack on Ukraine's power grid was a first-of-its-kind attack that sets an ominous precedent for the security of power grids everywhere.
Incident: Hacktivists Take Down Multiple Japanese Government Websites
A pro-Russia hacker group has claimed to be involved in attacks on Japanese government and company websites.
The DDoS attack on the e-Gov website shut down the site for a few hours on Sept. 6. It then became inaccessible again around noon on Sept. 7 until early morning, Sept. 9. The e-Gov website allows users to request disclosure of administrative documents and provides information on laws and regulations. The site receives about 7.8 million hits a day.
In addition, between Sept. 6 and 9, the attacks made 23 government websites temporarily inaccessible. These sites belonged to the Digital Agency, the Internal Affairs and Communications Ministry, the Education, Culture, Sports, Science and Technology Ministry and the Imperial Household Agency. Some sites of credit card business JCB Co. were inaccessible, while websites of social media company mixi, Inc. were also hard to access.
On September 6, 2022, the website of the Nagoya Port Authority was unreachable for about 40 minutes.
Victim: Japanese Government Departments
Japanese Government Ministries
Threat Actor: Killnet
Killnet is a hacktivist organization that uses cyber-attacks to support a political cause. DDoS attacks are a method hacktivists tend to use because they can easily see the damage of bringing a website down.
Killnet is a pro-Russian group, from which activities have been observed since early 2022. In May '22 it declared a “cyber war” on 10 nations, including the United States, United Kingdom, Germany and Italy.
Reference: Pro-Russia hackers claim to have temporarily brought down Japanese govt websites
Incident: Container Processing Halted at The Port of Nagoya
The Port of Nagoya, the largest and busiest port in Japan, has been targeted in a ransomware attack. The attack occurred around 6:30AM on July 4. A notice was issued reporting a malfunction in the “Nagoya Port Unified Terminal System” (NUTS), the central system controlling all container terminals in the port.
The attack held up shipments of Toyota auto parts containers for two days, but the port reopened Thursday morning.
All container loading and unloading operations at the terminals using trailers were canceled, causing massive financial losses to the port and severe disruption to the circulation of goods to and from Japan. LockBit 3.0 was confirmed as the attacker.
It took 3 days for the port to fully resume. A nearby Toyota auto parts packaging plant that exports through the port had to shutdown on Friday.
Victim: Nagoya Port Authority
The Nagoya port accounts for roughly 10% of Japan's total trade volume. It operates 21 piers and 290 berths. It handles over two million containers and cargo tonnage of 165 million every year. The port is also used by the Toyota Motor Corporation, one of the world’s largest automakers, to export most of its cars.
Reference: Japan’s largest port stops operations after ransomware attack
Incident: Hackers take control of a water treatment system at a hotel in Israel
NEED TO REVIEW AND SEARCH FOR ONE MORE SOURCE
GhostSec’s claimed breach of 55 Berghof PLCs in Israel. This weekend, on September 10, 2022, the hacktivist group published another announcement alleging that it successfully breached another controller in Israel.The affected controller is an Aegis II controller manufactured by ProMinent.
According to images that the GhostSec published, the group appeared to have taken control of a water system’s pH and chlorine levels. In the published message, the hacktivists said they “understand the damages that can be done …” and that the “Ph pumps” are an exception for their anti-Israeli cyber campaigns.
Incident: Russian Natural Gas Network System Attacked by pro-Ukrainian Hacker Group
A SCADA attack targeted the natural gas system of Khanty-Mansiysk city. The attack destroyed the city's natural gas facility, knocked out its power plant and caused a blackout at its airport, reports International Business Times. As the world's second biggest oil producing region (before western sanctions hit Russian oil) Khanty Mansi was the center of the old Soviet oil industry. The SCADA system of Khanty-Mansiysk city's natural gas network along with its backup system at the airport was completely destroyed in the attack.
Reportedly the pro-Ukrainian group: Team OneFist is behind the attack. The group stressed they observe the rules of war and had taken steps to avoid potential damage to hospitals and civilians. And said that the latest hack was launched by Team OneFist's new Ukrainian team members and Voltage as a "joint training-mission" to give the new members "a feel of what a SCADA attack is like."
Incident: Satellite Communications System Serving the Russian military Knocked Offline
A group of previously unknown hackers has claimed responsibility for a cyberattack on the Russian satellite communications provider Dozor-Teleport, which is used by energy companies and the country's defense and security services.
Doug Madory, the head of internet analysis at the network monitoring company Kentik confirmed to Record Future News that Dozor-Teleport has been disconnected from the internet and is currently unreachable. Dozor’s parent company, Amtel Svyaz, also suffered a significant outage late on Wednesday, according to Madory.
The hackers claim that they damaged some of the satellite terminals and leaked and destroyed confidential information stored on the company's servers. The group posted 700 files, including documents and images, to a leak site, as well as some to their newly created Telegram channel.
The group claims to be affiliated with the notorious Wagner Grouphackers. There was no mention of the hack on the official Telegram channel of the Wagner Group and several experts expressed skepticism that the group was involved.
Dozor did not respond to inquiries about the attack.
Reference: Hackers claim to take down Russian satellite communications provider
Reference: Hackers force Russian military satellite operator offline
Victim: Dozor-Teleport
Russian satellite communications operator.
Incident: AON MOVEit Hack affects Dublin Airport Staff Data
Some Dublin airport staff's financial information has been compromised by a cyber-attack on provider company Aon (AON.N) that also affected various other firms, the Dublin Airport Authority (DAA) said on Sunday.
Britain's Sunday Times reported that the attack on file-transfer software tool MOVEit, used by Aon, affected nearly 2,000 Dublin airport staff, as well other agencies and companies in the US and UK.
The cl0p ransomware gang has claimed to be behind the hacking of MOVEit.
Victim: AON
Aon is a global provider of risk management, insurance and reinsurance brokerage, human resources solutions, and outsourcing services.
Reference: Dublin airport staff’s salary data breached
Reference: Dublin airport staff’s pay and benefits compromised in cyberattack
Reference: Dallas ransomware attack prompts new threat detection system
Reference: AIIMS ransomware attack led to new SOP on cyber breaches: Ex-cybersecurity chief Pant
Incident: Confusion About $70M Ransom Demand: Kinmax or TSMC ?
"In the morning of June 29, 2023, the Company discovered that our internal specific testing environment was attacked, and some information was leaked," reads the Kinmax statement.
"The leaked content mainly consisted of system installation preparation that the Company provided to our customers as default configurations."
The Lockbit ransomware group claimed to have hacked chipmaker giant TSMC. TSMC stated its supplier Kinmax was attacked. Kinmax is not the corporate giant that TSMC is, so LockBit's demands for a $70 million ransom payment will likely be ignored.
While there appears to be a mixup as to who was compromised in this attack, the $70 million ransom demand is one of the largest seen to date.
Victim: Kinmax Technology
a Taiwan-based corporate group and manufacturer of RAM modules and memory cards. The principal company of the group is Kingmax Semiconductor Inc.
Reference: Lockbit Demands $70M of TSMC Chipmaking Giant
Reference: Kinmax Technology statement
Incident: Lockbit Demands $70M of TSMC Chipmaking Giant
Chipmaking giant TSMC denied being hacked after the LockBit ransomware gang demanded $70 million not to release stolen data.
On Wednesday, a threat actor known as Bassterlord, who is affiliated with LockBit, began to live tweet what appeared to be a ransomware attack on TSMC, sharing screenshots with information related to the company. While this Twitter thread has since been deleted, the LockBit ransomware gang created a new entry for TSMC yesterday on their data leak site, demanding $70 million or they would leak stolen data, including credentials for their systems.
A TSMC spokesperson told BleepingComputer that they were not breached, but rather the systems of one of their IT hardware suppliers, Kinmax Technology, were hacked. "Upon review, this incident has not affected TSMC's business operations, nor did it compromise any TSMC's customer information."
Apart from validating that its systems had not been impacted in any way, TSMC states that it also stopped working with the breached supplier until the situation cleared up.
Reference: Us, hacked by LockBit? No, says TSMC, that would be our IT supplier
Victim: TSMC (Taiwan Semiconductor Manufacturing Company)
TSMC is one of the world's largest semiconductor manufacturers, with its products used in a wide variety of devices, including smartphones, high performance computing, IoT devices, automotive, and digital consumer electronics.
Reference: TSMC denies LockBit hack as ransomware gang demands $70 million
Incident: Hackers Stole Source Code from Taiwanese PC Parts Maker MSI
Taiwanese PC parts maker MSI (Micro-Star International) was listed on the extortion portal of a new ransomware gang known as "Money Message". The threat actors claimed to have stolen 1.5TB of data from MSI's systems. The stolen data includes source code and databases. The group demanded a ransom payment of $4,000,000.
Victim: MSI (Micro-Star International)
MSI is a global hardware giant in Taiwan with an annual revenue that surpasses $6.5 billion.
MSI makes motherboards, graphics cards, desktops, laptops, servers, industrial systems, PC peripherals, and infotainment products,
Reference: Money Message ransomware gang claims MSI breach, demands $4 million
Incident: Pharmedica Discloses March Databreach Exposed Medical Data of 5.8M
Pharmacy services provider PharMerica has disclosed a massive data breach. According to a data breach notification to authorities, hackers breached the system on March 12th, 2023, stealing the full names, addresses, dates of birth, social security numbers (SSNs), medications, and health insurance information of 5,815,591 people.
The Money Message ransomware gang claimed the attack on March 28th, 2023, when they began publishing stolen data.
Threat Actor: Money Message ransomware gang
Money Message is a new ransomware operation that launched around March 2023, gaining media attention for its breach against Taiwanese PC parts maker MSI (Micro-Star International).
Victim: PharMerica
PharMerica is a pharmacy services provider in 50 U.S. states, operating 180 local and 70,000 backup pharmacies, and serving 3,100 medical facilities nationwide.
Reference: Ransomware gang steals data of 5.8 million PharMerica patients
Incident: Significant Revenue Loss at Indian Pharmaceutical Giant after Cyberattack
Pharmaceutical company Granules India has reported a significant loss of revenue and profitability after a cyber security attack late last month. The attack led to major disruptions in the company's IT systems, as well as delays in meeting regulatory requirements and quality standards.
The company reported the incident on May 25. News outlets reported on June 29 that the company said that it has managed to restore production near to normalcy.
Russian ransomware group LockBit has taken responsibility for the cyberattack on Granules India.
Reference: Granules India ransomware attack claimed by LockBit
Victim: Granules India
Indian pharmaceutical manufacturing company based in Hyderabad, India.
Granules manufactures several off-patent drugs, including Paracetamol, Ibuprofen, Metformin and Guaifenesin, on a large scale for customers in the regulated and rest of the world markets.
Reference: Granules India flags significant loss of revenue as it continues to recover from cyber attack
Reference: Paracetamol maker Granules India flags significant operations hit from cyber attack
Reference: Burton Snowboards discloses data breach after February attack
Editorial: Similar Attacks? Just Look at the Facts
Incident: Serious IT Breach at Wisag, German Aviation Services
Wisag, a German aviation services provider suffered a serious IT breach on Jan. 27. Operational business continued, but the processes were severely disrupted for about a week. Wages for 55,000 employees were paid late. Wisag board member Michael Wisser publicly insisted at the time that he would not allow himself to be blackmailed by criminals.
It’s not clear if it’s linked to the Mabanaft breach.
Reference: Official information from the WISAG group of companies on the cyber attack
Reference: Oiltanking and Wisag: Hacker attacks on German companies
Incident: Wisag Group Hacked Again a Year Later
Almost exactly a year after the first attack, the service group Wisag fell victim to hackers again. On Tuesday morning, the IT department found "irregularities" on the servers, said a spokeswoman for the Frankfurt-based company. As a result, all systems and applications were immediately taken off the network.
"At the current time, it is not apparent that customer or internal data has leaked," it continues. "We are optimistic that we can safely put all systems back into operation as soon as possible."
Reference: Another hacker attack on the Wisag group
Victim: Wisag Service Group
Family owned company active in the business areas of facility management, industrial services and airport services. The group recently reported annual sales of 1.2 billion euros.
Incident: Ransomware Attack Halts Operations at Ziegler Fire Engine Manufacturer
On February 9th, the company noticed a cyber attack and shut down all systems.
On March 13, company spokes person Matthias Mühlbacher said “It was almost possible to restore the current situation at that time. Normal everyday work is possible again in large parts of the plants. "All software and hardware components were checked, cleaned or replaced and reinstalled with the help of forensic experts from the IT industry." Some effects, he emphasizes, would accompany the company for a while.
UPDATE, 23 April: Since the ransom was apparently not paid, ALPHV publishes documents that are said to belong to the company.
Reference: Ziegler Data Breach on April 24, 2023
Victim: Ziegler
German manufacturer of fire-fighting vehicles.
Reference: After cyber attack in February: All systems restored
Reference: Availabilty partially restored
Reference: Cyber attack on pump manufacturers: unknown persons blackmail company in MK
Incident: Cyberattack Affects All Locations of German VDM Steel
Unknown perpetrators carried out a cyberattack on VDM Metals. All locations are affected, including those in Werdohl (administration, wire and strip production), Altena (plate and rod production), Unna (melting plant, forge and rod finishing shop) and Siegen (plate rolling mill). Significant parts of the company's IT infrastructure are affected. Production came to a standstill and parts of the workforce sent home.
Two weeks later production is gradually restarting. The problem seemed to lie in the logistics data flow. VDM communicates most parts of the business will be up and running again by next week.
Several hundred computers have been exchanged in the company. The plant uses server resources from the Spanish parent company Acerinox, as can be seen from the new e-mail addresses of the employees.
Victim: VDM Metals
VDM Metals, part of Spanish Acerinox Group since 2020, employs around 2000 people worldwide. Based in Werdohl, VDM is the city's largest employer with around 700 employees.
VDM develops high-performance materials which are used, among other things, in car catalytic converters, in high-temperature fuel cells, in energy and environmental technology, in aviation and in the oil and gas industry.
Reference: Technical failures at VDM Metals
Reference: After a hacker attack: VDM fights back
Reference: Breathing easy after hacker attack VDM assures workforce at least partial payment
Incident: Steico Group Operations Disrupted after Cyberattack
The building materials manufacturer Steico has become the target of a cyber attack. The incident impacted both manufacturing operations and administration, the company's website said. The full extent of the attack is currently unknown. It is also unclear whether it was an extortion attack with ransomware.
Victim: Steico Group
Steico SE manufactures energy saving insulating materials for building industry.
Reference: Cyber attack on German building materials producer
Reference: STEICO Group affected by cyber attack
Incident: Cyberattack at SAF-Holland Causes Three Month Production Backlog
The commercial vehicle supplier SAF-Holland was the target of a cyber attack. Production is interrupted at certain locations and could last seven to fourteen days. Management is currently assuming that it will be able to catch up on the resulting production backlog over the course of the next three months.
The share, which is listed on the SDax, slipped briefly into the red after the news became known, but was recently up a good one percent again.
Reference: SAF-HOLLAND SE affected by cyberattack
Victim: SAF-HOLLAND Group
The SAF-HOLLAND Group is one of the leading international manufacturers of chassis-related assemblies and components for trailers, trucks and buses.
Reference: Cyber attack on SAF Holland
Incident: Public Transportation “Deutschlandticket” Launch in Germany Disrupted by Ransomware Attack
Hannover transport company Üstra suffered a cyberattack with significant operational fallout. The display boards at stations and railways as well as email and telephone traffic in customer service only partially worked throughout the weekend. Since then, Üstra employees have probably been trying feverishly to get the computer systems under control before the planned start of sales of the "Deutschlandticket" on Monday. That didn't work.
The hackers penetrated the IT systems with a contaminated email attachment that encrypts files. Üstra did not want to say anything about the ransom demand for investigative reasons.
Reference: Hanover Update: Hackers attack Üstra
Reference: Cyber attack on Hannover Transportation Company
Reference: Hackers stop Germany ticket in Hanover
Victim: Üstra
Üstra : local transport company in Hanover Germany
Incident: German Steelmaker Hacked
The IT network of Badische Stahlwerke (BSW) is affected by unauthorized network access. BSW identified the hacker attack on Thursday. The company reacted immediately and shut down all relevant systems in an isolated and controlled manner.
This also affected parts of the production. Employees reportedly furloughed. Parts of the production facilities were started up again on Friday. Investigation is ongoing.
Victim: Badische Stahlwerke (BSW)
Badische Stahlwerke GmbH is one of the world's leading electric-steel plants and supplies all of Europe with high-quality reinforcing steel.
Reference: Hacker attack on Baden steelworks
Reference: Hacker attack on Badische Stahlwerke in Kehl
Reference: Cyber attack on Baden steelworks
Incident: Cyberattack Causes Widespread Operational Disruption at Rheinische Post Mediagruppe
The "Rheinische Post Mediengruppe" has to shut down some systems because of a cyberattack. The operation of the news portals is only possible to a limited extent. Emergency editions of the affected newspapers were published on Monday. Unfortunately, the printed and digital editions cannot be offered in the usual structure, stated the "Rheinische Post".
Individual technical systems had to be switched off and the connection to the Internet had to be cut, according to the "Rheinische Post". The "Aachener Zeitung", which belongs to the media group, addressed the readers on the first page and wrote of an emergency edition "that does not fully correspond to what you are used to from us". The Bonn "General-Anzeiger" reacted with an edition that appeared "not in the usual scope and in the usual timeliness".
Victim: Rheinische Post Mediengruppe GmbH
Rheinische Post Mediengruppe GmbH operates as a media company. The company offers call center, printing, purchasing, IT, logistics, market research, and publishing services. Rheinische Post Mediengruppe serves customers worldwide.
Reference: Newspapers launch emergency editions after cyber attack
Reference: Hacker attack paralyzes parts of Rheinische Post Mediengruppe
Reference: Cyber attack on media group – emergency edition newspapers
Incident: German Autoparts Specialist, the Bilstein Group, Confirms Cyberattack
The Bilstein Group was apparently recently hit by a ransomware attack. The perpetrators published company data on the dark web. The auto parts specialist confirmed to CSO that a recent cyber attack occurred. "However, this was quickly discovered by our systems and IT specialists, so that the effects were marginal," explained a spokesman. The company declined to release any further information about the case. It is not known if there was a ransom note.
The BianLian ransomware gang has put the Bilstein Group on its victim list. In late April, 60GB of internal company data surfaced on the dark web, this includes includes personnel, accounting and financial data.
Victim: Bilstein Group
Automotive supplier and manufacturer. The Bilstein group is a worldwide leading specialist in the Independent Aftermarket based in Germany
Reference: German auto parts specialist Bilstein hacked
Incident: Emergency Operational Shutdown at Maxim, German Cosmetics Manufacturer
The cosmetics manufacturer Maxim fell victim to a ransomware attack, reports CSO Online Germany. The IT systems and production are affected. According to media reports, hackers penetrated the IT systems of the cosmetics manufacturer Maxim in early May. The cyber attack was initially discovered due to a "disruption to the network structure". The perpetrators encrypted parts of the IT systems and demanded a ransom. So far it is unclear whether company data was stolen.
As soon as the attack was discovered, all IT systems were shut down immediately, a spokeswoman told the Kölner Stadt-Anzeiger . Because of the immediate shutdown, the ransom demand could not be seen, so it is not clear how much they asked for decrypting the hacked systems.
On May 10, company spokeswoman Janine Kops states that all IT systems and devices are currently being checked for malicious software. "The work is progressing rapidly and it is becoming apparent that the IT systems that are currently still deactivated will go into secure and monitored emergency operation this week," says Kops. The cyber attack at the end of April led to an emergency shutdown of the systems; since then, production and delivery at Maxim have been paralyzed.
A professional hacker group claimed responsibility for the attack on Maxim, but the spokeswoman declined to give any further details for security reasons.
Reference: Pulheim-based company wants to protect itself against a new hacker attack
Victim: Maxim Cosmetics
Maxim is a cosmetics manufacturer based in Pullheim, Germany
Reference: Ransomware attack on cosmetics manufacturer Maxim
Incident: Operations Paralyzed Across All Locations of German Automotive Supplier Fritzmeier Gruppe.
Hackers paralyzed the Internet, telephone and some machines at the large vehicle supplier Fritzmeier. The attack was detected early Tuesday morning, after which all relevant systems were immediately shut down. "The attack affects all systems across all locations, so that we are currently severely restricted in our ability to work and availability," said the company spokesman Florian Linnerbauer .
Four weeks after the hacker attack, operations are up and running again. However, it is still unclear who is behind the attack. "Currently, all locations are back to normal operation," said Linnerbauer. According to Linnerbauer, the ability to deliver was largely guaranteed during the cyber attack. Thanks to a "comprehensive backup strategy important data could be quickly made available again". After limiting the damage, the focus for the group is on repairing the damage and taking preventive measures.
The actual financial damage for the Fritzmeier Group is currently being evaluated internally. "We cannot and will not provide any information on this for reasons of investigative tactics."
(e Bike supplier ,M1-Sporttechnik, part of the Fritzmeier Group was also affected. )
Reference: Cyber attack on the Fritzmeier company: Internet, telephone and machines paralyzed
Reference: Hacker attack on Fritzmeier Group: No trace of the blackmailers yet
Victim: Fritzmeier Group
Fritzmeier Group is a manufacturer of complete cabins, plastic assemblies, metalworking and environmental technology, was also hit. The Fritzmeier Group has several German locations and employs around 2.200 people worldwide.
Incident: Schneider Hit In MOVEit Transfer Zero Day
Schneider Electric suffered cyberattack from the Clop ransomware group
“On May 30th, 2023, Schneider Electric became aware of vulnerabilities impacting Progress MOVEit Transfer software.” the company said in a statement. “Subsequently, on June 26th, 2023, Schneider Electric was made aware of a claim mentioning that we have been the victim of a cyberattack relative to MOVEit vulnerabilities,” the company said. “Our cybersecurity team is currently investigating this claim as well.”
No further information was released at this time.
Victim: Schneider Electric SE
Schneider Electric SE is a European multinational company that specializes in digital automation and energy management. It addresses homes, buildings, data centers, infrastructure and industries, by combining energy technologies, real-time automation, software, and services.
In fiscal year 2022, the company posted revenues of €34.2 billion.
Reference: Schneider Hit In MOVEit Transfer Zero Day
Reference: Siemens Energy Confirms Ransomware Attack
Incident: Proctor & Gamble Confirms Data Theft
Consumer goods giant Procter & Gamble confirmed a data breach affected an undisclosed number of employees. Its GoAnywhere MFT secure file-sharing platform was compromised in early February.
The company didn't say who was behind the security breach. This reportedly is linked to the Clop ransomware gang's attacks targeting Fortra GoAnywhere secure storage servers worldwide. The Clop ransomware gang exploited the CVE-2023-0669 GoAnywhere vulnerability to steal data of more than 130 organizations.
Victim: Proctor & Gamble
P&G is one of the largest consumer goods corporations in the world. About two dozen of P&G’s brands are billion-dollar sellers, including Always, Braun, Crest, Fusion, Gillette, Head & Shoulders, Mach3, Olay, Oral-B, and Pantene.
Reference: P&G Cyber Attack: CL0P Ransomware Group Claims to Hit the Consumer Goods Corporation
Reference: Procter & Gamble confirms data theft via GoAnywhere zero-day
Incident: Lumen Hit By Separate Ransomware, Malware Attacks
Multibillion-dollar telecommunications firm Lumen Technologies told regulators Monday that it had discovered two cybersecurity incidents, including a ransomware attack that crippled some of its systems, that degraded services for some of its enterprise customers.
Lumen said that it caught the ransomware attack when a “malicious intruder” inserted malware “into a limited number of the Company’s servers that support a segmented hosting service.” The company did not immediately respond to questions about the type of ransomware involved, the scope of the attack, or whether they have attributed it to a specific group. The company said that the incident “is currently degrading the operations of a small number of the Company’s enterprise customers.”
Additionally, the company said that it discovered a separate incident involving an intruder accessing and installing malware on “internal information technology systems,” allowing the cybercriminal to steal “a relatively limited amount of data.”
Victim: Lumen Technologies
Headquartered in Monroe, Louisiana, Lumen offers an enterprise technology platform that combines networking, cloud, security, and collaboration services.
Reference: Telecom giant Lumen says it discovered two separate cyber intrusions
Incident: Swiss, German-Language Newspaper NZZ Shut Down Production
The “Neue Zürcher Zeitung” continues to struggle with problems two weeks after a cyberattack on its computers. The publisher shut down central systems for newspaper production and had to pre-produce the Saturday edition on Thursday of last week. The company announced on Saturday that this “exceptional situation” was also associated with a reduction in scope.
Due to the cyberattack, some systems and services are still not available. NZZ's IT team is working with external specialists on corrective measures, it said. Newspapers from CH-Media-Verlag, which obtains IT services from NZZ, also appeared on a reduced basis over the weekend.
A ransomware attack on the infrastructure of NZZ's parent, NZZ Mediengruppe in Zürich, became known two weeks ago. 500GB data stolen from this was later published on the dark web.
Additional impact at three media companies:
On May 3, CH Media confirmed that data had been published, saying, “initial analyses show that the data is from our delivery organisations”.
The Blick Group is affected as a company that belongs to CH Media is responsible for the postal delivery of the Blick newspapers, and is directly affected by the cyber attack.
Customer data from Tamedia newspapers is also said to be affected
Reference: Hacker group publishes stolen Swiss media data
Victim: NZZ Mediengruppe in Zürich
The NZZ media group is a Swiss media company and one of the largest private media companies in Switzerland. The group is divided into the business areas NZZ Medien and Business Medien (events and information services). The main purpose of the group is the publication of the Neue Zürcher Zeitung and other media.
Reference: NZZ has to shut down the newspaper production system after a cyber attack
Incident: Cyberattacks on North German Shipyards
The Flensburger Schiffbau-Gesellschaft (FSG) and the Rendsburg shipyard Nobiskrug have fallen victim to a cyberattack. The external attack on the shipyard's IT was noticed on March 3, a spokesman for FSG-Nobiskrug Holding said on Friday. "All IT systems were therefore sealed off by our experts and the responsible authorities informed."
BianLian ransomware group claims responsibility as it added Flensburger Schiffbau-Gesellschaft and Nobiskrug to their victimlist and claims to have access to 3TB of company data.
FSG-Nobiskrug Holding did not comment on this.
Victim: FSG-Nobiskrug Holding
Flensburger Schiffbau-Gesellschaft is a German shipbuilding company located in Flensburg. FSG acquired Nobiskrug-Werft, specialized in building innovative, custom-made luxury superyachts, in 2021.
Reference: BianLian #ransomware group added Flensburger Schiffbau-Gesellschaft and Nobiskrug Yachts GmbH, to their victim list.
Reference: Cyber attack on shipyards FSG and Nobiskrug
Incident: Operations Halted at German Shipbuilder
German shipbuilder Lürssen, which makes military vessels as well as luxury yachts, reports it has been the target of a ransomware attack. The attack brought large parts of Lürssen’s shipyard operations to a standstill, according to local news outlet Buten un Binnen.
According to several German media outlets, Lürssen said it is collaborating with internal and external experts to manage the cyber incident.
Victim: Lürssen shipyard
Lürssen shipyard builds military vessels and luxury yachts. Located in Germany
Reference: German builder of yachts and military vessels hit by ransomware
Reference: German Superyacht Maker Targeted by Ransomware Cyberattack
Incident: Ransomware Attack Delays Shipyard Production at Marinette Marine Shipyard
Fincantieri Marinette Marine suffered a ransomware attack last week that delayed production across the shipyard. Large chunks of data on the shipyard’s network servers were rendered unusable by an unknown professional group.
The attack on Marinette Marine targeted servers that held data used to feed instructions to the shipyard’s computer numerical control manufacturing machines, knocking them offline for several days. CNC-enabled machines are the backbone of modern manufacturing, taking specifications developed with design software and sending instructions to devices like welders, cutters, bending machines and other computer-controlled tools.
Based on information from the Navy, it’s unclear if the attackers stole any data. The yard is currently on contract to build four combatants for the Saudis and three frigates for the U.S. Navy, with the service planning to ramp up procurement in the pursuit of buying two frigates per year. The Navy acknowledged the attack in a statement but did not provide additional details.
UPDATE: The company notified regulators in Maine that personal information of 16,769 individuals was leaked due to the ransomware attack.
Incident: Suncor Suffers Cyber Attack, Hurts Retail Operations
Canada’s leading integrated energy company, Suncor, said Sunday it suffered a cybersecurity incident that is affecting its ability to complete transactions with customers, officials said.
The company said it is taking measures and working with third-party experts to investigate and resolve the situation, and has notified appropriate authorities. At this time, the company said it was not aware of any evidence that customer, supplier or employee data suffered compromised or ended up misused as a result of this situation.
“While we work to resolve the incident, some transactions with customers and suppliers may be impacted,” the company said in a statement.
The issues began on Friday (June 23), when customers reported problems logging into the app and website for Petro-Canada, a gas station chain owned by Suncor.
Reference: Suncor Energy hit by cyber attack; Petro-Canada gas stations impacted
Reference: Suncor Energy Hit In Cyberattack
Victim: Suncor
Suncor’s operations include oil sands development, production and upgrading; offshore oil and gas; petroleum refining in Canada and the U.S.; and the company’s Petro-Canada retail and wholesale distribution networks (including Canada’s Electric Highway, a coast-to-coast network of fast-charging electric vehicle stations).
Reference: Ransomware Attack Hits Marinette Marine Shipyard, Results in Short-Term Delay of Frigate, Freedom LCS Construction
Incident: Ransomware Attack at Constellation Software; ALPHV Steals over 1TB Data
Constellation Software confirmed some of its systems were breached. "The Incident was limited to a small number of systems related to internal financial reporting and data storage". "The independent IT systems were not impacted by this Incident in any way." It had contained the attack and restored the IT infrastructure systems impacted. Business partners and individuals whose information was stolen are being contacted.
Constellation Software acquires, manages, and builds software businesses through six operating groups: Volaris, Harris, Jonas, Vela Software, Perseus Group, and Topicus.
Victim: Constellation Software
Constellation Software acquires, manages, and builds software businesses through six operating groups: Volaris, Harris, Jonas, Vela Software, Perseus Group, and Topicus.
The Canadian company has over 25,000 employees across North America, Europe, Australia, South America, and Africa, generating consolidated revenues exceeding $4 billion.
Constellation also provides services to 125,000 customers in over 100 countries and has acquired more than 500 software companies since 1995.
Reference: ALPHV gang claims ransomware attack on Constellation Software
Reference: Constellation Software hit by cyber attack, some personal information stolen
Incident: ScanSource Mitigates Business Impact after Cyberattack
ScanSource, a leading hybrid distributor connecting devices to the cloud, today announced that it was subject to a ransomware attack impacting some of its systems. Upon discovering the incident the Company immediately launched an investigation and implemented its Incident Response Plan.
ScanSource is working diligently to bring affected systems back online, while also mitigating the impact on its business. ScanSource regrets any inconvenience or delays in business this may cause customers and suppliers in North America and Brazil and appreciates their patience.
Victim: ScanSource Inc.
ScanSource Inc., a leading hybrid distributor connecting devices to the cloud
Reference: ScanSource Provides Information on Cybersecurity Incident
Incident: Enzo Biochem Breach Exposes Clinical Test Data on 2.5M People
Biotechnology company Enzo Biochem has revealed that the clinical test information of roughly 2.47 million individuals was exposed in a recent ransomware attack.
The incident resulted in certain systems being disconnected from the internet.
On April 11, Enzo Biochem’s investigation revealed that the attackers accessed and exfiltrated certain information from its systems, including names, clinical test information, and, in some cases, Social Security numbers.
UPDATE: Enzo Biochem pays states $4.5 million over breached data
Reference: Enzo Biochem Ransomware Attack Exposes Information of 2.5M Individuals
Victim: Enzo Biochem
Based in Farmingdale, New York, Enzo Biochem develops and provides molecular diagnostics technologies, including DNA-based tests.
Reference: Ransomware Attack on Bioscience Firm Exposes Clinical Test Data on 2.5M People
Incident: Eisai Pharma Takes Systems Offline After Ransomware Attack
Japanese pharma group Eisai Co., Ltd. says it is battling a ransomware attack that was launched on June 3. This resulted in some of its servers becoming encrypted. The attack affected servers both within and outside Japan, and resulted in some of the group’s IT functions, including logistics systems, being taken off line.
For now, it says the corporate websites and email services remain operational, and there’s no clear indication yet whether sensitive data has been leaked. "Eisai Group is working closely with external experts and law enforcement in an effort to protect its systems and to make a successful recovery."
“Any potential impact of this incident on the consolidated earnings forecast of this fiscal year is currently under careful examination,” it said.
At the time of writing, it’s not clear if the attack is linked to the other recent data hacks of Cl0p ransomware gang.
Victim: Eisai Co. Ltd.
Eisai CO. Ltd is a Japanese pharmaceutical company headquartered in Tokyo, Japan. It has some 10,000 employees, among them about 1,500 in research.
Reference: Eisai is latest pharma to suffer ransomware attack
Incident: US Hospital Closes 2 Years after Cyberattack: Unprecedented Case
St. Margaret’s Health, a hospital in Spring Valley, Ill., announced in May 2023 that it will have to close its doors due to the financial impact of a ransomware attack. That attack, which occurred in 2021, crippled the hospital’s computer systems and prevented financial claims from being submitted to insurance companies and government agencies for several months. This resulted in significant financial difficulties for the facility.
Experts believe this is the first time a hospital has had to close due to a cyberattack.
Hospital management said a combination of factors, including the Covid 19 pandemic, the cyberattack and a shortage of staff, had made it impossible to keep operations going.
Reference: Cyberattack Forces St. Margaret’s Health –Spring Valley to Shut Down Computer Systems
Victim: St. Margaret’s Health
St. Margaret's Health, the premier provider of health care in the Illinois Valley since 1903.
Reference: A cyberattack is partly to blame for St. Margaret’s Health closing all operations
Reference: Cyberattack is a factor in Illinois hospital’s closure
Incident: Gentex Corp. Hacked; Ransomware Gang Leaks 5TB of Data
Gentex Corporation confirmed it suffered a ransomware attack a few months ago. Gentex issued a statement saying "the breach has not had an impact on our operations."
TechTarget Editorial received an email May 18, 2023 purportedly from a Dunghill operator claiming the group breached the Michigan-based technology and manufacturing company. The email contained a link to a Tor site that allegedly contained 5 TB of sensitive corporate data, including emails, client documents and the personal data of 10,000 Gentex employees such as Social Security numbers.
The Dunghill ransomware gang claimed responsibility for the attack a month ago: "Gentex has ignored fact of the data leak. Some defence part of data leaked too," a Dunghill representative wrote in the email.
In addition, Dunghill claimed it has shared the stolen data with manufacturers from China, India and the U.S. "because Gentex refused to cooperate." It did not address whether those manufacturers were Gentex competitors, partners or both. Gentex has not responded to follow-up questions at press time.
Threat Actor: Dunghill ransomware gang
Dunghill ransomware gang, a relatively new threat group.
On April 10, 2023 Zscaler revealed the Dark Angels ransomware group had launched a new data leak site and rebranded as Dunghill.
Victim: Gentex Corporation
Gentex Corporation is an American electronics and technology company that develops, designs and manufactures automatic-dimming rear-view mirrors, camera-based driver assistance systems, and other equipment for the global automotive industry.
Reference: Gentex confirms data breach by Dunghill ransomware actors
Reference: Auto supplier Gentex hit by ransomware attack
Reference: Auto supplier Gentex hit by ransomware attack
Incident: Siemens Energy AG Confirms Ransomware Attack
Cl0p ransomware group claimed the cyber attack on Siemens Energy and four other organizations including Schneider Electric and the University of California Los Angeles.
Siemens Energy spokesperson, Claudia Nehring, stated, “Regarding the global data security incident, Siemens Energy is among the targets. Based on the current analysis, no critical data has been compromised and our operations have not been affected. We took immediate action when we learned about the incident.”
Siemens Energy in-house ProductCERT team has not released any statements or updates regarding the alleged cyber attack. The team is responsible for handling all security-related matters pertaining to their products, solutions, and services.
Cl0p listed Siemens Energy on their data leak site. The group has been wreaking havoc on various organizations in recent weeks.
Victim: Siemens Energy AG
Siemens Energy AG is considered one of the world’s largest energy technology companies wih 91,000 employees in more than 90 countries.
Reference: Cyber Attack on Siemens Energy: Company Confirms the Incident
Incident: Shell Investigates Ransomware Attack by the Cl0p Group
Oil and Gas giant Shell ransomware attack conducted by the Clop gang exploiting a MOVEit zero-day vulnerability. The company is investigating the security breach and said that at this time the attack had no impact to its core IT systems.
The Clop ransomware gang claims to have hacked hundreds of companies. At the time of this writing, the Clop ransomware group already added 27 companies to the list of victims on its dark web leak site. The group claimed to have compromised the companies by exploiting the zero-day CVE-2023-34362.
In March 2021, Shell disclosed another data breach resulting from the compromise of an Accellion File Transfer Appliance (FTA) used by the company.
Reference: Oil and gas giant Shell is another victim of Clop ransomware attacks
Reference: (Zellis) Press statement on MOVEit Transfer data breach
Reference: BBC and British Airways affected by data breach at payroll company Zellis
Incident: Accellion-related Data Breach Reported by QIMR Berghofer
The QIMR Berghofer Medical Research Institute has also announced today a data breach caused by the Accellion FTA service and has provided more detailed information regarding what information was accessed.
According to the research institute, the data breach appears to have occurred on December 25, 2020, when threat actors accessed approximately 4 percent, or 620MB, of data stored on the Accellion FTA service.
QIMR Berghofer states that they received their first notification to install Accellion's patch on January 4th, 2021. It wasn't until February 2nd, 2021 that Accellion notified them that they had suffered a data breach.
"The first notification QIMR Berghofer received from Accellion was on 4 January 2021, when the company advised the Institute to apply a security patch. The Institute immediately took the software offline and applied the patch."
"Accellion notified QIMR Berghofer on Tuesday 2 February 2021 that it believed the Institute had been affected by the data breach, which has also affected a number of Accellion’s other Australian and international clients," QIMR Berghofer disclosed in a data breach notice on their website.
Victim: QIMR Berghofer Medical Research Institute
QIMR Berghofer Medical Research Institute (QIMR Berghofer) is an Australian medical research institute located in Herston, Brisbane
Incident: Accellion-related Data Breach Reported by Singtel
Singtel, the largest mobile carrier in Singapore, announced that they suffered a data breach caused by the Accellion FTA service's vulnerability.
"A third-party file sharing system provided by Accellion called FTA has been illegally accessed through a zero-day vulnerability or previously unknown vulnerability. Singtel uses this system to share information internally as well as with external stakeholders and organisations," Singtel announced in a security incident notification.
The telecommunications company has not disclosed what data has been accessed in the attack and states that they are currently investigating who was impacted.
Reference: Singtel, QIMR Berghofer report Accellion-related data breaches
Incident: Brunswick Corp. Recovering from Serious Cyberattack
Marine industry giant Brunswick Corporation suffered a serious breach on June 13. The incident affecting part of its computer systems and its facilities at sites around the world.
On June 22 the company reported that all of its main manufacturing facilities are back online. Most of its primary distribution centers are back up and running. The rest of its locations should restart within a few more days, the firm said. The Mercury Marine plant in Fond du Lac, Wisconsin was among the locations affected, a spokesperson told local media. The site was not fully shut down by the cyberattack and many employees remained at work. Brunswick's management teams are focused on ramping production back up and filling backorders created by the shutdown. The process of catching up will likely continue through the third quarter, the company said.
On August 22, the company CEO stated that the ransomware attack would cost it “as much as $85 million.” “We have the opportunity to recover some lost production and distribution across our businesses, which will partially offset lost days in the second quarter. However, lost production days on high horsepower outboard engines will be challenging to recover because the production schedule was already full for the balance of the year.”
Victim: Brunswick Corporation
Brunswick is a major supplier for law enforcement agencies, as well as small commercial boat operators in coastal and inland settings, and it has a range of engines and workboats designed for commercial use. It is known best for its portfolio of consumer brands, including Boston Whaler.
Reference: Brunswick Corp. Works to Recover From Cyberattack
Reference: Acer says server for repair technicians accessed by hackers
Reference: Dish Network lawsuits pile up after crippling ransomware attack
Reference: Dish Network Shares Hit 14-Year Low After Cyber Attack Caused Major Outage
Incident: Website Outage and Passenger Data Breach at Scandinavian Airlines
A recent multi-hour outage of Scandinavian Airlines (SAS) website and mobile app was caused by a cyberattack. The cyberattack caused passenger data to become visible to other passengers. This data includes contact details, previous and upcoming flights, as well the last four digits of the credit card number.
Reference: Scandinavian Airlines says cyberattack caused passenger data leak
Reference: SAS CYBER ATTACK – UPDATE
Reference: Airline SAS network hit by hackers, says app was compromised
Incident: Hackers Demand $3M from Scandinavian Airlines (SAS)
The hacker group "Anonymous Sudan" has made an unexpected demand of $3 million from Scandinavian Airlines (SAS) in order to halt distributed denial-of-service attacks (DDoS) that have been targeting the airline's websites since February. Despite initially presenting themselves as politically-motivated hacktivists, the group appears to be resorting to using extortion tactics for financial gain.
On Monday, 29 May, Anonymous Sudan shared a ransom note on its Telegram channel claiming that SAS and its services have been paralyzed for more than five days. The company has responded to user complaints on Facebook, acknowledging an issue with its website and assuring customers that SAS is "working to resolve it quickly." SAS did not respond to The Record’s inquiries.
Meanwhile, Anonymous Sudan continues to escalate their demands, raising their initial price from $3,500 to a staggering $3 million. Anonymous Sudan first began targeting SAS in February, knocking its website offline and exposing some user data. Some customers who attempted to log in to the SAS mobile app were sent to others’ accounts and had access to their contact information and itineraries. The group blamed the burning of a Quran during demonstrations in January protests in Stockholm for motivating the attacks.
Anonymous Sudan followed up the incident with cyberattacks on Sweden’s national public television broadcaster, German airports, Danish hospitals, as well as Israeli banks, news websites, and, most recently, a missile warning system.
Threat Actor: Anonymous Sudan
Anonymous Sudan is not an authentic part of the Anonymous hacktivist movement but “most likely created as part of a Russian information operation to harm and complicate Sweden's NATO application,” according to a report published by Swedish cybersecurity company Truesec.
Truesec noted the Anonymous Sudan account on Telegram has its user location listed as Russia, and most of its targets are nations that support Ukraine in its fight against Russia. Other research from the Chicago-based company Trustwave found that there are indications that Anonymous Sudan is a sub-group of the Pro-Russian state-sponsored hacker group Killnet. Anonymous Sudan has openly associated itself with this group.
Trustwave also found some evidence that Anonymous Sudan is financially motivated, as it attempted to sell data stolen from French flag carrier Air France.
Although the group mainly carries out unsophisticated DDoS attacks, they can have serious consequences as they target critical facilities such as hospitals, airports, banks, and government institutions, the researchers said.
Reference: Hacker group Anonymous Sudan demands $3 million from Scandinavian Airlines
Incident: European defense contractor, Hensoldt, allegedly Victim of Snatch Ransomware Attack.
A French subsidiary of HENSOLDT AG, and part of its subsidiaries ("Nexeya"), have become the target of a serious cyber attack on its IT infrastructure in recent days. According to current information, both of Nexeya's data centers in France have been affected, and it is likely that a significant amount of data has been accessed and systems have been encrypted. Nexeya's ongoing operations have been impacted by this cyber attack.
A comprehensive investigation of the incident has been launched immediately, in close cooperation with the relevant authorities.
Work is proceeding at full speed to restore Nexeya's ongoing operations as quickly as possible. According to current knowledge, the IT infrastructure and data of other companies of the HENSOLDT Group are not affected.
Victim: Hensoldt
Hensoldt is a leading company in the European defence industry with global reach. Based in Taufkirchen near Munich, Germany
Reference: European defense contractor allegedly hit with ransomware
Reference: French subsidiary of HENSOLDT AG targeted by a serious cyber attack
Reference: Ingenico, new victim of Snatch cybercriminals after Hensoldt France and Hemeria
Reference: CERT EU report
Reference: Hemeria Group Data Breach: Palace of Versailles Denies Negotiating with Snatch
Victim: Hemeria Group
Hermeria Group specializes in the design, manufacture and assembly of equipment and systems for the space industry (including small satellites) and French deterrence.
Incident: Lockbit Attacks Portuguese Water Utility Company
Águas e Energia do Porto said on February 8 it had been hit with a cyberattack, with its security team able to limit the damage. Public water supply and sanitation were not affected by the attack.
The LockBit group added the company to its leak site on February 18, according to cybersecurity expert Dominic Alvieri. LockBit gave the utility until March 7 to pay a ransom, threatening to publish stolen information from Águas e Energia do Porto systems if the deadline passed without payment.
“Due to the incident, some customer services suffered constraints," the utility said. The company was still able to process customer requests at in-person service desks, and it urged people to get virtual service tickets that could be obtained instead of standing in line.
The utility did not respond to requests for comment about an update on the situation.
Victim: Águas e Energia do Porto
Owned by the city of Porto, it is one of the largest Portuguese water supply and wastewater sanitation companies, serving approximately half a million people. In addition to managing the water supply and wastewater, the company drains Porto's rainwater, controls about 85 kilometers of water lines, manages the city's waterfront, and more.
Reference: LockBit gang takes credit for attack on water utility in Portugal
Incident: Hackers disrupt IT network of Rome’s Public Utility and Power Company, ACEA
Acea's computer system network was restored 4 days after the cyber attack by the Black Basta ransomware group.
“The Group's websites and the online platforms for managing the commercial aspects of water, electricity and gas supplies are operational, as well as – from Saturday – the contact center service of the Group companies for customers" The Company reiterates "that the IT disruption generated by the cyber attack did not affect the essential electricity and water distribution services which have always been regularly guaranteed".
The Italian cybersecurity agency says at least a dozen hacks are likely tied to the BlackBasta ransomware group. Investigators say the ransomware campaign may have hit thousands of organizations worldwide since Thursday. The first attack was against energy company Acea.
Victim: ACEA
Rome's Public Utility and Power Company
Reference: BlackBasta Blamed for Global Attacks on VMware ESXi Servers
Reference: Acea: “After the hacker attack, the operations of the IT systems have been restored”
Incident: Pro-Ukrainian Hacktivist Groups Claim Disabling over 1000 Network Routers in Russia
The pro-Ukraine hacktivist group TeamOneFist and RoughSec conducted the operation "Turn Ruzzia Off" and claim it demolished or disabled some 1,260 network routers in 48 hours.
The operations combined 3 missions to attack Rostelecom and Beeline ISPs with the objective of creating Internet and VoIP phone outages across all of Russia in government buildings, military facilities and Oligarch homes. The goal of the attack was to cripple Russian war logistics and slow down the Russian process of reinforcing their army in Ukraine.
Threat Actor: Anonymous RoughSec
Anonymous RoughSec is a pro-Kyiv cyber threat actors and a sub-group of the decentralised Anonymous collective.
Victim: Beeline
Beeline (Russian: Билайн), formerly Bee Line GSM (Russian: Би Лайн GSM) is a telecommunications brand by company PJSC VimpelCom, founded in Russia.
PJSC VimpelCom is Russia's third-largest wireless and second-largest telecommunications operator.[ Its headquarters are located in Moscow.
Beeline was previously owned by Veon, a Netherlands-based company that also owns Ukraine's Kyivstar. Following the invasion of Ukraine, Veon began divesting its Russian operations and sold its Russian assets, including Beeline, as part of its exit strategy.
Victim: Rostelecom
Rostelecom is Russia’s largest provider of digital services for a wide variety of consumers, households, private businesses, government and municipal authorities, and other telecom providers. Rostelecom interconnects all local public operators’ networks into a single national network for long-distance service.
Reference: Pro-Ukrainian hackers hacked more than 1 000 routers across Russia – “Operation Turn Ruzzia Off”
Reference: CERT EU REPORT
Incident: Critical Infrastructure Disrupted in Martinique by Prolonged Cyberattack
The Caribbean island of Martinique is dealing with a cyberattack that has disrupted internet access and other infrastructure for weeks. The attack began on May 16, forcing officials to isolate the affected systems. Cybersecurity experts were mobilized to help gradually restore their operations.
“Regarding education services, technical solutions are being set up to restore internet access to colleges and high schools. School administrators and the government are coordinating in order to ensure the smooth handling of exams. The government will make every effort to ensure the payment of social benefits,” officials said in a statement.
“Regarding financial services, the community will be able to issue new purchase orders and ensure the payment of bills. These must be filed in paper format from the mail office in Plateau Roy. Concerning aid and subsidy services, the filing of requests must be made in paper format to the office in Plateau Roy due to the unavailability of online platforms.”
Threat Actor: Rhysida Ransomware Group
Because Rhysida ransomware first appeared in May 2023, not much is known about the ransomware or the group at this time [June 2023].
They do not seem to be listing victims to warn them publicly before leaking information. The only entries on the site currently are the ones that they have leaked totally. None of the listings indicate when Rhysida attacked or encrypted the victims.
Reference: Caribbean island of Martinique dealing with cyberattack that disrupted government services
Incident: Disruption of online vote in Martinique
The platform for the online vote on a flag and anthem for the French overseas department of Martinique had to be taken offline, on January 4, 24 hours after the start of the vote. The reason for the disruption was reported to be a cyberattack.
The attack on government servers upended a nearly two-week online voting window that began on Jan. 2. Officials said the attack was not successful but forced them to temporarily shut down the system.
Victim: Martinique
Martinique has a population of about 360,000 and is controlled by France, serving as an outermost region of the European Union.
Reference: Cyberattack halts Martinique’s search for new flag, hymn
Reference: Cybersecurity Brief Cert-EU
Incident: Ransomware Attack at Royal Mail Disrupts International Operations more than a Month
The LockBit ransomware operation has claimed the cyberattack on UK's leading mail delivery service Royal Mail that forced the company to halt its international shipping services due to "severe service disruption."
Royal Mail refused to pay an $80m (£67m) ransom sought by hackers linked to Russia after the “cyber incident”, which resulted in 11,500 Post Office branches across the UK being unable to handle international mail or parcels fro almost six weeks after the attack. The company has said it is losing £1m a day.
Victim: Royal Mail
International Distributions Services plc, trading as Royal Mail, Parcelforce and GLS, is a British multinational postal service and courier company, originally established in 1516 as a government department. The company's subsidiary Royal Mail Group Limited operates the brands Royal Mail and Parcelforce Worldwide
Reference: Royal Mail resumes overseas deliveries via post offices after cyber-attack
Reference: LockBit ransomware gang claims Royal Mail cyberattack
Incident: German Software Provider Bismarck Suffers Data Leak
On January 23, media reports suggested that Bitmarck, an IT service provider for
German health insurance companies, had suffered a data leak. A cybercrime group
reportedly extracted data from the company’s Jira project management and
databases and put it up for sale. There is no indication that any personal health
data was exposed.
Victim: Bitmarck
BITMARCK is a leading provider of IT solutions for the German public health insurance market, offering services to a variety of health insurers, including company and craft guild insurers, DAK-Gesundheit, and alternative insurers.
Reference: eHealth: 300,000 insured accesses affected by Bitmarck leak
Incident: Entire Data Centers Taken Offline at Giant German IT Service Provider Bitmarck
Bitmarck, one of the largest IT service providers within Germany’s statutory health insurance system, announced on Sunday it had taken all of its customer and internal systems offline due to a cyberattack.
Bitmarck, which employs around 1,600 people, said that the customer and internal systems were
Taking these services offline impacts a range of individuals and organizations associated with Bitmarck’s services, particularly those who rely on the company to issue electronic sickness certificates used in Germany to pay employees’ leave. Bitmarck also warned that pharmacies it works with may also experience technical problems.
In its statement, the company said disruptions were likely to continue “for the foreseeable future,” as entire data centers were taken offline and restarting these was likely to be accompanied by temporary service failure.
“We very much regret the inconvenience caused to our customers, service providers and insured persons and are working to restore the systems as quickly as possible,” the company stated.
Reference: Bitmarck, one of Germany’s largest IT providers, hit by cyberattack
Incident: Widespread Disruption at Norton Healthcare Operations after Ransomware Attack
Norton Healthcare says it has been victimized by a "cyber-event," and some of its computer network systems have been offline. Patient appointments, surgeries, emergency care and online services were all affected.
The BlackCat ransomware group claims responsibility for the attack and says to have exfiltrated 4.7 TB of data.
The effects of the attack are still impacting the health system’s network and services over a month later. With some communication platforms back in full operation, problems with the distribution of testing and imaging results, and [re]scheduling of procedures, exams persisted.
Reference: Cyberattack on Norton Health spurs long waits, prescription and lab delays
Victim: Norton Healthcare Services
Norton Healthcare serves nearly 600,000 patients across Louisville, KY a year. It has $4.7 billion worth of assets with five hospitals, eight outpatient centers, 18 urgent care clinics, and 289 doctor’s offices.
Reference: Norton Healthcare hit with ‘cyber-event’ amid ongoing computer system shutdowns
Incident: Data Breach at Luxottica’s Eyemed Vision Affects 820K Patients.
Luxottica disclosed that their appointment scheduling application suffered a data breach after being hacked on August 5th, 2020. The breach has exposed the personal and protected health information of 829,454 patients at partner eye care practices. Luxottica's Eyemed division partners get access to a web-based appointment scheduling application.
This data breach announcement comes on the heels of a Nefilim ransomware attack on Luxottica. This September 2020 attack caused significant outages, interruptions, and theft of unencrypted files.
Reference: Luxottica data breach exposes 820K EyeMed, LensCrafters patients
Reference: Eyewear giant Luxottica hit by Windows Nefilim ransomware, data leaked
Incident: Ransomware Attack Affects Worldwide Operations of Italian Eyewear Giant Luxottica
Italy-based eyewear and eyecare giant Luxottica has reportedly suffered a ransomware attack that has led to the shutdown of operations in Italy and China and data leaked on the dark web. .
Union sources confirmed to Italian media Ansa that the employees were sent home due to "serious IT problems." The ransomware attack affected the company worldwide, and for days offices were not fully operational.
Security official Nicola Vanin stated in a LinkedIn post "Once the event was analysed, the clues were collected in less than 24 hours and the procedure for cleaning up the affected servers began. Work activities are gradually returning to normal in the #Milano plants and headquarters."
He also stated that "There is currently no access or theft of information from users and consumers." However a month later the Windows Nefilim ransomware group leaked financial and human resources operations data on the dark web.
Reference: Ray-Ban owner Luxottica confirms ransomware attack, work disrupted
Incident: Luxottica Eyewear Group discloses 2021 Attack Affecting 70M Customers
Luxottica Group confirmed in May 2023 that one of its partners suffered a data breach in 2021. The breach exposed the personal information of 70 million customers. It was discovered after data was put up for sale on the dark web.
Andrea Draghetti, the leading researcher of the Italian cybersecurity firm D3Lab, analyzed the leaked data. She confirmed to BleepingComputer that it contains 305 million lines, 74.4 million unique email addresses, and 2.6 million unique domain email addresses.
Draghetti also determined the exfiltration date to be March 16th, 2021. This meant that the data likely originated from a previously undisclosed data breach.
Victim: Luxottica Group S.p.A.
Luxottica Group S.p.A. is an Milan-based eyewear conglomerate and the world's largest eyewear company, glasses, and prescription frames maker, and the owner of popular brands like Ray-Ban, Oakley, Chanel, Prada, Versace, Dolce and Gabbana, Burberry, Giorgio Armani, Michael Kors, and many other.
Luxottica employs over 80,000 people and generated 9.4 billion in revenue for 2019.
The company also operates Eyemed, a vision insurance company in the US.
Reference: Luxottica confirms 2021 data breach after info of 70M leaks online
Incident: Vesuvius Industrial Manufacturer Discloses $4.6M Cost as Result of Cyber Incident
Vesuvius, a UK-based molten metal flow engineering company issued an alert on February 6, 2023, which stated it was “currently managing a cyber incident, [which] has involved unauthorized access to our systems.” The London Stock Exchange-listed ceramics manufacturer disclosed in May that the perplexing cyber incident will incur a hefty cost of $4.6 million.
The exact nature of the incident remains shrouded in secrecy, as the company has refrained from providing specific details.
Notably, Vesuvius is the second British industrial ceramics manufacturer to disclose a cyber incident in 2023. In January, Morgan Advanced Materials, a company specializing in semiconductor production, also submitted a cybersecurity incident notice to the London Stock Exchange.
Victim: Vesuvius
Vesuvius is a global leader in molten metal flow engineering and technology
Reference: Vesuvius Faces Costly Consequences of Cyber Incident
Reference: UK Engineering Company Vesuvius Hit by Cyber Attack
Incident: Sysco, Global Food Distributor, Hit in Cyberattack
Global food distributor, Sysco fell victim to a “cybersecurity event” at the beginning of the new year where the attacker gain information on workers and the company.
Sysco said in a 10-Q report, “on March 5, 2023, Sysco became aware of a cybersecurity event perpetrated by a threat actor believed to have begun on January 14, 2023. Immediately upon detection, Sysco initiated an investigation, with the assistance of cybersecurity and forensics professionals.
“The investigation determined that the threat actor extracted certain company data, including data relating to operation of the business, customers, employees and personal data. This data extraction has not impacted Sysco’s operational systems and related business functions, and its service to customers continued uninterrupted."
The incident affected 126,243 people. It took the company just under two months to discover the breach. They notified victims earlier this month. In essence from breach to notifying victim, it took the company almost five months.
Reference: Sysco Hit In ‘Cybersecurity Event’
Victim: Sysco
A multinational company headquartered in Houston, Texas, Sysco is one of the largest distributors of food products, kitchen equipment, smallware, and tabletop products to restaurants, lodging establishments, healthcare and education organizations, and other entities.
Incident: Philadelphia Inquirer Unable to Print Sunday Paper
The Philadelphia Inquirer was hit with a cyberattack that resulted in significant disruptions to its operations. It was unable to print its Sunday paper on May 14, and it had to scramble to restore several systems. The paper closed its office through Tuesday and the newspaper is working with “third-party forensic specialists from Kroll to restore systems and fully investigate the matter,” according to the emailed statement.
With the timing of the attack right before the city’s mayoral primary election, political motivation is a possibility. The Philadelphia Inquirer has not made any ransom demands public, nor is it clear if the information of employees or customers has been compromised, according to The Philadelphia Inquirer coverage.
Victim: The Philadelphia Inquirer
Newspaper in PA
Reference: Cyberattack Takes Down Systems at Philadelphia Inquirer
Incident: Ransomware Attack at German Furniture Company Häfele.
German kitchen system specialist Hafele was hit by a ransomware attack at its headquarters on the night of Feb. 2, 2023. The attack targeted the IT systems of the Häfele Worldwide Group from an external source. According to the company, the shutdown of our systems is now being followed by a gradual and controlled reactivation, the company said in a statement on its website. The company did not say when it would be fully operational.
UPDATE: Häfele was able to rebuilt its 50+ country, 180-site network in under 30 days with the help of SASE.
Victim: Häfele
Häfele , German kitchen system specialist
Reference: Häfele IT systems down after cyber attack
Reference: Häfele Recovers from Ransomware Attack using SASE
Incident: Systems Shut Down at Stiles Machinery after Cyberattack
Stiles Machinery has detected a cyber-attack on its IT systems. The Grand Rapids-based equipment supplier announced that it had detected the attack and shut down its systems to protect its system.
The company issued a statement: "Out of an abundance of caution, we have decided to completely shut down our systems while we investigate the situation further. The security and data of our customers and business partners are one of our highest priorities. Currently, we have no indication of any data loss. We are working to restore operations to full functionality as soon as possible."
Victim: Stiles Machinery
Grand Rapids-based equipment supplier
Reference: Stiles Machinery detects cyber attack
Incident: Production at Canadian Tool Manufacturer Exco Technologies Interrupted
A Canadian-based international manufacturer of die cast tools and car parts has been the victim of a cyber attack. Exco Technologies said Monday that three production facilities within its Large Mould Group are recovering from a cyber incident last week. The Toronto-headquartered company temporarily disabled some computer systems as it investigated this incident. It is in the middle of bringing these systems back online, and expects operations to be substantially restored over the next two weeks.
Shipments to customers have not and are not expected to be materially interrupted. The statement didn’t detail the kind of attack, or whether personal or corporate data was accessed. It said independent experts have been retained to help the company in dealing with the matter.
Reference: Exco Technologies Limited Announces Cyber Security Incident
Victim: Exco Technologies
Exco Technologies, Canadian tool manufacturer
Reference: Canadian tool manufacturer hit by cyber attack
Incident: Attack Disables Irrigation Systems and Disrupts Water Treatment Processes
Water controllers for irrigating fields in the Jordan Valley were damaged, as were control systems for the Galil Sewage Corporation. Several water monitors – which monitor irrigation systems and wastewater treatment systems – were left dysfunctional on Sunday after a cyber attack targeted the monitoring systems. Specifically, water controllers for irrigating fields in the Jordan Valley were damaged, as were control systems for the Galil Sewage Corporation.
The management for both major systems was pushing all of Sunday morning to work through the issue and bring the systems back into full operation. Farmers in the region were warned several days prior about suspicions over a planned cyber attack. Some of them, as a result of the warning, disconnected the remote control option for their irrigation systems and switched them to manual operation, instead, to prevent any harm from the attack. Indeed, those who left their systems on remote control were the ones impacted by the attack.
The attack is thought to be part of an annual “hacktivist” campaign that takes place every April, and this year’s attempt at least managed to cause a nuisance for some farms in the Jordan Valley. The cyber attack is part of an annual campaign called “OpIsrael,” which strikes in April with DDoS attacks and breach attempts on targets in the country.
Each year of the cyber attack campaign seems to bring new targets of opportunity. This year the threat actors put a special focus on irrigation systems. The Galil Sewage Corporation was one of the targeted wastewater processors that was breached, and the company reports that the cyber attack blocked several controllers for about a day and disrupted some treatment processes.
Victim: Galil Sewage Corporation
Galil Sewage Corporation, Israel
Reference: Cyber attack leaves irrigation systems in Upper Galilee dysfunctional
Reference: Irrigation Systems in Israel Hit With Cyber Attack That Temporarily Disabled Farm Equipment
Incident: Cyberattack Halts Production at Factories of Suzuki Motorcycle India
Suzuki Motorcycle India – the Japanese two-wheeler maker has been compelled to stop production at its factories due to a “cyber-attack” on its operations. According to several people in the know, the production has been stalled since Saturday, May 10, and it is estimated to have incurred a production of loss of over 20,000 vehicles in this timeframe.
As part of its measures to address the situation at hand, a few days ago, Suzuki Motorcycle informed its ecosystem that due to an “unprecedented business requirement”, it has postponed its annual supplier conference, which was scheduled to be held next week.n as saying.
Victim: Suzuki Motorcycle India
Suzuki Motorcycle India, Private Limited is the wholly owned Indian subsidiary of Suzuki, Japan. It was the third Suzuki automotive venture in India.
Reference: Suzuki Motorcycle India plant shut for a week due to cyber-attack
Reference: Hi by Cyberattck Suzuki Motorcycle India Halts Production at its Factories
Incident: DDOS Hacktivist Attack at Quebec’s Power Utility
A pro-Russian hacking group has claimed responsibility for a cyberattack against Quebec's state-owned electricity provider. Hydro-Québec said on Thursday it was hit with a denial-of-service attack at approximately 3 a.m. ET and was working to try to get its website up and running again. Hydro-Québec's website, app and Info-Panne website for verifying power outages went offline.
"No critical Hydro-Québec systems were attacked and users' personal data was not compromised," said Philippe Archambault, head of media and government affairs for the utility. He said the cybersecurity team is working on restoring service.
"This is not a case of hacking and getting access to the information at the back end, at least not at this time, not with this type of tech," Waterhouse said. "It's really just to protest against Canada's involvement with Ukraine."
Victim: Hydro-Québec
Hydro-Québec is a public utility that manages the generation, transmission and distribution of electricity in the Canadian province of Quebec, as well as the export of power to portions of the Northeast United States. It was established by the Government of Quebec in 1944 from the expropriation of private firms.
Reference: Pro-Russian group claims responsibility for cyberattack against Hydro-Québec
Incident: DDOS Cyberattack at Canadian Primary Eastern Seaports: Halifax, Montreal and Quebec.
On April 14, 2023, in the early morning hours, the Port of Halifax in Nova Scotia and the Ports of Montreal and Quebec suffered a “distributed denial of service” (DDOS) cyberattack. Unlike ransomware attacks, these attacks flood network servers with so much internet traffic that it overwhelms a website, rendering it inaccessible or useless for legitimate users. The attacks appeared to be directed at the ports’ websites, causing them to crash for several hours. Further, Quebec’s state-owned electricity provider Hydro-Quebec also experienced a similar cyber assault the next morning.
Despite these attacks, it appears none of the ports’ operations or internal systems were impacted by the incident. The Port of Halifax’s spokesperson Lane Ferguson emphasized that their “internal systems continue to operate normally” and “port operations have not been affected.” Similarly, the spokesperson for the Port of Montreal asserted that the port’s security team had confirmed the port operations were unaffected and there was no risk of a data breach.
Afterwards, a pro-Russian hacking group called NoName057(16) took responsibility for the cyberattack and asserted it would continue to target Canada. This cyber assault is only the latest of several cyber issues that global ports and maritime infrastructure have suffered recently.
Threat Actor: NoName057(16)
The pro-Russian hacktivist group NoName057(16) is primarily focused on disrupting websites important to nations critical of Russia’s invasion of Ukraine – DDoS attacks act as the method to conduct such disruption efforts.
Victim: Port of Montreal
Port of Montreal, QC, Canada
Victim: Port of Quebec
Port of Quebec, QC, Canada
Victim: Port of Halifax
Port of Halifax, Nova Scotia
Reference: Maritime Industry Hit by Yet Another Swell of Cyberattacks
Reference: Fourth-Largest Generic Drugs Manufacturer Sun Pharmaceuticals Hit by Ransomware Attack
Incident: Databreach Impacts Business Operations at Sun Pharmaceutical
A ransomware group has claimed responsibility for 'IT security incident' at Sun Pharma whose effect included breach of certain file systems and the theft of certain company data and personal data, the drugmaker said in a stock exchange filing. "As part of the containment measures, we proactively isolated our network and initiated the recovery process. As a result of these measures, Company’s business operations have been impacted," it said. "Consequently, revenues are expected to be reduced in some of our businesses. The Company would incur expenses in connection with the incident and the remediation."
Sun Pharma first reported the incident on March 2. Back then it said that the incident did not affect Sun’s core systems and operations. On March 27 the company said it is currently unable to determine other potential adverse impacts of the incident.
Victim: Sun Pharmaceutical Industries Limited
Sun Pharmaceutical Industries Limited is an Indian multinational pharmaceutical company headquartered in Mumbai, that manufactures and sells pharmaceutical formulations and active pharmaceutical ingredients in more than 100 countries across the globe.
Reference: Sun Pharma eyes revenue hit due to ransomware attack
Incident: Rheinmetall’s Automotive Sector Hit by Cyberattack
German automotive and arms manufacturer Rheinmetall suffered a cyberattack on Friday, the company said. The attack hit Rheinmetall’s business unit that serves industrial customers, particularly in the automotive sector. The company’s defense division — which produces military vehicles, weapons, and ammunition — remained unaffected and continues to operate “reliably,” Rheinmetall’s spokesperson Oliver Hoffmann said in an email to Recorded Future News. Rheinmetall is currently investigating the extent of the damage and is in close contact with the relevant cybersecurity authorities, Hoffmann said.
UPDATE September '23, Reuters: “Normal production processes at these locations are currently experiencing significant disruption,” Rheinmetall said in a statement late on Thursday. “The IT infrastructure in the region has been shut down and is currently being rebuilt”,
The timing of the attack aligned with Rheinmetall's talks of constructing a new tank factory in Ukraine.
Victim: Rheinmetall AG
Rheinmetall AG is a German automotive and arms manufacturer, headquartered in Düsseldorf, Germany
Reference: German arms manufacturer Rheinmetall confirms cyberattack
Incident: German Biotechnology Company Evotec Shuts Down IT Systems
Evotec SE, the German biotechnology company, recently succumbed to a cyberattack. In a communiqué, the company said it preemptively shut down its IT systems as a result of the attack, disconnecting them from the internet. Evotec noted that its IT team is currently examining its IT systems to review the scope of the attack. “Highest diligence will be applied to data integrity,” it added in an announcement. Its Nasdaq shares appeared to be unaffected by the revelation, which described a IT network intrusion occurring on April 6.
The company has informed relevant authorities and said it had disconnected selected IT systems, but that it maintains business continuity at all global sites, prioritizing data integrity.
Victim: Evotec SE
Evotec SE (Nasdaq:EVO), the German biotechnology company
Reference: Evotec joins list of recent cyberattack targets in pharma
Reference: TECHNOLOGY Oakland police union files claim against city, seeks damages over ransomware attack
Reference: Oakland declares local state of emergency over ransomware attack
Reference: CRIME Oakland acknowledges ransomware attack has worsened with massive new release of personal info
Incident: Lacroix Hit in Cyberattack
Global electronics maker, Lacroix, suffered a cyberattack that left three operating sites shut down, company officials said.
Lacroix said during the night of Friday May 12 to Saturday May 13, it intercepted a targeted cyberattack on the French (Beaupréau), German (Willich) and Tunisian (Zriba) sites of the electronics activity.
The company said it immediately took measures to secure all the Group’s other sites.
“Prior to restarting the systems of these sites, investigations are underway to ensure that the attack is completely contained,” the company said in a statement. “However, some local infrastructures have been encrypted and an analysis is also being carried out to identify any exfiltrated data.
The activity of these three sites represents 19 percent of the group’s total sales in 2022. The company does not feel there will be any significant impact on the performances for the Group.
Reference: Electronics manufacturer Lacroix closes three factories after cyberattack
Incident: City of Dallas Operations Widely Disrupted by Ransomware Attack
The City of Dallas, Texas, has suffered a Royal ransomware attack, causing it to shut down some of its IT systems to prevent the attack's spread. Local media reported that the City's police communications and IT systems were shut down Monday morning due to a suspected ransomware attack. This has led to 911 dispatchers having to write down received reports for officers rather than submit them via the computer-assisted dispatch system. The Dallas County Police Department's website was offline for part of the day due to the security incident.
"Wednesday morning, the City’s security monitoring tools notified our Security Operations Center (SOC) that a likely ransomware attack had been launched within our environment. Subsequently, the City has confirmed that a number of servers have been compromised with ransomware, impacting several functional areas, including the Dallas Police Department Website," explained a media statement from the City of Dallas. "The City is currently working to assess the complete impact, but at this time, the impact on the delivery of City services to its residents is limited. Should a resident experience a problem with a particular City service, they should contact 311. For emergencies, they should contact 911."
BleepingComputer has also confirmed that the City's court system canceled all jury trials and jury duty from May 2nd into today, as their IT systems are not operational. Dallas is the ninth largest city in the United States, with a population of approximately 2.6 million people.
Reference: Cyberattack Shuts Down 3 Lacroix Plants
Victim: Lacroix
Lacroix designs and manufactures electronic equipment in the automotive, home automation, aerospace, industrial and health sectors. It also provides safe, connected equipment for the management of critical infrastructures such as smart roads and the management and operation of water and energy systems.
Reference: City of Dallas hit by Royal ransomware attack impacting IT services
Reference: Ransomware attack hampering Dallas police operations
Victim: The City of Dallas
The City of Dallas, TX, USA
Incident: Ransomware Disrupts Operations at Italian Water Management Company
Alto Calore Servizi SpA, an Italian company that provides drinking water to nearly half a million people said a recent hack rendered all of their IT systems unusable.
The company runs the collection, supply and distribution of drinking water for 125 municipalities Avellino and Benevento — two provinces in southern Italy. “It will not be possible to carry out any operations or provide information that requires querying the database,” the company said.
The organization did not respond to requests for comment about whether customers are impacted by the incident, but it appears the distribution of water is not affected by the attack.
The Medusa ransomware group took credit for the attack and said it took customer data, contracts, minutes from board meetings, reports, pipe distribution information, expansion documents and more.
Victim: Alto Calore Servizi SpA
Alto Calore Servizi SpA, an Italian company that provides drinking water to nearly half a million people manages 58 million cubic meters of water a year.
The company runs the collection, supply and distribution of drinking water for 125 municipalities Avellino and Benevento — two provinces in southern Italy. The government-run company also manages sewage and purification services for both provinces.
Reference: Italian water supplier serving 500,000 people hit with ransomware attack
Reference: Court records were lost in debilitating Vanuatu cyber attack
Incident: Qullig Energy Corporation Servers in Nunavut Territory Hit by Wide-ranging Cyberattack
A wide-ranging cyberattack on the Qulliq Energy Corporation (QEC) in Canada’s Nunavut territory has crippled the company’s administrative offices. Officials with the company said the attack started on January 15 and while power plants are still operating normally, computer systems at the corporation’s customer care and administrative offices are unavailable.
The company cannot accept bill payment through credit cards but customers can pay using cash or through bank transfers. Customers are warned to watch their bank and credit card accounts regularly for unusual activity. They are also being told to consider changing personal passwords for sensitive applications such as email and online banking.
Victim: Qulliq Energy Corporation (QEC)
Qulliq Energy Corporation is a Canadian territorial corporation which is the sole electricity utility and distributor in Nunavut. It is wholly owned by the Government of Nunavut. Its name is derived from the qulliq, a traditional oil lamp used by Inuit and other Arctic indigenous peoples.
Reference: Cyberattack on Nunavut energy supplier limits company operations
Reference: Qulliq Energy stops short of labelling cyberattack another Nunavut ransomware incident
Reference: Ransomware attack exposes California transit giant’s sensitive data
Incident: T-Mobile Data Breach Hits 37 Million
U.S. wireless carrier T-Mobile said an unidentified malicious intruder breached its network in late November and stole data on 37 million customers, including addresses, phone numbers and dates of birth.
T-Mobile said in a filing with the U.S. Securities and Exchange Commission that the breach was discovered Jan. 5. It said the data exposed to theft — based on its investigation to date — did not include passwords or PINs, bank account or credit card information, Social Security numbers or other government IDs.
"Our investigation is still ongoing, but the malicious activity appears to be fully contained at this time," T-Mobile said, with no evidence the intruder was able to breach the company's network. It said the data was first accessed on or around Nov. 25.
T-Mobile, based in Bellevue, Washington, became one of the country's largest cellphone service carriers in 2020 after buying rival Sprint. It reported having more than 102 million customers after the merger.
Reference: T-Mobile says breach exposed personal data of 37 million customers
Incident: T-Mobile Hit Again
While it may seem like a small attack, T-Mobile disclosed its second data breach this year after the company found attackers accessed personal information of over 800 customers in late February.
The first breach, which the company discovered in early January, hit 37 million customers. This attack affected 836 customers, according to a notification to the Maine Attorney General’s office.
The breach occurred between Feb. 24 and March 30, according to the notification. The Bellvue, Washington-based T-Mobile said it discovered the issue March 27. The information the attackers acquired entailed name and driver’s license number or non-driver identification card number.
Reference: Another T-Mobile Data Breach
Victim: T-Mobile
Wireless service provider.
Incident: ABB Hit in Cyberattack, Operations Suffer
Swiss multinational company ABB, an electrification and automation technology provider, suffered a cyberattack that disrupted its operations.
Zurich, Switzerland-based ABB released a statement on the incident:
“ABB recently detected an IT security incident that directly affected certain locations and systems.
“To address the situation, ABB has taken, and continues to take, measures to contain the incident. Such containment measures have resulted in some disruptions to its operations which the company is addressing. The vast majority of its systems and factories are now up and running and ABB continues to serve its customers in a secure manner.
Reference: ABB Suffers Cyberattack
Reference: Multinational tech firm ABB hit by Black Basta ransomware attack
Victim: ABB
The automation industry giant is also a major electrical equipment and robotics company and reported a revenue of nearly $30 billion in 2022 and has more than 105,000 employees across the globe. ABB also “operates more than 40 U.S.-based engineering, manufacturing, research and service facilities
Victim: Khanty-Mansiysk city,Russia
As the world's second biggest oil producing region (before western sanctions hit Russian oil) Khanty Mansi was the center of the old Soviet oil industry.
Reference: Team OneFist Destroys Natural Gas System At Russian Oil Hub, Knocks Power Plant And Airport Offline
Incident: Taxi Ride Hailing Service in Quebec Hacked
A ransomware gang breached Taxi Coop Quebec's ride hailing back-end systems. During the attack, staff at the coop shut down all servers while they recovered from the attack. After 2.5 hours, at 4:30 AM, 90% of system functionality was restored and taxis could be dispatched again.
Reference: Taxis Coop Québec victim of a cyberattack
Victim: Taxi Coop – ride hailing service
Taxi Coop Quebec's ride hailing service
Incident: System Outage at Maple Leaf Food Manufacturer in Canada after Ransomware Attack
Maple Leaf Foods has confirmed that it was struck by ransomware. The company stated that it will not pay any ransom. And expects "full resolution of the outage will take time and result in some operational and service disruptions." "The outage is creating some operational and service disruptions that vary by business unit, plant and site." This confirmation comes after the Black Basta ransomware gang listed Maple Leaf Foods as one of its victims. IT World Canada reached out to confirm if Black Basta was responsible for the ransomware attack. A Maple Leaf Food representative said that the company “won’t dignify criminals by naming them.”
UPDATE: On March 9, four months after the incident, the company released the financial results that showed the attack costing over US$16,5M. Maple Leaf Foods President and Chief Operating Officer Curtis Frank said: "We are immensely proud of how our team responded in the face of this crisis. In less than 48 hours, we were able to pivot our organization to operate in a fully manual process, basically going back to paper and pencils. With remarkable pace, our information systems team cleaned, rebooted and restored our systems, allowing us to start back on the road to recovery."
Victim: Maple Leaf Foods
Maple Leaf Foods Inc. is a Canadian consumer packaged meats company.
Reference: Maple Leaf Foods confirms cyberattack, will not pay ransomware gang
Reference: Canada’s Maple Leaf Foods hit by cyberattack
Reference: Hacking at Cartonnerie Gondardennes deciphered by Damien Bancal, journalist specializing in cybersecurity
Incident: Hackers Shut Down Production at Cartonnerie Gondardennes in France
A cardboard box manufacturer in Wardrecques, France was hit by a cyberattack, most likely ransomware (Fr: "piratage"). Production was shutdown, and workers sent home. News reports are all in La Voix Du Nord which unfortunately is paywalled, but the headlines and synopsis says enough. The company's systems were decrypted by a journalist, Damien Bancal, and ransom was not paid.
Victim: Cartonnerie Gondardennes
French manufacturer of corrugated board and packaging made from recycled paper.
Incident: OT Systems Impacted at HiPP, a German Baby Food Manufacturer
HiPP, a Pfaffenhofen, Bavaria based baby food manufacturer was hit by a cyber attack which affected it IT and OT systems. The company sells its baby food worldwide. The company was not forthcoming with many details as to the nature of the attack, but the Central Office for cybercrime Bavaria (ZCB) was involved in the investigation into the incident. Production was halted for days after the incident, and over 1,000 employees were not able to work and sent home.
Reference: HiPP hacked
Incident: Novosibirsk Transportation System Attacked by pro-Ukranian Hacker Group
Pro-Ukrainian hacktivist collective Team OneFist, allegedly created with the help of the IT Army of Ukraine, attacked the Novosibirsk City Transport Traffic Management System in Operation Yellow Submarine beginning at September 2nd, 2022. OneFist's founder, named "Voltage" (@SpoogemanGhost), claimed that the operation was "long-planned" and that the IT infrastructure had been breached about a month before the attack.
Due to the attack, city transportation officials were unable to have visibility over traffic conditions and coordinate their flows. The automated bus scheduling system as well as the electronic signs on buses and trolleys were damaged to hamper quick restoration and recovery. Voltage also explained that the attack paralyzed the city and the traffic problems remained for several days until the system was restored, forcing many commuters to walk. During the attack, Team OneFist downloaded the data and was in the process of deleting data when the Russian officials mitigated the damage by removing access to the system.
Threat Actor: Team OneFist
Group of volunteer cyber operatives newly founded in 2022 and making waves by taking on Russia, imposing costs and pain on the Russian economy.
Victim: Novosibirsk City Transport, Russia
Novosibirsk City
Reference: Pro-Ukrainian Team OneFist attacks Novosibirsk transportation system in Operation Yellow Submarine in September 2022
Reference: Russians In Novosibirsk Forced To Pound Pavements As Team OneFist Paralyzes Traffic – Exclusive
Incident: Hackers Paralyzed Computer System at Austrian Light Manufacturer EGLO
Ransomware attack has paralyzed the global group's computer system since Monday.
The Tyrolean lighting company Eglo, based in Pill (Schwaz district), has fallen victim to a cyber attack. As the " Tiroler Tageszeitung " (Wednesday edition) reported, the globally active group with 5,700 employees had been struggling with a global failure of the computer system and telephone system since Monday. A technical breakdown was finally ruled out on Wednesday. The ransomware attack happened on Monday night.
The attack impacted production for 12 days. Orders could not be processed or shipped.
Victim: EGLO
EGLO is an Austrian family business and a manufacturer of living room and outdoor lights as well as light sources with a focus on LEDs. The company headquarters are in Pill (Tyrol). The company operates worldwide with 5,500 employees and 94 sales companies.
Reference: Tyrolean lighting manufacturer Eglo hit by cyber attack
Incident: Ransomware Attack Halts Public Postal Services in Greece
Ransomware hit ELTA encrypting its systems and halting operations in a major service disruption. "Threat actors exploited an unpatched vulnerability to drop malware that allowed access to one workstation using an HTTPS reverse shell." To stop the spread, they shut down all data centers. Online parcel tracking and labelling is also down for customers. Full service was restored by April 6th. The attack affected mail system, financial transactions and bill payments.
Victim: Hellenic Post, ELTA
National postal services in Greece
Reference: Greece’s national postal service restoring systems after ransomware attack
Reference: Greece’s public postal service offline due to ransomware attack
Incident: Cyberattack Significantly Reduced Caledonian Modular’s Operating Capability
Offsite specialist Caledonian Modular was hit by a catastrophic cyber attack less than two weeks before it sank into administration, a report into the firm’s collapse has revealed. The loss-making firm, which was trying to strike new funding agreements in the days before administration, was also hit by a massive cyber attack on 24 February, 12 days before the administrator was formally appointed on 8 March.
The administrator’s report said the attack “infected its servers and encrypted its data. This reduced the company’s operating capability and would have required significant cost to remedy. It also restricted the information that could be provided to third parties as part of funding negotiations.”
Later, JRL bought Caledonian Modular out of administration and saves the jobs of 200 former workers.
Victim: JRL Modular – formerly Caledonian Modular
In 2022 Caledonian Modular, UK's largest modular housebuilders has been bought out of administration by concrete frame specialist JRL. The JRL Group offers integrated construction solutions and operates more than 14 divisions.
Reference: Caledonian hit by crippling cyber attack just days before it sank into administration
Reference: The Cybercriminal Ecosystem: Evolution and Extortion
Incident: Hackers Paralyze only Newsprinting Facility in Switzerland
The machines at the Perlen paper factory in the Lucerne town of the same name are at a standstill due to a hacker attack. Newsprint and LWC production at Perlen and packaging production in Müllheim, Germany, which has been down since 7 January, restarted 6 days later on January 13. The chemistry division was not affected and was therefore able to continue production normally.
The factory normally outputs 1400 tons of newsprint paper per day. In a statement, the CPH Group said all IT systems were shut down on the 7th out of an abundance of caution and to contain any spread, strongly suggesting but not confirming they were a ransomware victim. They resumed production in January 13, after 6 days of downtime.
Reference: Ad hoc announcement pursuant to Art. 53 LR Cyber attack on IT systems of the CPH Group
Reference: CPH to restart operations in Perlen and Müllheim tomorrow
Victim: CPH Chemie Papier Holding AG
CPH Chemie Papier Holding AG is a Switzerland-based company that develops, produces and distributes chemicals, papers and packaging films.
Incident: Israel Water Monitoring Systems in Cyber Attack
Several water monitors – which oversee irrigation systems and wastewater treatment systems – were not operational this past Sunday after a cyber attack targeted the systems.
Specifically, water controllers for irrigating fields in Israel’s Jordan Valley suffered damage along with control systems for the Galil Sewage Corporation.
Workers for the two systems worked throughout the day to get the systems back up and running. The source of the cyberattack, however, is unknown, according to a report in the Jerusalem Post.
Reference: Cyber Attack Affects Water Monitoring Systems
Reference: Cyber attack shutters Galilee farm water controllers
Victim: Irrigation controls on Farms in Northern Israel.
Farmers in the region were warned several days prior about suspicions over a planned cyber attack, according to the report. Some of them, as a result of the warning, disconnected the remote control option for their irrigation systems and switched them to manual operation, instead, to prevent any harm from the attack. Indeed, those who left their systems on remote control were the ones impacted by the attack.
The National Cyber Organization warned the previous week about the increase in attempts at cyber attacks by anti-Israeli hackers throughout the month of Ramadan. Indeed, Israeli media agencies, medical websites, government websites and university websites all faced massive cyber attacks throughout the past week, including throughout the Passover holiday.
Incident: Ransomware Attack at NCR
NCR is suffering an outage on its Aloha point of sale (PoS) platform after being hit by an ransomware attack claimed by the BlackCat/ALPHV gang.
NCR provides digital banking, PoS point of sale system, and payment processing solutions for restaurants, businesses, and retailers
On Friday, NCR released a statement saying: “On April 13, NCR determined that a single data center outage that is impacting some functionality for a subset of its commerce customers was caused by a cyber ransomware incident. Upon such determination, NCR immediately started contacting customers, enacted its cybersecurity protocol and engaged outside experts to contain the incident and begin the recovery process. The investigation into the incident includes NCR experts, external forensic cybersecurity experts and federal law enforcement.
Reference: NCR suffers Aloha POS outage after BlackCat ransomware attack
Reference: NCR Hit in Ransomware Attack
Victim: NCR
NCR provides digital banking, PoS point of sale system, and payment processing solutions for restaurants, businesses, and retailers.
Incident: Ransomware Attack at Major Tesla Competitor, NIO
Chinese electric vehicle manufacturer Nio revealed a major data breach. The hack exposed certain confidential customer and vehicle sales-related information before August 2021. It is believed the hackers demanded $2.25 million worth of Bitcoin in exchange for not leaking their internal data.
Victim: NIO
Chinese electric car maker - greatest Tesla rival
Reference: Chinese Tesla Rival Falls Victim to Bitcoin Ransomware Attack
Incident: A Year After Devastating Ransomware Attack, Electric Utility Company NV GEBE is Still Recovering
On March 12, 2022 NV GEBE, its customers, and the entire St. Maarten community faced a devastating ransomware attack. As a result of the hack, the entire customer database, financial data and other business data was encrypted. GEBE closed its doors temporarily on March 17.
A year later it is reported that NV GEBE has been steadily rebuilding its customer databases and billing systems. These processes have required more time than initially anticipated because of the complexity and intricate attention to detail required.
Victim: N.V. GEBE
Electric utility company in Philipsburg, Sint Maarten
Reference: NV GEBE files case against investigators of cyber-attack
Reference: Lack of Management Facilitated Cyberattack on GEBE
Reference: GEBE made it easy for hackers, no audit and proper cyber security measures were not in place.
Reference: NV GEBE Reflects on the 2022 Cyber-Attack with Renewed Commitment to Security and Resilience
Incident: Ransomware Attack Erases Ambulance Appointments for Next Few Weeks
The Trois Cantons ambulances in Peyrehorade were the victims of a ransomware attack. They have lost all their files and appointments for the next few weeks. It is not known which patients were scheduled, or at what times. Telephone numbers are also lost. Patients are invited to call the Three Cantons ambulances as soon as possible on 05 58 73 00 63. The ambulances operated on Wednesday, December 7 "pencil and paper".
Victim: Landes Ambulances
Small organization of Ambulances covering the area of the Three Cantons in Peyrehorade, in the south of the Landes, France.
Reference: Landes: victim of a cyberattack, an ambulance company appeals to its patients
Incident: Production Outage after Massive Ransomware Attack at Italian Fruttagel
Fruttagel, an Agricultural Cooperative Company from Ravenna, suffered an external computer attack. The attack partially and temporarily compromised the company information systems. "The company - reads the note - promptly activated all the emergency procedures, resorting to the expertise of the personnel and cybersecurity experts. However, it was not possible to avoid huge production damages, with the consequent temporary impossibility to send the its products to all customers. The IT system check and recovery times will take a few days, with the hope of being able to restart shipping activities on Thursday 15 December".
"What happened, despite our prompt reaction, is making it impossible to carry out all the production activities and to follow up with the shipment of the packaged products, with considerable damage for the company and obviously for our customers" – says Stanislao Fabbrino, managing director of Fruttagel -.
On January 7, BlackCat/ALPHV published more than 720 gigabytes of corporate data, listing it includes financial and corporate documents, customer data, contracts with companies like IKEA, PepsiCO, etc. SGS certificates, private date, GDPR files, employee contacts, management, large customer base with global companies. Drawings of the company’s products.
Reference: Fruttagel Italian ransomware attack claimed by BlackCat cybergang
Reference: BlackCat/ALPHV Ransomware Victim: Fruttagel
Victim: Fruttagel
Fruttagel is an Italian agricultural cooperative company that produces and distributes finished and semi-finished fresh fruit and vegetables.
Reference: Fruttagel suffered a cyber attack. “Massive damage to the company”
Incident: Italian Oven Manufacturer Suspends Production after Cyberattack
UNOX was the victim of a cyber attack. The company immediately activated its security protocols, blocking the attack. As a safety measure, the company initially suspended production activities for 2 days as a precaution in order to carry out the appropriate checks. Since Wednesday 14 December all production activities have restarted in total safety. There is no risk relating to short, medium and long-term business continuity.
Victim: Unox Ovens
Unox is the leading Italian manufacturer of professional ovens.
Reference: Hackers attack Unox, suspended activities for two days: “No data loss”
Incident: Cyberattack at Technolit GmbH, Employees sent Home
The company Technolit from Grossenlüder is affected by a cyber attack. The company can currently only be reached by telephone at the head office. Most of the employees were sent home because they are currently unable to work. The company's entire IT department was affected by the attack.
Managing Director Stephan Günther explains the current situation: "We have become the victim of a cyber attack." The company is currently in contact with the responsible authorities. Further information could not yet be released.
Victim: Technolit GmbH
Technolit GmbH is a trading company founded in 1979 and based in Grossenlüder, Germany. It includes the areas of welding technology, chemical-technical products, grinding and cutting technology, tools and machines as well as workshop supplies for trade and motor vehicles.
Reference: Cyber attack against Technolit – operations paralyzed – ZIT determined
Incident: Bl00dy ransomware Gang Targets Italian Steel Manufacturing Group Lucchini RS
The cybergang Bl00dy ransomware claims a cyber attack against the Italian Lucchini Group. The gang reported this within its Telegram channels. No official statement from the company has been published.
Threat Actor: Bl00dy ‘bloody’ Ransomware Gang
The Bl00dy 'bloody' cybergang was identified in September 2022 and has been defined as a "son of Lockbit", which used the builder released by the famous criminal gang to be able to create its own strain of malware that encrypted files with the extension . bl00dy.
However, according to the experts, the group is evolving continuously from one malware to another for two reasons: so they can avoid detection and also they have all the benefits of the functions of the various malware at their fingertips.
Victim: Lucchini RS SpA
Lucchini RS SpA (formerly Lucchini Sidermeccanica SpA specializes in the production of rolling stock for trains, trams and metros (wheels, rims and railway axles and complete wheelsets). It is also active in the production of forgings, castings, tool steels and forging ingots.
The company's headquarters are in Brescia, but the production plant is in Lovere (Bergamo) where the entire steel production process is present: steelworks, forging, foundry, running mechanics and heavy mechanics.
An Italian company, owned by the Lucchini family (through the Sinpar SpA holding) and separated in July 2007 from the rest of the Lucchini Group, which remained the property of the Russian Severstal group.
Reference: Bl00dy ransomware targets the Italian Lucchini Group
Reference: Cyber attack that EPM suffered this week occurred from the Ituango Power Plant
Incident: Black Basta Hacks Systems of Engineering Firm that Designs Hundreds of US Power Stations.
Sargent & Lundy, a Chicago-based construction and engineering firm fell victim to a Black Basta ransomware attack. The hack exposed information of over 6,900 individuals belonging to multiple electric utility companies. The organization works as a US government contractor handling critical infrastructure projects across the country.
The firm also handles nuclear security issues, working alongside the departments of Defense, Energy, and other agencies. Federal officials closely monitored the potential broader impact on the US power sector, though it is being reported that no other power-sector firms were involved.
Victim: Sargent & Lundy
Engineering firm Sargent & Lundy LLC specializes in professional services for electric power and energy intensive clients. The Company offers nuclear power, power delivery, and consulting services. Sargent & Lundy serves customers throughout the United States.
Reference: Black Basta ransomware allegedly struck an engineering firm
Reference: Black Basta stole data from numerous US electric utilities
Reference: EPM Falls Victim To Ransomware Attack
Reference: Royal Ransomware Victim: Mol
Incident: Cyberattack at Vehicle Wheel Manufacturer in Brazil
Brazilian automobile components manufacturer Iochpe-Maxion announced that it had suffered a cyberattack on December 5 in its IT environment. The attack resulted in the unavailability of part of its systems and operations in some units in Brazil and abroad.
The company explained in a statement sent to the Brazilian Securities Commission that it had activated its security protocols to contain the cyberattack and isolated some of its systems to protect the environment. The company confirmed that, together with its specialized advisors, it was acting diligently and making every effort to identify the causes of the incident, determine its extent and mitigate its effects.
Reference: Iochpe Maxion S A : 12/06/2022 Material Fact -Cyberattack
Reference: IOCHPE-MAXION (MYPK3) SUFFERS CYBER ATTACK AND IS LEFT WITH UNAVAILABLE SYSTEMS
Victim: Iochpe-Maxion
Iochpe-Maxion, Brazilian wheel and automotive component manufacturer with locations in Brazil and abroad.
Incident: Cyberattack at Czech Institute of Nuclear Research Did Not Threaten Reactor Operations
The Institute of Nuclear Research Řež was attacked by a hacker group. It only attacked economic systems, which caused, for example, a delay in sending wages. The technological systems remained intact, the operation of the reactors was not threatened by the attack.
Hackers penetrated the institute's internal system using the Ransomware program, which blocks the computer system and encrypts the data stored in it. It demands a ransom from the user for data recovery.
Zdroj: https://www.idnes.cz/zpravy/domaci/ustav-jaderneho-vyzkumu-kyberutok-hackeri.A221207_135851_domaci_vajo
Reference: Institute of Nuclear Research in Řež attacked by hackers, no sensitive data leaked
Victim: Řež Institute of Nuclear Research
The Řež Institute of Nuclear Research, in the Czech Republic, is primarily concerned with the safe and efficient operation of energy sources, especially nuclear ones. It also focuses on the development, production and distribution of radiopharmaceuticals in the field of nuclear medicine.
Reference: Hackers attacked the Institute of Nuclear Research Rez
Reference: Rackspace: Customer email data accessed in ransomware attack
Reference: Rackspace confirms Play ransomware was behind recent cyberattack
Reference: Rackspace confirms ransomware attack after Exchange outages
Reference: Rackspace ‘security incident’ causes Exchange Server outages
Reference: Press Release: Cybercrime
Incident: Cyberattack at SPTrans System in Sao Paulo Exposes Data of 13 Million Riders
On December 15, 2022, SPTrans became aware that its systems had experienced a cyber-attack resulting in the leak of personal
data of 13 million users of Bilhete Único, the public transportation card of the city of São Paulo. The Bilhete Único cards remain active and the respective balances are preserved , with no losses in the credits used in the transport service.
The exposed data is from the month of April 2020 and include social name, birth date, Individual Taxpayer Registration (CPF), national ID card, address, phone number, email, student’s enrollment, among others. The Cyber Crimes Division (DCCIBER) of the Criminal Investigations Department (DEIC) of the São Paulo State Civil Police has been notified among others, so that a criminal investigation can be initiated to verify the authorship and origin of the leak.
Victim: SPTrans system, Sao Paulo, BR
The SPTrans system, the company responsible for managing public transport in the city of São Paulo, Brazil.
Reference: SPTrans cyberattack results in data leak of 13 million users of Bilhete Único
Reference: Hacker invades SPTrans system and 13 million Bilhete Único users have data exposed
Incident: Central Ohio Transit Authority (COTA) Offline after Cyberattack
A cyber hack forced the Central Ohio Transit Authority (COTA) to shut down its computer network. Officials shut down its network, removed it from the internet and hired Surefire Cyber to collect and analyze data and logs from 590 COTA operating systems. COTA continued operating all transit services during the IT network outage. For weeks, riders didn't have Wi-Fi access and buses couldn't track real-time transit information or plan trips. All operations have since returned to normal.
There is no indication that "personally identifiable information was accessed" and that "there are no active, ongoing cyber-security threats within our systems," said Sophia Mohr, COTA's chief innovation and technical officer.
Reference: COTA buses still don’t have Wi-Fi, riders can’t track real-time info following December hack
Reference: COTA’s data breach investigation is complete. Was sensitive information compromised?
Incident: Operations of ÖBB, Austrian Federal Railways, Disrupted by Cyberattack.
The ÖBB confirms that it is not a technical fault but a DDoS attack. There have been massive problems at ÖBB since Friday morning . The website is very slow or not accessible at all. According to user complaints, online ticket purchase is not possible at all, or the purchase price is debited several times. ÖBB writes on Twitter that there is a technical problem and the solution is being worked on. The cause of the problem was not mentioned.
ÖBB has now confirmed to futurezone that it was a DDoS attack. Accordingly, all online services of ÖBB were affected. According to ÖBB, the problem was fixed at 12:30 p.m. If you visit the ÖBB website, it is still sometimes not available (as of 2:22 p.m.). It will probably take some time for the situation to normalize.
Victim: ÖBB-Infrastruktur AG
Austrian Federal Railways. As a mobility and logistics service provider, Austrian ÖBB transported a total of 323 million passengers and over 94 million tons of goods to their destinations in 2021. ÖBB invests more than three billion euros per year in rail infrastructure. 42,000 Employees in bus and rail, and 2,000 apprentices ensure that up to 1.3 million passengers and around 1,300 freight trains arrive safely at their destinations every day.
Reference: DDoS attack: ÖBB website and ticket sales disrupted
Incident: Production Disrupted at Belgian Truckbuilder Mol after Cyberattack.
Mol Cy, the company in Belgium that builds trucks, trailers and soon also armored vehicles, was hit by a ransomware attack. A week later, the company is still rebuilding the network. According to the CEO, production was not compromised. “Supplies had just taken place and orders were in progress. Our production was of course disrupted, but in the end it did not come to a standstill. It was a bit more difficult to work at a number of workstations where computers provide information. But our staff managed to make do.” In recent days, about 50 employees have been at home for a while. “Especially our administrative staff cannot do their work without a PC and network. Unfortunately, they were temporarily unemployed.”
Victim: Mol cy
Mol cy builds trucks, trailers and soon also armored vehicles, and employs around 500 people. Founded in 1944. Located in Hooglede, Belgium.
Reference: “Suddenly all printers printed the same message”: hackers demand a ransom from a company that builds vehicles for the Belgian army
Incident: Business Operations Continue Manually After Cyberattack at Textile Logistics Company
On December 6th there was a successful cyber attack on the systems of the well-known textile logistics company Meyer & Meyer. The company can still be reached, but various processes had to be converted to manual work. The extent of the damage caused by the cyber attack is currently being checked and the system has started to be restored. "We reacted quickly and decisively to the targeted attack," says Björn Plantholt, who is responsible for corporate communications at Meyer & Meyer. The company was able to maintain part of the business operations after the cyber attack, despite the systems being shut down, by switching to manual processes.
Victim: Meyer & Meyer
Osnabrück based, textile logistics company Meyer & Meyer has 1.800 employees and a turnover of 200 million. The company Meyer & Meyer is a service provider that focuses on the entire value chain of the textile industry. In this way, fashion companies are supported along all services in this value chain. The company calls this principle “From Sheep to Shop”.
Reference: CYBER ATTACK ON LOGISTICS COMPANY MEYER & MEYER
Reference: Cyber attack on logistics company
Incident: Daixin Threatens To Publish Network Vulnerabilities After AirAsia Does Not Pay
AirAsia has apparently fallen victim to a major ransomware attack by the Daixin Team gang. More than five million records, alleged to be from customers and staff, were exposed online. The claim has not been verified or confirmed by AirAsia. The attack was first reported on Twitter by security researchers with screenshots taken from the darkweb.
The group shared a sample of the data with AirAsia after encrypting its database and demanded an undisclosed fee to unlock it. Daixin Team said they avoided locking up critical files related to flying equipment. They did lock out access to staff and passenger records until payment is made.
Daixin Team say it plans to publish details on the AirAsia network as AirAsia did not plan to pay the ransom. Providing access to and details of flaws in the network on open hacker forums would potentially leave it open for more malicious groups. The group claimed full responsibility for any future negative consequences caused from their actions.
Reference: Daixin Team claims AirAsia ransomware attack with five million customer records leaked
Victim: AirAsia
AirAsia is the largest airline in Malaysia, it has some 22,000 employees from 60 nationalities and is based out of Kuala Lumpur where it operates both domestically and to more than 165 destinations worldwide.
Incident: Cyberattack Forces French Hospital to Cancel Operations
Hospital Centre of Versailles, near Paris, canceled operations and transfer some patients due to a cyber attack suffered over the weekend.
The computers at the hospital were infected with ransomware, threat actors demanded a ransom.
“A ransom, the amount of which I do not know, has been requested but we do not intend to pay it,” assured Delepierre, who is also mayor of Chesnay-Rocquencourt. Health Minister Francois Braun told AFP that six patients had been transferred from the beginning of the attack evening, three in intensive care and three from the neonatal unit.
The hospital is still facing problems and we cannot exclude that other patients will be transferred in other structures. “While the machines were still functioning in the intensive care unit, more people were needed to watch the screens as they were no longer working as part of a network, Braun said.” reported AFP.
In France, the law prohibits public establishments to pay ransoms.
Victim: Hospital Centre of Versailles
Hospital Centre of Versailles, near Paris, includes Andre-Mignot Hospital, Richaud Hospital and the Despagne Retirement Home.
Reference: French hospital cancels operations after a ransomware attack
Incident: Maritime Tech Giant Voyager Worldwide Takes Systems Offline
Singapore-based maritime technology solutions provider Voyager Worldwide was reported to have been hit by a cyber attack at the beginning of December. From December 2nd all systems were taken offline at the navigation services and solutions provider. The company has more than 1,000 shipping companies as customers around the world.
“As this is an ongoing investigation, and our priority is keeping the impact of the incident contained, the time frame for recovery could shift,” Voyager stated on its site.
Reference: Voyager Worldwide reportedly hit by cyber attack
Reference: Shipmanagement software vendors targeted by hackers
Victim: Voyager Worldwide
Voyager Worldwide is a leading maritime technology company. We provide navigation and maritime information solutions for shipping and adjacent industries.
Incident: Databreach at Montreal Car-Sharing Service Communauto
Communauto, the Montreal-based car-sharing service, confirmed on Friday that its computer systems were hit with a cyber attack. The attack compromised the personal information of some of its clients, including member numbers, names as well as email and civic addresses. The cyber hackers couldn’t get their hands on user passwords and credit card numbers.
In a letter sent to subscribers, the president and CEO of Communauto, Benoît Robert, explains that the company managed to obtain “reasonable assurance that the data to which [les cyberpirates] could have had access ”were destroyed. This attack “paralyzed many of our activities and explains some delays in the management of accounts payable and invoicing”, he indicated. The investigation is continuing to determine more precisely what data was stolen.
Reference: Communauto hit by cyber attack
Reference: Communauto victim of a cyberattack
Incident: Large Australia Energy Provider Hit by a “Cyber Incident” Impacting Small Percentage of Customers
One of Australia's largest energy providers has been hit by a "cyber incident" as a wave of data breaches impact big companies across the nation. AGL reported "elevated levels of suspicious activity" on its "My Account" platform on December 1. 9News understood a small percentage of customers - about 6000 - have been impacted. "Based on current analysis it appears malicious actors have used stolen credentials acquired externally (such as usernames and passwords used elsewhere by customers) to log into a number of customer accounts,"
Victim: AGL
AGL is one of Australia's largest energy providers.
Reference: Energy company AGL reports cyber incident
Reference: AGL hit by ‘cyber incident’ causing customer account lockdown
Incident: Cyberattack at Eesti Energia, Estonia
The website and online channels of state electricity generator Eesti Energia and some of its related companies are offline following a large-scale denial of service attack thought to have been conducted by pro-Kremlin hackers. The attack has affected Eesti Energia's site and mobile app, and also grid maintenance firm Elektrilevi's website, and its MARU mobile app, ERR reports.
At a little before 10.15 a.m. Saturday morning the State Information System Authority (RIA) discovered that the online services of five Estonian companies had started malfunctioning, including those of Eesti Energia. "Due to these attacks, in addition to the Eesti Energia's site, websites included those of Elektrilevi and [Eesti Energia subsidiary] Enefit Green." The incidents coincided with similar and simultaneous attacks on key sites in Latvia, Poland and Ukraine.
Victim: Eesti Energia
Eesti Energia is the state electricity generator in Tallin, Estonia
Reference: Eesti Energia website down after pro-Kremlin cyberattack
Incident: Bitcoin ATM Manufacturer Suffers Attack
General Bytes, a manufacturer of Bitcoin ATMs, disclosed a security incident that resulted in the theft of millions of dollars’ worth of funds. Attackers were able to steal cryptocurrency from the company and its customers using a Zero Day in its BATM management platform.
In terms of the March 17-18 incident, here is what General Bytes said what happened:
The attacker identified a security vulnerability in the master service interface used by Bitcoin ATMs to upload videos to server.
The attacker scanned the Digital Ocean cloud hosting IP address space and identified running Crypto Application Server (CAS) services on ports 7741, including the General Bytes Cloud service and other GB ATM operators running their servers on Digital Ocean (our recommended cloud hosting provider).
Using this security vulnerability, attacker uploaded his own application directly to application server used by admin interface. Application server was by default configured to start applications in its deployment folder.
Reference: Bitcoin ATM Maker Reimbursing Attack Victims
Victim: General Bytes
General Bytes makes Bitcoin ATMs allowing people to purchase or sell over 40 cryptocurrencies. Customers can deploy their ATMs using standalone management servers or General Bytes cloud service. The company has machines in over 120 countries.
Reference: Communauto is asking the boroughs for help to meet demand in Montreal
Reference: Cyber attack: pipeline builder Friedrich Vorwerk fell victim to ransomware
Reference: Medibank says hacker accessed data of 9.7 million customers, refuses to pay ransom
Incident: IT Systems of Hydraulic Office of Corsica Attacked by Ransomware
The Hydraulic Office of Corsica was hacked on the night of November 2 to 3. The agents were faced with 33 completely blocked computer systems. They immediately took them offline after the malfunctions were noted. A ransom, the amount of which has not been disclosed, has been demanded.
Two weeks after the event the company published a press release. They needed time to analyze and evaluate the damage on IT infrastructures,. And needed the time to assess the damage before deciding what to do. The company stated that essential activities are carried out normally, and "those relating to customer management will quickly be back to normal" . The problem remains mainly with the accounting and financial management of the organization. A large part of the historical data has been encrypted, "making this data inaccessible at this moment" .
Reference: Cyberattack: The OEHC refuses to negotiate, and promises a return to normal as soon as possible
Reference: The computer system of the Hydraulic Office of Corsica blocked by a cyberattack
Victim: OEHC – Hydraulic Office of Corsica
Hydraulic Office of Corsica
Incident: Ransomware Attack Encrypts Systems at German Medical Device Manufacturer Richard Wolf
The medtech company Richard Wolf was the victim of a cyberattack in early November. After almost 3 weeks, almost all restrictions on phones and email accounts have been resolved. By the end of November, all restrictions in the IT of logistics should also be removed. The company is receiving support from an external IT forensic expert to accompany the security process. The cybercriminals were able to infiltrate using sophisticated malware.
Richard Wolf had prepared for precisely this scenario in recent years by taking technical and organizational precautions, employing specialist personnel, conducting internal training and consulting externally. Thanks to the safeguards, systems with data were largely protected, but they were encrypted in order to use them to extort money from the company. The company did not respond to the ransom demand.
Reference: After cyber attack: Richard Wolf available again
Reference: Cyber attack on Richard Wolf GmbH: Restrictions on communication have been largely reduced, logistics gradually return to normal operations
Victim: Richard Wolf GmbH
Richard Wolf is a full-range supplier of endoscopic products in Germany
Incident: 55 Counties in Arkansas Offline or Temporarily Closed by Cyberattack
A cyber-attack is causing county offices across the state of Arkansas to go offline or temporarily close. The breach happened the Saturday before the election. There's 55 counties in Arkansas that were impacted by this ransomware attack. Each affected county is using the company Apprentice Information Systems for its online servers.
In Miller County, the county treasure, the county clerk and the county judges offices, are all having their computers swiped clean, and having the system re-loaded. County Treasure Teresa Reed says the firewall protected their system, but all the work stations were compromised. Right now, her office is handwriting everything.
At this time (18 November), county officials do not have a timeframe for when their computers will be back online.
Reference: Russians said to be behind hack that hamstrung Lonoke County operations
Victim: Arkansas Government
Arkansas Government, USA
Reference: Cyber-attack affects several northern Arkansas county offices
Reference: Miller County offices impacted by cyber attack
Incident: Ransomware Attack Paralyzes Vanuatu’s Government Ministries and Departments
The Office of the Vanuatu Government Chief Information Officer (OGCIO) has confirmed the Government’s Broadband Network has been compromised since Sunday, November 6, 2022. As a result all the online services such as email, network shares, VoIP services and other government online services offered by the government are currently down. This has paralysed all government ministries and department causing widespread delays throughout the country.
The cyber attackers demanded a ransom after the network was initially crippled last week, but Vanuatu’s government has refused to pay. The identity of the hackers and the value of the ransom has not been released. The Australian Cybersecurity Centre in the Australian Signals Directorate is assisting Vanuatu’s government in rebuilding the system, according to foreign affairs and security officials familiar with the situation. Vanuatu’s government has now been without effective access to its internal systems for more than a week as engineers attempt to rebuild the entire system from scratch.
Victim: Vanuatu Government
Vanuatu Government
Reference: Ransom attack cripples Vanuatu government systems, forces staff to use pen and paper
Reference: Vanuatu Govt network paralysed by cyber attack
Incident: Over 800 Greece Government Services Targeted in Unprecedented Cyberattack
More than 800 services of Greece’s Gov.gr and TAXISnet, as well as medical prescriptions, were frozen by an unprecedented DDoS attack. The cyberattack reportedly came from the Netherlands and attempted to temporarily take down or even completely stop the operation of approximately 800 Government websites. Among the problems caused, was to disabling electronic prescriptions. Doctors on call could only issue handwritten prescriptions on the weekend, on-call pharmacies could not fill emergency prescriptions, nor could hospital doctors prescribe to patients in emergency rooms.
As of Sunday afternoon (2 days later) about 600 websites had been “cleaned up” and were allowed access again after initializing settings.
Victim: Greece Government
Greece Government
Reference: 800 Services of Greece’s Gov.gr Taken Down By Hackers
Incident: French Oncology Hospital Suspends Treatments for 4 Days after Ransomware Attack
Saint-Jean Oncology and Radiotherapy Center was the victim of a ransomware-type cyberattack affecting its Saint-Doulchard and Moulins sites. This paralyzed its information system. It affected all data, in particular patient files (administrative data, medical and technical data).
The Center was forced to suspend its chemotherapy and radiotherapy activities from November 15 to 18, 202 . For these services access to the computerized patient file is essential (ballistics, assays, reports, etc.).
Victim: Saint-Jean Oncology and Radiotherapy Center
Saint-Jean Oncology and Radiotherapy Center is located in Saint-Doulchard, France
Reference: Cyberattack Center Saint-Jean
Incident: Cyberattack Shuts Down Operations at Precision Casting Foundry, Europea Microfusioni Aerospaziali
Europea Microfusioni Aerospaziali S.p.A, leader in aerospace investment casting, has been hacked on November 17 and was forced to stop the production lines. ITV News reported on 23 November that a team of 40 technicians is employed in the Altirpini plants, including experts sent by Rolls Royce and cyber security professionals. The team is working tirelessly to restore the servers. Telephone lines are also down at the moment. The partial opening of some production departments continue with respect to the standards disseminated by Rolls Royce. The English multinational confirms the cyber attack and the demanding restoration work, and an update of the conditions in the shortest possible time.
Reference: Europea Microfusioni Aerospaziali Spa under cyber attack, 40 technicians working to restore the servers
Victim: Europea Microfusioni Aerospaziali S.p.A
Europea Microfusioni Aerospaziali S.p.A. is a high-precision foundry specializing in the production of rotor and stator blades for turbogas of major aircraft thrusters and for power generation.
Incident: Cyberattack hits Communauto Operations Already Struggling with Frustrated Customers
Canadian car sharing company Communauto continues to have difficulties in its operation. On Monday, a cyberattack prevented users from starting or ending a ride with self-service Flex vehicles. The problem was resolved in the evening.
Communcar's users were already struggling to reserve a car, despite their subscription, due to lack of availability. Pushing some users to want to cancel their subscription. The shortage of new cars is linked to supply difficulties affecting certain components, Communauto ensures that it is looking for other solutions to acquire new vehicles.
Victim: Communauto
Communauto is a Canadian car-sharing company based in Montreal, Quebec, Canada, that operates in fifteen Canadian cities and Paris, France.
Incident: Outage at Leading Public Medical Institute in India affects Hundreds of Patients and Doctors
India’s leading public medical institute, All India Institute of Medical Services, or AIIMS, is experiencing outages following a cyberattack.
AIIMS officials told TechCrunch that patient care services have been badly impacted since early Wednesday. The medical institute moved to manual operations, including writing patient notes by hand, as the server recording patient data stopped working. The outages have resulted in long queues and errors in handling emergency cases and continued till Thursday.
Details of whether the attackers could access any patient data have yet to be publicly announced.
UPDATE [03Jul23]: Former cybersecurity chief says the ransomware attack on AIIMS prompted government to make cyber response framework. “A lot of lessons have come out from the incident from a government point of view, and these will, hopefully be implemented.” As reported by Hindustan Times.
Victim: AIIMS – All India Institute of Medical Services
India’s leading public medical institute: All India Institute of Medical Services (AIIMS)
Reference: India’s AIIMS hit by outages after cyberattack
Incident: Ransomware Attack at German Gas Pipeline Builder, Friedrich Vorwerk, Impacted Profitability
Friedrich Vorwerk, a group of companies that builds gas pipelines and thus critical infrastructure (Kritis), was the victim of a cyber attack at the end of last year. Ransomware infected large parts of IT and paralyzed it. Since shortly before Christmas last year, the systems could be used productively again, the company said at the request of heise online. "As a result of a cyber attack that was averted at the end of the year, profitability was also impacted and visibility restricted".
"During the approximately 4-week work to repair our IT infrastructure, our ERP system and other parts of the infrastructure were not available. Shortly before Christmas 2022, the main effects were remedied and the systems could be used productively again. "
Incident: Downtime Caused by Cyberattack Final Straw for German Bicycle Manufacturer
On November 25, 2022, Prophete was the victim of a cyber attack. As a result, the attack meant that no production, invoicing or deliveries could take place for around three weeks.
The company stated there were "considerable problems in procurement, which in turn had an impact on sales and turnover. The warehouses are unusually full because the purchasing department has served the target figures. However, due to disrupted supply chains, required parts would not arrive and bicycles could not be fully assembled and delivered."
The company had planned sales of EUR 210 million, but only achieved EUR 159 million. In June last year there was a financing round with shareholders and lenders from Prophete. However, the willingness to inject more money ended with the break-in of cyber criminals.
Victim: Prophete GmbH u. Co. KG
Prophete GmbH u. Co. KG was a German manufacturer for bicycles, e-bikes, scooters, and supply parts that traditionally trade under the Prophete brand name. The company (including the subsidiary company Cycle Union) employ a staff of about 400 people at 4 production sites.
Reference: Prophete and bicycle manufacturer: hackers loosen the wheel
Reference: Bicycle manufacturer: Prophete slipped into bankruptcy after cyber attack
Incident: Production Halted at Meat Processing Factory in Luxembourg
The Cobolux company fell victim to a cyberattack on November 25. As a result the computers were paralyzed and it was no longer possible to label the products. "Our computer scientists worked all weekend and made it possible for us to continue working on Monday morning," explains the general manager "We were able to stop production and deboning of the slaughtered animals," says Faltz, which prevented damage to the meat. Since operations are generally at a standstill on Sundays, there was only a loss of production on Saturday.
Almost three months later, the bills have skyrocketed. "The damage was already over 100,000 euros at the time and is now estimated at between 400,000 and 500,000 euros," says Paul Faltz. "Production failures, the network and the ERP software had to be restored, lost data re-encrypted and investments made in an even more secure IT structure. All of these are the consequences of the attack."
The company supplies meat to butcher shops, supermarkets and restaurants throughout Luxembourg and greater region.
Victim: Cobolux
Cobolux is a meat producer in Luxemburg
Reference: How is Cobolux doing after the cyber attack?
Reference: Cyber attack temporarily paralyzes operations at Cobolux
Reference: Most Infrastructure as a Service Cloud providers hit by ransomware this year
Incident: Ransomware Attack at Columbian Multinational Healthcare Provider Disrupts Operations
The Keralty healthcare organization had its company and subsidiary websites and operations disrupted by a RansomHouse ransomware attack. The Columbian healthcare provider Keralty and its subsidiaries, EPS Sanitas and Colsanitas, suffered disruption to their IT operations, the scheduling of medical appointments and its websites.IT outages have impacted Columbia’s healthcare system, where patients had to wait for over twelve hours to receive care and some fainted due to lack of medical attention.
Keralty is a Colombian healthcare provider and operates in Latin America, Spain, the US, and Asia.
Victim: Keralty Group
Keralty is a Colombian healthcare provider that operates an international network of 12 hospitals and 371 medical centers in Latin America, Spain, the US, and Asia. The group employs 24,000 people and 10,000 medical doctors who provide healthcare to over 6 million patients.
Reference: Cyberattack disrupts Keralty’s operations
Reference: RansomHouse attack disrupts multinational Colombian health provider
Reference: Keralty Ransomware attack disrupts Columbia’s Healthcare System
Incident: Restricted Operations at City of Drensteinfurt, Germany after Cyberattack
From an ongoing police procedure, it was determined on Monday that a possible cybercrime attack on the city of Drensteinfurt was being prepared. This is currently being checked and the Münster police have been called in. To be on the safe side, the entire systems have been shut down.
The city administration will be available again by telephone from Wednesday, November 30th, 2022 during normal business hours. The disruption in the IT system continues and only limited operation without IT support is possible until further notice.
The Rinkerode branch will remain closed. The restrictions will last at least until December 9th, 2022. The systems are currently being checked and gradually put back into operation.
Victim: City of Drensteinfurt , Germany
City of Drensteinfurt , Germany
Reference: Restricted operation of the city administration
Incident: IT Systems Shut Down after Ransomware Attack at Glutz, a Swiss Specialist in Access Solutions
Glutz, a specialist in access solutions, fell victim to a ransomware attack at the end of November. Cyber criminals encrypted data on the systems, as the Solothurn-based company announced at the time. As a security measure, all internal IT systems have been shut down.
"Since December 7th we have been working again in limited normal operation," writes Marco Hauri, CEO, at the request of inside-it.ch. Telephony and e-mail communication could be used consistently. The costs incurred by the attack cannot be estimated at this time.
Victim: Glutz A.G.
Glutz, based in Switserland, offers security solutions for access to buildings and objects - including access systems, locks or mechanical locking systems. The company is also represented in Austria, Germany and Great Britain.
Reference: Update: Cause of cyber attack on Glutz still unclear
Reference: Cyber incident at Glutz AG
Reference: Update: Läderach data appear on the dark web
Reference: Glutz AG is gradually returning to normal operations after the cyber incident
Victim: Uponor
Uponor Oyj is a global pioneer in intelligent plumbing and climate solutions that move water for buildings and infrastructure with customers in residential and commercial construction, municipalities and utilities, as well as different industries.
Uponor employs about 3,900 professionals in 26 countries in Europe and North America and Uponor’s products are sold in more than 80 countries. In 2021, Uponor's net sales totalled approximately €1.3 billion. Uponor Corporation is based in Finland and listed on Nasdaq Helsinki. www.uponorgroup.com
Incident: Operational Shutdown at Uponor, Global Intelligent Plumbing and Climate Solutions provider
On 5 November 2022, Uponor was subject to a ransomware attack, which impacted its operations in Europe and North America.
Uponor announced in its press release on 18 November 2022, the company’s operations are still affected by the ransomware attack that occurred on 5 November. After the attack, the company took immediate actions to investigate and remediate the situation. One of these actions was to shut down all systems and production as a precautionary measure. After one week of production shutdown, operating levels have started to recover, and customer deliveries have restarted in all divisions during the past week. Uponor’s current focus lies on accelerating operational performance back to the operating levels before the attack while protecting the company’s systems.
As the attack happened close to the end of the year, the ability to cover lost sales during 2022 remains uncertain. Therefore, Uponor is withdrawing its guidance for 2022 until there is better visibility on operational ramp up and sales coverage.
Reference: Profit warning: Uponor withdraws its guidance for 2022 following the cyber attack
Reference: Evidence of a data breach resulting from the ransomware attack on Uponor – the company is making progress on operations recovery
Incident: Ransomware Attack at Window and Door Manufacturer, PGT Innovations
Window and door manufacturer PGT Innovations recently disclosed that it "detected a ransomware infection that impacted portions of its network and caused disruption to daily business operations."
"We did recently discover that some of our information technology systems were affected by a security incident, which caused an interruption to our day-to-day business operations for two of our manufacturing locations,” company President and CEO Jeff Jackson says in the emailed statement. The company, in public filings, said it hadn’t found that any personal information had been accessed or acquired.
Reference: Prominent window manufacturer grapples with ransomware attack
Victim: PGT Innovations
PGT Innovations manufactures and supplies premium windows and doors. Based in Florida with $1.16 billion in revenue in 2021.
Reference: Cyberattack on Continental
Incident: Ransomware Attack at Landi Renzo, an Automotive Fuel Supply System Manufacturer in Italy
Landi Renzo SpA was added to Hive’s leak site yesterday. In an email received by the Italian company the threat actors claimed to have infiltrated their network where they remained for 11 days, accessing files and documents before encrypting their servers. Hive claimed to have exfiltrated 534GB of data. The data includes proprietary information of the firm as well as personal information on employees and vendors.
DataBreaches sent an email inquiry to Landi Renzo yesterday, no reply has been received by publication. Hive has seemingly given the firm until November 7 to negotiate or reach some agreement with them.
Reference: Landi Renzo S.p.A. victim of cyberattack by Hive
Victim: Landi Renzo SpA
Landi Renzo SpA is an Italian-headquartered firm that researches and manufactures eco-friendly automotive fuel supply systems.
Incident: Cyberattack at Osaka Hospital Halted Non-Emergency Services
Osaka General Medical Centre issued a statement that the ransomware attack temporarily disrupted the facility’s electronic medical record system. It has stopped providing outpatient care and postponed non-emergency surgeries. The medical centre’s Sumiyoshi Ward is still performing emergency operations.
Hospital staff noticed unusual activity in the hospital’s network in the early hours of October 31. Soon after, they received a message from the threat actors saying: “All files have been encrypted. Please pay in bitcoin for recovery. The amount depends on how quickly you email us.” Staff are working to restore the system and using paper medical records until the incident is resolved.
Reference: Ransomware attack on Osaka General’s network stalls critical surgeries & daily operations
Reference: Were hospital attacks in Osaka linked to a supply chain attack on lunch service by “Phobos?”
Victim: Osaka Hospital
Osaka hospital, operated by the Osaka Prefectural Hospital Organization, currently counts 865 beds and 36 departments.
Reference: Osaka Hospital Halts Services After Ransomware Attack
Incident: All Networks Shut Down after ‘Large Scale Cyberattack’ in Guadaloupe
The French island of Guadeloupe is dealing with the after effects of a cyberattack. "As a security measure, all computer networks have been shut down to protect data and a diagnosis is underway," the French overseas region said in a statement on Monday. "A continuity of services plan has been put in place to ensure public services," the regional authorities said. “At present, we know that the overall management of high schools and public transport services are, for the moment, preserved,” officials said. The statement notes that the government is working with CNIL – France’s data protection authority – as well as France's National Information Systems Security Agency (ANSSI), the National Police and the Gendarmerie.
Victim: Island of Guadeloupe
Guadeloupe is an overseas department and region of France in the Caribbean consisting of six islands with a population of about 385,000.
Reference: French island shuts down all computer networks after cyberattack
Reference: GUADELOUPE KICKSTARTS CONTINUITY PLAN AFTER WIDE-RANGING CYBERATTACK
Incident: Seville Urban Transportation affected by cyberattack
The urban transport company of Seville (Tussam) has suffered a cyberattack that has disabled both the Tussam mobile application (App) and the information panels at bus stops that warn of the frequency of passage of the different lines.
The Seville Urban Transport Company (TUSSAM) disclosed that both the mobile application and the information panels at bus stops were disabled as a result. Resorting to manual means guaranteed the provision of public service at all times. The operation of the App and the website remained offline.
Reference: Seville Urban Transportation affected by cyberattack
Victim: Seville Urban Transport Company (TUSSAM)
Seville Urban Transport Company (TUSSAM), Spain
Reference: A cyberattack disables the Tussam App and the information panels of the canopies
Incident: Operations Disrupted: Mexico Airport Internet Cables Cut
Passengers missed connections because thieves cut the fiber optic cables leading into the Mexico City airport, forcing immigration authorities to return to using slow paper forms. Authorities said the thieves who mistakenly thought the fiber optic cables were sale-able copper. They stressed it happened outside airport property but, in fact, it was a cable conduit that leads directly into the airport from less than a mile away.
Rogelio Rodriguez Garduño, an aviation expert who teaches aeronautical law at Mexico’s National Autonomous University, said the events reflect a decades long decay in Mexico’s aviation regulation. Mexico, unlike most countries, doesn’t have an independent aviation agency.
Victim: Mexico City Airport
Mexico City Airport
Reference: Mexico’s domestic airline industry in shambles
Reference: Cyberattack causes shutdown at communication, transportation and aviation agencies
Reference: Carriers seek dialogue with the SICT after suspension of procedures for hacking
Reference: Mexican cyber-attack threatens to cripple road freight movements
Incident: Mexico’s Transportation Ministery Halts Commercial Trucking Services for 2 Months
Mexico’s transportation ministry has stopped issuing new permits, license plates and driver’s licenses for commercial truck operators until Dec. 31 because of a cyberattack in late October, creating possible delays for transporters. Permits that expire on these dates will be automatically extended until December 31, the agency added. Officials for Mexico’s trucking industry said SICT’s decision to delay issuing new permits and licenses could hurt the country’s domestic supply chain, as well as cross-border trade with the United States.
“In cross-border transportation services, the American authority has the power to request the driver’s license — not having the registration of the procedure and the current document, supposes a large number of drivers and trucks that would be losing all opportunity to operate,” according to a news release from Mexico’s National Chamber of Freight Transport (CANACAR).
Victim: Secretariat of Infrastructure, Communications and Transportation (SICT)
Secretariat of Infrastructure, Communications and Transportation in Mexico
Reference: Cyberattack disrupts Mexico’s transportation systems
Incident: Sunwing Airlines Network Outage Caused by Cyberattack at Jeppesen, Owned by Boeing.
Sunwing confirmed that its third-party provider, Jeppesen, which offers navigational information, operations planning tools, flight planning products and software, was experiencing technical issues with its products. The glitch caused delays with both northbound and southbound Sunwing flights this week.
Sunwing wasn’t alone – the outage hit “multiple carriers in North America,” the Toronto-based tour operator wrote on its Twitter account on Nov. 2, the day the system failed.
Reference: Cyberattack attack at Boeing Subsidiary Causes Widespread Flight Disruptions
Reference: Cyber attack on Boeing subsidiary behind Sunwing outage
Incident: ALMA Observatory Shutdown Impacts Scientist Worldwide.
The Atacama Large Millimeter Array (ALMA) Observatory in Chile has suspended all astronomical observation operations and taken its public website offline following a cyberattack on Saturday, October 29, 2022. Email services at the observatory are currently limited, and IT specialists are working toward restoring the affected systems.
The observatory is used by scientists of the National Science Foundation, the European Southern Observatory, the National Astronomical Observatory of Japan, and other groups from around the world, so any halt in its operations impacts multiple science teams and ongoing projects.
Victim: ALMA Observatory
Atacama Large Millimeter Array (ALMA) Observatory in Chile. The ALMA observatory is comprised of 66 high-precision radio telescopes of 12 m diameter arranged in two arrays, located at an elevation of 5,000 m (16,400 ft) at the Chajnantor plateau. The project cost $1.4 billion, making it the world’s most expensive ground telescope, and it was developed thanks to a multi-national effort involving the United States, Europe, Canada, Japan, South Korea, Taiwan, and Chile.
Reference: ALMA Observatory shuts down operations due to a cyberattack
Incident: Cyberattack Paralyzes Bulgarian Food Safety Agency Electronic Services
The Bulgarian Food Safety Agency (BFSA) is unable to provide electronic services because the Agency’s website and servers have come under a cyber attack, the BFSA said in a press release on Monday. The attack was detected on August 6, and the BFSA’s full range of functionalities and services are currently inaccessible.
Work is underway to restart the electronic services. The cyber attack does not affect the operation of Bulgarian border checkpoints, the BFSA specified.
Victim: Bulgarian Food Safety Agency (BFSA)
Bulgarian Food Safety Agency (BFSA)
Reference: Cyber Attack Disrupts Bulgarian Food Safety Agency’s e-Services
Reference: Cyber attack disrupts Bulgarian Food Safety Agency’s e-Services
Reference: Cyber Attack Disrupts Bulgarian Food Safety Agency’s e-Services
Victim: Enecron
Enecron is a German wind power company
Victim: Satellite firm Viasat
Satellite firm Viasat
Reference: Satellite firm Viasat probes suspected cyberattack in Ukraine and elsewhere
Reference: Satellite cyber attack paralyzes 11GW of German wind turbines
Incident: Systems at German Wind Turbine Servicing company Windtechnik Targeted
On April 11 systems of Deutsche Windtechnik, a German wind turbine servicing company, were targeted by a cyberattack. The company was able to reactivate the remote data monitoring connections to the wind turbines after 1-2 days. The system had been switched off for security reasons. "We are very happy that the wind turbines that we look after did not suffer any damage and were never in danger. Deutsche Windtechnik's operational maintenance activities for our clients resumed again on April 14 and are running with only minor restrictions. We were able to assess all IT systems in a secure environment and to identify and isolate the problems." the company stated on their website.
The company disclosed that the attackers used ransomware only after Black Basta added Windtechnik to their victim list, which is posted on their Tor site.
Reference: Cyber attack on Deutsche Windtechnik
Victim: Deutsche Windtechnik
Deutsche Windtechnik, a German wind turbine servicing company.
Incident: Operational Impact After Cyberattack at Tavr Food Processing Group in Russia
On March 24 a cyberattack was conducted on Tavr, a major Russian food processing group in the Rostov region. As per the official company statement, the company business processes, including production, were temporarily paralyzed and a significant economic loss was recorded. A company representative assessed the event as “meticulously planned and significant sabotage”. Currently, the company's activities are carried out in a limited mode.
Reference: TAVR company was hacked
Victim: Tavr corporate group
Tavr is a major Russian food processing group in the Rostov region, a member of the Agrokom group of companies.
Incident: Russia’s Largest Meat Producer Hacked with Bitlocker Ransomware
On March 18 Miratorg Holding, one of Russia’s largest meat producers, was attacked using the Bitlocker ransomware. The attack targeted warehouse and accounting IT resources. It also interrupted the processing pipeline for electronic veterinary documentation. Eighteen companies in the Miratorg group were affected.
The point of compromise was VetIS, a state information system used by veterinary services and companies engaging in the field, making it likely a supply chain compromise. To reduce the impact of the cyberattack, the federal agency will assist Miratorg in transporting goods by temporarily lifting the strict documentation requirements for the movement of products. Moreover, it will accept hand-written certificates and give access to the federal platform (Mercury) to issue formal papers where needed. To ease customer concerns about the safety of the food during these critical times, Rosselkhoznadzor underlines that Miratorg has a track record of good reputation, so this exception is being made by taking that into account.
Rosselkhoznadzor (a government agency regulating agricultural affairs) announced that the group resumed normal operations on March 28. Unlike most ransomware attacks, the attackers did not demand money, so commercial interests were not the motivation for the attack.
Malware: Bitlocker Ransomware
The virus exploits the Windows built-in feature, BitLocker. With BitLocker turned on, the entire disk, including all partitions, will be encrypted without adding extra encryption to a single partition or file.
Infected by BitLocker virus, this malware can create a BitLocker encrypted file that contains a virtual partition (VHD) and move all data into this fake partition, known as VHD Locker Ransomware. What's worse, other than your Windows PC, all external hard drives, USB sticks, and other storage media can all encounter this ransomware.
Reference: Top Russian meat producer hit with Windows BitLocker encryption attack
Victim: Miratorg Agribusiness Holding
Miratorg Agribusiness Holding is one of Russia's largest meat producers
Incident: Hackers Changed Temperature Settings at Frozen Food Facility in Russia
Hackers hacked into the management of the equipment of the Selyatino agricultural hub in the Moscow region and tried to spoil 40 thousand tons of frozen meat and fish. An unknown user nicknamed ‘Supervisor’ penetrated the refrigeration remote monitoring network. Temperature settings were changed from – 24° C to +30°. The security service of the Selyatino agricultural hub prevented the negative consequences of the hacker attack. "At the moment, the operation of the installations has been restored. The equipment is disconnected from the Internet. The parameters are controlled locally, from a computer that is not connected to the Internet,"
Reference: Attacks on a Russian food processing organizations
Victim: Selyatino Agrohub
Seliatino Agrohub is a food processing facility in Russia
Reference: Hackers hacked the equipment of the agricultural hub “Selyatino”
Incident: Russian Electric Vehicle Chargers Hacked on M11 Highway as Political Protest
Russian electric vehicle charging points have been hacked to display messages supporting Ukraine. As a result stations along Russia's M-11 motorway, between Moscow and Saint Petersburg, were deactivated.
According to a Facebook Post by Russian energy company Rosseti, the charging points were hacked by the Ukrainian company that provided some of the parts for them. The company left a backdoor in their systems and used this to set the charging points to display the error messages. It was not reported how many electric vehicle charging points were hacked or deactivated, or for how long they would be unavailable to drivers of EV.
Victim: Russian energy company Rosseti
Russian energy company Rosseti
Reference: Hacked electric car charging stations in Russia display ‘Putin is a d*ckhead’ and ‘glory to Ukraine
Reference: Russian Electric Vehicle Chargers Hacked, Tell Users ‘PUTIN IS A DICKHEAD’
Reference: IHG hack: ‘Vindictive’ couple deleted hotel chain data for fun
Reference: Go North East taken offline as bus company hit by cyber attack
Reference: UK bus giant Go-Ahead battles ongoing cyberattack, reports incident to ICO
Reference: Bus and rail operator Go-Ahead Group confirms “cyber security incident”
Incident: Data Breach at Acer
Computer behemoth, Acer, suffered a data breach in mid-February after attackers were able to get into a server hosting private documents used by repair technicians.
That being said, the Taiwan-based computer firm said so far there are no indications the hack had an impact on stealing customer data.
The company’s confirmation of the breach comes after the attacker began selling on a popular hacking forum what they claim is 160GB of data stolen from Acer in mid-February, according to a report with BleepingComputer. The attacker said the stolen data contains technical manuals, software tools, backend infrastructure details, product model documentation for phones, tablets, and laptops, BIOS images, ROM files, ISO files, and replacement digital product keys (RDPK).
Reference: Acer Hit In Data Breach
Incident: Third-Party Attack Hits Hitachi Energy
Hitachi Energy fell victim to an unauthorized access to employee data in some countries after an attack by the Clop ransomware group that leveraged a Zero Day vulnerability in a third-party software provider, Fortra GoAnywhere MFT (Managed File Transfer), company officials said.
The vulnerability exploited in the attack is CVE-2023-0669, a remote code execution flaw disclosed by Fortra on February 1, after attacks exploiting it were detected. The company issued a patch a week after discovery.
Reference: Hitachi Energy Discloses Third Party Attack
Victim: Hitachi Energy
Hitachi Energy is a global energy solution provider.
Incident: Ferrari Hit in Ransomware Attack
Italian sports car giant, Ferrari S.p.A., reported Monday it suffered a ransomware attack affecting client details, but did not affect operations, officials said in an advisory.
The car company said it had been “recently contacted by a threat actor with a ransom demand related to certain client contact details. Upon receipt of the ransom demand, we immediately started an investigation in collaboration with a leading global third-party cybersecurity firm.”
In working with the third-party firm, they were able to confirm the stolen data was legitimate.
Reference: Ferrari Suffers Ransomware Attack
Incident: Cyberattack at Intercontinental Hotel Group (IHG) disrupts Franchisees, Customers and Supply Chains
Leading hospitality company InterContinental Hotels Group says its IT systems have been disrupted after its network was breached. Customers reported widespread problems with booking and check-in. "Booking channels and other applications have been significantly disrupted since yesterday," IHG said in an official notice lodged with the London Stock Exchange.
The attack disrupted business at franchisees during September, leaving a trail of angry customers, lost income and a class-action lawsuit. The hack on the hotel group highlights the potential ripple effects for franchisees, customers and supply chains, reports the WSJ.
The hotel chain giant was also the target of a three-month security breach in 2017—between September 29 to December 29—when more than 1,200 InterContinental franchised hotels in the United States were impacted. An IHG spokesperson denied commenting when contacted by BleepingComputer earlier today, saying that "outside of the statement, we don't have any more that we can say at the moment."
Reference: Cyberattack on InterContinental Hotels Disrupts Business at Franchisees
Victim: IHG – Intercontinental Hotels Group
IHG is a British multinational company that currently operates 6,028 hotels in more than 100 countries and has more than 1,800 in the development pipeline. Its brands include luxury, premium, and essential hotel chains such as InterContinental, Regent, Six Senses, Crowne Plaza, Holiday Inn, and many others.
Reference: InterContinental Hotels Group cyberattack disrupts booking systems
Reference: Holiday Inn bookings tank after suspected ransomware attack: franchisees
Incident: Cyberattack Closes City Hall in Denver Suburb
The demand was big: $5 million to unlock Wheat Ridge’s municipal data and computer systems seized by a shadowy overseas ransomware operation. The response was defiant: We’ll keep our money and fix the mess you made ourselves.
“The city has made the determination not to pay a ransom,” Amanda Harrison, a Wheat Ridge spokeswoman, said this week. It took three weeks from the Aug. 29 cyberattack for Wheat Ridge to determine that it had adequate redundancies and the know-how to put its databases and systems back into operation without the help of the hackers, who demanded payment in a hard-to-trace cryptocurrency known as Monero.
Following the attack, Wheat Ridge had to shut down its phones and email servers to assess the damage the cybercriminals had done to its network. That, in turn, prompted the city to close down City Hall to the public for more than a week.
Victim: Municipality of Wheatridge, Colorado
Municipality of Wheatridge, Colorado
Reference: Denver suburb won’t cough up millions in ransomware attack that closed city hall
Reference: Hive ransomware attacks Damart
Incident: Ransomware Attack at Electric Company of Ghana Left Customers Without Power for Days
Customers of the largest electricity seller in Ghana have been unable to buy power and others have had their power off for days. Hackers have changed the source code and taken control of parts of the Electricity Company of Ghana (ECG) server. The situation is widespread and has left both domestic and commercial customers stranded. It is not known yet how the hacker or hackers got access to the ECG servers.
Mr Charles Nii Ayiku Ayiku, General Manager in charge of external communications at the ECG told Ghana Business News on September 30, that the ECG has stabilized its district offices and they are able to sell power to consumers. The systems for third-party vendors however, he says are still unstable. ECG has extended its working hours to ensure that all customers who have been affected by the situation can buy power.
Ten operational regional areas of the ECG in the Volta, Kumasi, Accra, Takoradi, Tema, Cape Coast, Kasoa, Winneba, Swedru, Koforidua, Nkawkaw, and Tafo were all affected, according to a statement issued by the ECG.
Victim: Electricity Company of Ghana (ECG)
Electricity Company of Ghana (ECG), the largest electricity seller in Ghana.
Reference: ECG audits system – Fears cyber attack
Reference: ECG systems hacked with ransomware
Incident: Ransomware Attack Cripples Bosnia and Herzegovina Parliament
The government of Bosnia and Herzegovina has suffered a significant cyber attack that has crippled the operations of the country’s parliament.
Commenting on the news, Julia O’Toole, CEO of MyCena Security Solutions, said, “According to reports, this has brought the parliament in Bosnia and Herzegovina to a complete standstill. The website for the parliament has been rendered completely inoperable, while MPs have been told not to even turn on their computers. But, the consequences of this attack are far greater than just digital downtime. While these services are down, parliament workers are unable to perform their jobs, which will have a knock-on effect on other services and society. "
Victim: Government of Bosnia and Herzegovina
Government of Bosnia and Herzegovina
Reference: Bosnia and Herzegovina investigating alleged ransomware attack on parliament
Reference: Ransomware attack disrupts Bosnia and Herzegovina Parliament servers, stalls operations for two weeks
Incident: Italian Waste Management Service IT Systems Down after Ransomware Attack
Redhotcyber.com (RHC) reported that a second computer attack against Alia Servizi Ambientali SpA was intercepted 6 months after the first. Alia issued a statement on their website stating they temporarily took IT systems offline and reported "from the checks carried out, the company confirms that there have been no intrusions and/or compromise of functions or data."
Reportedly, the €400,000 ransom demanded was not paid. Systems operational 2 days later.
Incident: Ransom Not Paid by Italian Chemical Producer Dollmar SpA
Ragnar Locker, hits the Italian chemical company Dollmar SpA. The hacking group leaked 35GB of data, including samples on the company's letterhead, to make it clear that the data in its possession is real.
Publication on a data leak site generally occurs when the company has not paid the ransom.
no further updates.
Reference: Cyber attack on the Italian Dollmar Spa by Ragnar Locker
Victim: Dollmar SpA
Dollmar S.p.A. has been a European leader in the distribution of industrial chemicals for over 70 years.
Reference: The Italian Alia Servizi Ambientali suffers a new cyber attack
Reference: Full operation of the Call Center and Tari branches restored after the attempt to access the information systems
Victim: Alia Servizi Ambientali SpA
Alia Servizi Ambientali SpA is a large company that deals with the collection of environmental waste in the Florence area and in Tuscany and is active in 59 Tuscan municipalities, 1.5 million customers served and is the fifth Italian company in the sector with 1800 employees and 225 million euros in revenues. The company website states they are a "multi-utility of local public services: environmental, integrated water cycle and energy sectors."
Victim: Unknown hotel
in Israel
Reference: GhostSec Strikes Again in Israel Alleging Water Safety Breach
Incident: Operations Impacted at Swiss Chocolate Manufacturer Läderach
The Swiss chocolatier Läderach became the target of a cyber attack on 5 September. The responsible authorities were informed immediately.
Production, logistics and administration in particular are currently affected by the cyber attack. The use of internal tools and communication channels has been reduced to a minimum as a precautionary measure. "In production, it is still possible to work completely except for a sub-area," the company specifies on request.
UPDATE 10Nov22: The logistics are now also working again and the backlogs in deliveries have already been partially made up. "Since the cash register systems are still impaired, we resort to workarounds (use of cash sales, credit card terminals)," writes Läderach.
Victim: Läderach
Founded in 1962, the family company is headquartered in the canton of Glarus in Switzerland. Läderach monitors the entire production process from the cocoa bean to the shop counter and produces exclusively in Switzerland.
Reference: Laderach affected by cyberattack
Incident: Cyberattack at Major UK Transport Companies Affecting Bus Scheduling Services
UK travel company Go-Ahead Group has confirmed that it is dealing with an ongoing cyberattack reportedly affecting software used to schedule bus drivers and services.
The issues became more widespread on Monday, affecting several back office systems, including bus services and payroll software. Firm says software used to schedule bus services hit but Thameslink rail operations not affected. Go-Ahead said it was working with IBM to activate backup systems to ensure its bus services can keep running.
The cyber-attack does not affect its rail business, which runs on separate systems and is operating normally in the UK and abroad.
Victim: Go-Ahead
Go-Ahead runs Great Northern, Thameslink, Gatwick Express and Southern rail and also operates rail services in Norway and Germany. It runs nearly a quarter of London’s buses as well as bus services in southern and eastern England, and also has bus contracts in Singapore, Sweden and Ireland.
Reference: Major UK transport company Go-Ahead battles cyber-attack
Victim: Yandex Taxi
The largest taxi service in Russia.
Reference: Anonymous hacked Yandex taxi causing a massive traffic jam in Moscow
Incident: Hack at Largest Taxi Service in Russia Caused Chaos in Moscow Traffic
In a bizarre incident, hackers broke into the ride-hailing service provider Yandex Taxi’s software and sent dozens of cars to the same location, resulting in a traffic jam that lasted for three hours. According to cyber experts, the hackers bypassed Yandex’s security and generated several fake requests that directed drivers to simultaneously drive to the same location.
The Twitter page of Anonymous TV claimed that the hacking group Anonymous was behind the data breach. The Anonymous collective is part of a large-scale hacking campaign against Russia, called ‘OpRussia’.
Reference: Hackers send cabs to same location in Russia, creates huge traffic jam
Incident: Ransomware Attack at Dutch Maritime Global Logistics Company
Dutch maritime logistics company Royal Dirkzwager confirmed that it was hit with ransomware from the Play group. The attack is the latest in a string of attacks targeting the shipping industry. Company CEO Joan Blaas told The Record the ransomware attack did not have an effect on operations. The attack involved the theft of data from servers that held a range of contracts and personal information. Blaas confirmed that the Dutch Data Protection Authority has been notified of the attack and said he is in negotiations with the cybercriminals.
Blaas confirmed that the Dutch Data Protection Authority has been notified of the attack and said he is in negotiations with the cybercriminals.
Victim: Royal Dirkzwager
Founded in 1872 in The Netherlands, Royal Dirkzwager provides information to more than 800 organizations in the maritime industry and registers more than 200,000 ship movements a year. Its systems allow ports to know when ships will arrive and what nautical services will be available when they make it to a port.
Reference: Dutch shipping giant Royal Dirkzwager confirms Play ransomware attack
Incident: Major Airlines Affected in Massive Supply Chain Attack at Technology Giant SITA.
SITA, an airline technology and communication provider that operates passenger processing systems for airlines, was the victim of a cyber-attack involving passenger data. SITA serves 90% of the world's airlines and disclosed that among the airlines affected were various major airlines including Air India, Finnair, Japan Airlines, Jeju Air, Lufthansa, Malaysia Airlines, Singapore Airlines and Cathay Pacific.
Singapore Airlines reported that 580,000 of its frequent flyer members were compromised in the attack and Air India estimated that personal data relating to 4.5 million of its passengers was stolen.
Reference: Aviation IT Giant SITA Breached in Extensive Supply Chain Attack; Frequent Flier Programs of Major Airlines Compromised
Victim: SITA
SITA is a multinational information technology company providing IT and telecommunication services to the global air transport industry.
Reference: SITA falls victim to cyber-attack
Incident: Russian Federal Air Transport Association Forced to Resort to Manual Operations after Cyberattack
A cyberattack on the Russian Federal Air Transport Agency's (Rosaviatsia) infrastructure allegedly erased all documents, files, aircraft registration data and emails from the servers. The agency lost nearly 65 terabytes of data.
An unidentified group (presumed to be the Anonymous Hacking Group) carried out an extremely effective attack on the Russian Federal Air Transport Agency. As part of the attack, all aircraft registration data and emails, totaling approximately a massive 65 terabytes of data, were deleted from the Agency's servers. The attack was so successful that until back-up copies of the electronic data could be found the Agency was forced to resort to using pen and paper and to sending information in hard copy through the post.
There are reports claiming that the mass loss of data may be irretrievable, and sources claim that due to a lack of government funds, many files at Rosaviatsiya were never backed up.
Reference: Hackers Target Russian Federal Air Transport Agency
Reference: Russia’s air transport agency affected by cyberattacks
Victim: Rosaviatsiya – Russian Federal Air Transport Agency
Russian Federal Air Transport Agency
Incident: Data Breach at Air-Conditioner Manufacturer
On August 4, 2022, Friedrich Air Conditioning, LLC reported a data breach with the Office of the Attorney General of Vermont. The breach resulted in the names and Social Security numbers being compromised.
Victim: Friedrich Air Conditioning
Founded in 1883 and based in San Antonio, Texas, Friedrich Air Conditioning, LLC is a manufacturer of air conditioner units. Friedrich also manufactures air purifiers and dehumidifiers. Employing more than 138 people and approximately $27 million in annual revenue.
Reference: Friedrich Air Conditioning, LLC Announces Data Breach
Incident: Data Breach at Surgical Product Manufacturer in Savannah, Georgia
On August 17, 2022, Brasseler USA (“Brasseler”) reported a data breach with the Montana Department of Justice. An unauthorized party had gained access to the company’s computer network. According to Brasseler, the breach resulted in consumer information being compromised, This included names, social security numbers, driver’s license numbers, passport numbers; financial account information, medical and insurance information.
After confirming the breach and identifying all affected parties, Peter Brasseler Holdings, LLC began sending out data breach letters to all affected parties.
Reference: Brasseler USA Announces Data Breach
Victim: Brasseler USA
Founded in 1976, Brasseler USA is a dental and surgical product manufacturer based in Savannah, Georgia and designs and manufactures a wide range of products. Peter Brasseler Holdings, LLC employs more than 309 people and generates approximately $83 million in annual revenue.
Incident: Data Breach at Agricultural Mineral Powder Manufacturer in Iowa
Calcium Products, Inc. reported a data breach with the office of the Attorney General of Massachusetts after the company experienced a “data security incident." On August 17, 2022, Calcium Products sent out data breach letters to all individuals whose information was compromised as a result of the recent data security incident. The company did not explain how consumers’ data was compromised or the data types that may have been subject to unauthorized access.
Reference: Calcium Products, Inc. Confirms Recent Data Breach
Victim: Calcium Products
Calcium Products, Inc. is a manufacturing company based in Ames, Iowa. The company specializes in making superfine mineral powders for use in various agriculture applications. Some of the company’s products include pelletized limestone, pelletized gypsum, aglime and professional turf. Calcium Products employs more than 97 people and generates approximately $19 million in annual revenue.
Victim: National Petroleum Company (ENAP), Chile
National Petroleum Company (ENAP), Chile
Reference: Hackers violate ENAP systems and access secret information in an international fraud attempt
Incident: Systems Offline at Brazil’s National Agency for Petroleum
The announcement on gov.br websites states systems are unavailable due to an attempted cyberattack that took place last Thursday (4/8). As a security measure, all systems were taken offline to assess the risks to the Agency's cyber security. Among the unavailable systems are the weekly price survey, the Systems for Recording Documents at Dealer Stations (SRD-PR) and at LPG Dealers (SRD-GLP). The Electronic Information System (SEI), among others, were also unavailable.
Victim: ANP – Brazil National Agency for Petroleum, Natural Gas and Biofuels
Part of Ministry of Mines and Energy, Brazil
Reference: Announcement: ANP works to resume its systems
Reference: Announcement: ANP systems are down
Incident: Romanian Gas Stations Affected by Suspected Ransomware Attack.
Rompetrol, a Romanian gas station chain and part of KMG International, has confirmed it was subject to a “complex cyber-attack”. The company suspended operations of its website and its Fill&Go service at its gas stations. Operations at the gas stations remain normal with payment accepted by either cash or card. The company noted that the activity at Petromidia refinery, the largest oil refinery in Europe and operated by Rompetrol, has not been affected.
Romania’s National Cyber Security Directorate (DNSC) had been notified on 7 March by Rompetrol of the complex cyber-attack. As of 9 March, the Rompetrol.ro website remains unreachable.
Victim: Rompetrol
Rompetrol, a Romanian gas station chain and part of KMG International.
Rompetron operates Petromidia refinery, the largest oil refinery in Europe.
Reference: Romanian oil company hit by ‘complex cyber-attack’
Threat Actor: Yanluowang ransomware group
Yanluowang - named after the Chinese and Buddhist mythological figure Yanluo Wang, but leaked chat data in Oct. '22 revealed those involved in the organization spoke in Russian. The leak appears to have shut down the group for the time in Nov '22.
Reference: Cisco discloses a security breach, the Yanluowang ransomware group breached its corporate network in late May and stole internal data.
Incident: Entire System of Global Energy Provider ista International Hacked in Two Days
ista International GmbH announced a cyber attack on its website. All affected IT systems were initially taken offline, resulting in various functions and services being unavailable. The company’s customer portal and email functionality are switched off. ista asks to refrain from contacting them. “We will inform them immediately via our website when the contact options are available again .. you will temporarily be limited or unable to use certain functions and services."
ista describes the company: "..we already have 400,000 gateways in use for our customers that link over 25 million connected devices to each other". Daixin Team states they went through one of those gateways and took control of the entire system in two days.
ista International takes care of about 30 million networked devices in 22 countries in the field of sub-metering.
Victim: ista International GmbH
ista International GmbH provides submetering and billing of water and energy consumption. The Company offers heat allocation, water, and communication meters, installation systems, and smoke detectors. ista International caters their services to property managers, homeowners, and energy utilities worldwide.
Reference: SCOOP: ista International takes systems offline in wake of ransomware attack; Daixin Team claims thousands of servers encrypted
Reference: Cyber attack on ista paralyzes systems
Incident: Global Airline Technology Provider Accelya Hacked by AlphV/Black Cat.
Accelya, a technology provider for many of the world’s largest airlines, said it recently dealt with a ransomware attack impacting some of its systems.
Accelya provides services to Delta, British Airways, JetBlue, United, Virgin Atlantic, American Airlines and many more. The company confirmed Tuesday that company data was posted on a ransomware leak site. The AlphV/Black Cat ransomware group published data it allegedly stole from Accelya last Thursday. The group claimed to have stolen emails, worker contracts and more.
Victim: Accelya
Global technology and service provider to the air transport industry. Headquarered in Spain with over 250 airline customers and operations spread across nine countries, employing over 2,000 professionals worldwide.
Reference: Major airline technology provider Accelya attacked by ransomware group
Incident: Cyberattack at Singapore Specialist Shipbuilder: Sembcorp Marine
Singapore shipbuilder Sembcorp Marine has suffered a cyberattack that left information on employees and operations compromised. It said this cyber attack involved an unauthorised party accessing part of its IT network via third-party software products.
“Based on investigations and impact assessment to-date by the company and its cyber-security experts, the incident and related risks have been effectively addressed,” said Sembcorp. “The company’s business operations remained unaffected throughout.”
Victim: Sembcorp Marine
Singapore specialist ship and offshore rig builder, converter and repairer
Reference: Sembcorp Marine reports cyber incident; moves to address incident and support affected stakeholders
Reference: Sembcorp Marine addresses cyber-security incident
Reference: Sembmarine Reports Cyber Breach Affecting Information on Personnel
Reference: Italy warns of cyberattacks on energy industry after Eni, GSE incidents
Incident: GSE, Italy’s Energy Services Firm, Temporarily Takes Portals Offline
Italy's energy services firm GSE confirmed a hacking attack on its IT systems. GSE stated its gas purchases were not affected. The company added its website and portals were temporarily suspended to secure data.
The BlackCat ransomware group took credit for the attack on GSE, claiming to have stolen more than 700 GB of data from the agency.
Victim: GSE – Gestore dei Servizi Energetici
GSE is responsible for renewable energy in Italy
Reference: Italy’s GSE says gas purchases guaranteed despite cyber attack
Incident: TAP Air Portugal Hit by Ragnar Locker Ransomware Gang
The Ragnar Locker ransomware gang has claimed an attack on the flag carrier of Portugal, TAP Air Portugal. The airline disclosed this after its systems were hit on Thursday night. TAP initially said the attack was blocked. The company said it found no evidence indicating the attackers gained access to customer information stored on impacted servers.
In September the airlines told customers on Thursday that hackers had stolen some of their personal data and published it on the dark web. The state-owed airline said all payment details appeared to be safe.
Victim: TAP Air Portugal
Portugal's flagship air carrier
Reference: Portugal’s TAP says hackers stole, published passengers’ personal data
Reference: Ragnar Locker ransomware claims attack on Portugal’s flag airline
Incident: System Outage at Apex Capital Affects Medium and Small Size Trucking Companies’ Operations
Apex Capital and its subsidiary, TCS Fuel, confirmed that both companies’ systems were targeted in a malware attack. Small-business truckers were unable to log on to the companies’ systems, fuel their trucks or access funds to pay their owner-operators.
“We were infected by malware, and we are continuing to work around the clock to get our systems back online,” Sherry Leigh, chief product and marketing officer at Apex said in an email. “The good news is our core systems and client databases remain intact and we are successfully bringing our processing back online. However, this continues to be a slow process.”
Systems were offline for a week. Leigh declined to comment about what data may have been stolen by the hackers who accessed Apex’s system.
Victim: Apex Capital
Financial services for trucking companies, a "full-service freight factor"meaning they buy their clients' freight bills and offer support services, i.e. fuel cards etc.
Reference: Ransomware target Apex Capital declares systems ‘back up and running’
Reference: Apex Capital blames malware attack for ‘unplanned system outage’
Incident: Cyberattack at the Chinese Subsidiary of a German Furniture Manufacturer
A Chinese production site of the Hettich Group has involuntarily been the victim of a cyber attack. As yet unknown attackers have hacked the internal networks and deposited malware there. The company's website states: " It is not yet possible to say when the Chinese subsidiary will be able to fully access all IT systems again. Local production in China is continuing. As far as we know at present, other companies in the Hettich Group are not affected. From today's point of view, the ability to deliver to our customers outside China is not limited."
Reference: Hettich subsidiary in China hit by cyber attack
Victim: Hettich Group
The Hettich Group is one of the world's leading manufacturers of furniture fittings. The company's headquarters are located in the eastern Westphalian town of Kirchlengern. In 2015, 5900 employees worldwide worked for Hettich, of which more than 3,000 are in Germany. The company has 38 subsidiaries worldwide. Hettich is family-owned.
Incident: Ransomware Attack at Dish Network
Satellite TV behemoth Dish Network experienced a network outage last week that was the result of a ransomware attack, company officials said in an 8-K filing to the Securities and Exchange Commission (SEC). The attack appeared to affect Dish.com, the Dish Anywhere app, Boost Mobile (a subsidiary owned by Dish Wireless), and other websites and networks owned and operated by Dish Network. Customers also said the company’s call center phone numbers were unreachable. The attack effected 296,000 individuals.
Dish Network faces multiple class action lawsuits for allegedly making "materially false and misleading statements. The legal actions seek to recover damages for investors who purchased or acquired Dish Network securities between Feb. 22, 2021 and Feb. 27, 2023.
Reference: Dish Network confirms ransomware attack behind multi-day outage
Reference: Dish Network Reveals Ransomware Attack
Victim: Dish Network
“On February 23, 2023, DISH Network Corporation (the “Corporation”) announced on its earnings call that the Corporation had experienced a network outage that affected internal servers and IT telephony. The Corporation immediately activated its incident response and business continuity plans designed to contain, assess and remediate the situation. The services of cyber-security experts and outside advisors were retained to assist in the evaluation of the situation. The Corporation has determined that the outage was due to a cyber-security incident and notified appropriate law enforcement authorities.
“On February 27, 2023, the Corporation became aware that certain data was extracted from the Corporation’s IT systems as part of this incident."
Incident: Dole Suffers Ransomware Attack
Ransomware forced produce giant Dole to shut down production plants in North America and halt food shipments to grocery stores, company officials said.
The attack impacted about half of Dole’s legacy company’s servers and one-quarter of its end-user computers.
On May 18 Dole stated the February ransomware attack cost $10.5 million in direct costs About $4.8 million of those costs were related to continuing operations.
Reference: Cyberattack on food giant Dole temporarily shuts down North America production, company memo says
Reference: Dole Hit In Ransomware Attack
Victim: Dole Food Company
The multibillion-dollar company – officially known as Dole Plc after a 2021 merger between Dole Food Company and Ireland’s Total Produce – sources produce from dozens of countries around the world.
Incident: Hackers Had Weeks of Undetected Data Access at Pepsi Bottling Ventures
Pepsi Bottling Ventures LLC suffered a data breach caused by a network intrusion that resulted in the installation of information-stealing malware and the extraction of data from its IT systems.
The incident, Pepsi Bottling Ventures says, was discovered on January 10, but the investigation that was launched into the matter revealed that attackers gained access to the company’s network on December 23. The unauthorized access was blocked on January 19.
While dwelling in Pepsi Bottling Ventures’ network, the attackers deployed malware and downloaded information stored on the systems they had access to.
Stolen personal information includes names, addresses, email addresses, financial information, Social Security numbers, driver’s license numbers, ID card and password information, benefits information, health insurance information, medical history, health and health insurance claims, and digital signatures.
Reference: Pepsi Bottling Ventures Breached Following Malware Attack
Reference: Pepsi Bottling Ventures suffers data breach after malware attack
Victim: Pepsi Bottling Ventures LLC
Pepsi Bottling Ventures LLC is the largest bottler of Pepsi-Cola beverages in the US, responsible for manufacturing, selling, and distributing popular consumer brands and operates 18 bottling facilities across North and South Carolina, Virginia, Maryland, and Delaware.
Incident: MKS Suspends Operations to Contain Ransomware Attack
MKS Instruments Inc is investigating a ransomware attack and is temporarily suspending operations at some of its facilities. “The incident has affected certain business systems, including production-related systems, and as part of the containment effort, the company has elected to temporarily suspend operations at certain of its facilities”, Kathleen F Burke, senior vice president, general counsel and secretary at MKS Instruments, said in the SEC filing.
The ransomware incident was reported just a day after national cybersecurity agencies and security experts around the world warned about a global ransomware attack that hit thousands of servers running on VMware ESxi.
Applied Materials, Samsung Electronics Co., Taiwan Semiconductor Manufacturing Co. , Intel Corp. and ASML Holding NV are among MKS Instrument's customers. Applied Materials reported they will take a $250M hit to sales this quarter, thanks to a cyberattack at one of its (unidentified) suppliers.
Reference: MKS Instruments falls victim to ransomware attack
Victim: MKS Instruments
MKS Instruments is an Andover, Massachusetts-based provider of subsystems for semiconductor manufacturing, wafer level packaging, package substrate and printed circuit boards. MKS Instruments reportedly has 5,400 employees and a market capitalization of about $11 billion. As of 2021, sixty percent of the company's sales are from semiconductor products.
Reference: Applied Materials’ Sales Shortfall Linked to Cyberattack at MKS
Reference: Chip equipment maker MKS Instruments says it is investigating ransomware attack
Incident: Business Operations Offline at Burton Snowboards Manufacturing after Cyberattack
Burton Snowboards has canceled all online orders following what it describes as a "cyber incident." "We are currently experiencing a system outage due to a recent cyber incident and are unable to process online orders at this time," the snowboarding brand says in a prominent alert on its website. While the company is working on restoring business operations that were impacted, orders are no longer being processed. The company did not provide details on the nature of this "cyber incident" but will likely update its statement once the ongoing investigation is concluded.
Update June 2023: Burton Snowboards notified customers sensitive information was "potentially" accessed or stolen in February "cyber incident." The company reset the passwords of accounts linked to affected customers.
Victim: Burton Snowboards
Founded in 1977 by Jake Burton Carpenter, Burton is now one of the most well-known snowboard brands and its products are sold in thousands of stores worldwide. Burton's headquarters are in Burlington, Vermont, but it also has offices in Australia, Austria, Canada, California, China, and Japan.
Reference: Burton Snowboards cancels online orders after ‘cyber incident’
Incident: Ransomware Attack impacts City of Oakland, State of Emergency Activated
Oakland has declared a local state of emergency because of the impact of a ransomware attack. The state of emergency was declared to allow the City of Oakland to expedite orders, materials and equipment procurement, and activate emergency workers when needed. The ransomware attack impacted non-emergency services only, but many systems taken down immediately to contain the threat, are still offline a week later.
Victim: City of Oakland, CA
City of Oakland, CA
Reference: City of Oakland declares state of emergency after ransomware attack
Incident: Data breach at Scandinavian Airlines
Scandinavian Airlines (SAS) has posted a notice warning a cyberattack caused some form of a malfunction on the airline's online system. The attack caused passenger data to become visible to other passengers. This data includes contact details, previous and upcoming flights, as well the last four digits of the credit card number.
The attack on SAS was claimed by a group of so-called hacktivists called 'Anonymous Sudan'. The hackers stated they attacked SAS due to an event that took place in front of the Turkish embassy in Stockholm, Sweden.
Victim: Scandinavian Airlines (SAS)
SAS operates a fleet size of 131 aircraft and flies people to 168 destinations,
Reference: Scandinavian Airlines says cyberattack caused passenger data leak
Incident: Customer Data Breach at KLM and Air France
Air France and KLM have informed Flying Blue customers that some of their personal information was exposed after their accounts were breached. Air France and KLM confirmed the data breach in a statement sent to BleepingComputer and said that customers' sensitive data, such as passport or credit card numbers, was not exposed. The two airlines said that they also reported the incident to their countries' data protection authorities.
Flying Blue is a loyalty program allowing clients of multiple airlines, including Air France, KLM, Transavia, Aircalin, Kenya Airways, and TAROM, to exchange loyalty points for various rewards.
Victim: KLM
Royal Dutch Airlines
Victim: Air France
Air France
Reference: Air France and KLM notify customers of account hacks
Incident: Attempted Cyberattacks at Nuclear Research Laboratories in US in Summer ’22.
A Russian hacking team known as Cold River targeted three nuclear research laboratories in the United States this past summer, according to internet records reviewed by Reuters and five cyber security experts.
Between August and September Cold River targeted the Brookhaven (BNL), Argonne (ANL) and Lawrence Livermore National Laboratories (LLNL), according to internet records that showed the hackers creating fake login pages for each institution and emailing nuclear scientists in a bid to make them reveal their passwords.
Reuters was unable to determine why the labs were targeted or if any attempted intrusion was successful. A BNL spokesperson declined to comment. LLNL did not respond to a request for comment. An ANL spokesperson referred questions to the U.S. Department of Energy, which declined to comment.
Victim: Lawrence Livermore National Laboratory – LLNL
LLNL is a premier research and development institution for science and technology applied to USA national security
Victim: Argonne National Laboratory -ANL
Argonne National Laboratory is a science and engineering research national laboratory.
Victim: Brookhaven National Laboratory – BNL
Research at BNL includes nuclear and high energy physics, energy science and technology, environmental and bioscience, nanoscience, and national security.
Threat Actor: Cold River
Russian hacking team Cold River first appeared on the radar after targeting Britain’s foreign office in 2016, has been involved in dozens of other high-profile hacking incidents in recent years. Reuters traced email accounts used in its hacking operations between 2015 and 2020 to an IT worker in the Russian city of Syktyvkar.
Reference: Report: Brookhaven National Laboratory victim of attempted Russian cyberattack
Reference: Exclusive: Russian hackers targeted U.S. nuclear scientists
Incident: Vice Society Claims it Stole Leaked Data from San Francisco’s Bay Area Rapid Transit – BART
Vice Society, a prolific ransomware group, leaked data it claims to have stolen from San Francisco’s Bay Area Rapid Transit. BART's spokesperson Alicia Trost: "We are investigating the data that has been posted." "To be clear, no BART services or internal business systems have been impacted. As with other government agencies, we are taking all necessary precautions to respond." Trost did not say whether ransomware was involved nor when the incident occurred.
Transit sector remains highly vulnerable. “They have the worst security by far generally. It’s run on tax money and it’s run as a bureaucracy, and their mission is to deliver transit,” which means they often don’t spend enough on cybersecurity or properly assess the risk, according to Chester Wisniewski, principal research scientist at Sophos.
Reference: San Fran’s BART Investigates Vice Society Data Breach Claims
Victim: San Francisco’s Bay Area Rapid Transit – BART
BART is a rapid transit system serving the San Francisco Bay Area in California.
Reference: Ransomware attack exposes California transit giant’s sensitive data
Incident: Cyberattack takes DNV’s Maritime Vessel and Fleet Management Software Offline.
DNV confirms it has taken its ShipManager software product offline after the services’ IT servers had been the victim of a cyberattack. DNV reports that it has advised customers. In response to the incident the company shut down ShipManager’s IT servers.
ShipManager is a software solution used by shipping companies to oversee the technical, operational, and compliance aspects involved in vessel and fleet management.
UPDATE: Approximately 1.000 ships of 70 maritime operators were affected by a ransomware
attack reports the Computer Emergency Response Team for the EU institutions.
Reference: Cyberattack Forces DNV to Take ShipManager Service Offline
Reference: Cyberattack hits DNV ShipManager software
Victim: DNV
DNV provides services for several industries including maritime, oil and gas, renewable energy, electrification, food and beverage and healthcare.
An international accredited registrar and classification society headquartered in Høvik, Norway. The company currently has about 12,000 employees and 350 offices operating in more than 100 countries.
Incident: UK Manufacturer, Morgan Advanced Materials Hit in Cyberattack
UK manufacturing firm, Morgan Advanced Materials plc said Tuesday it is investigating and managing a “cybersecurity incident after detecting unauthorized activity on its network.” “Upon becoming aware of the incident, the company immediately launched an investigation, engaged its specialist support services and has implemented its incident response plans,” the company said in a notice filed with the London Stock Exchange.
August 2023 update: the company told the London Stock Exchange that some applications were still being recovered and that the incident had a £23 million (approximately $28 million) impact on the first half of 2023’s operating profit. Although the company did not provide information on the type of cyberattack it has experienced, taking systems offline is typically the response to a ransomware attack.
Reference: UK Manufacturing Firm Hit in Cyberattack
Reference: British Manufacturing Firm Morgan Advanced Materials Investigating Cyberattack
Victim: Morgan Advanced Materials
Morgan Advanced Materials specializes in solutions for the industrial, energy, transportation, healthcare, and semiconductor sectors. It provides thermal and technical ceramics, molten metal systems, electrical carbon, and seals and bearings. The company has 7,800 employees across 25 countries.
Threat Actor: Play, aka PlayCrypt
Play ransomware mainly works in the Latin American region targeting government entitles. This ransomware’s name was derived from its behavior, as it adds the extension “.play” after encrypting files. Its ransom note also contains the single word, “PLAY,” and the ransomware group’s contact email address.
Unlike most ransomware operations, Play gang affiliates use email as a negotiation channel and will not provide victims with a link to a Tor negotiations page within ransom notes dropped on encrypted systems. However, they are stealing data from their victims' networks before deploying ransomware payloads and will threaten to leak it online if the ransom is not paid.
Incident: The Guardian Closes Offices after Cyberattack
The Global IT system at The Guardian newspaper was hit by a ransomware attack on December 20. Offices are closed to “reduce the strain” on the company’s networks. All workers were told to work remotely until at least January 23.
Victim: The Guardian
The Guardian is a British daily newspaper founded in 1821.
Reference: The Guardian offices close after ransomware attack
Incident: Customer Data Breach at Toyota India
A data breach at Toyota Motor's Indian business might have exposed some customers' personal information, it said on Sunday. The car company warned that the accounts could be subject to spamming or phishing scams along with unsolicited emails.
Reference: Data Breach At Toyota-Kirloskar Motor Could Expose Customer Data: All You Need To Know
Victim: Toyota-Kirloskar Motor
Toyota Kirloskar Motor, based in India, is a joint venture between Kirloskar group and Toyota, Japan.
Reference: Toyota’s Indian unit warns of a possible customer data breach
Reference: Ransomware Group Claims Volvo Attack, Screenshots of the Stolen Files Released
Incident: R&D Data Breach at Volvo Cars
Car company Volvo suffered a cyberattack on some of its research and development property, the manufacturer said in a press release. Volvo Cars said "it could impact the company's operation", but did not specify what that might be.
In a statement published on the dark web on the evening of November 30, the Snatch ransomware gang said it had attacked the Volvo Car Corporation (VCC). Snatch published screenshots of allegedly stolen data from the Volvo hack on a Darknet website viewed by inside-it.ch.
Threat Actor: Snatch ransomware group
The Russian Snatch ransomware group uses the double extortion method; accordingly, the payload is made of ransomware and data stealer components. Threat actors use automated brute-force attacks against vulnerable applications in the target organizations. Also, the Snatch ransomware operators also use their affiliate partners to gain initial access to corporate networks.
Malware: Snatch Ransomware
Snatch ransomware is a stealthy malware that utilizes publicly available and built-in tools for its malicious activities. Since Windows does not often run endpoint protection mechanisms in Safe Mode, Snatch ransomware avoids detection by forcing infected hosts to reboot into Safe Mode.
Reference: The Snatch ransomware gang is making a comeback, releasing screenshots of stolen data.
Incident: Hacker Allegedly Sells Sensitive Data from Volvo
A threat actor is allegedly selling sensitive data, including information on vehicles the company sells to law enforcement.
Somebody has posted an ad on a popular hacking forum, claiming they are selling sensitive data of the Swedish manufacturing giant Volvo.
The threat actor behind insists that the company fell victim to a ransomware attack in late December. However, the attacker decided to sell the data instead, being convinced that Volvo would not pay the ransom. The relatively modest price set for the dataset signals the information might not be as sensitive.
Victim: Volvo
The Volvo Group is a Swedish multinational manufacturing corporation headquartered in Gothenburg. While its core activity is the production, distribution and sale of trucks, buses and construction equipment, Volvo also supplies marine and industrial drive systems and financial services.
Reference: Attacker claims Volvo suffered a data breach
Incident: Wabtec Discloses Data Breach Took Place less than a Year Ago
U.S. rail and locomotive company Wabtec Corporation has disclosed a data breach, that exposed a wide variety of personal and sensitive information, in a statement on December 30 2022. Wabtec says hackers breached their network and installed malware on specific systems as early as March 15, 2022.
News outlets reported the "possible ransomware attack" in June '22, Wabtec did not comment at that time.
Reference: Possible Ransomware Attack Allegedly Impacting Wabtec
Reference: Rail giant Wabtec discloses data breach after Lockbit ransomware attack
Victim: Wabtec
Wabtec is a U.S.-based public company producing state-of-the-art locomotives and rail systems. The company employs approximately 25,000 people and has a presence in 50 countries, being the world's market leader in freight locomotives and a major player in the transit segment, It is headquartered in Pittsburgh, Pennsylvania.
Incident: Port of Lisbon Suffered Cyberattack over Christmas
The administration of the Port of Lisbon suffered a cyberattack over Christmas. The Portuguese authorities didn’t specify the nature of the attack or who was behind it. However, the LockBit ransomware gang uploaded Port of Lisbon to its leak site, a darknet website where cybercriminals announce their victims. The gang claims to have stolen all of the data available on the port’s systems. Threat actors intentionally publicize what data was stolen to force victims into paying the ransom. LockBit demands close to $1.5m to download or destroy the data.
Victim: Port of Lisbon
Port of Lisbon is Portugal’s third largest port.
Reference: LockBit claims an attack on the Port of Lisbon
Incident: Boeing Hit by Wannacry
Boeing looks like it may be the latest victim of the WannaCry ransomware.
The company, however, said it detected only what it calls “limited malware intrusion” impacting a “small number of systems.”
The ransomware first hit Boeing Wednesday and Mike VanderWel, chief engineer at Boeing Commercial Airplane production engineering, sent out a memo to warn the infection could even affect airplane software.
“It is metastasizing rapidly out of North Charleston and I just heard 777 (automated spar assembly tools) may have gone down,” VanderWel was quoted as saying in The Seattle Times.
Reference: WannaCry Hits Boeing With ‘Limited Intrusion’
Malware: WannaCry
WannaCry is a ransomware worm that spread rapidly through across a number of computer networks in May of 2017. After infecting a Windows computer, it encrypts files on the PC's hard drive, making them impossible for users to access, then demands a ransom payment in bitcoin in order to decrypt them.
Victim: Boeing
American multinational corporation that designs, manufactures, and sells airplanes, rotorcraft, rockets, satellites, telecommunications equipment, and missiles worldwide.
Incident: Colombian Utility, EPM, Suffers Ransomware Attack
Colombian energy company Empresas Públicas de Medellín (EPM) suffered a BlackCat/ALPHV ransomware attack, which ended up affecting financial operations and taking down online services. EPM is one of Colombia’s largest public energy, water, and gas providers.
The company's information was decrypted, affected the alternate Data Center and analyzed a 25% contagion. of the infrastructure; in addition, the additional loss of information is still being studied.
The company who provide services to 123 municipalities, closed its customer service offices and asked 4,000 employees to work from home as a preventative measure. The same day they indicated that "fortunately the provision of energy, water and gas services was not affected." EPM provided alternative methods for customers to pay for services.
Reports claim that a sizeable amount of data was stolen and around 40 devices were compromised during the attack, but organization is yet to comment on these claims.
Reference: Ransomware Attack at Colombian Utility
Victim: Empresas Públicas de Medellín (EPM)
One of Colombia’s largest public energy, water, and gas providers, providing services to 123 municipalities. The company generated over $25 billion in revenue in 2022 and is owned by the Colombian Municipality of Medellin.
Reference: Copper Miner Hit In Ransomware Attack
Incident: Disney Toy Maker Extorted by Two Ransomware Gangs
BlackCat ransomware cartel claims to have obtained Jakks Pacific data. Two weeks ago, Hive ransomware posted Jakks Pacific on their leak site. Threat actors first hacked the maker of Super Mario, Sonic, Disney Princess, and other toys in early December.
“On December 8, 2022, JAKKS experienced a ransomware attack by inserted malware into JAKKS’ computer network which locked up our servers,” the company said in a statement.
At the time, Jakks Pacific believed that threat actors accessed personal information such as names, emails, home addresses, taxpayer ID numbers, and ‘banking information.’
Reference: Toy maker Jakks Pacific victimized by a second cybergang
Reference: Toy maker Jakks Pacific reports cyberattack after multiple ransomware groups leak data
Victim: JAKKS Pacific, Inc.
JAKKS Pacific, Inc. is a leading designer, manufacturer and marketer of toys and consumer products sold throughout the world, with its headquarters in Santa Monica, California.
Incident: Hackers Demand $60M Ransom from Intrado Telecommunications
The Royal Ransomware gang claimed responsibility for a cyber attack against telecommunications company Intrado on Tuesday.
While Intrado is yet to share any information regarding this incident, sources have told BleepingComputer early this month that the attack started on December 1 and the initial ransom demand was $60 million. The Royal Ransomware group, made up of experienced threat actors and operating without affiliates, has reportedly stolen some data from Intrado's systems and is now threatening to publish it on their data leak site unless the company pays the ransom. The attackers claim to have obtained internal documents, passports, and employee driver's licenses from compromised Intrado devices.
Although the ransomware gang has not yet leaked any of the files allegedly exfiltrated from Intrado's network, they did share a 52.8 MB archive containing scans of passports, business documents, and driver's licenses as proof of the breach.
Intrado has not yet responded to multiple requests for comment from BleepingComputer via email and voicemail.
Threat Actor: Royal Ransomware gang
Royal is an operation that launched in January 2022 and consists of a group of vetted and experienced ransomware actors from previous operations. Royal does not operate as a Ransomware-as-a-Service but is instead a private group without affiliates.
Initially, they used encryptors from other gangs like BlackCat, they quickly switched to using their own encryptors, the first being Zeon which generated Conti-like ransom notes.
Starting in mid-September, the ransomware gang rebranded again to "Royal" and uses a new encryptor that generates ransom notes with the same name. Unusually for a ransomware gang, the group also uses social engineering to trick corporate victims into installing remote access software following callback phishing attacks where the attackers impersonate software providers and food delivery services.
Victim: Intrado
Intrado, formerly West Corporation, is an American telecommunications company. Intrado says it provides services to approximately 82% of Fortune 500 companies and manages approximately 20 billion annual telephony minutes.
Reference: Royal ransomware claims attack on Intrado telecom provider
Incident: Louisiana Hospital Disclosed Hackers Accessed Systems
Hackers accessed the personal data of nearly 270,000 patients in an attempted ransomware attack on Lake Charles Memorial Health System. LCMH thwarted the hackers’ attempt to encrypt its computers and prevented any disruption to patient care, according to spokesperson Allison Livingston. The health care provider’s own security team detected the hack.
Victim: Lake Charles Memorial Health System
Lake Charles Memorial Health System employs more than 2700 full-time, part-time and PRN employees and is the largest health system in the SW Louisiana area.
Reference: HACKERS ACCESSED DATA ON 270K PATIENTS FROM LOUISIANA HOSPITAL SYSTEM IN ATTEMPTED RANSOMWARE ATTACK
Reference: Hackers accessed data on 270,000 patients from Louisiana hospital system in attempted ransomware attack
Incident: Ransomware attack at Copper Mountain Mining Corp.
Copper Mountain Mining Corp. was the target of a ransomware attack on Dec. 27. The attack targeted the IT systems at its Copper Mountain Mine and corporate office. Copper Mountain said it implemented risk management systems, isolated operations, switched to manual processes, and preventatively shut down the mill "to determine the effect on its control system." "There have been no safety or environmental incidents as a result of the attack," the company said.
Victim: Copper Mountain Mining Corporation
In 1884 copper ore was discovered, Copper Mountain operation was created and was officially closed in 1958. The town was abandoned shortly after. In the early 2000s mining was restarted by the Copper Mountain Mining Corporation with projected reserves for a further 21 years of mining.
The Copper Mountain mine, the Company's flagship asset, is located in southern British Columbia.
Reference: Copper Mountain Mining Reports Ransomware Attack
Reference: Thyssenkrupp Hacked, Again!
Reference: ThyssenKrupp reveals data stolen in cyber attack
Reference: ThyssenKrupp secrets stolen in ‘massive’ cyber attack
Incident: Thyssenkrupp System Engineering Group Target of Ransomware Attack
In August 2020, Mount Locker ransomware gang targeted Engineering and Technology giant ThyssenKrupp in what appears to be a data breach. Threat actors gained access to critical HR information and documentation regarding the company’s present and past employees through the ThyssenKrupp Materials group of firms in the United States and Canada.
Mount Locker ransomware operators advertise what seems to be 30 MB of data related to ThyssenKrupp System Engineering group.
Reference: Thyssenkrupp AG issued “Notice of Data Breach”
Incident: Netwalker Ransomware Group Behind Thyssenkrupp Attack in North America
ThyssenKrupp Materials group of companies based in U.S. and Canada were a victim of a ransomware cyberattack. The attack lead to encryption of its servers and employee workstations. On December 28, 2020, were breached by the NetWalker ransomware group.
Reference: ThyssenKrupp suffers ransomware attack for the third time
Incident: Thyssenkrupp Technical Trade Secrets Stolen
Technical trade secrets were stolen from the steel production and manufacturing plant design divisions of ThyssenKrupp AG in cyber attacks earlier n 2016. ThyssenKrupp was the victim of an economical espionage campaign carried out by hackers based in Southeast Asia. The company said the hackers' goals were to breach its network and steal technological know-how and research from its industrial research branches.
Reference: Asian Hackers Stole Technical Trade Secrets from German Steelmaker ThyssenKrupp
Reference: Industrial Giant Thyssenkrupp Again Targeted by Cybercriminals
Incident: Thyssenkrupp Target of Cyberattack
German ThyssenKrupp AG said today that it’s fending off a cyberattack against its Materials Services division and corporate headquarters. The form of attack was not disclosed. The attack is said to have been noticed at an early stage by the company’s cybersecurity staff and efforts are underway to limit the attack and bring it to an end. No other sections of ThyssenKrupp have been affected by the attack.
No cybercriminal group has yet accepted responsibility for the attack.
Victim: Thyssenkrupp AG
Thyssenkrupp AG is an independent group of industrial and technology businesses. Business segments include Materials Services, Industrial Components, Automotive Technology, Steel Europe, Marine Systems, and Multi Tracks. Based in Essen Germany, the businesses employ around 96,000 people.
Reference: German industrial giant ThyssenKrupp targeted in cyberattack
Incident: Marriott Data Hack Compromised 5.2M Guest Records
Marriott International announced that approximately 5.2 million guests could be affected by a recent data breach. Upon discovery, the company disabled the compromised login credentials, immediately began an investigation, implemented heightened monitoring, and arranged resources to inform and assist guests. Marriott also notified relevant authorities and is supporting their investigations.
Reference: 5.2M Guests Affected by New Marriott Data Breach
Reference: Marriott Hotels hacked AGAIN: Two compromised employee logins abused to siphon off 5.2m guests’ personal info
Incident: Marriott System Breach Undetected for 4 Years (2014 to 2018)
The first part of the cyber-attack happened in 2014, affecting the Starwood Hotels group, which was acquired by Marriott two years later. But until 2018, when the problem was first noticed, the attacker continued to have access to all affected systems. On that basis, the ICO said Marriott had failed to protect personal data as required by the General Data Protection Regulation (GDPR)
Information Commissioner's Office (ICO) dined Marriott hotel 18.4 Million pounds for the data breach.
Reference: Marriott Hotels fined £18.4m for data breach that hit millions
Incident: Marriott Hacked Again in 2022
Marriott International Inc. confirmed on Wednesday July 6th that they had suffered a second data breach this year. Initial reports say that attackers stole a total of 20GB worth of data including some sensitive information such as credit card information, confidential business documents, and customer payment information
Marriott is preparing to notify between 300 and 400 individuals about the data breach.
Reference: Marriott Hotels Suffers Second Data Breach in 2022
Incident: Taiwanese Chipmaker ADATA Attacked by Ragnar Locker Gang
The Ragnar Locker ransomware gang published download links for more than 700GB of archived data stolen from chip maker ADATA. A set of 13 archives, allegedly containing sensitive files, have been publicly available at a cloud-based storage service. A total of 1.5TB of data was compromised.
In October 2022 the Ransomhouse gang claimed to have hacked ADATA and published data on leak site. Bleepingcomputer compared the timestamps on the data shared by RansomHouse with the data leaked by Ragnar Locker in June 2021. They found that both sets of stolen data have similar timestamps, with no file being newer than May 2021. ADATA told Bleepingcomputer they were not hacked, and that this is the same data stolen by Ragnar Locker in 2021.
Reference: ADATA denies RansomHouse cyberattack, says leaked data from 2021 breach
Victim: ADATA
ADATA is a Taiwanese memory and storage chip maker.
Reference: ADATA suffers 700 GB data leak in Ragnar Locker ransomware attack
Incident: German Energy System Supplier Hit by Ransonware Attack
On November 10-11, Kisters AG in Germany was hit by a ransomware attack. Kisters AG is a critical infrastructure supplier for energy systems with the potential for downstream compromise. The software provider, which specializes in the energy industry, has shut down the system "to prevent further damage". Their website reports a new IT infrastructure was built. Close to normal operations was resumed by January 12, 2022.
Reference: Hackers cripple IT provider Kisters
Reference: Kisters AG victim of ransomware attack
Victim: Kisters AG
Kisters AG in Germany develops software solutions for the sustainable resource management of energy.
Incident: Hackers Demand $16.7M from Laptop Manufacturer Compal Electronics
Compal Electronics, a Taiwanese original design manufacturer (ODM),suffered a ransomware attack with attackers demanding almost $17M. While the company spokesperson emphasized that Compal is not being blackmailed by the hackers, BleepingComputer confirmed the ransomware attack after they obtained a ransom note used in the attack.
Victim: Compal Electronics
Compal Electronics a Taiwanese original design manufacturer (ODM), handling the production of notebook computers, monitors, tablets and televisions for a variety of clients around the world, including Apple Inc., Alphabet Inc., Acer, Lenovo, Dell, Toshiba, Hewlett-Packard and Fujitsu. It also licenses brands of its clients.
Reference: Laptop maker Compal hit by ransomware, $17 million demanded
Incident: REvil Extorts Apple in Supply Chain Attack
REvil ransomware gang ransomware group attacked Quanta, a Taiwan-based original design manufacturer (ODM). The attackers attempted to pressure Quanta into paying a ransom. When that didn’t work, they turned their attention to Apple by publicly releasing proprietary blueprints for new Apple devices that they had stolen from the tech giant’s business partner. According to the Tor payment page shared with BleepingComputer, Quanta has to pay $50 million until April 27th, or $100 million after the countdown ends.
Apple contracts Quanta to manufacture Apple Watch, Apple Macbook Air, and Apple Macbook Pro.
Victim: Quanta Computer Incorporated
Quanta Computer Incorporated is a Taiwan-based original design manufacturer (ODM) of notebook computers and other electronic hardware. Quanta has a long list of high-profile customers, including Apple, Dell, Hewlett-Packard, Alienware, Lenovo, Cisco, and Microsoft.
Reference: Apple supplier is the latest target of a $50 million ransomware hack
Reference: Apple targeted in $50 million ransomware attack resulting in unprecedented schematic leaks
Incident: REvil Demands $50Million Ransomware from Acer Electronics
The Sodinokibi/REvil ransomware gang has reportedly infected Taiwanese multinational electronics corporation Acer and demanded a ransom of $50 million. Those responsible for the Sodinokibi ransomware strain announced on their data leaks website that they had breached the computer giant.
This was the largest ransom ask made to date—many more times higher than what the Conti gang wanted from IoT manufacturer Advantech in November 2020.
Reference: Computer giant Acer hit by $50 million ransomware attack
Incident: Bay & Bay, a MN medium-sized Trucking Company, Pays “Five-Figure” Ransom
On July 12, 2018, Bay & Bay was hit with a variant of the SamSam ransomware “I Apologize”. The attack locked up the servers and desktop computers and demanded payment to decrypt those critical systems. Bay & Bay’s IT staff initially attempted to restore its systems, but the process suddenly stopped as an active hacker thwarted their efforts and backup points started disappearing right before their eyes. After consulting with numerous cybersecurity experts, contacting a legal firm and even speaking with the FBI, Bay & Bay decided the best course of action was to pay the ransom. Bay & Bay was able to recover 98% of its information, and forensic analysis showed that none of its data was stolen or transferred off-site.
Reference: Lack of driver training in cybersecurity ‘a gap waiting to be exploited’
Reference: Cybercrime: Yes, It Can Happen to Your Fleet
Incident: MN Trucking and Logistics Company Hit by Ransomware Attack Again
On December 1, 2021, Bay & Bay Transportation's IT systems started acting up and soon became apparent that malware encrypted data on the company’s systems. The company had been down this road before. A ransomware attack in 2018 crippled its systems and led the company to pay the criminals.
“The good part of it is we have a lot better tools, systems and processes than we did three years ago, but we knew it was bad because the spread was more heinous than the other one,” Wade Anderson, Bay & Bay’s chief information officer, chief technology officer and head of marketing, told FreightWaves. The company was able to return to “90% functionality” within about a day in a half, Anderson said. He credited quick action, training and cloud-based backups with enabling a rapid recovery.
Reference: Minnesota trucking company hit in 2nd ransomware attack
Victim: Bay & Bay Transportation
Bay & Bay is a family-owned trucking and logistics company in Minnesota, USA (est. 1941).
Reference: Bay & Bay hit with Ransomware 2nd time
Victim: Mabanaft – trading division of Marquard & Bahls.
Mabanaft is the trading division of Marquard & Bahls. Its business includes regional trading and wholesaling of petroleum products. The company also operates in the bunkering, service-station and heating oil retail businesses, as well as trading in liquid gas and biofuels. Its annual volume of sales is approximately 18.1 million tons (as at: December 2020)
Marquard & Bahls is a Hamburg-based company that is active in the fields of energy and chemicals and organized as a holding company operating through its subsidiaries Mabanaft, Oiltanking, Skytanking.
Reference: Oiltanking cyberattack larger than thought: Evos was hit in Holland
Incident: Malta Oil Terminal, run by Evos, One of Several European Facilities Hit by a Cyberattack
"Evos said it had suffered delays at its terminals in Terneuzen in the Netherlands, Ghent in Belgium and Malta." The company admitted to having several port terminals hit in multiple countries simultaneously: Terneuzen in The Netherlands; Ghent in Belgium and Birzebbuga in Malta. They only admitted to delays, not a complete shutdown. The Malta facility was acquired from Oiltanking last year, and could be subject to similar vulnerabilities.
Oiltanking Deutschland and Mabanaft, two German oil companies, were also hit by cyberattacks. Unconfirmed reports suggest that BlackCat ransomware may have compromised systems at these recent attacks.
Victim: Evos
Evos offers tank storage services and specializes in storage and handling of liquid chemicals, gases, and oil products.
Reference: Hackers Target Key Fuel-Distribution Firms in Europe
Reference: Malta oil terminal affected by cyber-attack on European facilities
Incident: Ransomware Attack halts Operations at Mizuno Sports Brand.
Ransomware attack at Mizuno affected order processing and caused shipping delays of over a month. The IT outages also affected Mizuno's 'Direct Connect' B2B website used by resellers to place orders. The company is tight lipped on details. Information instead has come from anonymous sources and others investigating reports on the incident.
Victim: Mizuno
Mizuno is a Japanese sports equipment and sportswear company with over 3,800 employees and locations throughout Asia, Europe, and North America.
The company sells a wide variety of sports equipment but are best known for their golf clubs, running sneakers, and baseball gear.
Reference: Sports brand Mizuno hit with ransomware attack delaying orders
Reference: Ransomware: The key lesson Maersk learned from battling the NotPetya attack
Reference: Cyberattack: Ransomware hits Jawaharlal Nehru port operations in Mumbai
Incident: Ransomware Attack Cripples Indian Port Container Terminal JNCPT
Jawaharlal Nehru Port Container Terminal was hit by a suspected ransomware attack. JNPCT operations are down and they are unable to process containers. Vessels were diverted and JNPCT stopped accepting ships for loading/unloading at the port.
JNPCT is owned and operated by the port authority, while the other terminals are private. This mirrors a NotPetya attack that occurred at the Gateway Terminal India (GTI) terminal at the same port, owned by Danish AP Moller-Maersk (APM), in 2017. At the time, 17 APM terminals around the world were hit simultaneously.
Reference: Ransomware attack hits Nhava Sheva container terminal
Reference: India’s Jawaharlal Nehru Port Container Terminal hit by cyberattack
Victim: Jawaharlal Nehru Port Container Terminal (JNPCT – JNPT)
State operated Jawaharlal Nehru Port Container Terminal (JNPCT) at the Jawaharlal Nehru Port Trust (JNPT) [a.k.a. Nhava Sheva port] in India
JNPCT began operations in 1989. It was designed with a quay length of 680 metres and an annual capacity of about 1.5m teu, but saw major liners and consortia migrating to private terminals in large part for productivity reasons, and so has seen its capacity utilisation levels sequentially fall in recent years. The public terminal ended fiscal year 2020-22 with some 544,000 teu, according to port data.
Incident: Acuity Brands Data Purloined
Lighting and building management company, Acuity Brands, said it ended up hit by two data breaches over the past two years, and it appears it is just now getting around to informing the public and workers.
Atlanta, Georgia-based Acuity Brands said it identified a data security incident one year ago and it immediately took steps to secure its systems, and hired a third-party cybersecurity firm to conduct a thorough investigation.
Acuity discovered evidence of an unauthorized access that occurred on October 6 and October 7, 2020, which included an attempt to copy certain files out of its network.
Reference: Lighting Firm Hit In 2 Separate Attacks
Incident: Acuity Brands Hit in Cyber Attack
Lighting and building management company, Acuity Brands, said it ended up hit by two data breaches over the past two years, and it appears it is just now getting around to informing the public and workers.
Atlanta, Georgia-based Acuity Brands said it identified a data security incident one year ago and it immediately took steps to secure its systems, and hired a third-party cybersecurity firm to conduct a thorough investigation.
“The investigation determined that an unauthorized person obtained access to some of Acuity’s systems on December 7 and December 8, 2021, and copied a subset of files out of its network during that time,” Acuity said in an advisory.
The files involved in the December 2021 incident may have included the name, Social Security number, and enrollment and claims information related to current and former employees’ participation in Acuity’s health plan. In addition, the information in the files may have included the name, driver’s license number, financial account information, and limited health information related to other aspects of an individual’s employment with Acuity, such as injury information related to workers compensation claims or related to requests for leave under the Family and Medical Leave Act. The types of information in the files were not the same for all individuals
Reference: Lighting Firm Hit In 2 Separate Attacks
Victim: Acuity Brands
Acuity Brands is a lighting and building management company.
Incident: Ransomware Attack for Cloud Provider, Rackspace
Cloud computing provider Rackspace said Tuesday morning a ransomware attack is behind its ongoing Hosted Exchange outage that started early Friday morning.
“As you know, on Friday, December 2nd, 2022, we became aware of suspicious activity and immediately took proactive measures to isolate the Hosted Exchange environment to contain the incident,” the company said in an update to the initial incident report. “We have since determined this suspicious activity was the result of a ransomware incident.”
The investigation, led by a cyber defense firm and Rackspace’s own internal security team, is in its early stages and is still investigating if any data ended up purloined.
Reference: Cloud Provider Hit In Ransomware Attack, Expects Losses
Victim: Rackspace Technology
San Antonio, Texas-based cloud service provider.
Incident: Belarus Rail Network disrupted by Hacktivist Group
Second reported attack on Belarus Rail, this time with OT consequences. Hacktivist group "Cyber Partisans" disrupted routing and switching by hacking into computers controlling the rail network, halting trains in Minsk, Orsha and Osipovichi. They did this to slow troop movements into Ukraine, who are transiting from Russia through Belarus to support the Russian invasion which began 4 days prior.
Impact: Rail routing and switchgear disabled, trains in Minsk, Orsha, and Osipovichi stopped.
Threat Actor: Cyber-Partisans
Cyber Partisans (Belarusian: кіберпартызаны, romanized: kiberpartyzany, Russian: киберпартизаны, romanized: kiberpartizany) is a Belarusian decentralized anonymous hacktivist collective emerged in September 2020, known for its various cyber attacks against the authoritarian Belarusian government.
Reference: Hackers say they encrypted Belarusian Railway servers in protest
Reference: Belarus Hackers Allegedly Disrupted Trains to Thwart Russia
Victim: Belarus Railway
Belarus Railway
Incident: Dairy Plant Operations Offline; No Milk at Schools in New England
H.P. Hood Dairy said Friday that it was the target of a “cyber security event,” that forced it to temporarily shut its 13 dairy plants around the country this week. The closures meant Hood had to get rid of some dairy products, and the company warned there could be delivery delays for some customers as Hood’s facilities get “back up and running.”
HP Hood LLC took all operational systems at their plants (13) offline. As a result, they were unable to receive raw materials or produce milk and other alternative products. The cyberattack affected school lunch programs throughout New England.
Reference: ConVal School District to be Impacted by Milk Shortage Due to Cyber Attack at Dairy Supplier
Reference: Hackers hit Hood. Dairy shut down milk production this week after ‘cyber security event.’
Victim: HP Hood LLC
HP Hood LLC is an American dairy company based in Lynnfield, Massachusetts. Hood was founded in 1846 in Charlestown, Massachusetts, by Harvey Perley Hood. Recent company acquisitions by HP Hood have expanded its reach from predominantly New England to the broader United States. Today, the company has an annual sales revenue of about $2.7 billion.
Incident: Ransomware Attack Paralyses Greek Postal Services
Ransomware hit ELTA encrypting its systems and halting operations in a major service disruption. "Threat actors exploited an unpatched vulnerability to drop malware that allowed access to one workstation using an HTTPS reverse shell." To stop the spread, they shut down all data centres. Online parcel tracking and labelling is also down for customers. Full service was restored by April 6th.
Impact: Ransomware halted all mail, financial transactions and bill payments thru the national carrier
Reference: Greece’s national postal service restoring systems after ransomware attack
Victim: Greece – Postal Services
ELTA, the state-owned provider of postal services in Greece
Reference: Greece’s public postal service offline due to ransomware attack
Incident: Complete State Postal System Outage in Bulgaria
A major Russian-originated ransomware attack occurred on the Bulgarian State Post Office system. Six hours passed between the beginning of their attack and the moment when the servers were turned off and the system's connection to the Internet was cut off. During this time, hackers had access to the entire database and were able to encrypt or even delete archives Hackers moved laterally into all IT and OT systems affecting all 26 services offered.
Besides affecting systems for payment and transfer of money, pensions, etc, the sending and receiving of post, domestic and international was interrupted for weeks. After a time, post could be received but only if the recipient did not owe amounts at time of delivery.
Reference: Poor cyber defense and delayed reaction to hacking have led to massive damage to Bulgarian Posts
Reference: The Work of Bulgarian Posts remains Blocked for Two Weeks
Victim: Bulgarian State Post Office
Post Office - Bulgaria
Reference: Boeing hit by WannaCry virus, but says attack caused little damage
Incident: Cyberattack attack at Boeing Subsidiary Causes Widespread Flight Disruptions
Jeppesen, a wholly-owned Boeing subsidiary that provides navigation and flight planning tools, confirmed on Thursday that it is dealing with a cybersecurity incident that has caused some flight disruptions. Receipt and processing of so-called notice to air missions, which inform pilots and airlines about potential hazards during flights, have also been impacted. Flying with an expired GPS or inaccurate navigation data can be dangerous.
Boeing has declined to comment on what caused the cyberattack or the full scope.
Reference: Cyber Incident Impacts Boeing Subsidiary Jeppesen’s Flight Planning Tools
Victim: Jeppesen
Jeppesen is an American company offering navigational information, operations planning tools, flight planning products and software.
Jeppesen's aeronautical navigation charts are often called "Jepp charts" or simply "Jepps" by pilots, due to the charts' popularity.
Incident: Check-in Systems Offline for Days at Sunwing Airlines
Sunwing Airlines CEO, Mark Williams, revealed that the system the airline uses for check-ins and boarding was “breached” over the Easter long weekend. “A system that is up and running all the time, which never fails, was hacked,” Williams told CP24.
After 5 days, delays still occurring as service is restored. Williams told CP24 that due to the sensitive information that might have been breached, government agencies want to ensure that the breach has been remediated before resuming operations.
188 flights, thousands of passengers stuck and delayed when check-in systems taken offline, for 5+ days.
PAX reports the company targeted by the cyber attack was Illinois-based Airline Choice, which provides airline check-in and passenger security solutions.
Reference: Cyber attack on Boeing subsidiary behind Sunwing outage
Victim: Sunwing Airlines Inc.
Canadian low-cost airline.
Reference: Cyber-Attackers Hit Sunwing Airlines
Reference: Sunwing technical issue continues to disrupt travel plans for thousands of passengers
Incident: AlphV Ransomware Gang attacks Canadian Defense Contractor
On May 31, 2022, CMC Electronics (CMC) identified that an unauthorized third-party had gained access to their computer network and disrupted operations in connection with a ransom demand. They proactively took steps to shut down network to protect systems and data. AlphV ransomware claimed responsibility on their site.
Procurement records show CMC has done millions in work for the Canadian Armed Forces, chiefly in aerospace engineering and research and development — approximately $19.5 million since 2011, according to DND.
The majority of the contracts (66) were for research and development or engineering services.
According to the FBI, AlphV, also called BlackCat, had compromised at least 60 organizations worldwide as of March 2022..
Victim: CMC Electronics
CMC Electronics is a Canadian avionics manufacturer. CMC has three primary operating business units: Navigation Systems, Cockpit System Integration, Panels and Sensors. It has an approximate 50/50 split between commercial and military sales.
Reference: News Alert: Canadian national defence contractor victim of cyberattack
Reference: National Defence looking at potential ‘impacts’ after cyberattack on military contractor
Reference: Canadian military provider suffered ransom attack, says news report
Incident: Millions of Yodel Customers in UK Face Parcel Delivery Delays
Yodel, a UK courier service was hacked forcing systems to shut down. Critical operating systems including delivery tracking, customer service helpline and apps used by drivers were all affected, The Sun reports. Experts at the National Crime Agency were brought in to assist. Experts believed it was a ransomware attack but this has not been confirmed at this time.
A source close to Yodel told The Sun: "It's a complete disaster, the hack has affected every digital part of the business. Nobody is getting a parcel anytime soon."
Reference: YODEL HACKED: Millions of customers face parcel delays after delivery service hit by cyber attack
Reference: Yodel parcel company confirms cyberattack is disrupting delivery
Victim: Yodel
U.K.-based delivery service company
Threat Actor: Predatory Sparrow
Some say their name is a play on “Charming Kitten”, the name of the notorious Iranian APT (advanced persistent threat) group. Although Predatory Sparrow has their own social media accounts, these are not searchable under their English nom but under its Persian equivalent, Gonjeshke Darande.
At this point (July 2022) no one knows whether Predator Sparrow is a state-sponsored group. Are they just mere hacktivists out to punish corporations they see are crossing the line?
Reference: Predatory Sparrow massively disrupts steel factories while keeping workers safe
Victim: Hormozgan Steel Company (HOSCO)
Hormozgan Steel Company (HOSCO) - state operated Iranian steel plant.
Victim: Mobarakeh Steel Company (MSC)
Mobarakeh Steel Company (MSC), Iranian steel plant.
Incident: Ransomware Attack Cripples Printing Systems at German Newspaper
Attack at German newspaper ‘Heilbronn Stimme’ impacted the entire Stimme Mediengruppe media group, which includes the companies ‘Pressedruck’, ‘Echo’, and ‘RegioMail.’ The newspaper published Saturday's 28-page issue in e-paper format after a Friday ransomware attack crippled its printing systems. Phone and email communication remained offline during the weekend. Ransomware attack encrypted all systems.
The regional publication has a circulation of about 75,000 copies, but due to printing issues has temporarily lifted the paywall from its website, which counts approximately 2 million visitors per month.
Reference: Cyber attack on the Heilbronn voice
Reference: Ransomware attack halts circulation of some German newspapers
Victim: Stimme Mediengruppe
Stimme Mediengruppe media group includes the companies ‘Pressedruck’, Heilbronner Voice', ‘Echo’, and ‘RegioMail,
Incident: RansomEXX Attacks CNT Telecommunications in Ecuador
Ecuador's state-run Corporación Nacional de Telecomunicación (CNT) has suffered a ransomware attack that has disrupted business operations, the payment portal, and customer support.
BleepingComputer has learned that the attack was conducted by a ransomware operation known as RansomEXX. Additionally the site reported they contacted CNT with further questions but 'have not received a response at this time."
Victim: Corporación Nacional de Telecomunicación (CNT)
CNT is Ecuador's state-run telecommunication carrier that offers fixed-line phone service, mobile, satellite TV, and internet connectivity.
Reference: Ecuador’s state-run CNT telco hit by RansomEXX ransomware
Incident: Texas DOT Operations Affected by Ransomware Attack
A ransomware attack affected the Texas government as hackers got into the network of the state’s Department of Transportation (TxDOT).
TxDOT is responsible for air, road, and railway transportation across Texas.
TxDOT said that it detected the attack on May 14, after finding unauthorized access to the agency’s network. Further examination determined that the event was part of a ransomware incident. Immediate action was taken to isolate affected computers from the network and block further unauthorized access. It is unclear how many systems are impacted.
UPDATE: the ransomware used was later identified as RansomEXX.
Victim: Texas Department of Transportation
TxDOT is responsible for air, road, and railway transportation across Texas. This includes the construction and maintenance of the state highway systems and traffic cameras.
Reference: Ransomware attack impacts Texas Department of Transportation
Incident: Ransomware Attack Disrupts Tyler Technologies’ Operations.
Leading government technology services provider Tyler Technologies has suffered a ransomware attack that has disrupted its operations.
Bleepingcomputer reports that local government employees were told by MISAC (Municipal Information Systems Ass.) that Tyler Technologies suffered a ransomware attack affecting their phone ticketing system and support systems.
Victim: Tyler Technologies
Tyler Technologies is one of the largest U.S. software development and technology services companies dedicated to the public sector. With a forecasted $1.2 billion in revenue for 2020 and 5,500 employees, Tyler Technologies provides technical services for local governments in many states in the USA.
Reference: Government software provider Tyler Technologies hit by ransomware
Incident: Konica Minolta hit by RansomEXX
Business technology giant Konica Minolta was hit with a ransomware attack at the end of July. It started with customers reporting that the company's product supply and support site was not accessible. The attack impacted services for almost a week. Some Konica Minolta printers were also displaying a 'Service Notification Failed' error.
BleepingComputer reported a source shared a copy of the ransom note used in the attack and reported devices in the company were encrypted. The ransom note belongs to RansomEXX.
Victim: Konica Minolta
Konica Minolta is a Japanese multinational business technology giant with almost 44,000 employees and over $9 billion in revenue for 2019. The company offers a wide variety of services and products ranging from printing solutions, healthcare technology, to providing managed IT services to businesses.
Reference: Business technology giant Konica Minolta hit by new ransomware
Incident: RansomEXX Claims Attack on Taiwanese Computer Manufacturer
Taiwanese motherboard maker Gigabyte has been hit by the RansomEXX ransomware gang. The ransomware gang threaten to publish 112GB of stolen data unless a ransom is paid. The attack forced the company to shut down systems in Taiwan. The incident also affected multiple websites of the company, including its support site and portions of the Taiwanese website.
Victim: Gigabytes Technologies
Gigabyte, Taiwan, is best known for its motherboards, but also manufactures other computer components and hardware, such as graphics cards, data center servers, laptops, and monitors.
Reference: Computer hardware giant GIGABYTE hit by RansomEXX ransomware
Reference: RansomEXX claims ransomware attack on Sea-Doo, Ski-Doo maker
Incident: Trains Stop for Danish Train Operator DSB
A breakdown of Denmark’s train network last weekend was the result of a hacker attack on an IT subcontractor’s software testing environment, Danish train operator DSB said.
“We were contacted by our subcontractor who told us that their testing environment had been compromised by criminal hackers,” DSB’s chief of security, Carsten Dam Sonderbo-Jacobsen, told public broadcaster DR.
“It hasn’t targeted infrastructure or DSB, it was economic crime,” Sonderbo-Jacobsen said in a Reuters report, adding it was not clear who was behind the attack, but that investigations were ongoing.
Reference: Trains Halted In Denmark After Cyberattack
Victim: DSB Train Operator
Trains throughout Denmark stopped running in the morning on Oct. 29 and only started running again at 1 p.m. and DSB said it expected regional and long-distance trains would not run fully until the next day, October 30.
Incident: Continental Auto Group Hit in Attack
German multinational automotive group Continental suffered a cyberattack back in August and while the company said it successfully avert the assault, a ransomware group is now threatening to divulge information it said it stole during the hack.
In an August 24 statement, Continental said “in a cyberattack, attackers infiltrated parts of Continental’s IT systems. The company detected the attack in early August and then averted it. Continental’s business activities have not been affected at any point.
UPDATE: German business newspaper Handelsblatt reported in early November that the hackers had stolen around 40 terabytes of data from the company. The FBI is also involved in the investigation. Continental did not provide any information on the possible economic consequences in the statement. The reason for the lengthy internal investigations is partly due to the extent of the data leak. The company must analyze more than 55 million file entries from the list in the darknet.
The theft was said to include sensitive data from customers such as Volkswagen Group, information on supervisory board meetings and correspondence from chief controller Wolfgang Reitzle.
Reference: LockBit ransomware claims attack on Continental automotive giant
Reference: Continental Auto Group Cyberattack Continues
Victim: Continental
German multinational automotive group.
Reference: Copper Smelter Hit In Cyberattack
Incident: Overly Delayed Disclosure of Ransomware Attack at Australian Clinical Labs
On October 31, Australian Clinical Labs (ACL) disclosed a February 2022 data breach that impacted its Medlab Pathology business. The breach exposed the medical records and other sensitive information of 223,000 people.
Quantum ransomware gang took responsibility for the attack. 86GB stolen files were uploaded on its Tor site on June 14, 2022. Leaked data included patient and employee details, financial reports, invoices, contracts, forms, subpoenas, and other private documents. According to Quantum ransomware’s website, the data leak page for MedLab has been accessed 130,000 times.
Victim: Australian Clinical Labs (ACL)
ACL is an Australian healthcare company that operates 89 laboratories and performs six million tests annually, offering its services to 92 private and public hospitals across Australia.
Reference: Pathology company Australian Clinical Labs reveals it was hit by cyber attack in February
Reference: Australian Clinical Labs says patient data stolen in ransomware attack
Threat Actor: Black Reward
A group of anti-Iranian government hackers.
Incident: Cyberattack at Iranian Nuclear Power Plant
The Iranian Atomic Energy Organization (AEOI) has confirmed that one of its subsidiaries' email servers was hacked after the ''Black Reward' hacking group published stolen data online. AEOI says an unauthorized party from a specific foreign country, which is not named, stole emails from the hacked server, which consisted of daily correspondence and technical memos. The agency says it immediately took the necessary preventive measures to mitigate the results of this incident and informed all concerned parties and officials to be prepared for potential exploitation attempts.
The hacker group responsible for the attack calls itself 'Black Reward' and has leaked some of the stolen data on their Telegram channel. Black Reward posted a 27GB 14-part collection of RAR archives allegedly containing 85,000 email messages characterized as "perfect for researchers." The hackers' message is signed "For women, life, freedom," giving the email server breach and data leak action the character of hacktivism.
Victim: Iranian Atomic Energy Organization (AEOI)
(AEOI)
Reference: Iran’s atomic energy agency confirms hack after stolen data leaked online
Reference: Toyota’s Supply Chain Cyber Attack Stopped Production, Cutting Down a Third of Its Global Output
Incident: Major German Regional Energy Company Hit by Cyberattack
Enercity, one of Germany’s largest municipal energy suppliers, confirmed it was targeted by a cyberattack on Wednesday morning. The Hannover-based company said its security systems “reacted immediately” and that “greater damage to the company” has been averted. Enercity confirmed that it would continue supplying energy to customers, explaining its operational technology and critical infrastructure was not affected. “Our grids and power plants are stable and the security of supply is guaranteed,” the company stated. However the attack has impacted customer service, which has limited availability. The company added: “Not all IT systems can currently be used to their full extent, which means that they may be minor restrictions.”
Victim: Enercity AG
Enercity AG is one of Germany’s largest municipal energy suppliers, based in Hannover.
Reference: Major German energy supplier hit by cyberattack
Incident: Apparently Unsuccesful Cyberattack at Arvig Communications.
Arvig experienced a network-wide service outage affecting nearly all of its customers statewide. Beginning at approximately 6:45 a.m., internet, television and most voice services unexpectedly went down. The outage was the result of an apparently unsuccessful cyberattack. The threat was eliminated and services were restored within a matter of hours. 'Though our investigation of this matter is still in its early stages, to our knowledge at this time, no customer data was exposed, accessed or lost as a result of this attack." Arvig said in a statement.
Victim: Arvig
Arvig is a Minnesota employee-owned Telecommunications Company that has been providing homes and businesses with high-speed cutting-edge products and services since 1950.
Reference: Arvig service shutdown on Tuesday was due to a cyber attack
Incident: BRP Suspends Operations Following Ransomware Attack
The Quebec-based company, which makes snowmobiles, personal watercraft and all-terrain vehicles, said it had been the target of “malicious computer activity” and had taken “immediate steps to contain the situation.” BRP (formerly Bombardier Recreational Products) said it has hired cybersecurity experts to help secure its systems and support an internal investigation. Suspending operations could delay some transactions with customers and vendors, BRP said.
BRP provided an update on the situation on August 15: "The Company confirms that the malware infiltration came through a third-party service provider. BRP believes that the impact of the cyberattack was limited to its internal systems." "The evidence collected so far allows BRP to believe that the impact of this incident from a data privacy perspective should be limited. "
Victim: Bombardier Recreational Products (BRP)
BRP (formerly Bombardier Recreational Products) is a Quebec-based company which makes snowmobiles, personal watercraft and all-terrain vehicles. BRP employs nearly 20,000 workers, primarily in manufacturing and distribution facilities in Mexico, Canada, Austria, the United States, Finland and Australia. Its products are sold in more than 120 countries.
Reference: BRP PROVIDES INFORMATION ON DATA LEAK
Reference: Operations at vehicle maker BRP remain suspended days after cyberattack
Incident: World’s Largest Copper Smelter Largely Maintains Operations after Cyberattack
Aurubis, Europe's largest copper smelting company, sustained a cyberattack. The company believes it was targeted as part of a larger campaign against the metals sector. It responded by shutting down certain IT systems and isolating them from the Internet. Its core industrial processes have continued to function. "The production and environmental protection facilities at the smelter sites are running, and incoming and outgoing goods are also being maintained manually," Aurubis said. "Transitional solutions are being implemented to make the company's full services available to business partners again starting next week. Customers and suppliers can still reach their Aurubis contacts by phone."
Reference: Largest EU copper producer Aurubis suffers cyberattack, IT outage
Victim: Aurubis AG
Aurubis AG is listed on the stock exchange and is the largest copper producer in Europe and the largest copper recycler worldwide. Its headquarters is in Hamburg, Germany. Aurubis has 6,900 employees worldwide, and produces one million tonnes of copper cathodes yearly.
Reference: Aurubis says it was hit in wider cyberattack on metals industry
Malware: Agenda
Agenda Ransomware is a new ransomware strain written in the Golang language "Malware written in the Go language (aka Golang) has become common among threat actors, one possible reason for this uptick in popularity is that Go statically compiles necessary libraries, making security analysis much harder."
It targets educational and healthcare institutions in countries like Saudi Arabia, Thailand, Indonesia, and South Africa. Trend Micro researchers said, "Agenda can reboot systems in safe mode, attempts to stop many server-specific processes and services, and has multiple modes to run."
Threat Actor: Qilin
Qilin (or the Agenda ransomware group) offers affiliates options to customize configurable binary payloads for each victim, including details such as company ID, RSA key, and processes and services to kill before the data encryption. Additionally, the ransom amount requested is different per company, ranging from US$50,000 to US$800,000.
Incident: Ransomware Attack on ForceNet Communication Platform used by Australian Military
Hackers attacked ForceNet's communications platform used by Australian military personnel and defense staff. The ForceNet service is run by Dialog Information Technology. The Australian Dept. of Veteran Affairs' website states: "Defence has announced that it has been informed that an external ICT service provider which facilitates ForceNet has been subject to a ransomware attack. ForceNet is a Defence e-communications platform used to connect registered users within secure online communities. To be clear, this is not an attack on Defence ICT"
ITWire in Australia reports on 31 October that Dialog was hit by an attack which used the Agenda ransomware that runs only on Windows. The group behind the attack, Qilin, announced it on the dark web on 19 September.
This is the 9th attack in little over a month, affecting Australia's biggest companies, likely exposing the details of millions of customers.
Reference: Ransomware attack on Dialog also took down defence app ForceNet
Reference: Ransomware hackers hit Australian defense communications platform
Victim: Dialog Information Technology
Dialog Information Technology, owned by Singtel, is one of Australia's leading technology services organizations trading nationally from offices in Brisbane, Sydney, Canberra, Melbourne, Adelaide, Perth and Darwin. Established in 1979, Dialog employs over 1,200 IT specialists. Among Dialog's customers in Australia are the Australia Defense Department, NSW Electoral Commission, the Department of Human Services, Queensland Health, Virgin Australia, NAB, Suncorp, Alfred Health, University of Tasmania, and Rio Tinto. The company was bought by Singtel in April 2022 for $325 million.
Incident: Blackbyte Group Claims Compromising Precious Metal Manufacturer in HongKong demanding $1.1M
The BlackByte ransomware group claims to have compromised Asahi Group Holdings, a precision metal manufacturing and metal solution provider. The BlackByte ransomware group claims to have stolen gigabytes of documents from Asahi Group Holdings, including financial and sales reports. The ransomware gang is demanding 500k$ to buy data and 600k$ to delete the stolen data.
Victim: Asahi Holdings / ARE Holdings, Inc.
Asahi Holdings / ARE Holdings, Inc. is a precision metal manufacturing and metal solution provider. Founded in the 1970s in Hong Kong, the company has been delivering end-to-end services in the industries of precision metals and thin-film coatings to renowned multinational corporations in Europe and the US.
Reference: BlackByte ransomware group hit Asahi Group Holdings, a precision metal manufacturing and metal solution provider
Incident: Canada Post Customers Affected by Ransomware Attack at Supplier
Canada Post disclosed that a third-party supplier named Commport Communications suffered a ransomware attack where threat actors accessed data stored in their systems. This accessed data includes shipping manifest data for large parcel business customers, including sender and receiver contact information, names, and mailing addresses.
In total, the breach affected 44 Canada Post commercial customers and 950,000 receiving customers.
Victim: Commport Communications
Commport Communications, est. 1985, provides a wide range of innovative and comprehensive supply chain management solutions for Electronic Commerce (EC). This includes Electronic Data Interchange (EDI), Value Added Networks (VAN), and Global Data Synchronization Networks (GDSN).
Threat Actor: Lorenz ransomware gang
Lorenz is a ransomware gang targeting the enterprise. A new ransomware operation known as Lorenz targets organizations worldwide with customized attacks demanding hundreds of thousands of dollars in ransoms.
The Lorenz ransomware gang began operating in April 2021, and has since amassed a growing list of victims whose stolen data has been published on a ransomware data leak site
The Lorenz ransomware gang may have a link to the ThunderCrypt operators. The Lorenz gang began operating last month. Since then, the group has developed a notable list of victims. A data leak site houses victims’ stolen and exposed data.
It is not clear if Lorenz is the same group or purchased the ransomware source code to create its own variant.
Like other human-operated ransomware attacks, Lorenz will breach a network and spread laterally to other devices until they gain access to Windows domain administrator credentials. While spreading throughout the system, they will harvest unencrypted files from victims' servers, which they upload to remote servers under their control. This stolen data is then published on a dedicated data leak site to pressure victims to pay a ransom or to sell the data to other threat actors.
Victim: Canada Post
Canada Post is the primary postal operator in Canada, serving 16.5 million Canadian residential and business addresses.
Reference: Canada Post hit by data breach after supplier ransomware attack
Incident: Cyberattack at Large Global Cookware Distributor Affects 1000’s of Employees
Meyer Corporation, the largest cookware distributor in the U.S. fell victim to a cyberattack on October 25, 2021. In response, the firm launched an investigation that was concluded on December 1, 2021, revealing that threat actors gained access to personal information belonging to employees of Meyer and its subsidiaries.
BleepingComputer reports finding a relevant listing on the Conti extortion site dating to November 7, 2021. The Meyer entry on Conti's portal offers a ZIP file containing 2% of the data allegedly stolen by the ransomware gang during the cyberattack. However, the notorious ransomware group hasn’t followed up to publish the remainder 98% in the months that followed.
Reference: Cookware giant Meyer discloses cyberattack that impacted employees
Victim: Meyer Corporation
Meyer Corporation is a cookware distributor based in Vallejo, California, United States, whose parent company is Hong Kong based Meyer Manufacturing Co. Ltd. It is the largest cookware distributor in the United States and second largest in the world. Cookware lines are stainless steel, hard-anodized aluminum, and non-stick aluminum.
Reference: Ubiquiti cyberattack may be far worse than originally disclosed
Reference: Networking giant Ubiquiti alerts customers of potential data breach
Reference: Massy Stores investigates cyber attack information leak
Incident: Drone Cyberattack at US Financial Firm
Modified off-the-shelf drones carried wireless network-intrusion kit to the rooftop of a US East Coast financial firm and hacked into the network. The financial firm spotted unusual activity on its internal Atlassian Confluence page that originated from within the company's network. The incident, that occurred during the summer in '22, was not widely reported.
The story was recently recounted by security researcher, Greg Linares. The Register corresponded with an individual affiliated with the affected company who corroborated the incident.
(The individual asked not to be identified owing to a non-disclosure agreement and employment concerns.)
Reference: How Wi-Fi spy drones snooped on financial firm
Incident: Lockbit Ransomware Gang Say Japan Hospital Paid $30K Ransom
Russian hackers claim a Japanese hospital paid $30,000 to regain access to electronic medical records. The records were encrypted in a ransomware attack last October, causing major disruption to the medical institution's operations.
At the time of the Oct. 31 attack, Handa Hospital refused to pay the ransom. The hospital said it will build a new electronic medical record system at a cost of 200 million yen.
The town of Tsurugi, which runs the targeted Hospital, has denied paying ransom money. Experts suspect that an IT firm involved in attempts to restore access to the records secretly reached a deal with the hackers.
Japanese police have been urging those targeted in ransomware attacks to not pay money demanded of them.
Victim: Handa Hospital
Handa Hospital is located in Tsurugi, Tokushima. Handa Hospital is a general hospital with 120 beds, visited by around 250 to 300 patients every weekday.
Reference: Russian hackers say Japan hospital paid $30,000 in ransomware attack
Incident: Michigan IT Service Provider Victim of Ransomware Attack
A ransomware attack took place recently against the Midland Information Technology Consortium (MiTCON). Midland Police Department, along with other law enforcement agencies, is conducting an investigation. The attack affected its clients' internet and email services as well as phone lines. The MiTCON team quickly contained the threat and has been working diligently to bring back services for its clients.
Victim: Midland Information Technology Consortium – MiTCON
MiTCON is an IT provider serving 85 non-profit organizations and small businesses with 800 computers in the Great Lakes Bay Region in MIchigan, US, that is a wholly owned subsidiary of the Midland Business Alliance. It is a wholly-owned subsidiary of the Midland Business Alliance.
Reference: Police Investigating Ransomware Attack Against Tech Consortium
Threat Actor: Daixin Team
Since June 2022, Daixin Team attackers have been linked to multiple health sector ransomware incidents where they've encrypted systems used for many healthcare services, including electronic health records storage, diagnostics, imaging services, and intranet services.
They're also known for stealing patient health information (PHI) and personal identifiable information (PII) and using it for double extortion to pressure victims into paying ransoms under the threat of releasing the stolen information online.
The ransomware gang gains access to targets' networks by exploiting known vulnerabilities in the organizations' VPN servers or with the help of compromised VPN credentials belonging to accounts with multi-factor authentication (MFA) toggled off. Once in, they use Remote Desktop Protocol (RDP) and Secure Shell (SSH) to move laterally through the victim's networks.
Incident: Jordanian Company Data Compromised in LV Ransomware Attack
A recent intrusion, performed by an LV group affiliate, involved the compromise of the corporate environment of a Jordan-based company. In this incident, the attackers used the double-extortion technique to blackmail their victims, threatening to release allegedly stolen data in addition to encrypting the victim’s files.
Reference: LV Ransomware Exploits ProxyShell in Attack on a Jordan-based Company
Incident: Cyberattack at Global Wholesale Company METRO
International wholesale giant METRO is experiencing infrastructure outages and store payment issues following a recent cyberattack.
The company's IT team is currently investigating the incident with the help of external experts. Even though its stores are still operating, METRO says that it was forced to set up offline payment systems and that online orders are delayed.
Victim: METRO – MAKRO
METRO is an international wholesale company for customers in the HoReCa (hotel, restaurants, and catering) industry, operating in over 30 countries and employing more than 95,000 people worldwide.
It operates 661 wholesale stores (as of September 30, 2022) under the METRO and MAKRO brands.
Reference: Wholesale giant METRO hit by IT outage after cyberattack
Incident: Hive Ransomware Group Attacks International French Clothing Stores
Damart, a French clothing company is being extorted for $2 million after a cyberattack from the Hive ransomware gang. Damart operates over 130 stores across the world. Operational issues were still reported on Aug. 24, when 92 of its stores were found to be disrupted. Attackers infiltrated its Active Directory, which prompted the encryption of some systems.
The threat actors haven't posted the victim on their extortion site, opting to keep negotiations private. Damart has not engaged in negotiations with the cybercriminals. The company informed the national police of the incident, which makes it unlikely that Hive would receive a payment.
Victim: Damart
Damart, a French clothing company with over 130 stores across the world,
Reference: Damart clothing store hit by Hive ransomware, $2 million demanded
Incident: Hive Ransomware Group Leaks NY Racing Assoc. Data
The Hive ransomware operation claimed responsibility for an attack on the New York Racing Association (NYRA), which previously disclosed that a cyber attack on June 30, 2022, impacted IT operations and website availability and compromised member data, including Social security numbers (SSNs), Driver's license identification numbers, Health records, Health insurance information.
Victim: New York Racing Association – NYRA
NYRA is the operator of the three largest thoroughbred horse racing tracks in New York, namely the Aqueduct Racetrack, the Belmont Park, and the Saratoga Race Course.
Reference: Hive ransomware claims attack on New York Racing Association
Incident: Hive Ransomware Group Attacks Canadian Bell Technical Solutions (BTS)
The Hive ransomware gang claimed responsibility for an attack that hit the systems of Bell Canada subsidiary Bell Technical Solutions (BTS). BTS is currently investigating the incident with the help of the Royal Canadian Mounted Police's cybercrime unit.
Ransomware group Hive has accessed scores of personal information belonging to Bell’s employees, including files relating to finances, recruitment, birthdays, and COVID-19 information, along with other data.
Reference: Hive ransomware claims cyberattack on Bell Canada subsidiary
Victim: Bell Technical Solutions, Canada
Bell Technical Solutions (BTS) is a wholly owned subsidiary of Bell Canada that specializes in the installation of Bell services, including Home Phone, Internet and Fibe TV. With over 6000 employees, BTS operates in the residential and business sectors throughout Québec and Ontario.
Incident: Australian Health Insurance Firm Medibank Hit by Ransomware Attack
Major Australian health insurance provider Medibank Private Limited disclosed being hit by a ransomware attack on October 12. The attack resulted in a temporary service outage, which has since been resolved. The company claim that no systems were encrypted during the attack.
UPDATE 07Nov22: Medibank Says Hacker Accessed Data Of 9.7 Million Customers, Refuses To Pay Ransom
Reference: Australian insurance firm Medibank confirms ransomware attack
Reference: Ransomware attack at Australia’s Medibank confirmed
Victim: Medibank Private Limited
One of the largest Australian private health insurance providers, covering 3.7 million people in 2021
Incident: Aussie Woolworths Online Unit, MyDeal, Suffers Data Breach
Australia’s Woolworths Group Ltd’s majority-owned online retailer MyDeal said a “compromised user credential” ended up exploited Friday to access its systems that left 2.2 million users exposed.
MyDeal’s exposed customer data includes names, email addresses, phone numbers, delivery addresses, and in some instances date of birth of the customers, the Sydney-based retailer said in an advisory.
It further clarified that MyDeal’s website and application were not impacted, and none of the other platforms of Woolworths group were compromised.
Reference: Woolworths’ Online Unit Suffers Breach
Victim: MyDeal
Online retailer, MyDeal, owned 80 percent by the Woolworths grocer in Australia, said it was contacting the affected customers and working with authorities to investigate the incident.
Reference: Tata Power Hit In Cyberattack
Reference: US airports’ sites taken down in DDoS attacks by pro-Russian hackers
Reference: Tata Power, a top power producer in India, confirms cyberattack.
Incident: India’s Largest Integrated Power Company, Tata Power, Hit by Cyberattack
Tata Power, a leading power generation company in India, confirmed it was hit by a cyberattack. In a brief statement released on Friday, the Mumbai-based company said that the attack impacted some of its IT systems.
“The company has taken steps to retrieve and restore the systems. All critical operational systems are functioning. As a measure of abundant precaution, restricted access and preventive checks have been put in place for employee and customer-facing portals and touchpoints,”
Victim: Tata Power Company Limited
Tata Power Company Limited is an Indian electric utility company based in Mumbai, Maharashtra, India and is part of the Tata Group. The core business of the company is to generate, transmit and distribute electricity.
Reference: Tata Power Hit by Cyberattack! This is what happened.
Reference: Hackers leak 500GB of data stolen during ransomware attack
Incident: San Francisco Municipal Transportation Agency Hit by Ransomware
During the Thanksgiving weekend, the San Francisco Municipal Transportation Agency, sometimes called Muni or SFMTA, was the victim of a ransomware attack that affected internal computer systems including email and ticketing. It used backup data to restore most of the affected system in the next few days, minimizing the attack's impact. The hacker's goal was to extort 100 bitcoins ($73,000) from the SFMTA for the release of its systems. SFMTA denied paying the ransom and restored its systems on its own. It reportedly lost up to $50,000 in uncollected fees by the time systems recovered from the attack.
Victim: San Francisco Municipal Transportation Agency – SFMTA
San Francisco Municipal Transportation Agency - SFMTA
Reference: The San Francisco Public Transit Ransomware Attack: What We’ve Learned
Reference: Ransomware Crooks Demand $70,000 After Hacking San Francisco Transport System
Incident: Britain’s Ad Agency WPP Hit by a Cyberattack
Britain’s WPP, the world’s biggest advertising agency, said on Tuesday it had been hit by a cyber attack. WPP Plc’s Chief Executive Officer Martin Sorrell, at a Bloomberg event in Davos half a year later stated: "WPP shut down all its systems when it was hacked and communicated internally on an hourly basis", Sorrell said. Several weeks before WPP has hacked, a WannaCry ransomware attack infected more than 300,000 computers across 150 countries. Microsoft Corp. and others responded quickly by providing software updates, including to WPP, but to no avail, Sorrell said. “Those patches couldn’t stop the malware attack that we had in June".
Reference: WPP’s CEO Provides Insights from His Advertising Firm’s Cyber Attack
Victim: WPP plc
WPP plc is a British multinational communications, advertising, public relations, technology, and commerce holding company headquartered in London, England.
Reference: British ad agency WPP affected by cyber attack
Incident: Household Products Giant Reckitt Benckiser Attacked by NotPetya
Household products giant Reckitt Benckiser has said last month's malware cyber-attack could lead to a permanent loss of revenue. The attack disrupted manufacturing and ordering systems at the company, whose products include Nurofen and Dettol. Although it had "largely contained" the attack, Reckitt said the disruption meant like-for-like revenue growth in the second quarter would be down 2%. It also said it expected to lose "some further revenue permanently"
Victim: Reckitt Benckiser Group plc
Reckitt Benckiser Group plc, trading as Reckitt, is an Anglo-Dutch multinational consumer goods company headquartered in Slough, England. It is a producer of health, hygiene and nutrition products
Reference: Massive cyber-attack could cost Nurofen and Durex maker £100m
Reference: Reckitt Benckiser warns of permanent sales hit from cyber-attack
Incident: Nivea’s parent company, Beiersdorf, Target of NotPetya Attack
German skin care company Beiersdorf said it was a "target" of the cyberattack, which affected its IT and telephone systems. The firm's headquarters in Hamburg, as well as its affiliates around the world, were affected. While Beiersdorf expects sales worth roughly €35 million ($41 million) to be shifted from the second quarter to the third, the company does not expect a material impact on its profits for this year.
Victim: Beiersdorf
Beiersdorf AG is a German multinational company that manufactures and retails personal-care products and pressure-sensitive adhesives.
Its brands include Elastoplast, Eucerin (makers of Aquaphor), Labello, La Prairie, Nivea, Tesa SE and Coppertone.
Reference: Nivea’s parent company shrugs off cyber-attack
Reference: Beiersdorf says global cyber attack hits IT, phone systems
Incident: Saint-Gobain, a Major European Building Supply Maker Suffers NotPetya Cyberattack
French construction giant Saint-Gobain said Thursday, July 13, that it had restored all systems affected by the start of the week after the attack. The company said the attack led to downtime of IT systems and supply chain disruptions and claimed that no personal data had been lost. The NotPetya attack has had a negative impact of €220 million ($258 million) on sales and €65 million ($76 million) on operating income in the first half of 2017. Until the end of the year, total losses are expected to rise to €330 million ($387 million).
Victim: Compagnie de Saint-Gobain S.A.
Compagnie de Saint-Gobain S.A. is a French multinational corporation, founded in 1665 in Paris and headquartered on the outskirts of Paris, at La Défense and in Courbevoie. Originally a mirror manufacturer, it now also produces a variety of construction, high-performance, and other materials.
Reference: Cyber Attack Update
Reference: Cyber Attack Likely Cost Saint-Gobain 1% of First Half Sales
Incident: FedEx TNT Global Operations Disrupted by NotPetya Attack
Operations of FedEx's TNT Express unit in Europe were disrupted by the attack and the company previously warned that the financial cost of the incident was likely to be significant. While no data breach or data loss occurred as a result of Petya, the company previously warned that it may not be able to recover all of the systems affected by the cyber attack. "Most TNT Express services resumed during the quarter and substantially all TNT Express critical operational systems have been restored. However, TNT Express volume, revenue and profit still remain below previous levels," the company said.
Reference: NotPetya cyber-attack cost TNT at least $300m
Victim: FedEx
FedEx Corporation, formerly Federal Express Corporation and later FDX Corporation, is an American multinational conglomerate holding company focused on transportation, e-commerce and business services based in Memphis, Tennessee.
Reference: NotPetya cyber attack on TNT Express cost FedEx $300m
Incident: Hackers Hit Nuance Communications Again 6 Months After NotPetya
A recent SEC filing by the voice and language tool vendor outlined a December cyberattack, which impacted the records of 45,000 individuals. While the company was still working to dig out of the June NotPetya incident, a hacker got into a single transcription platform and accessed the records of 45,000 individuals. Officials said they promptly shut down the platform, and the incident was contained to one platform.
Incident: Nuance Communications Cyberattack Results in $98M Revenue Loss
Nuance Communications, a major voice and language tool vendor, lost $98 million in revenue as a direct result of falling victim to the global NotPetya attack in June 2017, according to a recent Securities and Exchange Commission filing. That number is projected to increase as they move into 2018 to enhance and upgrade its security.
Victim: Nuance Communications
Nuance Communications, Inc. is an American multinational computer software technology corporation, headquartered in Burlington, Massachusetts, that markets speech recognition and artificial intelligence software.
Reference: Hackers hit Nuance again in 2017, while NotPetya cost $98 million in lost revenue
Reference: Nuance says NotPetya attack led to $92 million in lost revenue
Reference: Malware Attack Disrupts Merck’s Worldwide Operations
Reference: Mondelez files $100m claim from Zurich Insurance for NotPetya Cyber Attack
Reference: NotPetya Attack Costs Big Companies Millions
Victim: Ukrenergo – Ukrainian power company
Ukrenergo is an electricity transmission system operator in Ukraine and the sole operator of the country's high-voltage transmission lines.
Reference: Inside the Cunning, Unprecedented Hack of Ukraine’s Power Grid
Reference: Cyberattack cost Maersk as much as $300 million and disrupted operations for 2 weeks
Incident: Hackers Attack Taiwan’s Major Oil Refiner Affecting Customers at the Pump.
Ransomware has struck the computer systems of Taiwan’s state-owned energy company, CPC Corp., according to local media and private forensic reports reviewed by CyberScoop.
Although the attack didn’t affect the company’s energy production, it did disrupt some customers’ efforts to use CPC Corp.’s payment cards to purchase gas.
Reference: Taiwan’s state-owned energy company suffers ransomware attack
Reference: Taiwan’s CPC suffers malware attack, experiences system outage
Victim: CPC Corp, Taiwan
Taiwan's state-owned petroleum and natural gas company, CPC Corp
Incident: Cyberattack Paralyzes Operations at Suffolk County Offices in NY
Since September 8, Suffolk County has been trying to recover from a cyberattack by a ransomware group known as “ALPHV” or “BlackCat.” The attack disabled the county’s 911 system as well as other services. The county reverted to older methods for handling essential county operations, dispatching, and paying bills. Real estate industry was most impacted by the cyberattack. Access was cut off to key records required in property sales transactions.
Victim: Suffolk County, Long Island, NY
Suffolk County government
Reference: “BlackCat” attempts to up the pressure on Suffolk County; starts to leak data?
Reference: Cyber Snafu: Suffolk Ransomware Attack Ripples Across County
Incident: 300 GB of Sensitive Data Breached at Large Swiss Car Dealer
One of Europe's biggest car dealers, Emil Frey, was hit with a ransomware attack last month, according to a statement from the company. The Swiss company showed up on the list of victims for the Hive ransomware on February 1 and confirmed that they were attacked in January. "We have restored and restarted our commercial activity already days after the incident on January 11, 2022," a spokesperson said, declining to answer more questions about whether customer information was accessed.
Reference: Cyber-attack on Emil Frey AG
Victim: Emil Frey Group
The Emil Frey Group is a group of automobile-related businesses in Switzerland.
The company is completely privately owned by the founding family and only publishes very limited business figures. It was ranked as the number 1 car dealership in Europe based on revenue and the total number of vehicles for sale.
Reference: Europe’s biggest car dealer hit with ransomware attack
Incident: Ferrari Confirms Internal Documents Leaked, States No Evidence of Cyberattack.
Luxury car maker Ferrari is denying that it was hit with a ransomware attack after a gang added the company to its list of victims this week. The ransomware group RansomEXX posted to its leak site claiming to have stolen 7 GB of data from the company. The stolen documents allegedly include contracts, invoices, internal company information, repair manuals and more.
In a statement to The Record on Tuesday, a Ferrari spokesperson said it was aware of reports that documents from the company have been leaked online but said it is not dealing with any kind of ransomware attack or cybersecurity incident.
Developing story.
Victim: Ferrari S.p.A.
Ferrari S.p.A. is an Italian luxury sports car manufacturer based in Maranello, Italy.
Reference: Ferrari denies data breach and ransomware attack following gang’s online claims
Reference: RansomEXX ransomware attack refuted by Ferrari
Incident: Cybersecurity Attack at City of Dunedin, Pinellas County, Florida
Florida officials at City of Dunedin, in Pinellas county, discovered a cybersecurity attack on Wednesday October 5. The city is investigating. Dunedin says its Water and Wastewater Treatment Facilities, city phones and social media networks are all secure. As reported by MSN,
these operations are not available: city email, online payments for permits, utility billing, Parks & Recreation programs, inspection scheduling, and Marina fees.
Reference: Cybersecurity attack in the City of Dunedin
Reference: Dunedin email, some web services down after ‘cybersecurity incident’
Victim: Dunedin, Pinellas County, Florida
City of Dunedin, Pinellas County, Florida
Incident: City of Tucson Discloses Data Breach Exposing 123K Individuals
The City of Tucson, Arizona, disclosed a data breach affecting the personal information of more than 123,000 individuals. The threat actors had access to the network between May 17 and May 31. They potentially accessed or stolen documents containing the information of 123,513 individuals.
"On May 29, 2022, the City learned of suspicious activity involving a user's network account credential," the data breach notification reads. "On August 4, 2022, the City learned that certain files may have been copied and taken from the City's network." The City began notifying potentially impacted individuals on September 23. The he attacker potentially accessed files included certain individuals' name, Social Security number, driver's license or state identification number, and passport number.
Victim: City of Tucson
City of Tucson, AZ, USA
Reference: City of Tucson discloses data breach affecting over 123,000 people
Incident: 2nd Singtel Business hit by Cyberattack – Dialog Group’s Data Leaked
The Dialog Group, an Australia-based IT services consulting company, has been hit by a cybersecurity attack. The second Singapore Telecommunications (Singtel) owned business to report a breach in over two weeks. Singtel stated there is no evidence there is any link between this incident and the recent Optus cyberattack. Dialog’s systems are completely independent from NCS, Optus and Singtel.
An unauthorized third party may have accessed company data, potentially affecting fewer than 20 clients and 1,000 current Dialog employees as well as former employees.
Reference: The Dialog Group customers, staff hit by data breach – 2nd Singtel-owned business to report a breach in over two weeks.
Victim: Singapore Telecommunications Limited – Singtel
Singapore Telecommunications Limited, commonly known as Singtel, is a Singaporean telecommunications conglomerate and one of the four major telcos operating in the country. The company is the largest mobile network operator in Singapore with 4.1 million subscribers and through subsidiaries, has a combined mobile subscriber base of 640 million customers at the end of financial year 2017.
Reference: Singtel’s Dialog Group hit by cyber security attack, company data leaked
Reference: CommonSpirit’s ‘IT security incident’ was likely cyberattack, security experts say
Incident: CommonSpirit, a Large US Hospital Chain, Patient Care Impacted by Ransomware Attack.
One of the largest hospital chains in the U.S. was hit with a suspected ransomware attack this week. The attack lead to delayed surgeries, hold ups in patient care and rescheduled doctor appointments across the country. Multiple hospitals were affected, including CHI Memorial Hospital in Tennessee, some St. Luke’s hospitals in Texas, and Virginia Mason Franciscan Health in Seattle.
Reference: Ransomware attack delays patient care at hospitals across the U.S.
Victim: CommonSpirit Health
CommonSpirit Health is the largest Catholic health system, and the second-largest nonprofit hospital chain, in the United States (as of 2019). It operates more than 700 care sites and 142 hospitals in 21 states
Incident: Second Largest US Public School District in CA Hit by Ransomware Attack
A cyberattack prompted an unprecedented shutdown of The Los Angeles Unified School District, the second largest in the nation. The attack sounded alarms across the country, from urgent talks with the White House and the National Security Council after the first signs of so-called ransomware were discovered late Saturday night to mandated password changes for 540,000 students and 70,000 district employees. On September 30, the Los Angeles Unified School District said that cybercriminals who targeted it with a ransomware attack plan to release some of the hacked data online. LAUSD has not disclosed the ransom demanded by the criminal organization.
UPDATE: 500GB of data that was stolen during a cyberattack against the Los Angeles Unified School District (LAUSD) has been made public by hackers, media reports said on October 4.
Threat Actor: Vice Society
Vice Society emerged in 2021, this ransomware group targets small and medium businesses rather than large ones and has targeted Education, Healthcare, Non-governmental organizations the most since it emerged last year. There is no specific geographical area of operation.
Reference: Huge Los Angeles Unified School District Hit by Cyberattack
Victim: Los Angeles Unified School District
Los Angeles Unified School District (LAUSD) is a public school district in Los Angeles, California, United States. It is the largest (in terms of number of students) public school system in California and the 2nd largest public school district in the United States.
Reference: Cybercriminals behind ransomware attack plan to release hacked data, Los Angeles Unified School District says
Incident: Hackers Accessed HMIs at Israeli Water Facility
An Iranian threat-actor published a video of a breach in an Israeli reclaimed water reservoir HMI system. According to industrial cybersecurity firm OTORIO, the hackers accessed a human-machine interface (HMI) system that was directly connected to the internet without any authentication or other type of protection. The target was apparently a reclaimed water reservoir. “This gave the attackers easy access to the system and the ability to modify any value in the system, allowing them, for example, to tamper with the water pressure, change the temperature and more. All the adversaries needed was a connection to the world-wide-web, and a web browser,” OTORIO said in a blog post.
Reference: What We’ve Learned from the Dec 1st Attack on an Israeli Water Reservoir
Reference: Iranian Hackers Access Unprotected ICS at Israeli Water Facility
Incident: PLCs Targeted in Water and Wastewater Facilities Attacks in Israel
The Israeli government revealed that wastewater treatment plants, pumping stations and sewage facilities across the country were targeted in a coordinated attack on April 24 and 25. Sources told SecurityWeek that the attackers targeted programmable logic controllers (PLCs) used to control valves. The changes made to the PLC logic were valid, which indicates that the attackers knew exactly what they were doing. The attack may have been discovered after the compromised PLCs caused suspicious valve changes, but it’s unclear if the attackers were trying to cause damage by tampering with valves or if they made an error that led to their discovery.
Victim: Israel Water Facilities
Israel
Reference: Hackers Knew How to Target PLCs in Israel Water Facility Attacks: Sources
Incident: Cyberattack Source of Widespread Electricity Cuts Across Istanbul
Sources from the Energy Ministry claim that a major cyberattack is the source of the widespread electricity cuts across Istanbul in recent days, according to reports in the Turkish media. “Many infiltration attempts to the systems controlling our transmission and electricity producing lines were determined and prevented. The infiltration attempts are indicators of a major sabotage preparation against Turkey’s national electricity network,” a senior anonymous source said, as quoted by state-run Anadolu Agency. Energy Minister Berat Albayrak said a comprehensive investigation has been launched to figure out the real reasons behind the electricity cuts in a trip to the northwestern province of Kocaeli, which is the main center of the breakdowns.
Victim: City of Istanbul, Turkey
Istanbul
Reference: Major cyber-attack on Turkish Energy Ministry claimed
Reference: ICS-CERT Warns of Easily Hackable Road Signs
Reference: Flaw Lets Hackers Control Electronic Highway Billboards
Victim: Daktronics
Manufacturer of electronic scoreboards, programmable display systems and large-screen video displays, founded in 1968. Daktronics employs more than 2,500 people worldwide, with more than half of those in South Dakota, USA.
Incident: Patient Dies After Hackers Hit ‘Wrong’ Hospital in Germany
University Hospital Düsseldorf (UKD) in Germany suffered a cyberattack. Through an unpatched vulnerability, hackers penetrated the hospital’s network with ransomware, forcing planned and outpatient treatments and emergency care to have to occur elsewhere. A patient died after being forced to go to another hospital.
The ransom notes left on the hospital's encrypted servers were incorrectly addressed to Heinrich Heine University, rather than the hospital itself. After the police contacted the threat actors and explained that they encrypted a hospital, the ransomware operators withdrew the ransom demand and provided a decryption key.
Victim: University Hospital Düsseldorf (UHD)
University Hospital Düsseldorf (UHD)
Reference: Ransomware attack at German hospital leads to death of patient
Reference: Hospital ransomware attack leads to fatality after causing delay in care
Incident: Ransomware Attack at Electricity Provider for Johannesburg, SA
A major electricity supplier in South Africa's largest city has suffered a ransomware attack. The ransomware shut down IT systems, affecting more than 250,000 people through regional blackouts, and prevented customers from purchasing prepaid electricity.
Victim: City Power, Johannesburg
Electric utility company in Johannesburg, South Africa
Reference: Ransomware hits Johannesburg electricity supply
Reference: City Power Hit by Ransomware Attack
Reference: Hackers Hit COVID-19 Biotech Firm, Cold Storage Giant with Cyberattacks
Incident: System Outage at Miltenyi Biotec after Ransomware Attack
Miltenyi Biotec announced that it experienced malware attacks that affected some of its order processing capabilities. “During the last two weeks, there have been isolated cases where order processing was impaired by malware in parts of our global IT infrastructure,” the company says. Mount Locker ransomware gang claimed responsibility for the attack earlier this month. The gang claims to have stolen more than 1GB of documents from Miltenyi Biotec.
Threat Actor: Mount Locker
Starting around the end of July 2020, Mount Locker began breaching corporate networks. Mount Locker uses ChaCha20 to encrypt the files and an embedded RSA-2048 public key to encrypt the encryption key.
Reference: Biotech Company Miltenyi Biotec Discloses Malware Attack
Victim: Myltenyi
Germany-based biotech company provides solutions for cell and therapy research, including COVID-19-related products. It has facilities in 28 countries and employs more than 3,000 people.
Reference: Biotech Miltenyi, aiding in COVID-19 research, recovering from malware
Incident: Ransomware Attack at Global Food Supply Giant Americold Impacts Supply Chain
Americold was hit with a cyberattack that led them to shut down their computer systems to prevent the spread of the attack. Sources have told BleepingComputer that the attack has impacted numerous systems, including phone, email, order fulfillment, and inventory management. Customers who have attempted to pick up inventory for delivery have been unable to get access to warehouses. The ransomware operation behind the attack is unknown at this time.
The Atlanta based company has admitted that the attack has hit its supply chain because of which certain companies might see a slowdown in their food processing and distribution operations to retailers rendering services in countries like New Zealand, Argentina, Canada, and Australia.
Victim: Americold
Americold is a leading temperature-controlled warehouses operator who offers supply-chain services and inventory management for retailers, food service providers, and producers. Americold manages 183 warehouses worldwide and has approximately 13,000 employees.
Reference: Food-Supply Giant Americold Admits Cyberattack
Reference: Cold storage giant Americold hit by cyberattack, services impacted
Reference: UHS Hospitals hit by Ryuk ransomware, forced to shut down systems
Incident: Ryuk Ransomware Attack Reported Cost Universal Health Services (UHS) an Estimated $67 Million
Universal Health Services (UHS), one of the largest healthcare services provider shut down systems at healthcare facilities around the U.S. after a cyberattack hit its networks. UHS managed to restore most affected systems and hospital operations systems during late-October. UHS said that the Ryuk ransomware attack had an estimated impact of $67 million. In October 2020, the U.S. government warned of Ryuk ransomware attacks against healthcare industry organizations including hospitals and healthcare providers.
Victim: UHS – Universal Health Care System
UHS, a Fortune 500 hospital and healthcare services provider, has over 90,000 employees who provide services to roughly 3.5 million patients each year in more than 400 US and UK healthcare facilities.
Reference: Universal Health Services lost $67 million due to Ryuk ransomware attack
Reference: Revealed: Details of ‘First of Its Kind’ Disruptive Power Grid Attack
Incident: Ransomware Attack Shuts Down Production at Loom Manufacturer in Belgium
A cyber-attack partially incapacitated operations at West Flemish weaving machine producer Picanol. Large segments of production are at a standstill. The company’s entire production process is managed by computers. Plants in Ieper (Belgium), Romania and China were hit.
Reference: Ransomware shuts down production at Flemish multinational
Victim: Picanol
Picanol specializes in the manufacture of looms, is situated in the city of Ieper in the West Flanders province in Belgium.
Picanol employs 2,300 including 1,600 in Ieper and has 14 plants worldwide.
Reference: Press release cyber attack
Incident: Costa Rica Declares National Emergency in Response to Ransomware Attack
For the last two months (April/May 2022) Costa Rica has been under siege. Two major ransomware attacks have crippled many of the country’s essential services, plunging the government into chaos as it scrambles to respond. Officials say that international trade ground to a halt as the ransomware took hold and more than 30,000 medical appointments have been rescheduled, while tax payments have also been disrupted. Millions have been lost due to the attacks, and staff at affected organizations have turned to pen and paper to get things done.
Impact: 8 Major Gov. Agencies and services shutdown (30+ hit in total). National State of Emergency declared by President. Can't collect taxes, delays processing imports/exports, 10k+ public employees can't be paid. Medical attention and surgeries delayed or halted due to attack on Public Health (CCSS), container freight shipments slowed to a trickle at the port of Limón
Conti claimed responsibility for the first attack against Costa Rica’s government and is believed to have some links to the ransomware-as-a-service operation HIVE, which was responsible for the second attack impacting the health care system.
Victim: Costa Rica
Costa Rica
Reference: Conti’s Attack Against Costa Rica Sparks a New Ransomware Era
Reference: Conti’s Reign of Chaos: Costa Rica in the Crosshairs
Reference: How Conti ransomware group crippled Costa Rica — then fell apart
Incident: City of Shanghai Health App Hack Affects over 48.5 Million Mandatory Users.
A hacker has claimed to have obtained the personal information of 48.5 million users of a COVID health code mobile app run by the city of Shanghai, the second claim of a breach of the Chinese financial hub's data in just over a month.The hacker with the username as "XJP" posted an offer to sell the data for $4,000 on the hacker forum Breach Forums on Wednesday. The hacker provided a sample of the data including the phone numbers, names and Chinese identification numbers and health code status of 47 people.
The app collects travel data to give people a red, yellow or green rating indicating the likelihood of having the virus and users have to show the code to enter public venues. All residents and visitors have to use it.
Victim: City of Shanghai
More specifically: Suishenma, City of Shanghai's health code system.
Reference: Hacker offers to sell data of 48.5 million users of Shanghai’s COVID app
Incident: City of Lafayette, CO Opts to Pay Ransom of $45,000
Lafayette, Colorado fell victim to ransomware on July 27, which encrypted the city's computer networks and caused disruptions to phone services, email and online-payment and reservation systems. It's thought that the unidentified ransomware entered the city's network via a phishing or brute force attack. Lafayette opted to pay the cyber criminals perceiving it to be the quickest and most cost effective way to restore municipal services to residents.
Other cities across the US have paid hundreds of thousands of dollars to criminals in exchange for returning the network.
Victim: City of Lafayette (Colorado)
City of Lafayette (Colorado) USA
Reference: City of Lafayette (Colorado) paid $45,000 ransom after ransowmare attack
Reference: Ransomware: Why one city chose to the pay the ransom after falling victim
Incident: Magecart attacks Plague the Already Troubled Payment Platform Click2Gov
A new wave of data breaches in eight U.S. city governments is the work of online scammers using malicious code against the troubled online payments platform Click2Gov, according to research published Friday by the cybersecurity firm TrendMicro. The attacks involved Magecart-style attacks, in which lines of JavaScript code are injected into e-commerce platforms to rip off financial and personally identifiable information, like credit card numbers, names, addresses and other credentials. Click2Gov has for several years posed data-security problems for as many as 6,000 local governments across the United States who use Click2Gov. But according to TrendMicro, there’s no evidence directly linking the recent Magecart-style attacks to incidents in 2018 and 2019. Still, five of the eight cities analyzed had been victims of previous Click2Gov breaches.
Magecart attacks have plagued corporate websites, including big-name targets like British Airways, Ticketmaster and more than 2 million other websites, according to research published last October.
Reference: Click2Gov breaches in eight cities attributed to Magecart hackers
Incident: Colorado Water Utility Customer Data Compromised by Data Breach at Payment Vendor Click2Gov
Colorado water supplier are the latest victims of a series of attacks on the Click2Gov municipality payment software. In a statement issued to press on Monday (December 30), Aurora Water said that the personal information of customers who had used the platform between August 30 and October 14 had been impacted. An unauthorized actor, it explained, had “modified a piece of computer code” used by Click2Gov “to capture limited personal information such as first and last name, billing address, payment card type, payment card number, payment card verification value, and payment card expiration date.”
Aurora Water, which provides water to 360,000 residents in Aurora, Colorado, said that upon discovering the incident it took “Click2Gov offline for any new reoccurring or one-time payments” and launched an investigation.
Reference: Colorado municipality falls victim to Click2Gov software breach
Victim: Click2Gov
Popular platform that many local US governments use to process online payments.
Victim: Aurora City Water Utility Administration Department, CO
The City of Aurora water system covers nearly 2,000 acres and consists of approximately 50 miles of water main ranging in size from 2” to 16”.
Incident: Colorado County Pays $300,000 Ransom after Virus Hits Computer Systems
A computer virus downloaded to Archuleta County computers on Nov. 23 encrypted all county servers and files and demanded a $300,000 Bitcoin ransom.
Victim: Archuleta County, CO
Archuleta County, CO, USA
Reference: County computers hit with virus, phone system not affected
Incident: Town of Erie, CO Loses over $1M in Business Email Compromise Scam.
A hacked email account scammed the Town of Erie to wire $1 million to a falsified contractor’s account. The FBI is still investigating the case. These comments were offered on the matter: on November 13, 2019, the Erie Police Department opened an investigation into a cyber intrusion which had affected the Town of Erie. The Erie Police Department contacted the FBI Denver Division and requested assistance with the investigation. There is a Canadian Internet Service Provider (ISP) the unknown suspect used. The Internet Provider (IP) Address of the unknown suspect who completed the electronic ACH Enrollment form is in Canada. This Internet Provider (IP) in Canada will not cooperate with this investigation. The FBI continues to look into this aspect of the case.
Reference: Colorado Town Wires Over $1 Million to BEC Scammers
Victim: Town of Erie, CO
Town of Erie, CO, USA
Reference: Event Timeline
Incident: Colorado Private University Campus Systems Down after Ransomware Attack
“Malicious actors” carried out a cyberattack on Regis University in August 2019 — crippling the Denver campus’s IT network and downing phones, email and Wi-Fi — university officials paid the hackers a ransom in hopes of restoring their incapacitated systems. “The attack hit us the morning students were moving back to campus,” said Salvador Aceves, Regis’ senior vice president and chief financial officer. Aceves declined to say how much the university paid the hackers. University officials also have not revealed how much they’ve spent on recovery from the attack, which led them to distribute paper course schedules to students last fall and post signs on campus that read, “Enjoy a break from the connected life.”
Victim: Regis University, CO
Private Jesuit University in Colorado, USA
Reference: Denver’s Regis University paid ransom to “malicious actors” behind campus cyberattack
Incident: Colorado Water and Sanitation District Locked Out of Engineering Data and Drawings
When employees of the Fort Collins Loveland Water District and South Fort Collins Sanitation District got to work the morning of Feb. 11, they were locked out of technical and engineering data and drawings stored on their computers. The districts had fallen victim to a ransomware cyberattack, the second in two years, General Manager Chris Matkins said. Hackers were holding the data hostage and demanding a ransom payment before they'd unlock the information. Matkins won't say how big the ransom demand was or how payment was to be made. "It's not something we will talk about," he said. "It didn't have any bearing on how we responded."
Victim: Fort Collins Water & Fort Collins Sanitation District
Fort Collins Loveland Water District and South Fort Collins Sanitation District in Colorado, US.
Reference: Cyberattacker demands ransom from Northern Colorado utility
Reference: Cybercrime group known as ‘Wizard Spider’ hackers behind Ireland HSE ransomware attack
Reference: Colorado Hack Offers Larger Lessons for Cybersafety
Incident: SamSam Ransomware Takes Down Colorado DOT
The Colorado Department of Transportation (CDOT) was hit by a SamSam ransomware attack that penetrated a temporary system being tested without full security. Once inside, bad actors used it to access CDOT, ultimately affecting roughly half its computing environment, around 400 servers, all databases and applications and around 1,300 workstations. The agency was back to 80 percent functionality six weeks after the ransomware attack, at an estimated cost of up to $1.5 million. The state’s new backup system prevented data loss, but personal data on employees’ computers may not be recovered.
Victim: Colorado Department of Transportation
Colorado Department of Transportation, USA
Reference: Cyber attack on CDOT computers estimated to cost up to $1.5 million so far
Incident: Ransomware Attack Shuts Down City of Atlanta, GA,
On March 22, 2018, Atlanta’s connected systems city-wide were hit with a ransomware message locking their respective files and demanding an approximately $50,000 payment in bitcoin (the price has fluctuated since). The ransomware is believed to be from the group known as SamSam, which has been operating and executing similar attacks since at least 2015. Atlanta residents were unable to do simple city system-dependent tasks like paying parking tickets or utility bills. City employees didn’t get the all-clear to turn on their computers until five days later and many city systems still have not recovered. The cyberattack took more than one-third of Atlanta’s 424 software programs offline or partially offline. The first month of recovery cost almost $3 million.
Victim: City of Atlanta
City of Atlanta, GA, USA
Reference: How Atlanta’s CIO rebuilt IT after the city’s cyberattack — and what’s next
Reference: A Cyberattack Hobbles Atlanta, and Security Experts Shudder
Incident: OT Attack on Bowman Avenue Dam Illustrates Vulnerability of the U.S. Infrastructure
Extensive information about the Bowman Avenue dam in Rye, New York state was taken by the hackers. The hacker broke into the SCADA (Supervisory Control and Data Acquisition) system of the New York dam by exploiting a susceptible modem connection. While there are multiple theories behind the intention of the attack, the hackers wouldn't have been able to do any damage at that time because the sluice gate had been manually disconnected for maintenance. An investigation pointed to Iran as the likely source of the attack. This and similar attacks seemed intent on gathering detailed information, including engineering drawings, about networks and facilities.
Reference: Iranian Hackers Claim Cyber Attack on New York Dam
Victim: Bowman Avenue Dam, NY
Bowman Avenue dam in Rye, New York state
Reference: Iranian hackers ‘targeted’ New York dam
Reference: Throwback Attack: How the modest Bowman Avenue Dam became the target of Iranian hackers
Incident: Target Suffers Largest Retail Data Breach in U.S. History.
The Target Corp hackers managed to break into its payments network by first breaching a “data connection” between the U.S. retailer and its HVAC systems contractor. The data connection was used by the vendor, Fazio Mechanical Services, to bill Target and exchange contract and project management information with the retailer. Target, the third-largest U.S. retailer, has said the hackers stole about 40 million credit and debit card records, as well as personal information, such as addresses and phone numbers, belonging to about 70 million customers.
Many in the industry immediately recognized that a similar attack could happen with credentials for a BAS or energy management system, especially if a third-party company is performing a remote monitoring service.
Reference: Target vendor says hackers breached data link used for billing
Reference: Target attack shows danger of remotely accessible HVAC systems
Reference: Target Settles HVAC Data Breach for $18.5 Million
Reference: Hack attack causes ‘massive damage’ at steel works
Victim: Unidentified
unnamed victim
Reference: Throwback Attack: A cyberattack causes physical damage at a German steel mill
Incident: Covid vaccine-maker Dr Reddy Laboratories hit by cyber-attack
Pharmaceutical company Dr Reddy's, which is developing a Covid-19 vaccine, stated it has been hit by a cyber-attack. Sites around the world have been affected, including those in the UK, Brazil, India, Russia and the US. The India-based company said it had isolated all of its data centre services to contain the attack. The attack came only days after the pharmaceutical company was gearing up for a phase 2/3 clinical trial of Russia’s COVID-19 vaccine, dubbed Sputnik V, after gaining the trial go-ahead from Indian regulators last week.
Victim: Dr Reddy’s Laboratories
Dr. Reddy's Laboratories is an Indian multinational pharmaceutical company located in Hyderabad, Telangana, India. The company was founded by Kallam Anji Reddy, who previously worked in the mentor institute Indian Drugs and Pharmaceuticals.
Reference: Dr. Reddy Labs discloses cyberattack soon after getting ok for final COVID vaccine trial
Reference: Dr. Reddy’s shuts ‘key’ plants worldwide after potential cyberattack hits COVID work
Incident: Oil India Ltd. Hackers Demand US$7.5M Ransom Payment
A cyberattack on Oil India Limited (OIL) led the energy giant to disable its IT systems at its headquarters in Assam’s Dibrugarh district. OIL server, network and other related services are affected. OIL spokesperson Tridiv Hazarika told ET, "data is secured, as per protocol, we disabled our systems. Infected computers are being checked. Our SAP is running and hence operations are going on smoothly. " He added, "our IT department will restore computers phase wise. Computers are put out of lan (local area network). Our drilling activities are going on without interruption. "
A senior police official said that it was Russian malware planted from a server in Nigeria. The cyber attacker has demanded US$ 7500000 as a ransom through a note from the infected PC.
Victim: Oil India
Formed in 1889, OIL is the second largest national oil and gas company in India, under the administrative control of the Ministry of Petroleum and Natural Gas, Government of India.
Reference: Oil India cyber attack: Russian malware planted from Nigeria
Reference: Cyberattack in Oil India’s headquarters, attackers demand over Rs 57 crore as ransom
Incident: Hackers Manipulated Water Supply at Unnamed Water District – ‘Kemuri’.
The unnamed water district, referred to as Kemuri, had asked Verizon Security Solutions to conduct a proactive assessment as part of its efforts to keep systems and networks healthy. Experts soon discovered clear signs of malicious activity. They immediately noticed that the organization had a poor security architecture, with Internet-facing systems plagued by high-risk vulnerabilities. Hackers took advantage of outdated systems and poor cyber hygiene and were able to cross breach, jumping from the IT side to the OT side, to access 2.5 million financial records and to manipulate the area’s water supply.
The 'Kemuri' Water Company was able to remediate the changes made to the water supply, and the customer impact was minimal. But the insecurity of the plant’s networks could have led to far more serious consequences, including risk to human safety.
Reference: Attackers Alter Water Treatment Systems in Utility Hack: Report
Victim: “Kemuri” Water company – KWC
an unnamed water facility referred to as the Kemuri Water Company - a pseudonym was used due to the sensitive nature of the breach.
Reference: Throwback Attack: Kemuri Water Company attack puts critical infrastructure at risk
Reference: Optus hacker apologizes and allegedly deletes all stolen data
Incident: Exponential Rise in IRS-Themed SMS Phishing Attacks in U.S.
The Internal Revenue Service (IRS) warned Americans of an exponential rise in IRS-themed text message phishing attacks trying to steal their financial and personal information in the last few weeks. "In recent months, the IRS has reported multiple large-scale smishing (MMS/SMS/text scams) campaigns targeting taxpayers, that have delivered thousands – and even hundreds of thousands – of IRS-themed messages in hours or a few days, far exceeding previous levels of activity."
The Federal Communications Commission (FCC) issued a similar warning in July 2022. According to the U.S. communications watchdog's Robocall Response Team, these phishing messages (or robotexts as the FCC calls them) will hit billions of phones every month.
Malware: Unknown phishing attack
Phishing attack
Reference: IRS warns Americans of massive rise in SMS phishing attacks
Incident: Sophisticated Phishing Campaign Targets Military and Weapons Contractors
Security researchers have discovered a new campaign targeting multiple military contractors involved in weapon manufacturing, including an F-35 Lightning II fighter aircraft components supplier. The highly targeted attacks begin with a phishing email sent to employees, leading to a multi-stage infection involving many persistence and detection avoidance systems.The campaign stands out for its secure C2 infrastructure and multiple layers of obfuscation in the PowerShell stagers. The campaign stands out for its secure C2 infrastructure and multiple layers of obfuscation in the PowerShell stagers.
Reference: Stealthy hackers target military and weapons contractors in recent attack
Victim: Gundremmingen nuclear power plant in Germany
The Gundremmingen Nuclear Power Plant is a nuclear power station in Germany. It is located in Gundremmingen, district of Günzburg, Bavaria. It is operated by Kernkraftwerk Gundremmingen GmbH, a joint operation of RWE Power AG and PreussenElektra. Unit B was shut down at the end of 2017.
Reference: Concerns Raised Over Malware in German Nuclear Plant
Reference: Malware Shuts Down German Nuclear Power Plant on Chernobyl’s 30th Anniversary
Incident: Lansing, MI, Public Utility Compromised by Attack, $25K Ransom paid.
The Board of Water and Light (BWL) in Lansing, Michigan, was struck by ransomware on Monday, April 25. 2016. The cyberattack shut down BWL's accounting and email systems after an employee unknowingly opened an email with an infected attachment. This would seem to be the first disclosed example of a utility being successfully compromised by ransomware.
The Lansing Board of Water & Light paid a $25,000 ransom to unlock its internal communications systems after they were disabled by a cyberattack last spring, officials said Tuesday. BWL General Manager Dick Peffley pegged the cost of responding to the emergency, including the ransom and technology upgrades to prevent future attacks, at $2.4 million. All but $500,000 of those costs are covered by insurance. Paying the ransom was “the only action we could take to unlock our system and free it from the ransomware.”
Reference: BWL paid $25,000 ransom after cyberattack
Victim: Lansing Board of Water & Light (BWL)
The Lansing Board of Water & Light is a municipally-owned public utility that provides safe, reliable and affordable utility products and services to around 100,000 electric and 58,000 water customers throughout the greater Lansing area.
Reference: BWL cyberattack: 20 questions
Reference: Lansing Board of Water & Light Hit By Ransomware Attack
Reference: Hackers tried poisoning town after breaching its water facility
Reference: Water Utilities: So ‘Vital, Overlooked’
Reference: FL Water Plant Warnings, Mitigations
Reference: ONWASA: $277K spent on recovery, defense after cyber attack [Jan 2019]
Reference: Feds Investigate After Hackers Attack Water Utility
Incident: American Airlines Suffers Breach
American Airlines informed some if its customers Friday (September 16) about a security incident that occurred July 5 and resulted in a breach of personal information.
In July the airline found an attacker compromised email accounts of airline workers via a phishing attack and were then able to pivot from there to get in and purloin personal information.
In a letter dated September 16, Russell Hubbard, deputy general counsel and chief privacy and data protection officer at American Airlines said: “We are writing to inform you about a recent incident that involved some of your personal information.
Reference: American Airlines Suffers Data Breach
Victim: American Airlines
Leading global air carrier.
Incident: Optus, Aussie Telecom Firm, Hit In Cyberattack
Optus, the Australian unit of telecoms firm Singapore Telecommunications is investigating the unauthorized access of current and former customers’ information.
Optus said in a statement it had immediately shut down the attack after discovering it, and that payment details and account passwords had not been compromised.
However, information that may have been exposed include customers’ names, dates of birth, phone numbers, email addresses, and, for a subset of customers, addresses, ID document numbers such as driver’s license or passport numbers.
Reference: Aussie Telecom Firm Hit In Cyberattack
Victim: Optus
Telecom provider in Australia.
Incident: Uber Hit in Cyberattack
Uber, the ride-hailing and food delivery company has suffered a systems breach, according to a report, with employees unable to access internal tools such as Slack. One employee resource page is said to have had a not safe for work image posted to it by the hacker.
An official statement posted to Twitter said, "We are currently responding to a cybersecurity incident. We are in touch with law enforcement and will post additional updates here as they become available."
Uber said the hacker behind the breach is affiliated with the Lapsus$ extortion group and the group used the stolen credentials of an Uber EXT contractor in an multi-factor authentication (MFA) fatigue attack where the contractor was inundated with two-factor authentication login requests until one of them was accepted
Reference: Uber hacked, internal systems breached and vulnerability reports stolen
Victim: Uber
Uber suffered a cyberattack apparently by an 18-year-old hacker downloading HackerOne vulnerability reports and sharing screenshots of the company's internal systems, email dashboard, and Slack server.
The screenshots shared by the hacker and seen by BleepingComputer show what appears to be full access to critical Uber IT systems, including the company's security software and Windows domain.
Other systems accessed by the hacker include the company's Amazon Web Services console, VMware vSphere/ESXi virtual machines, and the Google Workspace admin dashboard for managing the Uber email accounts.
Reference: Samsung admits user data breach following strange notifications
Incident: Samsung Data Breach
Samsung admitted what it calls a "small number" of users could indeed read other people's personal data following an unexplained Find my Mobile notification.
Users said they found strangers' personal data displayed to them. Find My Mobile is a Samsung app that comes pre-loaded with its Android devices and can only be disabled, not uninstalled. The only way to uninstall Samsung apps is to wipe the operating system completely and install a different ROM.
The company has admitted a data security breach did occur.
A company spokeswoman said, "A technical error resulted in a small number of users being able to access the details of another user. As soon as we became of aware of the incident, we removed the ability to log in to the store on our website until the issue was fixed."
Reference: Samsung cops to data leak after unsolicited ‘1/1’ Find my Mobile push notification
Incident: Samsung Hit in Cyberattack, Again
For the second time this year in a span of less than six months, electronics giant South Korea-based Samsung, suffered a data breach this past July, but the company did not discover it until early August.
After discovery, the company found the attackers stole personal data from customers.
“At Samsung, security is a top priority,” the company said in an advisory it posted September 2 almost a month after discovering the incident. “We recently discovered a cybersecurity incident that affected some customer information.
“In late July 2022, an unauthorized third party acquired information from some of Samsung’s U.S. systems. On or around August 4, 2022, we determined through our ongoing investigation that personal information of certain customers was affected. We have taken actions to secure the affected systems, and have engaged a leading outside cybersecurity firm and are coordinating with law enforcement."
This was the second attack against Samsun this year and third since 2020.
Reference: https://www.isssource.com/samsung-suffers-third-attack-second-in-6-months/
Incident: Eni, Italian Oil Giant, Suffers Cyberattack
Italian oil company Eni’s computer networks suffered a cyberattack – and a possible ransomware attack – but the company appeared to have caught it in time, officials said Wednesday.
Eni disclosed a security breach, threat actors gained access to its network, but according to the company the intrusion had minor consequences because it was quickly detected.
“The internal protection systems have detected unauthorized access to the corporate network in recent days,” a spokesperson for the company said.
Reference: Hackers hit Italian oil company Eni’s computer networks
Reference: Italian Oil Giant Eni Hit In Cyberattack
Victim: Eni
Eni S.p.A. is an Italian multinational oil and gas company headquartered in Rome. Considered one of the seven "supermajor" oil companies in the world, it has operations in 69 countries.
Incident: Russian Streaming Giant Suffers Major Data Leak Impacting 44M Customers
Russian streaming giant START said on Sunday that the personal information of its customers was leaked during a cyberattack. The company did not disclose how many users were affected by the breach. The Russian Telegram channel Information Leaks — which first publicized the incident — reports the 72 GB database contains data on 44 million customers. The leaked information includes usernames, email addresses, hashed passwords, IP addresses, users’ countries of registration, subscription start and end dates, and the last login to the service.
START, which sells films and TV shows in more than 174 countries, is one of many Russian companies that have suffered data leaks and hacks following Russia’s invasion of Ukraine. The data breach allegedly affects viewers worldwide, including 24.6 million users from Russia, 2.3 million from Kazakhstan, 2.1 million from China, and 1.7 million from Ukraine.
Victim: START
START is a subscription-based international streaming service with subscribers in 174 countries co-owned by MegaFon, Russia’s second-largest mobile phone operator.
Reference: Russian streaming giant suffers a massive data leak affecting 44m users
Reference: Leading Russian streaming platform suffers data leak allegedly impacting 44 million users
Incident: $10 Million Ransom Demand Disables French Hospital – Patients Send Elsewhere.
The Center Hospitalier Sud Francilien (CHSF), a 1000-bed hospital located 28km from the center of Paris, suffered a cyberattack on Sunday, which has resulted in the medical center referring patients to other establishments and postponing appointments for surgeries. CHSF serves an area of 600,000 inhabitants, so any disruption in its operations can endanger the health, and even lives, of people in a medical emergency. "This attack on the computer network makes the hospital's business software, the storage systems (in particular medical imaging), and the information system relating to patient admissions inaccessible for the time being," explains CHSF's announcement (translated).
French cybersecurity journalist Valéry Riess-Marchive identified signs of a LockBit 3.0 infection. If LockBit 3.0 is responsible for the attack on CHSF, it will violate the RaaS program's rules, which prohibit affiliates from encrypting systems of healthcare providers.
Victim: Center Hospitalier Sud Francilien (CHSF),
CHSF is a 1000-bed hospital located 28km from the center of Paris.
Reference: French hospital hit by $10M ransomware attack, sends patients elsewhere
Incident: $600K demanded in Dominican Agrarian Institute Quantum Ransomware Attack,
The Dominican Republic's Instituto Agrario Dominicano has suffered a Quantum ransomware attack. The attack encrypted multiple services and workstations throughout the government agency. The Instituto Agrario Dominicano (IAD) is part of the Ministry of Agriculture and is responsible for executing Agrarian Reform programs in the country. "They ask for more than $600K. We were affected by four physical servers and eight virtual servers; virtually all servers," IAD Director of Technology Walixson Amaury Nuñez told local media. The National Cybersecurity Center (CNCS) says that the IP addresses of the attackers were from the U.S. and Russia.
Quantum is becoming a major player among enterprise-targeting ransomware operations, linked to an attack on PFC that impacted over 650 healthcare orgs
Malware: Quantum Ransomware
Quantum is becoming a major player among enterprise-targeting ransomware operations, linked to an attack on PFC that impacted over 650 healthcare orgs
The ransomware gang is believed to be an offshoot of the Conti ransomware operation, which took over the previous rebrand of the MountLocker ransomware operation. MountLocker was first deployed in attacks starting in September 2020 but rebranded multiple times under various names, including AstroLocker, XingLocker, and finally Quantum.
The rebrand to Quantum occurred in August 2021, when their ransomware encryptor switched to adding the .quantum file extension to encrypted files' names. After that, however, the rebrand never became particularly active, with the operation mostly lying dormant. That was until the Conti ransomware operation started shutting down, and its members began looking for other operations to infiltrate.
According to Advanced Intel's Yelisey Boguslavskiy, some of the Conti cybercrime syndicate joined the ranks of the Quantum operation, which also immediately saw an increase in attacks.
Victim: Instituto Agrario Dominicano (IAD)
The Instituto Agrario Dominicano (IAD) is part of the Ministry of Agriculture and is responsible for executing Agrarian Reform programs in the Dominican Republic.
Reference: Quantum ransomware attack disrupts govt agency in Dominican Republic
Reference: Cyberattack Raises Pressure on European Water Providers During Drought Attack on British water company increases concerns about sector’s vulnerability
Incident: City of Hamilton Informs Water Customers of Ransomware Attack
The City of Hamilton alerted customers of a recent ransomware attack connected with a third party vendor that sends emails to water customers. In a release, staff say the “possible data breach” may have ties to Neptune Technology Group, who replace and maintain water meters, and a third-party mailing vendor that informs residents of a need to replace a meter. The city said “Hamilton Water considers this is a low-risk incident for residents, but felt it important to inform the community." It’s believed 2,387 out of about 156,000 accounts may have been subject to attack giving access to personal information like names and mailing addresses. Neptune Technology Group has stopped using and sharing information with the mailing vendor as a precaution.
Victim: Neptune Technology Group Inc.
Neptune Technology Group Inc. is a technology company serving more than 4,000 water utilities across North America. "We make data actionable using effective software and hardware tools that are interconnected by a smart network, with expertise and experience specifically focused on the business of water."
Reference: City reveals thousands of Hamilton Water customers may have been subject to data breach
Reference: New MailChimp breach exposed DigitalOcean customer email addresses
Reference: Okta one-time MFA passcodes exposed in Twilio cyberattack
Threat Actor: Scatter Swine / 0ktapus
Scatter Swine/0ktapus likely uses commercial data aggregation services to collect mobile phone numbers belonging to employees of technology companies, telecommunications providers, and individuals linked to cryptocurrency.
Reference: Twilio hackers hit over 130 orgs in massive Okta phishing attack
Incident: Cyberattack at Global Password Management Firm, LastPass, Compromises Users’ Master Passwords
Many LastPass users report that their master passwords have been compromised after receiving email warnings that someone tried to use them to log into their accounts from unknown locations. The email notifications also mention that the login attempts have been blocked because they were made from unfamiliar locations worldwide. "Someone just used your master password to try to log in to your account from a device or location we didn't recognize," the login alerts warn. LastPass says it's credential stuffing.
While LastPass didn't share any details regarding how the threat actors behind these credential stuffing attempts, security researchers Bob Diachenko said he recently found thousands of LastPass credentials while going through Redline Stealer malware logs. Two years ago, in September 2019, LastPass fixed a security vulnerability in the password manager's Chrome extension that could have allowed threat actors to steal the credentials last used for logging into a site, according to Bleepingcomputer.
Reference: LastPass users warned their master passwords are compromised
Incident: Source Code, Proprietary Technical Info Stolen at LastPass, a Global Password Management Firm
Password management software firm LastPass, owned by GoTo (formerly LogMeIn), has suffered a data breach that led to the theft of source code and proprietary technical information. The firm said that the customer master passwords or any encrypted password vault data were not compromised. The latest hack comes on the heels of LastPass users being targeted with “credential stuffing” attacks that use email addresses and passwords obtained from third-party breaches.
Bleepingcomputer reported that security researchers Bob Diachenko said he recently found thousands of LastPass credentials while going through Redline Stealer malware logs. LastPass users are advised to enable multi-factor authentication to protect their accounts. BleepingComputer reports this as a developing story and has reached out with further questions about the attack.
Reference: LastPass developer systems hacked to steal source code
Reference: LastPass Says Source Code Stolen in Data Breach
Victim: LastPass
LastPass is a freemium password manager that stores encrypted passwords online. The standard version of LastPass comes with a web interface, but also includes plugins for various web browsers and apps for many smartphones. It also includes support for bookmarklets. LogMeIn, Inc. acquired LastPass in October 2015. LastPass is one of the largest password management companies in the world, claiming to be used by over 33 million people and 100,000 businesses.
Incident: Over 2,5 Million Individuals Impacted by System Breach at Federal Student Loan Services Provider.
Data for over 2.5 million individuals with student loans from Oklahoma Student Loan Authority (OSLA) and EdFinancial was exposed after hackers breached the systems of technology services provider Nelnet Servicing. Sometime in June, unidentified intruders compromised Nelnet Servicing and stayed on its systems until July 22. The hackers compromised the company's network likely after exploiting a vulnerability. EdFinancial underlines that not all its clients are hosted by Nelnet Servicing. Due to the seriousness of this incident, law firm "Markovits, Stock & DeMarco" launched an investigation on the potential of a class action lawsuit.
Victim: Nelnet Servicing
Nelnet is a federal student loan servicer working on behalf of the U.S. Department of Education, the government agency that lends you or your child student loans. A loan servicer acts as the customer service provider for the loans that the Department of Education lends to borrowers.
Reference: Nelnet Servicing breach exposes data of 2.5M student loan accounts
Incident: Ransomware Attack at Germany’s Largest Library Services Deletes Media Files
One of the largest library services in Germany, EKZ Bibliotheksservice, has been impacted by a ransomware attack. The attack has left book lovers unable to rent and borrow eBooks, audio books, and electronic magazines. Onleihe, a popular online app that connects users via EKZ's service to their local libraries, reported that its copy-protected eBooks had been deleted. Bleepingcomputer reported that the LockBit ransomware group has claimed responsibility. LockBit released 100% of the data, according to Bleepingcomputer, indicating EKZ will not pay the ransom and is likely restoring from backups,
Reference: Online library app Onleihe faces issues after cyberattack on provider
Victim: EKZ Bibliotheksservice
EKZ is one of the largest library services in Germany. EKZ supplies services to Onleihe, Goethe-Institut’s digital library (eLibrary) with more than 23,000 German language eBooks, audio books, movies, materials for German language learners, magazines and newspapers.
Reference: German library service struggling to recover from ransomware attack
Victim: Onleihe Library
The Onleihe is Goethe-Institut’s digital library (eLibrary). More than 23,000 German language eBooks, audio books, movies, materials for German language learners, magazines and newspapers are available for downloading from the Onleihe.
Incident: Business Critical Systems Disrupted at Largest Library Content, Software and Services Provider.
Baker & Taylor confirmed being hit by ransomware. The world's largest global distributor of books to libraries revealed that disruptions to its business-critical systems would persist through the week while technical teams work on restoring impacted servers. Currently, there is no information on what ransomware group or affiliate is behind the attack. Based on the company's statement that it's working on restoring affected servers, it's safe to say that Baker & Taylor will not pay the ransom demand, reports Bleepingcomputer.
Reference: Major U.S. library service confirms ransomware attack, struggling to restore affected systems
Victim: Baker & Taylor
Baker & Taylor is a privately held company founded over 190 years ago and based in Charlotte, North Carolina. A leading library content and software supplier in the United States and around the globe, They currently provide services to more than 5,000 public and academic libraries.
Reference: Leading library services firm Baker & Taylor hit by ransomware
Malware: 0Ktapus phishing campaign
0ktapus campaign has been underway since at least March 2022, aiming to steal Okta identity credentials and 2FA codes and use them to carry out subsequent supply chain attacks.
In Aug. 2022 SMS phishing messages baited Twilio's employees into clicking the embedded links by warning them that their passwords had expired or were scheduled to be changed.
Incident: Twilio Suffers Data Breach
Cloud communications company Twilio says some of its customers' data was accessed by attackers who breached internal systems after stealing employee credentials in an SMS phishing attack.
"On August 4, 2022, Twilio became aware of unauthorized access to information related to a limited number of Twilio customer accounts through a sophisticated social engineering attack designed to steal employee credentials," Twilio said in an advisory.
"The attackers then used the stolen credentials to gain access to some of our internal systems, where they were able to access certain customer data."
The company also revealed the attackers gained access to its systems after tricking and stealing credentials from multiple employees targeted in the phishing incident.
Reference: Twilio discloses data breach after SMS phishing attack on employees
Victim: Twilio
Twillio provides programmable voice, text, chat, video, and email APIs used by over 10 million developers and 150,000 businesses to build customer engagement platforms.
Reference: Ransomware Group Hit In DDoS Attack
Editorial: Water Industry Needs Cybersecurity Help
Incident: DESFA, Greece’s Natural Gas Supplier, Suffers Cyberattack
Greece’s largest natural gas supplier, DESFA, said Saturday it fell victim to a cyberattack on part of its IT infrastructure by cybercriminals who tried to gain access to electronic files and with a confirmed impact on the availability of certain systems and possible leakage of a number of files and data.
Ragnar Locker ransomware group claimed them as its victim on Friday by leaking some of the DEFSA data.
“We managed to ensure and continue the operation of the National Natural Gas System (NSGS) in a safe and reliable manner,” the company said in an advisory. “The management of DESFA continues to operate smoothly and DESFA continues to supply natural gas to all entry and exit points of the country safely and adequately. We are investigating the root causes of the attack and have mobilized teams of technical and specialist experts to assist us in this matter and in getting the systems back up and running as soon as possible.”
Reference: Greek natural gas operator suffers ransomware-related data breach
Reference: Greece’s Natural Gas Supplier Suffers Cyberattack
Threat Actor: Ragnar Locker
Ragnar Locker is a family of ransomware, which first came to prominence in early 2020 when it became known for hitting large organizations, attempting to extort large amounts of cryptocurrency from its victims.
Victim: DESFA
DESFA is Greece’s largest natural gas supplier.
Incident: Sferra Fine Linens Hit in Cyberattack
Attackers were inside textile manufacturer, Sferra Fine Linens, LLC’s network ten days before the company discovered a cyberattack back in April, but just released notification of the incident Friday.
“To date, we have no evidence of actual or attempted misuse of information as a result of this incident,” the company said in a statement. “This event did not impact any of Sferra’s e-commerce platforms or any information retained in our e-commerce systems.”
On April 24, Sferra said it became aware of suspicious activity on its computer servers. The company then took immediate steps to secure the network, and then called in third-party forensic specialists, who then deployed countermeasures to contain the attack.
Reference: Textile Manufacturer Hit In Cyberattack
Victim: Sferra Fine Linens LLC
Founded in 1891, Edison, New Jersey-based Sferra designs and sells Italian-made luxury linen products, including luxury sheets, table linens, and bedding collections.
Reference: Ransom paid after cyberattack on Cedar Rapids schools likely necessary, expert says
Incident: Global Freight Forwarding Company, Expeditors Intl., hit by Ransomware Attack.
A crippling ransomware attack completely shutdown all operations at Expeditors, a global freight forwarder and logistics company based out of Seattle. The company expects the cyberattack will have a material adverse impact on its business, revenues, expenses, results of operations, cash flows and reputation. A later report revealed the cost to the company was $60m in remediation and lost business. Expeditors' operations were shutdown, as they were unable to ship, manage customs, or process customer's freight for 3 weeks+ .
After three weeks of downtime, systems were mostly restored with some operations are still feeling the impact in minor ways.
Victim: Expeditors International
Expeditors has 350 locations and over 18,000 employees worldwide, providing critical logistics solutions for its customers. Its services include supply chain, warehousing and distribution, transportation, customs and compliance. The company is based in Seattle, WA. with an annual gross revenue of around $10 billion,
Reference: Expeditors outlines severity of cyberattack, partially resumes operations
Reference: Expeditors Targeted in Cyber-attack
Reference: US logistics giant Expeditors International goes down in major cyberattack
Incident: 26 Healthcare Organizations Impacted by Cyberattack on NY Medical Billing Company.
New York billing company Practice Resources, LLC (PRL) disclosed a ransomware attack that impacted 942,000 individuals and 26 healthcare organizations. PRL began notifying 942,138 individuals of a ransomware attack that impacted 26 of its healthcare organization clients.
According to a notice posted on the California Attorney General’s Office website, PRL suffered a ransomware attack on April 12, 2022. PRL immediately took steps to secure its systems and gained assistance from third-party experts.The information involved in the attack potentially included names, addresses, health plan numbers, dates of treatment, and medical record numbers.
Victim: Practice Resources, LLC (PRL)
New York-based medical billing and practice management company. Founded in 1996.
Reference: NY Billing Company Suffers Ransomware Attack, 942K Impacted
Incident: Kansas City MSP NetStandard Forced to Disable MyAppsAnywhere Cloud Service.
NetStandard, a managed IT services company in Kansas City, suffered a cyberattack causing the company to shut down its MyAppsAnywhere cloud services.
According to an email sent to MyAppsAnywhere customers shared on Reddit, the company detected signs of a cyberattack on Tuesday morning and quickly shut down cloud services to prevent the attack's spread. While the company says that only the MyAppsAnywhere services are affected, the attack appears to have had a broader impact, with the company's main site shut down as well. BleepingComputer has reached out to NetStandard with questions about the attack but has not received a reply at this time.
MyAppsAnywhere cloud services consist of hosted Dynamics GP, Exchange, Sharepoint, and CRM services.
Victim: NetStandard
Netstandard is a full-service business technology company that offers strategic managed services, virtual servers, cloud computing. The company is based in Kansas City, KS.
Reference: Kansas MSP shuts down cloud services to fend off cyberattack
Incident: Supply Chain Cyberattack Closes Ontario Cannabis Retail Corporation (OCS) Warehouse for Days.
Ontario Cannabis Store (OCS) said on August 9 it still can’t fulfill or deliver new orders after a cyber incident at the U.S. parent company of its distribution partner, Domain Logistics. As a result of the incident OCS has had to close its warehouse. The OCS says there is “currently no indication that OCS systems or its customers’ information was targeted or compromised as a result of this attack.”
Legacy Supply Chain - U.S. parent company of Domain Logistics - detected unusual activity on its network on August 5th. The IT network and a number of applications were taken offline "impacting order processing for a small number of Legacy customers".
Reference: Ontario Cannabis Store to resume deliveries to pot shops following cyberattack on partner
Victim: Legacy Supply Chain, the parent company of Domain Logistics
Domain Logistics is a Toronto-based third-party logistics provider specializing in supply chain solutions for omni-channel businesses in Canada. The parent company, Legal Supply Chain is based in Indiana USA
Reference: OCS third party logistics provider subject to “cyber attack” last Friday, online and retail orders to be delayed
Reference: Canadian recreational vehicle maker BRP, Ontario Cannabis Store dealing with cyber attacks
Reference: Update on Cyber Incident | August 12, 2022
Incident: UK Water Utility Suffers Cyberattack
Customers have been assured there is safe drinking water after South Staffordshire PLC, the parent company of South Staffs Water and Cambridge Water in the UK, fell victim to a cyberattack Monday.
The company supplies 330 million liters of drinking water to 1.6 million customers.
“This incident has not affected our ability to supply safe water and we can confirm we are still supplying safe water to all of our Cambridge Water and South Staffs Water customers," the company said in a statement. "This is thanks to the robust systems and controls over water supply and quality we have in place at all times as well as the quick work of our teams to respond to this incident and implement the additional measures we have put in place on a precautionary basis."
Reference: Clop gang targeted UK drinking water supplier South Staffordshire Water
Reference: UK Water Utility Hit In Cyberattack
Victim: South Staffordshire PLC, the parent company of South Staffs Water and Cambridge Water
The company supplies 330 million liters of drinking water to 1.6 million customers.
Reference: Sodinokibi Ransomware Threatens to Publish Data of Automotive Group
Incident: German Automotive Parts Manufacturer Hit by Sodinokibi/REvil Ransomware Group
Gedia Automotive Group headquarters in Attendorn fell victim to a cyberattack on January 21. Shutdown of all systems was enforced to prevent a complete IT infrastructure breakdown. The company confirmed the attack shortly after the Sodinokibi ransomware gang threatened to publish sensitive data.
Victim: Gedia Automotive Group
The Gedia Automotive Group employs more than 4,300 people at production plants in Germany, China, Hungary, India, Mexico, Poland, Hungary, Spain, and the USA. Gedia produces pressed body parts and welded assemblies for the automotive industry and had an annual turnover of €600 million (over $665 million) in 2017.
Reference: Travelex hackers shut down German car parts company Gedia in massive ‘cyber attack’
Reference: South Denver Notice to Patients
Incident: Unidentified Automotive Supplier Breached Three Times within Two Months
An automotive supplier had its systems breached and files encrypted by three different ransomware gangs over two weeks in May, two of the attacks happening within just two hours. The attacks followed an initial breach of the company's systems by a likely initial access broker (IAB) in December 2021, who exploited a firewall misconfiguration to breach the domain controller server using a Remote Desktop Protocol (RDP) connection. After the initial compromise, LockBit, Hive, and ALPHV/BlackCat affiliates also gained access to the victim's network on April 20, May 1, and May 15, respectively.
While dual ransomware attacks are increasingly common, "this is the first incident we've seen where three separate ransomware actors used the same point of entry to attack a single organization," Sophos X-Ops incident responders said according to a report in Bleeping Computer.
Victim: Unidentified
Unidentified at this time
Incident: Cyberattack Cost Eberspächer Automotive Supplier $60Million says CEO
The German supplier Eberspaecher Group fell victim to a large-scale cyberattack on October 24, 2021. To prevent the possible spread of the attack within the company and externally, the company shut down all networks and servers. Later reports stated that at this point, some of the data had already been tapped and encrypted. Stellantis, Volkswagen, Audi, BMW among the automakers that could be impacted.
UPDATE July 2022,: Automotive News reports that the company is finally eliminating the remaining effects from its 80 sites worldwide. The attack cost the company a “mid-double-digit million amount,” Eberspaecher CEO Martin Peters told journalists.
Reference: Eberspaecher Reveals Details of $60 Million Cyberattack
Reference: Eberspaecher says ‘most’ plants delivering parts to customers amid cyberattack
Reference: HACKER ATTACK ON EBERSPÄCHER GROUP
Victim: Eberspächer Group
Eberspächer Group employs more than 10,000 workers (2022), operates production plants in 80 locations across 28 countries, and is known for building air conditioning, heating, and exhaust systems, which it supplies to almost all of today’s top car brands.
Reference: Automotive supplier breached by 3 ransomware gangs in 2 weeks
Incident: Cyberattack on South Denver Cardiology Associates (SDCA) Affects 287,000 Patients
South Denver Cardiology Associates (SDCA) announced it was the victim of a cyberattack in January 2022. Files containing protected healthcare information of thousands of thousands of heart patients were accessed and potentially stolen by hackers. Unusual network activity was detected on January 4, 2022, and the SDCA breach response process was immediately initiated. Systems were isolated from the network and shut down. The breach has been reported to the HHS’ Office for Civil Rights as affecting up to 287,652 individuals.
Reference: Maui ransomware operation linked to North Korean ‘Andariel’ hackers
Victim: South Denver Cardiology Associates
South Denver Heart Center.
Reference: South Denver Cardiology Associates Confirms Data Breach Affecting 287,000 Patients
Victim: Kansas Heart Hospital
Specialized cardiovascular healthcare.
Malware: Maui ransomware
Maui ransomware started attacks in April 2021 (based on build timestamps), maintaining an apparent focus on healthcare organizations in the United States. In Aug22 researchers at Kaspersky made the link between Maui and Andariel, attributing it with medium confidence.
Malware: GwisinLocker Ransomware
Ransomware family 'GwisinLocker' targets South Korean healthcare, industrial, and pharmaceutical companies with Windows and Linux encryptors, including support for encrypting VMware ESXi servers and virtual machines.
Incident: Globant IT and Software Consultancy Stolen Data Leaked by Lapsus$ Extortion Group
IT and software consultancy firm Globant confirmed a data breach by the Lapsus$ data extortion group. Stolen data, consisting of administrator credentials and source code, was leaked by the threat actors. The hacking group released a 70GB archive describing it as “some customers source code.”
Victim: Globant
Globant is an IT and software development firm with over 16,000 employees worldwide and $1.2 billion in revenue for 2021. Founded in Buenos Aires, Argentina and currently headquartered in Luxembourg. Globant boasts a well-known list of customers, including Metropolitan Police, SmileDirectClub, Autodesk, Electronic Arts, Santander, Interbank, Royal Carribbean, and many more.
Reference: Globant confirms hack after Lapsus$ leaks 70GB of stolen data
Incident: Court of Córdoba’s Infrastructure in Argentina Hit by PLAY Ransomware Attack
Argentina's Judiciary of Córdoba has shut down its IT systems after suffering a ransomware attack. The attack was reportedly at the hands of the new 'Play' ransomware operation and caused the Judiciary to shut down IT systems and their online portal. The outage is also forcing the use of pen and paper for submitting official documents.
The Judiciary confirmed that it was engaged with Microsoft, Cisco, Trend Micro, and local specialists to investigate the attack.
Reference: Argentina’s Judiciary of Córdoba hit by PLAY ransomware attack
Malware: PLAY
The PLAY ransomware operation that launched in June 2022, belongs to a very notorious type of malware family. The ransomware appends the ".Play" extension to encrypted files.
Victim: Judiciary of Córdoba, Argentina
Court of Córdoba
Reference: Argentina’s Judiciary of Córdoba hit by PLAY ransomware attack
Incident: Cisco Hit in Cyber Attack, Data Taken
Cisco discovered a security incident May 24 targeting its corporate IT infrastructure, and took immediate action to contain and eradicate the attackers, officials said. Cisco disclosed the incident Wednesday because the attackers published a list of files from the incident to the dark web. In light of the attack, Cisco did not report any impact to its business, including it products, services, customer data, employee information, intellectual property or supply chain operations.
Cisco did say since the attack, the company has taken steps to remediate the impact of the incident and further harden its IT environment. In addition, the tech giant said no ransomware has been observed or deployed and Cisco has successfully blocked attempts to access Cisco’s network since discovering the incident.
Updated report in September '22 : The Yanluowang leader is claiming Cisco is downplaying the severity of the attack, telling BleepingComputer “that they stole thousands of files amounting to 55GB and that the cache included classified documents, technical schematics, and source code.” At least one Cisco partner said that the Yanluowang ransomware gang attack against Cisco is another sign of the difficulty of securing a large global enterprise in the wake of the post-pandemic work-at-home era. In a blog post, Cisco said “initial access” to the Cisco VPN was achieved “via the successful compromise of a Cisco employee’s personal Google account.”
Reference: Cisco Hacked: Ransomware Gang Claims It Has 2.8GB Of Data
Reference: Cisco Suffers Attack, Data Stolen
Victim: Cisco
American-based multinational technology conglomerate corporation headquartered in San Jose, California.
Incident: Foxconn Hit in Ransomware Attack for Second Time
Smartphone manufacturing giant Foxconn is recovering from a May ransomware attack that disrupted operations at one of its Mexico-based production facilities, officials said. This is the second attack the company suffered in two years. The LockBit ransomware group claimed to have attacked the company’s offices in Tijuana and threatened to leak the data stolen during the attack by June 11.
The affected production plant is Foxconn Baja California, located in the city of Tijuana, MX, which specializes in the production of medical devices, consumer electronics and industrial operations.
Dragos claimed plant was down for two weeks, without mentioning their source.
Reference: Foxconn confirms ransomware attack disrupted production in Mexico
Reference: Foxconn Recovering from Ransomware Attack, Again
Incident: NHS 111 Emergency Line Hit by Cyberattack
A cyberattack at UK company Advanced causing a software outage affected NHS 111 digital services. The attack targeted Adastra clinical patient management software. Adastra is used to refer patients for care, including ambulances being dispatched, out-of-hours appointment bookings and emergency prescriptions. Advanced has indicated the issue might not be fully resolved until next week. According to NHS England, 111 services are still available. However, the Welsh Ambulance Service has warned that 111 calls may take longer to answer. In addition, NHS England warned that GPs could see an increase in the number of patients.
Victim: Advanced Computer Software Group Ltd.
Operating as Advanced British private company (2008), provides information technology services including hosting and cloud based systems to the NHS and many other organizations.
Through acquisitions it became the third largest software provider in the UK market in 2016 with 2400 employees and more than 20,000 customers.
Reference: NHS 111 software outage confirmed as cyber-attack
Reference: UK NHS suffers outage after cyberattack on managed service provider
Victim: German Chambers of Industry and Commerce (DIHK)
DIHK is a coalition of 79 chambers representing companies within the German state, with over three million members comprising businesses ranging from small shops to large enterprises in the country.
Incident: Cyberattack Takes German Chambers of Industry & Commerce Largely Offline
The German Chambers of Industry and Commerce (DIHK) association shut down all of its IT systems and switched off digital services, telephones, and email servers, in response to a cyberattack. A short statement published on the DIHK site describes the shutdown as a precaution and a way to give IT teams time to develop a solution and build up defense. The General Manager of DIHK, Michael Bergmann, informed the public via a LinkedIn post that the cyberattack occurred Wednesday August 3 and characterized the incident as 'massive."
Reference: German Chambers of Industry and Commerce hit by ‘massive’ cyberattack
Incident: Blackcat / ALPHV Ransomware Attack Hits Luxembourg-based Critical Infrastructure Companies
A ransomware gang with direct ties to the group behind last year’s attack on Colonial Pipeline has struck again. This time hitting a Luxembourg-based critical infrastructure companies pipeline Creos and electricity operator Enovos. Encevo, the parent company of both business units, said data was exfiltrated during the attack between July 22 and 23, rendering the customer portals of Creos and Enovos non operational. The company said electricity and gas are still flowing to customers without interruption.
Threat actor ALPHV, also known as BlackCat, claimed responsibility for the attack on July 29 . In a post on a leak site, the group claims it exfiltrated 180,000 files totaling 150 gigabytes from Creos and threatened to publish the data. The group said the data includes contracts, agreements, passports, bills, and emails.
Reference: Luxembourg energy supplier Encevo hit by ransomware attack
Reference: Encevo Cyberattack
Reference: ALPHV/BlackCat ransomware gang claims to have stolen data from Creos Luxembourg S.A.
Victim: Encevo, parent company of Creos
The company is based in Luxembourg and operates CREOS, a natural gas pipeline, and ENOVOS electricity network in five European countries.
Incident: ‘Massive’ Cyberattack on Government Services in Albania
Albania has come under a “massive cybernetic attack”. Albanians were unable to use scores of government services on Monday July 18, as the main servers went down, following what the authorities called 'a synchronised criminal attack from abroad'. The main servers of the National Agency for Information Society were all down after being hit. “Albania is under a massive cybernetic attack that has never happened before. This criminal cyber-attack was synchronized… from outside Albania,” the Council of Ministers said in a press release. The government recently closed desk services for the population and ordered mandatory use of its online services for everything from enrolling in school to obtaining an ISBN number for a new book at the National Library. However, several important services, such as online tax filing, are still working, as they use separate servers.
Reports later on suggests the attack to be of Iranian origin: "Research published by the threat intelligence firm Mandiant attributes the attack to Iran."
Malware: ROADSWEEP
ROADSWEEP is a ransomware tool, which upon execution will enumerate files on the device and encrypts the content in blocks using RC4. Window API names, malware configuration parameters, and the basis of a ransomware note are RC4 encrypted within ROADSWEEP. During execution, ROADSWEEP will decrypt these encrypted strings and dynamically resolve necessary imports. ROADSWEEP was reportedly used in the July 2022 attack on Albanian government systems.
Victim: Albanian National Agency for Information Services
Albanian government agency.
Reference: Likely Iranian Threat Actor Conducts Politically Motivated Disruptive Activity Against Albanian Government Organizations
Reference: Albania Blames ‘Massive Cyber Attack’ as Govt Servers go Down
Incident: Semikron ‘Holding Production’ after Cyber Attack
A German semiconductor maker with a focus on industrial automation systems and electric vehicles said it suffered a cyber-attack that resulted in data encryption, and as a result is “holding our production.”
Nuremberg, Germany-based Semikron, which claims to power 35 percent of the wind turbines installed globally each year, fell victim to the attack, the company said Monday. As a result of the attack on its IT system, the company is halting production for the time being.
“Due to the cyber incident, we are currently holding our production,” Semikron said in a statement to its customers on Thursday. As long as we cannot guarantee clearance of the cyber-attack completely from our systems, we will not have access to our landline or E-mail communication. We are however still reachable via our business mobile contacts.”
Reference: Semiconductor manufacturer Semikron hit by LV ransomware attack
Reference: Chip Maker Hit in Cyber Attack, ‘Holding Production’
Threat Actor: LV
LV ransomware has been operating since 2020 and uses a modified variant of REvil ransomware, according to cybersecurity company Secureworks.
Malware: LV
LV ransomware has been operating since 2020 and uses a modified variant of REvil ransomware, according to cybersecurity company Secureworks.
Victim: Semikron
Nuremberg, Germany-based Semikron claims to power 35 percent of the wind turbines installed globally each year. Semikron has more than 3,000 employees in 24 offices and eight production sites worldwide across Germany, Brazil, China, France, India, Italy, Slovakia and the United States.
Incident: Ransomware Attack at German Supply Chain & Logistics Giant
A cyberattack forced Hellman Logistics to temporarily remove all connections to their central data center. The company said the shut down was having a "material impact" on their business operations. "Operations will be restored step by step, with the security and integrity of the systems as the top priority."
BleepingComputer reported last week that ransomware group RansomEXX has claimed responsibility for the attack. After negotiations with Hellmann fell apart, the group published 70.64 GB of stolen documents on their leak site that included business agreements, intra-company emails, and more, the outlet explained. They added that the leaks explained the increase in scam calls.
Malware: RansomEXX
RansomExx is a ransomware variant that debuted as Defray777 in 2018. It made a name for itself in 2020, after it was used in widely reported attacks on government agencies, manufacturers, and other such high-profile only months apart. By then, it was dubbed RansomEXX after the string “ransom.exx” was found in its binary. In 2020, the group also started a leak site for publishing stolen data.
Threat Actor: Gold Dupont
A financially motivated cybercriminal group active since 2018. Their main arsenal includes RansomEXX or Defray777, Cobalt Strike, Metasploit, and Vatet Loader.
GOLD DUPONT establishes initial access into victim networks using stolen credentials to remote access services like virtual desktop infrastructure (VDI) or virtual private networks (VPN).
Reference: German logistics giant Hellmann reports cyberattack
Reference: Logistics giant warns of BEC emails following ransomware attack
Victim: Hellman Worldwide Logistics
Hellmann Worldwide Logistics is one of the largest international logistics providers, providing air and sea freight, rail and road transportation, and other services. Hellmann Worldwide Logistics is represented in 56 countries with 263 branches with 10,601 employees. Through the network, the company has access to 437 offices in 162 countries and handles approximately 16 million shipments per year, and in 2020, it reported revenues of $2.8bn.
Incident: RansomHouse Gang Claims Attack on Largest Supermarket Chain in Africa
Shoprite has been hit by a ransomware attack. On June 10 the company disclosed that they suffered a security incident. RansomHouse, a ransomware gang, has claimed responsibility for the cyberattack, which compromised customer data in Eswatini, Namibia and Zambia. Shoprite said the data breach “included names and ID numbers but no financial information or bank account numbers.”
In messages posted on RansomHouse’s Telegram channel and seen by TechCrunch, the gang, which is said to be targeting companies with weak security, claimed to have obtained 600 gigabytes of data from Shoprite. It said to have collected personal data that was “in plain text/raw photos packed in archived files, completely unprotected.”
Reference: Ransomware ring claims attack on Africa’s largest retail chain Shoprite
Victim: Shoprite
Shoprite is Africa's largest supermarket chain, with a revenue of $5.8 billion and 149,000 employees. The retailer has 2,943 stores, serving millions of customers in South Africa, Nigeria, Ghana, Madagascar, Mozambique, Namibia, DRC, Angola, and other countries. The company's headquarters are in Brackenfell in the Western Cape province of South Africa.
Reference: Extortion gang ransoms Shoprite, largest supermarket chain in Africa
Incident: RansomHouse Databreach Extracted 450 GB of Data at Chipmaker AMD
After the last few years of disruption and amid the global chip shortage, the company has been attacked by the RansomHouse Extortion Group, which claims to have exfiltrated more than 450 GB of data. The RansomHouse gang did not initially release samples, but AMD acknowledged the breach.
"No, we haven't reached out to AMD as our partners consider it to be a waste of time: it will be more worth it to sell the data rather then wait for AMD representatives to react with a lot of bureaucracy involved," a RansomHouse representative told BleepingComputer. RansomHouse claims that the stolen data includes research and financial information, which they say is being analyzed to determine its value.
The threat actors have not provided any proof of this stolen data other than a few files containing information allegedly collected from AMD's Windows domain. This data includes a leaked a CSV containing a list of over 70,000 devices that appear to belong to AMD's internal network, as well as an alleged list of AMD corporate credentials for users with weak passwords, such as 'password', 'P@ssw0rd', 'amd!23', and 'Welcome1.'
Victim: AMD – Advanced Micro Devices
Advanced Micro Devices, Inc. is an American multinational semiconductor company based in Santa Clara, California, that develops computer processors and related technologies for business and consumer markets.
Threat Actor: RansomHouse Extortion Group
RansomHouse extortion group gets into victims' networks by exploiting vulnerabilities to steal data and coerces victims to pay up, lest their data is sold to the highest bidder. And if no criminal is interested in buying the data, the group leaks it on their leak site.
"We believe that the culprits are not the ones who found the vulnerability or carried out the hack, but those who did not take proper care of security. The culprits are those who did not put a lock on the door leaving it wide open inviting everyone in," the RansomHouse threat actors write on their 'about us' page.
Incident: Major Supply Chain Breach Involving the SolarWinds Orion System.
Over 18,000 SolarWinds customers installed malicious updates in three versions of its Orion monitoring and management software, with the malware spreading undetected. Through this code, hackers accessed SolarWinds’s customer information technology systems, which they could then use to install even more malware to spy on other companies and organizations.
The SolarWinds hack was a major event because it triggered a much larger supply chain incident that affected thousands of organizations, including tech giants and U.S. government agencies.
Threat Actor: Nobelium hacking group
Nobelium is the hacking division of the Russian Foreign Intelligence Service (SVR), commonly known as APT29, The Dukes, or Cozy Bear. The Russian state hackers have been observed using the FoggyWeb backdoor in the wild since April 2021.
Reference: AMD investigates RansomHouse hack claims, theft of 450GB data
Reference: AMD Latest Victim of RansomHouse Gang
Editorial: SolarWinds: How To React During A Crisis
Incident: Entire Network of Large Australian Prison Security Firm Hacked
A ransom attack compromising G4S’s nationwide database impacted the Port Phillip Prison in Melbourne’s west computer systems. “G4S Australia Holdings have confirmed the incident involves data stored on their national corporate IT network,” the spokesperson said. The Port Phillip prison run by G4S, which currently houses 1000 inmates, has increased security and suspended prisoner visits.
Mount Gambier prison also has been caught up in the cyber-attack made on its operator G4S, the incident involved data from its national corporate IT network. Although the attack occurred at Port Phillip prison, the hacker was able to access the company’s entire network in Australia.
October '23 update: “Since the first detection of the incident, we took immediate action to contain the situation by shutting down our local network" a G4S spokesperson said. G4S told current and former employees on Tuesday that it had been the subject of “a cyber incident” that gave an unauthorized third party, “or malware program”, access to G4S systems.
Reference: Apetito, Exela and G4S among seven alleged victims of ransomware gang Hive
Victim: G4S, Australia
G4S is a nationwide security company, operating Victorian correctional facilities as well as the South Australian facility.
Reference: South Australian Prison caught up in cyber attack
Reference: Port Phillip Prison: Melbourne jail targeted by anonymous hackers in sophisticated cyber attack
Incident: Hive Ransomware Note Demands £500,000 from Wooton Upper School, UK
Ransomware thieves are demanding £500,000 after an attack against Wooton Upper School in Bedfordshire, said press reports this week. The attack, said to be the work of the Hive ransomware group, also affected the Kimberley college for 16-19-year-olds. Both of these organizations are part of the Wootton Academy Trust.
The cyber-criminal group reportedly messaged students and parents, informing them that they had compromised the Trust’s networks several weeks ago. It stole home addresses, bank details, medical records and even students’ psychological reviews. The Hive group believes that Wooton has £500,000 in cyber insurance, according to local newspaper Bedford Today. It has threatened to release all of the data unless the Trust pays up.
Reference: Ransomware Group Demands £500,000 From School
Victim: Wooton Academy Trust.
An education management company. Wooton Upper School and Kimberley college are both part of the company.
Incident: Chemical Distribution Company Brenntag paid $4.4M Ransom to Darkside Gang
Chemical distribution company Brenntag paid a $4.4 million ransom in Bitcoin to the DarkSide ransomware gang to receive a decryptor for encrypted files and prevent the threat actors from publicly leaking stolen data.
At the beginning of May 2021, Brenntag suffered a ransomware attack that targeted their North America division. As part of this attack, the threat actors encrypted devices on the network and stole unencrypted files. From the information shared with BleepingComputer by an anonymous source, the DarkSide ransomware group claimed to have stolen 150GB of data during their attack. To prove their claims, the ransomware gang created a private data leak page containing a description of the types of data that were stolen and screenshots of some of the files.
Reference: Brenntag sheds light on DarkSide ransomware attack
Victim: Brenntag SE
Brenntag SE is a German chemical distribution company founded in 1874 in Berlin. The company is headquartered in Essen, Germany and has operations in more than 78 countries worldwide.
Reference: Chemical distributor pays $4.4 million to DarkSide ransomware
Incident: Cyberattack at MCG Health Affected over 1.1M Patient Records, Lawsuits Filed.
More than 10 U.S. health care systems were breached during a cyberattack of Seattle-based MCG Health, affecting up to 1.1 million patients, HIPAA Journal reports. MCG Health, a subsidiary of Hearst Health, is facing multiple class-action lawsuits as a result of the breach, during which an “unauthorized third party” obtained patient files that included names, Social Security numbers, medical codes, mailing addresses, telephone numbers and email addresses. The lawsuits allege MCG Health acted negligently by failing to recognize the breach for at least two weeks - while one lawsuit alleges hackers gained access to data 2 years before the hack was discovered.
Reference: MCG Health Data Breach Impacts 8 Organizations, 793K Individuals
Reference: Multiple Class Action Lawsuits Filed Against MCG Health Over Data Breach
Victim: MCG Health
MCG is part of the Hearst Health network. The company provides an assessment of research and scholarly articles, along with data analysis, to give patients, providers, and payers information to make care decisions. MCG, formerly known as Milliman Care Guidelines, initially a wholly owned subsidiary of Milliman Inc., has produced evidence-based clinical guidelines since 1990.
Incident: 2021 Benson Health Breach Affected 29,000 Patients.
North Carolina-based Benson Health began notifying 28,913 individuals of a healthcare data breach. On May 5, 2021, Benson Health discovered that an unauthorized party had attempted to gain access to Benson Health’s computer network. Further investigation revealed that the unauthorized party potentially accessed a dataset containing names, birth dates, Social Security numbers, and health and treatment information.
Benson Health’s investigation concluded on July 7, 2022, more than a year after the initial incident. Benson Health is providing individuals affected by the incident with free single-bureau credit monitoring services. HIPAA requires covered entities to notify impacted individuals of a healthcare data breach within 60 days of discovery.
Victim: Benson Health, NC
Benson Health is a medical group practice located in Benson, NC that specializes in Family Medicine and Nursing (Nurse Practitioner).
Reference: Data Breach Notifications (Office of the ME Attorney General)
Incident: Over 38 Vision Practices Report Data Breaches Involving Eye Care Leaders EHR Incident
Eye Care Leaders, which offers an ophthalmology-specific EMR solution, experienced unauthorized access to its myCare Integrity system in December 2021. Since ECL began notifying impacted organizations of the breach, organizations have been steadily contributing reports to HHS’ Office for Civil Rights (OCR) data breach portal. The hack compromised data of millions of patients.
The types of information that have been exposed included patient names, dates of birth, medical record numbers, health insurance information, Social Security numbers, and information regarding the care received at the affected eye care practices. The breach was confined to the myCare Identity solution.
Reference: Breach at Eye Care Software Vendor Hits Millions of Patients
Reference: Eye Care Leaders Hack Impacts Millions of Patients
Reference: Cloud-Based EHR Vendor Hack Affects Eye Care Practices
Reference: Eye Care Leaders EMR Data Breach Tally Surpasses 2 Million
Victim: Eye Care Leaders
Eye Care Leaders provides eye care solutions. The Company focuses on delivering solutions, services, and software to ophthalmology practices such as revenue cycle, electronic health records, practice management, patient retention, patient reactivation, patient portal, capital financing, and analytics. Eye Care Leaders operates in the United States.
Incident: Theft of Member Data Reported in ADA Ransomware Attack
ADA suffered a cyberattack that forced them to take affected systems offline. Online services were inaccessible, including the ADA Store, the ADA Catalog, MyADA, Meeting Registration, Dues pages, ADA CE Online, the ADA Credentialing Service, and the ADA Practice Transitions. As a result the cyberattack also affected state dental associations who rely on ADA's online services to register an account or pay dues, such as those in New York, Virginia, and Florida,
Black Basta has claimed responsibility for the attack, and soon after begun leaking approximately 2.8 GB of data, including W2 forms, NDAs, accounting spreadsheets, and information on ADA members, which the threat actors claimed to be 30% of the data stolen in the attack.
Victim: American Dental Association [ADA]
ADA is a dentist and oral hygiene advocacy association providing training, workshops, and courses to its 175,000 members.
ADA Accepted seal appears on oral hygiene products, such as toothpaste and toothbrushes, indicating that the product is safe and contributes to oral health.
Reference: Cyberattack Strikes the ADA
Reference: American Dental Association hit by new Black Basta ransomware
Reference: 37,800 people sent privacy breach notifications linked to N.L. cyberattack
Incident: Ransomware Attack Ultimately Causes Closure of Lincoln College in Illinois.
A cyber-attack proves to be the final nail in the coffin for a US college battling financial crisis. Lincoln University, founded in 1865 and home to a Black student body, shut its doors on May 13. The rural institution in Illinois has been experiencing economic difficulties as a result of Covid-19’s effect on recruitment and funding.
According to the Chicago Tribune, an assault by a cyber group in December dealt the last blow to the institution. The group’s hack encrypted vital information, rendering it harder for officials to conduct “enrollment, retention, as well as fund-raising initiatives,” according to a notice lately posted on the school’s website. Lincoln College reportedly paid a $100,000 ransom to the hackers, but they were ultimately unable to fully recover from the attack.
Victim: Lincoln College, IL
Lincoln College, founded in 1865, was a four-year private, liberal arts college located in Lincoln, Illinois.
Reference: When a Ransomware Attack Sends Students Home
Reference: IOTW: Cyber-attack forces Lincoln College to close
Reference: Ransomware’s prime target: Schools and universities
Incident: Ransomware Attack Hits Entire Canadian Town of St. Mary’s
The cyber incident locked and encrypted its internal server. St. Marys officials first became aware of the attack around 11 a.m. Wednesday 20 July, prompting staff to lock down the town’s IT systems and isolate its network to prevent any further damage, said Mayor Al Strathdee. “Since that time, we realized that it is a malware attack. There was a message asking for ransom,” he said.
According to cybernews.com, a group known as LockBit has taken responsibility for the recent ransomware attack, listing the small Southwestern Ontario town among its victims in a post on the dark web and is allegedly threatening to release troves of sensitive information if the Perth County town doesn’t pay up.
Victim: Town of St. Mary, ON, Canada
St. Marys is a town in southwestern Ontario, Canada and operates under its own municipal government that is independent from the county's government. The town is also known by its nickname, "The Stone Town", due to the abundance of limestone in the surrounding area.
Reference: Infamous cyber gang demanding ransom from St. Marys: Report | #malware | #ransomware
Reference: St. Marys, Ont. grapples with cyberattack as ransomware group threatens to publish stolen data
Reference: NOTORIOUS RANSOMWARE GANG EXTORTS SMALL CANADIAN TOWN
Reference: An Entire Canadian Town Is Being Extorted By Ransomware Cyber Criminals
Incident: Cyber Attack at Entrust Security Provider
Minneapolis, MN-based security provider, Entrust, suffered a cyber attack last month where some data ended up stolen.
Entrust provides security solutions for user and machine identities, payments, and digital infrastructure.
Todd Wilkinson, entrust president and chief executive released a statement discussing the incident.
“I am writing to let you know that on June 18, we learned that an unauthorized party accessed certain of our systems used for internal operations. We have been working tirelessly to remediate this situation since that moment."
Reference: SECURITY VENDOR ENTRUST: HACKERS STOLE ‘SOME FILES’ DURING RECENT DATA BREACH
Reference: Security Firm, Entrust, Hit In Cyber Attack
Victim: Entrust
Entrust provides security solutions for user and machine identities, payments, and digital infrastructure
Reference: Cyber attack on subsidiary: Entega customer data published en masse on the dark web
Incident: Energy Supplier Entega’s Customer Data Posted on the Dark Web after Ultimatum Expired
Hacker attacks paralyzed the websites of the regional utility Entega and the municipal utility Stadtwerke Mainz. There is no fear of supply interruptions for private and commercial customers, as these systems are separately secured.
At the same time as Entega, the lights also went out on the Stadtwerke Mainz website. Both companies are managed by their joint subsidiary, the IT service provider Count+Care. The malware got into the system because an employee had accidentally opened an email attachment. Entega's website and e-mail server were paralyzed as a result. The systems of the Darmstädter Bauverein and the Frankfurt utility company FES were also affected by the attack on Count+Care, an Entega subsidiary.
To repair the damage, the hackers apparently demanded a ransom of 15 million euros. Entega let the ultimatum expire without paying, and much of the customer data was leaked on the dark web. An Entega spokesman said the majority of customers could be affected, but to varying degrees. The investigation into the stolen data is still ongoing. According to Entega's annual report, the number of customer contracts at the end of 2021 was almost 700,000.
According to information from the Frankfurter Rundschau, the hacker gang "Black Cat" is said to be behind the attacks. The newspaper relies on information from an insider. "Black Cat" was recently also responsible for attacks on the IT systems in the Austrian state of Carinthia , where they also demanded a ransom.
Victim: Entega AG
Entega AG provides utility services. The Company offers generation, transmission, and distribution of electricity, natural gas, water, and heat, as well as waste disposal, construction, telecommunications, and other infrastructure services. Entega serves customers in Germany.
ENTEGA subsidiaries include Mainzer Stadtwerke AG and COUNT+CARE- an information technology and services company.
Reference: 15 million euros ransom demanded – Entega did not pay
Reference: Hackers knock out two German energy suppliers
Reference: ENERGY SUPPLIER ENTEGA HACKED – DATA IS ON THE DARK WEB
Reference: Hackers attack Entega and Mainz public utilities
Incident: Staff Members Personal Data Potentially Compromised in Cedar Rapids School District Cyberattack.
In the wake of a cybersecurity breach, an Iowa school district put programs on hold while investigators ascertain whether the incident was a ransomware attack or a data breach. The district suspended its summer programs because of the cybersecurity breach.
Data theft may have included staff members' names, Social Security numbers, driver's license numbers, bank account and routing numbers and medical information.
Reference: District notes reveal new details of cyber attack at Cedar Rapids Schools
Reference: Personal Info May Have Been Stolen from Cedar Rapids Schools
Reference: Cedar Rapids Suspends Summer Programs Amid Cyber Investigation
Victim: Cedar Rapids Community School District
A public school district located in Cedar Rapids, Iowa. It has the second largest enrollment in the state of Iowa. The district has 21 elementary schools, 6 middle schools, 3 high schools, and 1 alternative high school. The district is in Linn County
Reference: SHI CYBERATTACK: ‘VAST MAJORITY’ OF SYSTEMS NOW ‘FULLY OPERATIONAL’
Incident: SHI International takes systems offline after malware attack
SHI International has confirmed that a malware attack hit its network over the 4th July weekend. SHI is a New Jersey-based provider of Information Technology (IT) products and services.
The company said in a statement: "SHI was the target of a coordinated and professional malware attack. Measures were enacted to minimize the impact on SHI's systems and operations. We are liaising with federal bodies including the FBI and CISA and there is no evidence to suggest that customer data was exfiltrated during the attack."
Reference: SHI INTERNATIONAL MALWARE ATTACK: 5 BIG THINGS TO KNOW
Victim: SHI IT Services
SHI IT Services provides information technology products and services. The Company offers program assistance, reporting and tracking, configuration, software licensing, and information technology asset management services. SHI International serves customers worldwide.
SHI claims to be one of North America's largest IT solutions providers, with $12.3 billion in revenue in 2021 and 5,000 employees around the world in operations centers in the U.S., the United Kingdom, and the Netherlands. It also says it provides services to over 15,000 corporate, enterprise, public sector, and academic customer organizations worldwide.
Reference: IT services giant SHI hit by “professional malware attack”
Incident: Rhode Island Sewer System Operator Hit by Cyberattack
he Narragansett Bay Commission, which runs sewer systems in parts of the metropolitan Providence and Blackstone Valley areas, was hit by a ransomware attack on its computer systems. A spokeswoman for the commission acknowledged the attack in a Friday evening email to The Providence Journal.
"Last week, the Narragansett Bay Commission identified a cybersecurity incident that involved the encryption of data on certain computers and systems in its network," spokeswoman Jamie R. Samons said in the email. While she did not specify a ransomware attack, such attacks typically involve hackers encrypting data on a victim's computer system and refusing to supply the key to decode the data until a ransom is paid.
Samons did not reply to a follow-up email asking whether a ransom was paid. She did note that the systems hit by the attack are not ones that control the operation of the sewage system.
Victim: Narragansett Bay Commission, RI
Runs sewer systems in parts of the metropolitan Providence and Blackstone Valley areas in Rhode Island, USA
Reference: Rhode Island sewer-system operator hit by cyber attack
Incident: Largest Building Material Producer Attacked by Black Basta Ransomware Group
The Knauf Group ransomware attack took place on June 29, 2022. The incident resulted in emails as well product-ordering software being taken offline, the company said in a series of updates for customers.
As ever, the extent of the compromise was hard to ascertain from the outside, with systems being rapidly shut down in the wake of the attack in a bid to contain its impact: “Many of our systems and email communication are fully functional again, other areas are currently being restarted” it said on July 20, but was still directing customers to rapidly spun up alternative PDF forms for product orders as The Stack published on July 20.
The incident could not have come at a worse time for a construction industry already embattled by supply chain issues and rampant inflation in the wake of the pandemic, which caused raw material shortages for a huge range of construction materials – plasterboard prices were reported as set to soar up to 25% in July '22.
Threat Actor: Black Basta Group
First discovered in April 2022, hitting almost 50 organization in the months after.
Victims include manufacturing, utilities, transport, and government agencies in countries around the world including the United States, UK, India, Canada, Australia, New Zealand, and UAE.
Recently, VMWare ESXi variants of Black Basta have been discovered that target virtual machines running on Linux servers, alongside the versions which infect Windows systems.
In addition, many of the attacks have made use of Qakbot (also known as QBot) to help it spread laterally through an organisation, perform reconnaissance, steal data, and execute payloads. Furthermore, a group policy object is created on compromised domain controllers to disable Windows Defender and anti-virus solutions. [source: tripwire.com]
Reference: Plasterboard giant Knauf Group pummelled by ransomware
Reference: Construction Giant Knauf Hit with Ransomware
Victim: Knauf Gips KG
Knauf, a family-owned company based in Iphofen, Germany, is one of the world's largest producers of building materials and construction systems.
The German multinational, which has 300 factories and a footprint in 90 countries, employs 40,000 including in the UK at plasterboard manufacturing facilities in Sittingbourne, Kent, and North East Lincolnshire. It is owned by one of Germany’s richest families and makes insulation, plasterboard, cement board, plaster and other products.
Reference: Building materials giant Knauf hit by Black Basta ransomware gang
Reference: System In Goa, India – Perspective From Industry Leaders
Reference: Cyber attackers strike flood monitoring system in Goa, India
Incident: Indian Flood Monitoring System Targeted by Hackers
A Ransomware attack hit Goa’s flood monitoring system according to the Hindustan Times, which reports that the state government’s water resources department that maintains the data said that all its files have been encrypted and can no longer be accessed.
The data center server in Panaji stores the data of 15 flood monitoring systems on major rivers in the Goa region, as part of disaster management and flood control. Access is unavailable to data relating to batteries and to real time monsoon activity.
Reports are in that the servers of Flood Monitoring System were hit by the file-encrypting malware on June 21st,2022 and the hackers are demanding BTC in double-digit figures to free data from encryption. The department reportedly has no dedicated IT staff or security professional to react to such situations. Officials are not interested in paying a ransom to hackers and are sure to recover the locked-up data by other means.
Victim: Water Resource Department (WRD), Goa, India
Government Department of Water Resources. - The Goa’s Flood Monitoring System is installed at 15 places, is connected to all major rivers in the state, and is consolidated at a data center in Panaji.
Reference: Hackers target WRD’s flood monitoring system
Reference: Ransomware Attack on Indian flood monitoring system and demand Bitcoins
Incident: Largest Crypto Hack against a Decentralized Finance Network Hit Ronin Network (RON) Blockchain Network.
Earlier in March this year, Ronin Network (RON), a blockchain network underpinning the famous crypto game Axie Infinity and Axie DAO suffered the largest crypto hack against a decentralized finance network reported to date.
In May 2022, the United States issued an advisory according to which highly skilled hackers from North Korea were trying to get employed by posing as IT freelancers. Now, it has been revealed that Axie Infinity hacking was socially engineered in which North Korean government-backed hacker group Lazarus used a fake job offer to infiltrate Sky Mavis’ network by sending one of the company’s employees a PDF file containing spyware.
Lazarus’ involvement in such a high-profile hack should not come as a surprise. In January 2022, researchers from different crypto security firms concluded that North Korean hackers have so far stolen $1.3 billion from cryptocurrency exchanges across the globe, while their prime suspect in these hacks was the infamous Lazarus gang.
Reference: U.S. ties North Korean hacker group Lazarus to huge cryptocurrency theft
Victim: Sky Mavis
Sky Mavis is a technology company that creates decentralized applications and services. They specialize in the fields of information technology, blockchain, video game, and more. The Ronin extension allows users to play Axie Infinity and other decentralized applications running on Ronin, an Ethereum sidechain built specifically for Blockchain games.
Threat Actor: Lazarus
A North Korean cyber collective backed by the North Korean government that has, according to Symantec, targeted high-profile organizations in 31 different countries, including Sony and the Bangladesh Bank.
Reference: Hackers Used Fake LinkedIn Job Offer to Hack Off $625M from Axie Infinity
Incident: SpiceJet’s (Low Cost Airline in India) Systems and Operations impacted by Ransomware Attack
Low-cost Indian airline SpiceJet has informed its customers today of an attempted ransomware attack that has impacted some of its systems and caused cascading delays on flight departures. The airline announced on its social media channels that its IT team managed to thwart the attack. However, multiple customer reports on Twitter and Facebook still reflect ongoing problems, highlighting flight delays, saying that customer service via phone is unreachable, and the bookings system remains unavailable.
In 2021, SpiceJet went through severe financial trouble result of grounding its fleet due to COVID-19 restrictions. It is easy to assume that this dire financial situation didn't leave much margin for investing in cybersecurity and incident response, which might be what allowed the ransomware actors in this case to launch a successful attack. (reports Bleepingcomputer.com - link below)
* "planes grounded/delayed >5hrs" based on total downtime of all reports. Actual passenger reports suggest shorter individual delays
Victim: Spicejet,
SpiceJet is SpiceJet is an Indian budget airline headquartered in Gurgaon, Haryana. Ranked as the second-largest airline in India, operating a fleet of 102 aircrafts to serve over 60 destinations. The firm has more than 14,000 employees and holds about 15% of the local market share.
Reference: SpiceJet airline passengers stranded after ransomware attack
Reference: SpiceJet postpones March quarter results after ransomware attack
Reference: SpiceJet: Passengers stranded as India airline hit by ransomware attack
Incident: Baton Rouge General Hit by Cyberattack
General Medical Center had to switch to paper record-keeping after a cyberattack brought its EHR system offline June 28, WAFB reported. "First, and most importantly, the attack has not changed our ability to care for patients," the hospital said in a statement to the TV station posted June 29. "We are continuing to provide patient care at all locations." The medical center added that it is working with state and federal authorities and its security vendors to ensure patient data remains private. Baton Rouge General didn't respond to requests from Becker's for updates.
Reference: Baton Rouge General operations disrupted by cyberattack
Reference: Baton Rouge General responds to cyber attack
Victim: Baton Rouge General
also known as Mid City or The General, is a long term care, not-for-profit, community-owned hospital located in Baton Rouge, Louisiana.
Incident: Cyberattack at Shields Healthcare Group Compromises Personal Medical Data of Millions of Patients
Shields Health Care Group reported a healthcare cyberattack to HHS impacting 2 million individuals. The Massachusetts-based healthcare group provides MRI, PET/CT, and ambulatory surgical services to patients across New England at more than 30 locations.
According to a notice on Shields’ website, the organization discovered suspicious activity on its network on March 28, 2022. Shields immediately launched an investigation and took steps to contain the incident. The investigation revealed that an unknown actor gained access to certain Shields systems from March 7 to March 21. The unknown actor also acquired certain data from the systems.
Shields relies on partnerships with hospitals and medical centres. It is believed that up to 53 separate facilities and their patients are affected.
Victim: Shields Healthcare Group
Medical diagnostic imaging center with more than 30 facilities throughout New England, offering MRI, PET/CT
Reference: Notice of Data Security Incident
Reference: 2 million affected by Shields Health Care Group cyberattack
Reference: 2 Million Individuals Impacted By Shields Health Care Group Cyberattack
Incident: IT & OT Attack forces Macmillan Publishers to Take Operations Offline and Close Physical Offices
Book publisher Macmillan has been hit with what it describes as a “digital security incident”, with experts believing it could be ransomware. According to emails seen by Publishers Weekly, the publisher initially said that a portion of the company’s files had become encrypted and that it had taken all of its systems offline to prevent further compromise. The company’s US sales team confirmed that it was unable to process, receive, place, or ship orders as a result of the company-wide shut down of digital systems and physical offices. The attack also impacted its U.K. branch, known as Pan Macmillan.
The company declined to answer further questions on the nature of the incident or how its systems were compromised, the use of encryption by the hackers indicates that it was ransomware. The attack has not yet been claimed by any major ransomware groups, and it remains unclear whether any sensitive data was stolen.
WSJ reported on July 6 "Macmillan Says Retailers Can Again Order Its Books After Recent Cyberattack" and doesn't anticipate having to change the publishing date of any of its books.
Victim: Macmillan Publishers
With its headquarters in New York, NY, Macmillan Publishers Ltd is a British publishing company traditionally considered to be one of the 'Big Five' English language publishers. Founded in London in 1843 by Scottish brothers Daniel and Alexander MacMillan, the firm would soon establish itself as a leading publisher in Britain.
Reference: Macmillan Says Retailers Can Again Order Its Books After Recent Cyberattack
Reference: Macmillan Publishers hit by apparent cyber attack as systems are forced offline
Reference: US publisher Macmillan confirms cyberattack forced systems offline
Incident: Novartis claims no sensitive data breach in latest cyberattack by Industrial Spy.
June 2022: Pharmaceutical giant Novartis says no sensitive data was compromised in a recent cyberattack by the Industrial Spy data-extortion gang. Industrial Spy is a hacking group that runs an extortion marketplace where they sell data stolen from compromised organizations. On June 2, 2022 the hacking group began selling data allegedly stolen from Novartis on their Tor extortion marketplace for $500,000 in bitcoins. The data being sold consists of 7.7 MB of PDF files, which all have a timestamp of 2/25/2022 04:26, likely when the data was stolen. As the amount of data for sale is minimal, it is not clear if this is all the threat actors stole or if they have further data to sell later.
Novartis declined to answer any further questions about the breach, when it occurred, and how the threat actors gained access to their data.
Threat Actor: Industrial Spy
Industrial Spy is a hacking group that runs an extortion marketplace (Tor extortion) where they sell data stolen from compromised organizations. They are known to use ransomware in their attacks.
Industrial Spy is trying to build a brand for itself as a source of illicit trade secrets for unscrupulous businesspeople around the world. It is designed for non-technical darknet users and makes itself widely available to people who may not be experienced using darknet technologies.
Reference: Novartis is latest victim of cyberattack, but claims no confidential data compromised — report
Reference: Novartis says no sensitive data was compromised in cyberattack
Victim: Novartis
Novartis International AG is a Swiss -American multinational pharmaceutical corporation based in Basel, Switzerland and Cambridge, Massachusetts, United States. It is one of the largest pharmaceutical companies in the world
Reference: 1 year later: How the Colonial Pipeline attack has changed cybersecurity
Incident: Apetito’s Security Systems Breached in Sophisticated Cyberattack
Wiltshire Farm Foods and its parent company, Apetito IT and computer systems have been affected by a cyberattack which is causing problems with deliveries in the short term.
The Trowbridge-based company assured customers that no credit card details have been stolen as they are not kept on its computer system. The company’s CEO Paul Freeston said: “Our Crisis Management and IT teams (assisted by specialist external partners) are working all hours to bring critical systems back into operation as soon as possible. However, we expect substantial disruption in the coming days while we address these issues."
Mr Freeston said that WFF and apetito will be unable to make many deliveries in the next few days. The companies are also unable to contact customers personally as they do not have access to their telephone numbers. The company added: “We expect local Meals On Wheels deliveries made by apetito to continue using our emergency procedures."
Reference: Ready meal distributor Apetito restores ‘limited’ deliveries in UK following cyber-attack
Reference: International criminal cyber attack hits Wiltshire Farm Foods and Apetito
Reference: Wiltshire Farm Foods suffers devastating cyber-attack
Victim: Apetito
Germany-based frozen-food supplier. Meal delivery to Hospitals, Care homes and Schools. Parent company of Wiltshire Farms - a home delivery of frozen meals.
Reference: Frozen-food firm Apetito hit by cyber attack
Incident: Georgia Hospital Takes Computer Systems Offline – Continues to Provide Care.
A cyberattack on Jack Hughston Memorial Hospital has led the Georgia hospital to pull certain systems offline and operate under electronic health record procedures, local news outlets reported Wednesday. It’s unclear the type of attack behind the network outage. Patient care has not been interrupted. At this stage of the investigation, it is unclear if, and to what extent, patient information has been compromised.
Victim: Jack Hughston Memorial Hospital
Hughston Clinic specializes in orthopedic care and operates in AL, FL, GA and TN https://hughston.com/
Reference: Georgia hospital probing cyberattack
Reference: Georgia hospital recovering from cyberattack with EHR downtime procedures
Incident: Cyberattack Disrupts Unemployment Services for Tens of Thousands of People in Multiple US States.
An apparent cyberattack on Florida-based IT provider Geographic Solutions disrupted unemployment and workforce benefits for thousands of people in multiple states and Washington, DC. Unemployment payments are delayed for people in Tennessee, where about 12,000 people rely on the program, and in Nebraska, according to statements from state labor departments. In Washington, the outage has prevented residents from filing new paid family leave claims and conducting job searches using a tool provided by Geographic Solutions. In a statement, Geographic Solutions described "anomalous activity" on its computer network but did not specify the cause; the Nebraska Department of Labor called it a "cyberattack." After discovering the activity, Geographic Solutions "immediately took some systems offline to halt the activity," its statement said. Agencies in several states said they were notified of the problem by GSI on June 26.
The incident is the most recent in a growing pattern of software supply chain attacks, in which cybercriminals target one company with the intention of infecting its partners and clients later on, basically widening the malware's system vulnerabilities.
Reference: Employment and Labor Websites Across the US Are Offline Due to Cyberattack — How Many States are Affected?
Victim: Geographic Solutions (GSI)
Geographic Solutions, Inc. is privately-held corporation headquartered in Palm Harbor, Florida with a west coast office in Salinas, California. "The only vendor to offer a system that combines all aspects of workforce development and unemployment insurance into one solution."
USA's leading provider of software solutions of online employment software for state and local workforce agencies. Clients include more than 35 states and territories.
Reference: Cyberattack shuts down unemployment, labor websites across the US
Reference: Cyberattack Shuts Down Unemployment Services Across US
Reference: Apparent cyberattack disrupts unemployment benefits in multiple states
Malware: SessionManager
SessionManager backdoor allows threat actors to maintain persistent, update-resistant, and fairly stealthy access to a targeted organization’s IT infrastructure. Once inside a victim’s system, cybercriminals behind the backdoor can gain access to company emails, update malicious access by installing other types of malware, or surreptitiously manage compromised servers, which can be leveraged as malicious infrastructure.
SessionManager has been used in the wild without being detected since at least March 2021, right after the start of last year's massive wave of ProxyLogon attacks. Implementing a backdoor within IIS is a trend for threat actors. It has affected government institutions and NGOs around the world with victims in eight countries in the Middle East, Turkey and Africa region including Kuwait, Saudi Arabia, Nigeria , Kenya and Turkey.
Incident: Khuzestan Steel among Plants Hit in Cyber Attack; Production Halts
Khuzestan Steel Co. (KSC) said the plant had to stop work until further notice “due to technical problems” following “cyberattacks.” The company’s website of the major Iranian steel companies was down on Monday.
Hacktivist group or also possibly nation state actor, Predatory Sparrow (Gonjeshke Darande) claimed responsibility. The attackers caused the foundry to spew hot molten steel and fire onto the factory floor, but not until workers had already cleared the area, unbeknownst of what was about to happen. The timing of their attack is deliberate.
A video captured during one of these attacks was shared on their social platforms as proof. It already has 200,000 views.
Predator Sparrow leaked “top secret documents and tens of thousands of emails” and “trading practices” from the steel makers they attacked. Only the hack on KSC resulted in a public acknowledgment of downtime. Not enough details or evidence avail. on MSC and HOSCO attacks.
Reference: Iranian Steel Firm Hit In Attack, Production Stops
Victim: Khuzestan Steel Co.
Khuzestan Steel Co., based in Ahvaz in the oil-rich southwestern Khuzestan province, has a monopoly on steel production in Iran along with two other major state-owned firms.
Founded before Iran’s 1979 Islamic Revolution, the company for decades afterward had some production lines supplied by German, Italian and Japanese companies.
Incident: Nichirin-Flex U.S.A Hit in Ransomware Attack
Japanese automotive hose maker Nichirin Co. said a U.S. subsidiary suffered a ransomware attack June 14 forcing it shut down its computerized production controls.
The U.S. unit, Nichirin-Flex U.S.A, which supplies hoses to Japanese carmakers, switched to manual production and shipping in order to keep parts flowing to customers, it said in a release. The attack occurred June 14, and the company reacted as soon as it detected the unauthorized access on its network and moved operations into manual mode.
Reference: US Subsidiary of Automotive Hose Maker Nichirin Hit by Ransomware
Reference: Auto Parts Supplier Hit In Ransomware Attack
Victim: Nichirin-Flex U.S.A, U.S. unit of Nichirin Co.
Nichirin-Flex U.S.A supplies hoses to Japanese carmakers. The hoses manufactured by Nichirin end up used in brake systems, air conditioning, power steering, and various hydraulic and pneumatic systems. What comes in play is these products are very specialized, so finding replacement vendors isn't simple, and any disruption in their production can cause a domino effect in the auto industry.
Incident: Kaiser Permanente Hit in Attack; 70,000 Records Exposed
Kaiser Permanente, the largest nonprofit health plan provider in the United States, suffered a data breach after an attacker gained access to a worker’s emails which exposed health information of almost 70,000 patients.
In a notice to patients on June 3, Kaiser revealed someone gained access to an employee’s emails at the Kaiser Foundation Health Plan of Washington on April 5 that contained protected health information, including patient names, dates of service, medical record numbers, and lab test result information.
Financially sensitive information, including social security and credit card numbers, was not exposed by the breach, according to the healthcare provider.
Reference: Kaiser Permanente Worker’s Email Hacked; 70,000 Records Exposed
Victim: Kaiser Permanente
Largest nonprofit health plan provider in the United States.
Malware: Meteor
A new file wiping malware called Meteor was discovered used in the recent attacks against Iran's railway system. The attack itself is dubbed 'MeteorExpress,' and utilizes a toolkit of batch files and executables to wipe a system, lock the device's Master Boot Record (MBR), and install a screen locker.
A wiper is malware that intentionally deletes files on a computer and causes it to become unbootable. Unlike ransomware attacks, destructive wiper attacks are not used to generate revenue for the attackers. Instead, their goal is to cause chaos for an organization or to distract admins while another attack is taking place.
Reference: Irish health cyber-attack could have been even worse, report says
Reference: Indra — Hackers Behind Recent Attacks on Iran
Threat Actor: Indra
Indra is a politically motivated group of hackers who has operated since 2019. Indra developed and deployed at least three different variants of a wiper dubbed Meteor, Stardust, and Comet on victims' networks throughout the years since they first surfaced in 2019. Despite this, the group's modus operandi, the quality of their tools, and willingness to claim attacks on social media make it unlikely that Indra is a nation-state sponsored threat actor.
While the group deployed wiper malware on the networks of multiple Syrian organizations, it has managed to stay under the radar until the Iran Rail Attack in 2021 - even though the group has not taken responsibility for this attack on Iran, the multiple similarities in tactics and techniques indicate otherwise.
INDRA’s official twitter account states that they are “aiming to bring a stop to the horrors of QF and its murderous proxies in the region” and they claim to be very focused on attacking different companies who allegedly cooperate with the Iranian regime, especially with the Quds-Force and Hezbollah. Their posts are all written in English or Arabic (both don’t seem to be their native language). The group called themselves Indra, after the Hindu god of war.
Reference: [Press Release] WestRock Provides Update on Ransomware Incident
Reference: Beneteau: “2021 growth almost evaporated in cyber attack”
Incident: Belgian Hospital CHwapi victim of a cyberattack: operations canceled
Cyberattack at Center Hospitalier de Wallonie Picarde (CHwapi) in Tournai, Belgium has left its systems crippled cancelling surgeries for 2 days and diverting emergency cases to other hospitals for one week.
No less than 80 of the 300 computer servers were affected. Since the personal data of the admissions department were no longer accessible, the staff has returned to using pen and paper. No computer theft was committed and no ransom demand was made.
A team from the federal police's Computer Crime Unit was on site to support the hospital's computer specialists.
Reference: Le CHwapi victime d’une cyberattaque: des opérations annulées
Reference: Hospital in Belgium Forced to Redirect Patients Due to Cyberattack
Victim: CHwapi – Center Hospitalier de Wallonie Picarde
Center Hospitalier de Wallonie Picarde (CHwapi) in Tournai, Belgium
Incident: Crypto-virus RYUK Attacks French Hospitals in Lyon Area
Hôpital Nord-Ouest, the hospital group for the North of Lyon, reported two hospitals were stricken with ransomware attacks, and a third pre-emptively cut connections with an IT provider, in less than a week. Surgeries were postponed and emergency patients re-routed to other facilities as each hospital site’s team set up limited procedures to ensure the exchange of information necessary for patient care, as well as a crisis unit to organise the operation of all three sites. The attack by the crypto-virus RYUK, a kind of ransomware, "strongly impacts" the Villefranche, Tarare and Trévoux sites of the North-West Hospital, the hospital said in a statement.
Following the attack, French President Emmanuel Macron said his office plans to inject one billion euros (US$1.21 billion) into the country’s cyberdefense.
Reference: France Plans to Boosts Cyberdefense After Attacks on Hospitals
Reference: Cyber attacks hit two French hospitals in one week
Reference: Several French hospitals crippled by cyberattacks
Victim: Hospital Nord-Ouest
Hôpital Nord-Ouest is the hospital center for the North of Lyon, France. Its 5 hospitals (Villefranche-sur-Saône, Tarare-Grandris, Trévoux, Belleville and Beaujeu) and its 10 nursing homes provide the public health service in the area.
Reference: Cyberattack against Molson Coors pushes production, shipments later into 2021
Reference: Cybersecurity Breach Halts Production of Molson Coors Beer
Reference: Cybersecurity Breach Halts Production of Molson Coors Beer
Reference: Cyberattack against Molson Coors pushes production, shipments later into 2021
Incident: REvil Ransomware Shut Down Multiple Plants at Asteelflash
Asteelflash, a leading French electronics manufacturing services company, has suffered a cyberattack by the REvil ransomware gang who is demanding a $24 million ransom. While Asteelflash has not publicly disclosed an attack, BleepingComputer found this week a sample of the REvil ransomware that allowed access to the Tor negotiation page for their cyberattack. LeMagIT, a French cybersecurity news portal, reported an Asteelflash representative stated that "the incident is being evaluated." Neither BleepingComputer nor LeMagIT could confirm whether the attack was successful in encrypting files on affected systems.
The company's press release states: "Asteelflash has detected a cyber security incident during a routine check by its IT teams. We immediately took action to contain the REvil-type ransomware and limit its spread. We have not been in touch with the Hackers" There are no details about the company's intentions regarding the ransom.
Reference: Asteelflash electronics maker hit by REvil ransomware attack
Victim: Asteelflash
Asteelflash is a world-leading French electronics manufacturing services (EMS) company that specializes in the design, engineering, and printing of printed circuit boards.
Reference: [PRESS RELEASE] Cyber Security Incident Update
Incident: Ransomware Attack at Bakker Logistiek Caused Cheese Shortage in Dutch Supermarkets
Bakker Logistics was hacked over the 2021 Easter weekend, bringing deliveries from its distribution centres to a standstill. The company was no longer able to receive orders from customers, and it also had no visibility into which products were where in the warehouses. Moreover, the hack disrupted the transport planning, according to Director Toon Verhoeven in an interview with the Dutch news broadcaster NOS. This resulted in empty shelves in some stores.
Verhoeven confirmed that it was a ransomware attack and was not willing to comment on whether Bakker actually paid a ransom, but did confirm that the company had reported the incident to the police. It took a specialized security company several days to get the computer systems up and running again. According to Verhoeven, the backlog was expected to be cleared within a week, so the hack was unlikely to lead to a major shortage of cheese products or other groceries.
In a local media report spotted by Bitdefender, Verhoeven said he suspected the attackers gained a foothold through a Microsoft Exchange server vulnerability
Victim: Bakker Logistiek
Specialist in the field of logistics in the food sector providing air conditioned warehousing and transportation services across the Benelux and Germany.
Reference: Ransomware Attack Creates Cheese Shortages in Netherlands
Reference: Hack at logistics service provider causes cheese shortage for grocery retailer Albert Heijn
Reference: Dutch supermarkets run out of cheese after ransomware attack
Incident: 600 Ticketing Kiosks Offline with Ransomware Attack at Northern Train.
A ransomware attack at publicly owned rail operator Northern Trains left self-service ticketing booths offline. Customers were able to continue purchasing tickets with cell phone apps, in physical ticketing booths and on the website.
"This is the subject of an ongoing investigation with our supplier, but indications are that the ticket machine service has been subject to a ransomware cyberattack. Working with the supplier, we took swift action and the incident has only affected the servers which operate the ticket machines. Customer and payment data has not been compromised." A representative for Northern Trains referred further questions on to Flowbird Transport, which provides the ticketing system in question, telling us "it's their system that's been affected."
Reference: Northern Train’s ticketing system out to lunch as ransomware attack shuts down servers
Victim: Northern Trains Limited
Northern plays a vital role in the north of England by transporting tens of thousands of people every day. Northern Trains Limited is owned by DfT OLR Holdings Limited (DOHL), which took on the operation of Northern services on 1 March 2020.
Incident: Scripps Health Ransomware Attack Costs Expected to Exceed $113M.
In the May 2021 ransomware attack, Scripps Health lost access to information systems at two of its hospitals, staff couldn’t access the electronic medical record system, and its offsite backup servers were also affected. Without access to critical IT systems, Scripps Health was forced to re-route stroke and heart attack patients and trauma patients could not be accepted at its main hospitals. The company stated it took 4 weeks to recover from the attack.
Losses sustained as a result of the attack are expected to exceed $113 million. The costs are likely to increase further still. The protected health information of 147,267 patients was compromised in the attack, and several class action lawsuits have been filed against Scripps Health over the theft of patient data. The expected losses do not include litigation costs.
Victim: Scripps Health
Scripps Health is a California-based $3.1 billion not-for-profit health care organization with 15,000 employees, 3,000 affiliated physicians operating 5 hospitals and 19 outpatient facilities in the state.
Reference: Scripps Health Ransomware Attack Cost Increases to Almost $113 Million
Incident: Ransomware Attack Forces Agricultural Grain Firm in Minnesota to Take Systems Offline
Minnesota agricultural firm Crystal Valley Cooperative targeted in a ransomware attack prompting it to take operating systems offline and to stop accepting major credit cards. . The attack left Crystal Valley unable to mix fertilizer or fulfill orders for livestock feed for 4 days. Grain elevators switched to manual operations issuing paper tickets when receiving grain.
Victim: Crystal Valley Cooperative
Crystal Valley is a farm supply and grain marketing cooperative in southern Minnesota and northern Iowa with core business products and services in Agronomy, Energy, Feed, and Grain.
Crystal Valley operates eight grain elevators with the capacity to store a total of 25 million bushels in Minnesota, the third biggest U.S. soybean-producing state and fourth biggest corn producer, according to its website. Two locations load huge 110-car trains for delivery to big buyers or exporters.
Reference: Minnesota grain handler targeted in ransomware attack
Incident: HVAC and IT System Down at Lufkin Independent School District
Several internet systems of Lufkin ISD down due to a ransomware attack. The district realized it had been attacked Saturday morning, according to Sheila Adams, executive director of communications and public relations. School operations that were affected include HVAC at some campuses and Skyward, a school management software. The school announced the HVAC systems were operational again by 2:45 p.m. Tuesday afternoon, 3 days after the attack.
"While its cybersecurity program appears to have worked, leadership does not know for sure if any data was compromised. The district also does not currently know how or why the attack happened as it is still under investigation." Adams said.
Victim: Lufkin Independent School District
Lufkin ISD is a Class 6A school district in the Pineywoods of East Texas with 15 campuses stretching over 307.5 acres.
Reference: Lufkin ISD comments on weekend ransomware attack
Reference: Hack-and-leak group Black Shadow keeps targeting Israeli victims
Reference: Black Shadow hackers leak medical records of 290,000 Israeli patients
Incident: Hillel Yaffe Hospital Ransomware Attack Paralyzed Majority of Hospital’s Computer Systems.
According to reports, among the affected systems are the hospital’s electric doors, as well as the patient registry system - which severely hampered the medical center's ability to receive and discharge patients. Some non-urgent procedures were canceled, but most of the hospital’s work continued using alternative IT systems and pen and paper. Cybersecurity experts said the hospital did not deploy the best possible security options, making it vulnerable to attack.
The hospital was back to being fully operational over a month after a ransomware attack. To reduce the vulnerability of follow-up attacks, medical centers across Israel shut down some IT systems.
Reference: Medical centers across Israel shut down some systems to reduce vulnerability
Victim: Hillel Yaffe Medical Center
Israel
Reference: Israel reports rare cyber attack on one of its hospitals
Reference: Hadera hospital back to work over month after cyberattack
Incident: Lewis & Clark Community College Shut Down in Ransomware Attack.
LCCC classes and other on-campus activities shut down due to ransomware attack impairing computers including those managing smoke and fire detectors. School officials elected to close campus until the attack has been dealt with. The campus and its computer system are closed down at least through Dec. 3.
Reference: Ransomware attack idles Trailblazers
Victim: Lewis and Clark Community College
Lewis and Clark Community College is a two-year higher education institution with multiple campuses, a river research center, a humanities center, a training center and Community Education Centers located throughout the more than 220,000-person college district, which reaches into seven counties.
Incident: Ransomware Attack Disrupted Entire Milk Supply Chain at Scheiber Foods For Days.
Cybercriminals compromised Schreiber Foods plants and distribution centers in October Schreiber uses a variety of digital systems and computers to manage milk processing, "that meant our plants and distribution centers couldn't use those systems, which they need to run. It impacted all of our locations." Andrew Tobisch, director of communications for Schreiber Foods said.
Schreiber resumed accepting milk deliveries, producing dairy products and shipping products to customers five days after a "cyber event" halted operations at the company's plants and distribution centers. A cream cheese shortage that hit bagel shops was partially attributed to this attack.
Reference: Schreiber Foods back to normal after ransomware attack shuts down milk plants
Reference: Cream cheese shortage stemmed partially from cyberattack
Victim: Schreiber Foods
Large dairy manufacturer of cream cheese, natural cheese, process cheese, beverages and yogurt based in North America. More than 9,000 employees, presence on five continents with annual sales of more than $5 billion.
Reference: Cyber Security Incident
Reference: Cyber attack costs Ardagh Group $34 million
Reference: What has the UK’s Weir Group cyber-attack taught us?
Reference: Kia Motors America Suffers a $20 Million Suspected DoppelPaymer Ransomware Attack
Incident: Cyberattack: Surgeries Postponed At Melbourne Hospitals.
A number of hospitals in Melbourne shut down elective surgeries after a suspected cyber attack on its computer network. Healthcare centers in the city's east run by Eastern Health were forced to postpone the surgeries and shutdown several IT systems. The hospitals affected (Box Hill, Maroondah, Healesville and Angliss) continued with category 1 elective surgeries, which impacted patients who require treatment within 30 days - all other operations stopped.
The company issued a statement on the issue, confirming their system had been taken offline until they identified the problem but stressed that no patient information had been leaked.
Victim: Eastern Health – Melbourne Healthcare Centers
Healthcare centers in Melbourne's east stopped elective surgeries after cyber attack. Hospitals are affected by the IT system issues
Reference: Surgeries are CALLED OFF as Melbourne hospitals are hit by cyber attack
Incident: Cyberattack Delays Start of Classes At Portsmouth University.
Key IT systems at the University of Portsmouth continue to remain offline this week after a supposed ransomware attack, delaying the start of the new term.
A notice on the university’s homepage doesn’t explicitly name ransomware as the cause of the “cyber incident,” but the “ongoing technical disruption” it describes is a tell-tale sign of such attacks. However, The News has reported that it has seen an email from the university claiming it suffered a ransomware attack.
Reference: Campus Still Closed as Portsmouth University Reels from Suspected Ransomware
Victim: Portsmouth University
Ransomware delayed start of the new 2021 term.
Reference: Mass. Steamship Authority Recovering From Cyber Attack
Incident: Iowa Community College Classes Disrupted By Cyberattack
A “cyberattack” is disrupting classes at the Des Moines Area Community College, where the school has cancelled in-person classes for four days and counting. Hackers forced it to shut down parts of the school's network and telephone system. The hack, which appears to be ransomware, has forced the Des Moines Area Community College (DMACC) to resort to posting updates on Facebook, Twitter, and a barebones version of its site. The school has also asked faculty, staff, and students to avoid using Microsoft Office 365, as well as the popular online learning platform Blackboard.
DMACC has not published details of the cyberattack, only saying on Facebook that it "required us to shut down parts of our network."
Victim: Des Moines Area Community College
IA
Reference: Hackers Force Iowa College to Cancel Classes for Four Days
Incident: Cyberattack Significantly Impacts Menominee Casino And Tribal Community
Menominee Casino in Keshena, WI closed for nearly two weeks due to "technical difficulties" following a cyberattack. The casino says it doesn't believe hackers got to any secure information. Tribal leaders tell NBC 26 the casino's security breach was 'beyond significant.' No reports of OT systems being affected.
"They can't make money for the community itself [right now]," Williams, a Keshena resident, said about the disabled casino. "I know that the casino does provide a lot of money for the community. It funds sponsorships for the college and other businesses. So I feel like the money impact is gonna be really bad."
Victim: Menominee Casino
Wisconsin
Reference: Menominee Casino still closed nearly two weeks after cyberattack
Incident: FBI Investigates Ransomware Attack At Lucky Star Casinos.
All six Lucky Star Casino locations in Oklahoma remain closed after a ransomware attack penetrated the venues’ information technology (IT) networks. Lucky Star said it is working closely with federal law enforcement, including the FBI, to resolve the matter. The casino said its insurer will provide credit monitoring services for the next 12 months. Casino officials have not said what the hackers are demanding.
Owned and operated by the Cheyenne and Arapaho Tribes of Oklahoma, Lucky Star has casinos in Concho, Clinton, Canton, and Watonga. The tribes also have gaming parlors inside their travel centers in Hammon and Concho.
Victim: Lucky Star Casinos
Oklahoma
Reference: All Six Lucky Star Casinos Remain Closed Following Weekend Ransomware Attack
Victim: Eskenazi Health
Indianapolis hospital hit by ransomware attack diverting ambulances to area hospitals.
Incident: Ransomware Attack Forced Ambulance Diversion At Eskenazi Health
Eskenazi Health in Indianapolis went on diversion for more than 5 days, meaning all incoming ambulances were routed to other hospitals after an attempted ransomware attack early Wednesday morning. The attack occurred around 3:30 a.m., and the diversion began at 7:51 a.m. Wednesday. The move affected all of the health system's locations, including Sidney & Lois Eskenazi Hospital downtown. Outpatient clinics remained open. Eskenzai contacted patients with an appointment or procedure that needed to be rescheduled because of the incident. "Monitoring systems responded as they should have and no employee or patient data appeared to be compromised." Tom Surber, media relations coordinator for Eskenazi Health, said in an emailed statement.
Reference: Indianapolis hospital still on diversion 5 days after ransomware attack
Reference: Eskenazi Health diverts incoming ambulances due to attempted ransomware attack
Incident: Toronto Transit Commission Systems Down After Ransomware Hit
The Toronto Transit Commission's Wheel-Trans online booking portal, trip-planning apps and other communications systems down after the transit agency was hit by a ransomware attack. The TTC first learned about the hack Thursday night when an IT employee found “unusual network activity." The TTC said the attack was initially “minimal” but then became progressively worse by mid-Friday. TTC resorted to emergency radio communications backup system to maintain communication with vehicle operators. Online ride booking service was also disrupted, but passengers could still book rides by telephone.
TTC continues to investigate ransomware attack
Victim: Toronto Transit Commission
TTC
Incident: Cyberattack on N.L. Healthcare System Possibly Worst In Canadian History
Thousands of Newfoundland and Labrador residents had appointments cancelled as a result of the attack, ranging from blood work to cancer care. Patient and employee information has been stolen from three out of the four regional health authorities. System had to be rebuild from scratch taking over a month. Sources say ransom was paid, but decryption key did not work. Later reports indicated 200,000 patient and employee files were taken from a network drive.
UPDATE: July 2022: Newfoundland and Labrador's largest health authority has notified 37,800 people that their privacy was breached as part of last fall's devastating cyberattack.
Victim: Newfoundland and Labrador Healthcare Systems
Cyberattack possibly worst in Canadian history
Reference: Newfoundland and Labrador health system attackers copied 200,000 patient and employee files
Reference: Over a month after the cyberattack on health care in N.L. began, Furey is still mum on details
Reference: Possible cyberattack hits ‘brain’ of N.L. health-care system, delaying thousands of appointments
Incident: Ransomware Attack at Maritime IT Company Danaos Propagated to Greek Shipping Companies
Several Greek shipping companies fell victim to a cyber attack on Halloween over the weekend, resulting in the loss of important files. The companies affected used the communication systems of Danaos Management Consultants and came in direct contact with the company. Reportedly, the cyber attack blocked their communication with ships, suppliers, agents, charterers and supplies, while at the same time the files with their correspondence were lost.
Danaos Management Consultants sent instructions to its customers, asking them among other things to back up critical files to external hard drives. Danaos is among the oldest maritime IT companies and could face litigation.
Victim: Danaos Management Consultants
Maritime IT Company
Reference: Greek Shipping Software Hit by Ransomware
Incident: Ransomware Attack At Diamond Comic Distributors Disrupts Retailer Shipments
Maryland-based Diamond Comic Distributors reported it had suffered a ransomware attack that temporarily took down the company’s website and disrupted its ability to process customer orders. The affected shipments currently include comics bound for drop points in Baltimore, Boston, and Dallas. The delays will also ensnare some comic book orders sent via UPS and to markets overseas.
Diamond Comic Distributors, , a top middleman for transporting Marvel, Dark Horse, and Image comics to retail stores, has yet to provide details about the attack, such as which ransomware strain was involved.
Victim: Diamond Comic Distributors
Maryland, ransomware attack caused operational disruptions and 2-4 day delays of scheduled shipments of comic books to retailers.
Reference: Ransomware Hits Major US Comic Book Distributor
Incident: Cyber Attack Disrupted Southern Ohio Medical Center (SOMC)
Southern Ohio Medical Center says its computer software has been hit by a targeted cyber-attack. Officials say a third party gained access to computer servers. The hospital says it is currently working with federal law enforcement officers and internet security firms to investigate the incident.
It is not affecting inpatient care, however. The hospital says it is currently diverting ambulances to other hospitals and may have to reschedule some procedures. The hospital says patients will be contacted directly to let them know. The hospital says it will continue to provide more information as it becomes available.
Victim: Southern Ohio Medical Center
(SOMC)
Reference: SOMC hit by cyber-attack, says operations not affected
Page: Request Access to OT Security Incidents Report
Incident: SPAR Supermarkets in Northern England Hit by Ransomware Attack.
The supermarket chain SPAR in Northern England confirmed it was hit by a ransomware attack. More than 300 stores have been affected by the incident, although some have avoided closing by switching to cash payments.
A spokesperson confirmed the nature of the incident to Sky News, but said policy was to not identify the criminal organisation involved. The ransomware attack had impacted all of the company's IT systems and left staff without access to emails.
Reference: SPAR: Supermarket chain confirms ransomware attack has forced stores to close
Victim: SPAR supermarket chain
Ransomware attack affected 300 stores in UK.
Incident: Cyberattack in the Neenah Joint School District in Wisconsin.
The Neenah Joint School District experienced an apparent cyberattack. The District was closed for two days after its technology systems went down early morning the day before. Law enforcement and cyber security experts were contacted to investigate. The district's phone and wireless systems, along with staff access to digital files, were restored at the end of second day.
Reference: Neenah schools to reopen Thursday after apparent cyberattack
Victim: Neenah Joint School District
Neenah Joint School District in Wisconsin
Incident: Ransomware Attack Causes Wide Spread Disruption in Ireland’s Healthcare Service
Ireland’s health service shut down its IT system after experiencing a “significant ransomware attack”. The incident has affected more than 80% of IT infrastructure, with the loss of key patient information and diagnostics, resulting in severe impacts on the health service and the provision of care. All computer systems were switched off. Doctors, nurses and other workers lost access to systems for patient information, clinical care and laboratories. Emails went down, and staff had to turn to pen and paper.Lab test data had to be handwritten and manually entered - leading to greater risks of mistakes. Thousands of people's healthcare was disrupted. Confidential medical files were also stolen, with hackers threatening to release the data. A response was quickly mobilised internally, and the Irish Defence Forces were called in to help.
HSE commissioned PWC for independent report on the cyber attack: On 18 March, someone in the Irish Health Service Executive (HSE) opened a spreadsheet that had been sent to them by email two days earlier. But the file was compromised with malware. The criminal gang behind the email spent the next two months working their way through the networks. There were multiple warning signs that they were at work, but no investigation was launched, and that meant a crucial opportunity to intervene was missed, according to the report, and on May 14 the ransomware was released. Senior staff set up a "war room", but the report criticises the lack of preparation or contingency planning for such a loss of systems. "The response teams could not initially focus on the highest priority response and recovery tasks due to the lack of preparedness for a widespread disruptive IT event," it says.
The attackers demanded payment to restore access to the computer systems, Then on 20 May, the attackers, for reasons not entirely clear - but perhaps realizing the scale of what was happening - posted a link to a key that would decrypt files. This allowed a long recovery to begin, and it took the service four months to fully recover.
Reference: Irish health service shut down amid ransomware attack
Victim: HSE – Ireland Public Health Service
Health Service Executive (HSE) of Ireland provides all of Ireland's public health services in hospitals and communities across the country.
Incident: Cyberattack Shut Down Oahu Transit Services
Oahu Transit Services suffered a cyberattack causing a “mass disabling of online servers” for TheBus and TheHandi-Van systems. City officials said they are working with the FBI, the Secret Service, and Honolulu police as those agencies investigate.
The cyberattack on Oahu’s bus system “has the trappings” of being a ransomware attack, according to Roger Morton, director of the Department of Transportation Services, although it is still being investigated. Morton said that to his knowledge, no personal information from TheBus or TheHandi-Van riders using the HOLO card has been compromised. “The HOLO card information that we do have is contained in a city server, not an OTS (Oahu Transit Services) server, and there’s no evidence that there has been any intrusion into the city system,” he said.
Unable to access, view, or print the day’s customer reservations, OTS fell back to schedule reservations manually urging customers to call for same day reservations starting from 5:00am.
Reference: City officials confirm cyberattack caused ‘mass disabling’ of TheBus, Handi-Van servers
Victim: Oahu Transit Services
operator of the city’s TheBus and TheHandi-Van
Incident: Ransomware Attack Put Entire School System Out Of Operation In Haverhill, MA
Students in Haverhill, Massachusetts, returned to the classroom after a massive ransomware attack crippled the district's computer system. The Haverhill Public School District said its IT department noticed early Wednesday morning, April 7, that something was wrong with the system, shutting down the network "before large scale corruption of the system occurred." Start of in-person schooling was delayed one day because of ransomware attack. The district said that the school's entire system, including its remote learning platform, was out of operation.
It's a kind of attack that's becoming increasingly common in Massachusetts -- at least one in six communities statewide was infected by ransomware in the past, and at least 10 paid hackers taxpayer money to unlock their files, the NBC10 Boston Investigators found.
Reference: Haverhill Public Schools Reopen Following Massive Ransomware Attack
Victim: Haverhill Public Schools
a massive ransomware attack crippled the district's computer system.
Reference: Iran says cyberattack closes gas stations across country
Incident: Cyberattack Leaves Motorists Stranded At Gas Stations in Iran.
A cyberattack crippled gas stations across Iran, leaving angry motorists stranded in long lines. No group immediately claimed responsibility for the attack, which rendered useless the government-issued electronic cards that many Iranians use to buy subsidized fuel at the pump.
It bore similarities to another attack months earlier that seemed to directly challenge Iran's Supreme Leader Ayatollah Ali Khamenei as the country's economy buckles under American sanctions. Israeli cybersecurity firm Check Point later attributed the Iran train attack to a group of hackers that called themselves Indra, after the Hindu god of war.
Victim: Iran gas stations
Iran.
Incident: Cyberattack forced 10 Day Closure of Tesuque Casino.
New Mexico’s Tesuque Casino reopened this week after a cyberattack. The cyber incident at the Santa Fe tribal gaming property initially was identified on Sept. 25. The casino immediately closed once the attack was discovered and remained shuttered for about 10 days. Findings from the investigation will “strengthen the casino’s cyber security defenses,” the casino said. "Through our fast-acting team and external IT specialists, we were able to contain and remedy the issue as swiftly as possible,” wrote Mark Mitchell, a Pueblo of Tesuque tribal official. Casino officials have not said if personal info belonging to players was in any way compromised, according to KRQE, a local TV station.
No indication OT systems were compromised - outage seemed to be over concern re: possible leakage of Tesuque Casino customers' Personally Identifiable Information(PII).
Reference: New Mexico’s Tesuque Casino Reopens Following Cyberattack Closure
Victim: Tesuque Casino
Tesuque Casino in New Mexico
Reference: Supermarket chain Coop closes 800 stores following Kaseya ransomware attack
Incident: Sweden’s Largest Supermarket Chain Closes Stores in Ransomware Attack
Coop, one of Sweden’s largest supermarket store chains, has shut down nearly 800 stores across the country after one of its contractors was hit by ransomware in the aftermath of the Kaseya security incident on Friday. The stores were closed after cash registers and self-serving stations went down and prevented Coop employees from processing in-store payments. Stores remained closed for two days.
The incident took place at the same time that a ransomware gang managed to infiltrate its way into the network of Kaseya, a provider of remote management app solutions, and deployed a version of the REvil ransomware to some of Kaseya’s customers, disguised as an update to the VSA software.
Victim: Coop, Swedish grocery chain
Coop shut down nearly 800 stores across the country after one of its contractors was hit by ransomware in the aftermath of the Kaseya security incident. Stores were closed for two days. 795 stores were affected.
Reference: Albuquerque schools remain closed for second day following cyber attack
Reference: Cyberattack Shuts down Albuquerque Schools
Incident: Nikkei’s Singapore Publishing Unit Hit by Ransomware
Publishing giant Nikkei disclosed that the group's headquarters in Singapore was hit by a ransomware attack almost one week ago, on May 13, 2022.
"Unauthorized access to the server was first detected on May 13, prompting an internal probe," the company revealed in a press release published on Thursday.
"The affected server likely contained customer data, and Nikkei is currently in the process of determining the nature and scope of the attack," Nikkei added.
Reference: Media giant Nikkei’s Asian unit hit by ransomware attack
Victim: Nikkei’s Singapore publishing unit
Nikkei is one of the largest media corporations worldwide, with roughly 4 million print and digital subscribers and over 40 affiliated companies involved in publishing, broadcasting, events, database services, and the index business.
Incident: Norway Media Company, Amedia, Hit in Cyberattack
Amedia, the largest local news publisher in Norway, said December 28 several of its central computer systems were shut down in what it is calling an apparent “serious” cyberattack.
The attack is preventing the company from printing the next day's edition of the newspapers, and presses were halted until the issue was resolved. The hack impacted the company’s advertising and subscription systems, preventing advertisers from purchasing new ads and stopping subscribers from ordering or canceling subscriptions.
The company said it is unclear whether personal information has been compromised—the subscription system affected by the attack contains names, addresses, phone numbers, and subscription history of customers. Data such as passwords, read history, and financial information are not affected, the company said.
Reference: Cyberattack on one of Norway’s largest media companies shuts down presses
Victim: Amedia
Amedia publishes more than 90 newspapers and other publications that reach more than 2.5 million Norwegians, according to the company’s website.
Incident: Parker-Hannifin Hit in Breach
Parker-Hannifin Corporation suffered a data breach March 14, which forced the company to shut down some of its systems while some employees’ personally identifiable information ended up purloined.
Upon learning of this incident, Parker said its IT team immediately activated its incident response protocols, which included shutting down certain systems. Parker then launched an investigation with the assistance of a forensic investigation firm and other third-party cyber security and incident response professionals.
Parker, one of the largest companies in the world in motion control technologies, said it is working with law enforcement authorities. A security researcher called BlackFog said the Conti ransomware group, which has Russian ties, claimed responsibility for the attack back in April.
Reference: US Manufacturing Giant Parker Hit by Conti Ransomware Gang
Reference: Parker-Hannifin Hit In Cyber Attack
Victim: Parker-Hannifin
Parker-Hannifin is one of the largest companies in the world in motion control technologies.
Reference: IA Grain Cooperative Recovering from Cyberattack, Remains Mum on Ransom
Editorial: OT Security Incidents: 2021 Trends and Analysis
Incident: Kellogg Community College Open after Attack
Kellogg Community College (KCC), forced to close its campuses and cancel classes after falling victim to a ransomware attack starting on Friday and over the weekend, is going to reopen Wednesday morning.
The attack caused continued technology problems, according to an alert that first appeared on the college’s website Sunday. All five Kellogg campuses, located in Michigan, closed during the attack.
An alert first posted KCC web page said the computer systems were targeted over the weekend of May 1 and KCC IRT experts were working on the situation. The alert went on to say, “We have learned that the technology issues we have been experiencing were caused by a ransomware attack that continues to affect our systems.”
Reference: College To Open After Ransomware Attack Shuts It Down
Victim: Kellogg Community College
Kellogg Community College (KCC), forced to close its campuses and cancel classes after falling victim to a ransomware attack.
Incident: Ransomware Attack at AGCO
Global maker and distributor of agricultural equipment, AGCO said it fell victim to a ransomware attack. Production affected world-wide, sales and orders halted, "majority restored" by May 20 with work ongoing. Few details made public.
Early May is planting season, and this has stalled tractor sales at dealers. In addition, AG equip indus. already facing labour strikes and serious supply chain disruptions. Dealers report being unable to access or place orders through AG website.
Reference: Ag Equipment Maker, AGCO, Hit In Ransomware Attack
Victim: AGCO
AGCO is a global designer, manufacturer and distributor of agricultural machinery and precision ag technology.
AGCO’s brand portfolio includes Challenger, Fendt, GSI, Massey Ferguson and Valtra. Founded in 1990 and headquartered in Duluth, Georgia, AGCO had net sales of $11.1 billion in 2021.
Incident: Coca-Cola Hit in Cyberattack
A ransomware gang that falls on the side of Russia said it purloined 161 GB of data from the Coca-Cola company.
Stormous ransomware group said it hacked servers belonging to the Coca-Cola company. Coca-Cola officials, on the other hand, said they are looking into the matter and have contacted law enforcement.
A note on Stormous’ leak site says the they stole 161 GB of data. The stolen file list shows file names suggesting that threat actors stole financial data, passwords, commercial accounts, email addresses, and other data, according to a report on CisoAdvisor.
Reference: It’s a Real Think: Coke Attacked
Threat Actor: Stormous ransomware group
Stormous gained some attention at the beginning of 2022 when it said they stole 200 GB of data from Epic Games. They have sought to make its name by taking advantage of the rising tensions between Russia and Ukraine.
On Feb. 24, 2024, Stormous group mentioned on “The Five Families” Telegram channel that they have started their new ransomware-as-a-service (RaaS) program “STMX_GhostLocker” along with their partners in GhostSec. The new program is made up of three categories of services for the affiliates: paid, free, and another for the individuals without a program who only want to sell or publish data on their blog (PYV service).
Victim: Coca-Cola
Coca-Cola said it is investigating reports of a data breach after a ransomware group claimed to have stolen documents from the beverage giant.
In a statement, a Coca-Cola spokesperson said they have already contacted law enforcement about the incident.
“We are aware of this matter and are investigating to determine the validity of the claim,” said Coca-Cola communications vice president Scott Leith.
Incident: Ransomware Hits Snap-On Tool Maker
American automotive tools manufacturer Snap-on suffered an attack from the Conti ransomware gang.
The attacker started leaking the company’s data in March. Snap-on is a manufacturer and designer of tools, software, and diagnostic services used by the transportation industry through various brands, including Mitchell1, Norbar, Blue-Point, Blackhawk, and Williams.
Snap-on disclosed a data breach Thursday after they detected suspicious activity in their network, which led to them shutting down all of their systems. After conducting an investigation, Snap-on found attackers purloined personal employee data between March 1 and March 3.
Reference: Snap-on discloses data breach claimed by Conti ransomware gang
Reference: Snap-On Tool Maker Hit By Ransomware
Victim: Snap-on
Snap-on is a manufacturer and designer of tools, software, and diagnostic services used by the transportation industry through various brands, including Mitchell1, Norbar, Blue-Point, Blackhawk, and Williams.
Reference: Kia Ransomware 101: How It Started and How The Situation Developed
Incident: Attack on Satellite Firm Viasat Interrupted Wind Power Generation Systems
Satellite communications giant Viasat said a “multifaceted and deliberate” attack hit “several thousand” customers in Ukraine the same day Russia attacked. The Feb. 24 incident, which also hit tens of thousands of other fixed broadband customers across Europe, was localized to a single consumer-oriented partition of the KA-SAT network operated on Viasat’s behalf by a Eutelsat subsidiary, Skylogic.
A targeted denial of service attack (DoS) first ended up discovered after high volumes of focused, malicious traffic made it difficult for modems to remain online, said Viasat’s incident summary. The traffic emanated from several SurfBeam2 and SurfBeam 2+ modems and/or associated customer premise equipment physically located within Ukraine.
Reference: Viasat: Feb. cyber attack impacted tens of thousands of customers in Ukraine, Europe
Reference: Viasat Ukraine, Europe Cyberattack Details Emerge
Victim: Viasat
Viasat provides satellite broadband services to governments worldwide and aviation, military, energy, maritime, and enterprise customers. Last month, the telecom giant told shareholders that it had approximately 189,000 broadband subscribers in the United States.
Incident: German Wind Turbine Maker Enercon’s Services 90% Restored
German wind turbine maker, Enercon GmbH, is still restoring remote monitoring and maintenance capabilities for its turbines affected by a satellite outage at the end of February.
The company said over 90 percent of its 5,800 machines are online. The communication link has been restored for 1,156 wind parks in central Europe and service teams continue to work on the remaining 193 wind farms, the wind turbine manufacturer said Friday.
The remote monitoring and maintenance of the 5,800 machines with a combined output of more than 10 GW was affected by a satellite outage at Viasat on the same day as Russia invaded Ukraine. Viasat also had satellite operations going on in Ukraine and Enercon may have suffered as a part of being collateral damage in the attack.
Reference: Other German Turbine Maker Services 90% Restored
Victim: Enercon
German wind turbine manufacturer.
Incident: German Wind Turbine Maker Hit in Cyberattack
A cyberattack shut down a German wind turbine maker’s IT systems across multiple locations and business units March 31.
Nordex designs, sells and manufactures wind turbines, reporting just over $5.9 billion in sales last year. The company has factories in Germany, China, Mexico, United States, Brazil, Spain and India.
“On 31 March 2022 Nordex Group IT security detected that the company is subject to a cyber security incident,” the company said in an advisory. “The intrusion was noted in an early stage and response measures initiated immediately in line with crisis management protocols. As a precautionary measure, the company decided to shut down IT systems across multiple locations and business units."
Reference: German wind-turbine maker Nordex hit by cyberattack
Reference: Cyberattack Shuts German Turbine Maker
Victim: Nordex
Nordex designs, sells and manufactures wind turbines, reporting just over $5.9 billion in sales last year. The company has factories in Germany, China, Mexico, United States, Brazil, Spain and India.
Incident: Auto Parts Supplier Denso Suffers Ransomware Attack
Global automotive parts supplier Denso suffered a ransomware attack last week, company officials said.
The ransomware attack group was Pandora. Japan-based Denso officials said they detected unauthorized access using ransomware at Denso Automotive Deutschland GmbH, a group company that handles sales and engineering in Germany, on Thursday (March 10).
Denso “promptly responded,” spokeswoman Izumi Saito said Sunday in a published report. Eventhough the company is still reeling from the attack, it has not had an impact on operations, Saito said.
Reference: Automotive giant DENSO hit by new Pandora ransomware gang
Reference: Auto Supplier’s German Group Hit By Ransomware
Victim: Denso
Global auto parts manufacturer, Denso clients include Toyota, Honda, General Motors, and Ford. Consolidated revenue in the 2020-2021 fiscal year was reported as $44.6 billion.
Threat Actor: Pandora
Pandora ransomware is a new operation launched in March 2022 that targets corporate networks and steals data for double-extortion attacks.
Once they gain access to a network, the threat actors will spread laterally through a network while stealing unencrypted files to be used in extortion demands.
When encrypting a device, the ransomware will append the .pandora extension to encrypted files names.
Incident: German Subsidiary Of Russia’s Rosneft Hacked
The German subsidiary of Russian energy giant Rosneft has been hit by a cyberattack, the Federal Office for Information Security (BSI) said Monday.
The hacker group Anonymous is claiming responsibility, according to a report from the French wire service, AFP. Rosneft Deutschland reported the incident in the early hours of Saturday morning, the BSI said.
Anonymous published a statement Friday claiming responsibility for the attack saying it had captured 20 terabytes of data. Prosecutors in Berlin have opened an investigation, according to a report in Der Spiegel magazine.
Reference: Rosneft’s German unit reports cyber attack
Reference: German Subsidiary Of Russian Oil Giant Hacked
Threat Actor: Anonymous
Anonymous is a decentralized international activist- and hacktivist collective and movement primarily known for its various cyberattacks against several governments, government institutions and government agencies, and corporations.
Victim: Rosneft
Rosneft Deutschland said was responsible for around a quarter of all crude oil imports to Germany in recent years and has stakes in three refineries in the country.
Rosneft chief executive Igor Sechin is a close ally of Russian President Vladimir Putin. Former German Chancellor Gerhard Schroeder is chairman of the board of directors, for which he received heavy criticism in recent weeks.
Incident: Tire Manufacturer Bridgestone Hit in Ransomware Attack
One of the largest tire manufacturers in the world, Bridgestone Americas, is working on a recovery after suffering a ransomware attack by the LockBit ransomware gang.
Bridgestone said it started to investigate “a potential information security incident” it detected in the morning hours of February 27. “Out of an abundance of caution, we disconnected many of our manufacturing and retreading facilities in Latin America and North America from our network to contain and prevent any potential impact,” Bridgestone said in a statement.
The ransomware gang said it will leak all data stolen from the company and launched a countdown timer. The LockBit gang claimed the attack by adding Bridgestone Americas to the list of their victims.
Reference: Bridgestone Americas confirms ransomware attack, LockBit leaks data
Reference: Ransomware Attack Hits Bridgestone
Victim: Bridgestone
Bridgestone has production units across the world and over 130,000 employees, as per the company’s data at the end of 2020.
Incident: Samsung Hit in Cyberattack
South Korea-based Samsung suffered a cyberattack over the weekend, but it doesn’t see there being any impact on its business or customers, company officials said Monday.
South American hacking group Lapsus$ said it had stolen 190GB of confidential data, including source code, from the tech giant’s servers. The group also posted snapshots of data online.
Samsung confirmed in a statement there was a security breach, but it said there was no compromise of customer personal information.
“We were recently made aware that there was a security breach relating to certain internal company data. Immediately after discovering the incident, we strengthened our security system,” the company said.
Reference: Hackers leak 190GB of alleged Samsung data, source code
Reference: Samsung Suffers Breach
Victim: Samsung
Lapsus$ published a description of the upcoming leak, saying it contains “confidential Samsung source code” originating from a breach. The attacker said it has:
-- Source code for every Trusted Applet (TA) installed in Samsung’s TrustZone environment used for sensitive operations (e.g. hardware cryptography, binary encryption, access control)
-- Algorithms for all biometric unlock operations
-- Bootloader source code for all recent Samsung devices
-- Confidential source code from Qualcomm
-- Source code for Samsung’s activation servers
-- Full source code for technology used for authorizing and authenticating Samsung accounts, including APIs and services
Incident: Nvidia Suffers Cyberattack
A threat actor leaked Nvidia Corp. employee credentials and some company proprietary information online after the chipmaker’s systems ended up breached in what appears like a ransomware attack.
The Santa Clara, California-based company became aware of the breach on Feb. 23. The company is analyzing the leaked information and does not anticipate any disruption to the company’s business.
A ransomware group under the name “Lapsus$” reportedly claimed to be responsible for the leak and seemingly has information about the schematics, drivers and firmware, among other data, about the graphics chips.
Reference: Nvidia says hackers are leaking company data after ransomware attack
Reference: Worker, Company Info Stolen In Attack On Nvidia
Threat Actor: Lapsus$
The ransomware group is new to the scene and some researchers believe the Lapsus$ gang is based in South America, but no one really knows for sure. Others said the group looks a bit like amateurs, which could mean they are just getting their feet wet and will learn and grow into stronger and more active attackers.
Victim: Nvidia
At a market cap of about $600 billion, Nvidia is the most valuable chipmaker in the United States. It is known for its graphics processing units (GPU) that enhance videogaming experiences and advanced computer simulations.
Incident: Kojima Industries, a Toyota Supplier, Suffers Cyberattack
Toyota shut down production in Japan because Kojima Industries , one of its domestic suppliers, suffered a cyberattack. Kojima Industries provides plastic and other parts to Toyota.
Toyota employs a kanban "just-in-time" production method, so when Kojima was hit by ransomware which halted their key plastic and electronics parts production, Toyota chose to shutdown all 14 plants, and their network connections, to contain the spread. Toyota and subsidiaries were unable to keep their plants running. This is occurring amid ongoing parts and component shortages in the industry.
Toyota subsidiaries Hino Motors and Daihatsu Motor will also halt operations at some plants in Japan.
Reference: Toyota halts operations at all Japan plants due to cyberattack
Reference: Toyota Halts Production After Cyberattack On Supplier
Victim: Kojima Industries
Kojima Industries is the supplier hit in the attack and it provides plastic and other parts to Toyota.
Many of the roughly 400 tier 1 suppliers that Toyota deals with directly are connected to the automaker's Kanban just-in-time production control system, which allowed the problems at Kojima Industries to spill over to Toyota. The automaker halted production to prevent longer-term damage, and prioritized inspection and recovery of the system.
Incident: Axis Communications Hit in Cyberattack
Axis Communications, a Swedish maker of network cameras and other physical security solutions used by government and private sector organizations globally, suffered a cyberattack earlier this month that disrupted its operations, company officials said.
“On the night between Saturday February 19 and Sunday February 20, Axis was the subject of a cyberattack. Using several combinations of social engineering, attackers were able to sign in as a user despite protective mechanisms such as multi-factor authentication,” company officials said in an advisory posted.
“Inside, the attackers used advanced methods to elevate their access and eventually gain access to directory services."
Reference: Physical Security Provider Hit In Cyberattack
Victim: Axis Communications
Axis Communications is a Swedish maker of network cameras and other physical security solutions used by government and private sector organizations globally.
Threat Actor: Phoenix
Phoenix is a ransomware family that is believed to be linked to the criminal group Evil Corp.
Malware: Phoenix Locker
Phoenix Locker, a variant of ransomware dubbed ‘Hades.’ Hades was created by a Russian cybercrime syndicate known as Evil Corp., according to cybersecurity experts.
Malware: BlackCat
BlackCat (ALPHV), dubbed the ‘most sophisticated’ ransomware group of 2021, has claimed the responsibility for the Swissport ransomware attack by leaking a small set of sample files that the group claimed to have obtained from Swissport. The threat actor is striving to sell the entire 1.6 TB ‘data dump’ to a prospective buyer.
Threat Actor: BlackCat / ALPHV
BlackCat extorts money from targeted organizations by stealing sensitive data and threatening to release it publicly, and encrypting systems. But BlackCat goes one stage further and also threatens to launch a distributed denial-of-service (DDoS) attack if its demands are not met.
This technique is known as “triple extortion.”
BlackCat has gained traction since late 2021 by offering payouts to its affiliates of up to 90%.
Editorial: Ransomware Attack Strikes 49ers Football Team
Incident: Ransomware Hits 49ers Football Team
One of the teams in the National Football League (NFL) ended up falling victim to a ransomware hack with the attackers saying they purloined the teams financial data.
The San Francisco 49ers suffered the attack at the hands of ransomware gang BlackByte. The attackers appeared to have posted some of the stolen team documents on a site on the dark web in a file marked “2020 Invoices.”
The gang did not make its ransom demands public or specify how much data it had stolen or encrypted.
Reference: Football Team Hit In Ransomware Attack
Threat Actor: BlackByte
As of November 2021, BlackByte ransomware had compromised multiple U.S. and foreign businesses, including entities in at least three U.S. critical infrastructure sectors (government facilities, financial, and food & agriculture). BlackByte is a Ransomware as a Service (RaaS) group that encrypts files on compromised Windows host systems, including physical and virtual servers. BlackByte executable leaves a ransom note in all directories where encryption occurs. The ransom note includes the .onion site that contains instructions for paying the ransom and receiving a decryption key. Some victims reported the actors used a known Microsoft Exchange Server vulnerability as a means of gaining access to their networks. Once in, actors deploy tools to move laterally across the network and escalate privileges before exfiltrating and encrypting files. In some instances, BlackByte ransomware actors have only partially encrypted files. In cases where decryption is not possible, some data recovery can occur. Previous versions of BlackByte ransomware downloaded a .png file from IP addresses 185.93.6.31 and 45.9.148.114 prior to encryption. A newer version encrypts without communicating with any external IP addresses. BlackByte ransomware runs executables from c:windowssystem32 and C:Windows. Process injection has been observed on processes it creates.
Malware: BlackByte
BlackByte executable leaves a ransom note in all directories where encryption occurs.
RELATED STORIES
Ransomware Found in Critical Infrastructure Sectors
SIM Swapping Attacks Growing: FBI
Embedded Devices Vulnerable to Ransomware Attacks
Russian Cyber Alert Misses Mark For OT
The ransom note includes the .onion site that contains instructions for paying the ransom and receiving a decryption key. Some victims reported the actors used a known Microsoft Exchange Server vulnerability as a means of gaining access to their networks.
Victim: San Francisco 49ers Football Team
The team said in a statement Sunday it recently became aware of a “network security incident” that had disrupted some of its corporate IT network systems. The 49ers said they’d notified law enforcement and hired cybersecurity firms to assist.
“To date, we have no indication that this incident involves systems outside of our corporate network, such as those connected to Levi’s Stadium operations or ticket holders,” the team said in a statement.
Incident: Barcelona’s Damm Brewery Ransomware Attack
Spain's second biggest beer maker Damm halted output at its main brewery outside Barcelona after a cyber attack hit its computer systems earlier this week, a spokesperson said November 12.
The attack hit the brewery on Nov. 9 night and for a few hours the plant in El Prat de Llobregat, which produces 7 million hectolitres of beer a year, was "entirely paralyzed", said Olga Vidal, Damm's head of communications.
A Damm spokesperson said the brewery had suffered a “computer incident in the operating system,” which was “under investigation.”
The same spokesperson said the brewery had activated its emergency response plan and was now working to restore production to its normal level.
Sources close to the brewery said the attack would have been more catastrophic had it taken place in the summer months when more beer is consumed. At that time of year, stocks only last around three days.
Reference: Spanish Brewery “Paralyzed” by Cyber-Attack
Reference: Cyber attack turns off the taps at Barcelona’s Damm brewery
Victim: Damm Brewery
Spain's second largest beer maker. Damm bottles several other beer brands beside its iconic Estrella Damm and has honoured all deliveries to bars, restaurants and supermarkets thanks to existing stocks
Incident: Ransomware Strikes Candymaker
Ferrara, the Chicago-based manufacturer of candies like SweeTarts, Laffy Taffy, Nerds, Red Hots, Lemonhead candies, Boston Baked Beans, Atomic Fireballs, Pixy Stix and Everlasting Gobstoppers, has been able to resume production only “in select manufacturing facilities,” a spokesperson said. Ferrara first noticed that hackers were encrypting its computers and demanding a payment on Oct. 9, and has hired outside experts to help restore its systems, the statement said. It disclosed the attack on Tuesday. Hackers encrypted the company's computer system and demanded a payment.
Reference: Ferrara Ransomware Attack: US Candy Maker Struggles in Production After Hackers Encrypt its Systems
Victim: Ferrara
Chicago-based manufacturer of candies like SweeTarts, Laffy Taffy, Nerds, Red Hots, Lemonhead candies, Boston Baked Beans, Atomic Fireballs, Pixy Stix and Everlasting Gobstoppers.
Incident: Ransomware Hits Store Fixture Manufacturer
Madix, Inc., a manufacturer of store fixtures with plants in Goodwater and Eclectic, Alabama, was hit with a ransomware attack over Nov. 13-14 that has disabled its computers and halted production, according to sources familiar with the situation.
Employees in Goodwater and Eclectic were sent home Monday with no specified date of return as the company works to resolve the cybersecurity breach.
Reference: Madix, Inc hit with ransomware attack
Malware: Unknown
Unknown cost of attack at this time.
Victim: Madix Inc.
Madix, headquartered in Terrell, Texas, is one of the top 10 largest employers in Tallapoosa and Coosa counties in Alabama with over 300 employees at its Goodwater plant, according to data from the Lake Martin Area Economic Development Alliance. The company produces shelving for retailers including Walmart and Publix.
Incident: Norwegian Food Producer Hit in Cyberattack
Nortura has been the victim of a computer attack. We have therefore decided to shut down our IT systems and remove Internet access at our locations to minimize possible damage to systems and operations.
The result is the activity at several factories and expeditions has been reduced until further notice.
We are now working to get a complete overview of the situation and the extent, as well as make plans to deal with the consequences of the situation that has arisen. The priority is securing data and stabilizing the systems.
Reference: Nordic companies targeted in wave of cyber attacks
Victim: Nortura
The Norwegian meat processing company to shut down its entire IT system ahead of a forensics investigation and the cleansing of computers connected to the company’s central IT system.
Nortura detected the attack at an early stage and was able to limit damage to its IT system by shutting down Internet access, said CEO Anne Marit Panengstuen. The swift action prevented hackers from capturing data or encrypting operating system files.
“Cyber threats are becoming more common generally and we keep investing to protect our business against bad actors. We have good contingency plans, which were activated when we became aware of the attack,” said Panengstuen. “We also had an element of luck on our side as we had conducted an IT cyber security contingency exercise in 2021 that was based on a similar threat profile.”
Nortura’s standby cyber security protocols were employed to forensically establish if computers within the group’s IT system had been compromised. A full cleanse was carried out before the central IT system, which supports Nortura’s meat processing plants across Norway, was fully restored on 10 January 2022.
Incident: Albuquerque Hit in Cyberattack
Albuquerque, New Mexico have cancelled classes for Thursday and Friday due to a cyberattack. The shutdown took place just days after a ransomware attack hit government services across Bernalillo County.
Albuquerque Public Schools (APS) website reportedschools will remain closed "as the district continues to investigate a cyberattack that compromised the student information system used to take attendance, contact families in emergencies, and assure that students are picked up from school by authorized adults."
Reference: Albuquerque schools remain closed for second day following cyber attack
Reference: Cyberattack shuts down Albuquerque schools; county copes with ransomware incident
Victim: Albuquerque Public Schools
The largest school district in New Mexico will remain closed "as the district continues to investigate a cyberattack that compromised the student information system used to take attendance, contact families in emergencies, and assure that students are picked up from school by authorized adults."
The district said it was working with cybersecurity experts to get systems back up and running as soon as possible.
Victim: Albuquerque Public Schools
The largest school district in New Mexico will remain closed "as the district continues to investigate a cyberattack that compromised the student information system used to take attendance, contact families in emergencies, and assure that students are picked up from school by authorized adults."
On Wednesday, the school said it was working with cybersecurity experts to get systems back up and running before Jan. 14.
Incident: Iran’s Rail Service Delayed with Fake Messages
Iran's railroad system came under cyberattack on July 2, a semi-official news agency reported, with hackers posting fake messages about train delays or cancellations on display boards at stations across the country.
The hackers posted messages such as “long delayed because of cyberattack" or “canceled" on the boards. They also urged passengers to call for information, listing the phone number of the office of the country’s supreme leader, Ayatollah Ali Khamenei. Israeli cybersecurity firm Check Point attributed the train attack to a group of hackers that called themselves Indra, after the Hindu god of war.
Reference: Hackers disrupt Iran’s rail service with fake delay messages
Malware: Hacker Attack
Hackers posted messages such as “long delayed because of cyberattack" or “canceled" on the boards. They also urged passengers to call for information, listing the phone number of the office of the country’s supreme leader, Ayatollah Ali Khamenei.
Victim: Iran’s railroad system
The semiofficial Fars news agency reported that the hack led to “unprecedented chaos” at rail stations.
No group took responsibility. Earlier in the day, Fars said trains across Iran had lost their electronic tracking system. It wasn't immediately clear if that was also part of the cyberattack.
Incident: Business Services Firm Hit in Ransomware Attack
Business services provider, Morley Companies Inc., just disclosed a ransomware attack and data breach it suffered this past summer affecting over 500,000 workers.
Saginaw, Michigan-based Morley suffered the attack on July 20 last year, according to a report filed with the Maine Office of the Attorney General. The company, which said it discovered the attack January 26, offers business services to Fortune 500 and Global 100 firms, including meeting management, back-office processing, contact centers, and the creation of trade show exhibits.
Reference: Ransomware Attack At Business Services Firm
Malware: Ransomware – unknown
Type of attack unknown.
Victim: Morley Companies Inc.
Morley officials said when they suffered the ransomware attack, it led to their data becoming unavailable.
After investigating the hack, the company determined attackers stole the personal information of 521,046 individuals, including data for Morley’s employees, contractors, and clients.
“The incident began on August 1, 2021, when Morley’s data became unavailable,” Morley officials said in an advisory. “Upon receipt of this information, Morley immediately took steps to secure its environment and commenced an investigation to determine what happened and to identify the specific information that may have been impacted. In so doing, Morley engaged leading independent cybersecurity experts for assistance. As a result, Morley learned that additional data may have been obtained from its digital environment. Morley thereafter began collecting contact information needed to provide notice to potentially affected individuals, which was completed in early 2022.”
According to Morley, the threat actors may have stolen the following types of data during the attack: Full name, Social Security number, date of birth, client ID number, medical diagnostic and treatment information, and health insurance information.
Incident: Ransomware Attack at Swiss Airport Services Firm
Swissport, the world’s largest airport ground services and cargo handling company, fell victim to a ransomware attack.
The Zurich-based firm said it spotted the hack early on Feb. 3 to contain potential damage to its IT systems. Some flights were delayed at Zurich airport and passengers are being warned of further potential disruption.
Swissport’s website was forced offline by the cyberattack and the company said some services had been affected for passengers and freight.
Reference: Swiss Airport Services Firm Hit By Ransomware
Malware: Ranwomare attack
Unknown
Victim: Swissport
Opfikon, Switzerland-based Swissport is the world’s largest airport ground services and cargo handling company.
Incident: Cyberattack Cuts Service for Vodafone Portugal
Vodafone Portugal, one of the country’s top telecommunications companies, said Tuesday it suffered a cyberattack, while no confidential customer ended up compromised.
“A deliberate and malicious cyberattack aimed at causing damage and disruption” was underway, the company said.
The attack Feb. 7 affected the company’s 4G and 5G services, fixed line and SMS services, and digital and voice customer services, the company said.
The company hadn't received any ransom demand that would indicate it was hit by a ransomware attack. The CEO also said he had no indications the attackers had accessed subscriber information or other sensitive data. Specifics of the attack remain unknown.
Reference: Vodafone Portugal Cyberattack Halts Services
Victim: Vodafone Portugal
Vodafone Portugal says it provides fiber services to 3.4 million Portuguese homes and companies and has 4.7 million cellphone customers.
By early Feb. 8 , the company said it had restored mobile voice services, while national and international teams and consultants were working to bring back other services.
Incident: German Oil Tank Farm Shut Down
German tank logistics company Oiltanking fell victim to a cyber attack Saturday which shut down the loading and unloading of the company’s tank farms. The company confirmed the attack to the publication “Handelsblatt” Monday. The attack also affected the mineral oil trader Mabanaft, like Oiltanking, a subsidiary of the Hamburg, Germany, group Marquard & Bahls. Port services and tank farms were unable to unload bulk oil, and fuel could not be loaded onto trucks at depots and distributed across the country.
Oiltanking operates fuel terminals at ports internationally. Mabanaft distributres fuel to 26 companies and 2,000 Shell stations from a network of 13 fuel tank farms across Germany. Both units declared 'Force Majeure' after the attack prevented them from operating.
Reference: Cyber Attack Shuts Down German Oil Firm
Victim: Oiltanking – subsidiary of Marquard & Bahls
The incident affects the company’s 13 tank farms across the country. The company said among other things, the loading and unloading of the tank farms is affected. Since that process is automated and only possible to a limited extent manually, the tanker trucks cannot be loaded at the moment.
Oiltanking - a subsidiary of Marquard & Bahls - is one of the largest independent tank storage providers for petroleum products, chemicals and gases worldwide. The company owns and operates 64 terminals in 24 countries with a total capacity of 20 million cubic meters (as at: December 2020). The total throughput of all tank terminals in 2019 was about 155 million tons.
Marquard & Bahls is a Hamburg-based company that is active in the fields of energy and chemicals and organized as a holding company operating through its subsidiaries Mabanaft, Oiltanking, Skytanking.
Incident: Oil Terminals In Europe Suffer Cyberattack
Major oil terminals in Western Europe’s largest ports have fallen victim to a cyberattack, sources confirmed.
Belgian prosecutors launched an investigation into the hacking of oil facilities in the country’s maritime entryways, including Antwerp, Europe’s second largest port after Rotterdam. In Germany, prosecutors said they were investigating a cyberattack targeting oil facilities in what was described as a possible ransomware strike, in which hackers demand money to reopen hijacked networks.
Reference: Oil Terminals In Europe Suffer Cyberattack
Victim: SEA-Tank Terminal
SEA-Tank Terminal, which has storage facilities in Antwerp, was hit, Belgian daily De Morgen reported. Dutch National Cyber Security Centre said the attacks were “probably committed with a criminal motive” and pledged to take further action “if necessary.”
Incident: UK Snack Provider Hit by Ransomware Attack
A British snack food provider, Kenyon Produce (KP) Snacks, suffered an attack by the Conti ransomware group, which had an effect on distribution to supermarkets, and could now be in negotiations for the decryption key. The German-owned company said it became aware of the attack on January 28, and it immediately took steps to contain the attack. A letter from KP Snacks sent to store owners February 2 said it its systems had been “compromised by ransomware” and it “cannot safely process orders or dispatch goods.”
Company press reports are confusing, because they say that "Deliveries delayed" for 2 months time and they can't "safely deliver snacks." BUT they also say they will use up existing stock and cap orders so can logically conclude production has halted.
Editorial: Ransomware Attack at UK Snack Provider
Reference: KP Snacks giant hit by Conti ransomware, deliveries disrupted
Reference: Ransomware Attack At UK Snack Provider
Victim: Kenyon Produce (KP) Snacks
KP Snacks includes brands such as PopChips, Skips, Hula Hoops, Penn State pretzels, McCoy’s, and Wheat Crunchies. The company has over 2,000 employees and has annual revenues at $600 million.
Because of the attack, deliveries from the company to superstores are being delayed or canceled altogether. According to discussions between KP Snacks and its partner supermarkets, the supply shortage issues may last until the end of March.
Incident: Pharma Service Provider Hit in Cyber Attack
Digital prescription fulfillment provider, Ravkoo, suffered a cybersecurity incident this past September where an unauthorized third party infiltrated the company’s AWS cloud portal affecting 105,000 of its customers.
On September 27, Auburndale, Florida-based Ravkoo fell victim to a cybersecurity incident, which may have exposed prescription and health information located on the AWS portal, according to the letter to the New Hampshire Attorney General signed by Ross M. Molina of Wilson Elser Moskowitz Edelman & Dicker LLP.
Reference: Pharma Service Provider Hit in Cyber Attack
Victim: Ravkoo
Ravkoo is a digital software as a service (SaaS) platform for prescription fulfillment providing prescription delivery to patients’ doorsteps. It has over 400 distribution centers nationwide in over 110 major cities.
Incident: Chemical Maker Hit in Cyber Attack
Fort Lauderdale, Florida-based Specialty chemical maker, Element Solutions Inc., suffered a cyber attack, company officials said Monday.
“Element Solutions recently detected a cyber intrusion on certain of the Company’s information technology systems,” the company said in a statement. “Upon detection of the incident, the company promptly took action to contain it and implement business continuity and data recovery protocols.”
Reference: Chemical Maker Hit In Cyber Attack
Victim: Element Solutions Inc.
Element Solutions Inc is a specialty chemicals company. Developed in multi-step technological processes, these solutions enable customers’ manufacturing processes in several industries, including consumer electronics, power electronics, semiconductor fabrication, communication and data storage infrastructure, automotive systems, industrial surface finishing, consumer packaging and offshore energy.
Victim: Ensinger
Ensinger creates high performance and engineering thermoplastics. Develops, produces and sells extruded, compression molded and cast semi-finished materials, as well as injection molded parts, and window profiles for commercial building construction.
Victim: Bolpegas SRL
Santa Cruz de la Sierra, Bolivia-based Bolpegas provides engineering services to the oil and gas industry operating in Bolivia. Services include technical audits of construction and engineering projects with particular emphasis on pipelines, project and construction management, and manpower supply in Bolivia and other areas of the world.
Incident: Photography Giant Hit In Ransomware Attack
Manufacturing at Shutterfly, the photography industry giant, was one of the areas suffering from a Conti ransomware attack earlier in December that encrypted thousands of devices and stole data.
The company’s photography-related services are aimed at consumer, enterprise, and education customers.
The various brands that fly under the Shutterfly banner include GrooveBook, BorrowLenses, Shutterfly.com, Snapfish, and Lifetouch. The main website can end up used to upload photos to create photo books, personalized stationary, greeting cards, post cards, and more.
Reference: Shutterfly services disrupted by Conti ransomware attack
Reference: Photography Giant Hit In Ransomware Attack
Victim: Shutterfly
Shutterfly issued a statement confirming the ransomware attack:
“Shutterfly, LLC recently experienced a ransomware attack on parts of our network. This incident has not impacted our Shutterfly.com, Snapfish, TinyPrints or Spoonflower sites. However, portions of our Lifetouch and BorrowLenses business, Groovebook, manufacturing and some corporate systems have been experiencing interruptions. We engaged third-party cybersecurity experts, informed law enforcement, and have been working around the clock to address the incident."
Incident: Global IT Firm Recovering From Ransomware Attack
Global IT services company, Inetum Group, suffered a ransomware attack December 19, impacting operations in France.
While the global company suffered the hit in France, its operations were ongoing in other parts of the world. Among the multiple sectors the company works with are energy and utilities, aerospace, automotive, and chemicals and life sciences. The company said none of the main infrastructures, communication, collaboration tools or delivery operations for its clients ended up affected.
Reference: Global IT Firm Recovering From Ransomware Attack
Victim: Inetum Group
Inetum is an IT services company that provides digital services and solutions on a global basis. The company operates in 26 countries, has nearly 27,000 employees and in 2020 generated revenues of $2,23 billion (€1.97) billion.
Incident: United Hack Connects To Attack Group
United Airlines, the world’s second-largest airline, detected an incursion into its computer systems in May or early June, said several people familiar with the probe. Three of those people said investigators working with the carrier linked the attack to a group of China-backed hackers they said are behind the theft of security-clearance records from the U.S. Office of Personnel Management and medical data from health insurer Anthem Inc.
Reference: United Hack Connects To Attack Group
Threat Actor: Black Vine
China-backed Black Vine is targeting multiple industries including energy, aerospace and healthcare. The most prominent attack to date from Black Vine occurred when healthcare provider, Anthem, suffered a breach and over 80 million records ended up stolen. That attack came to light when an administrator noticed multiple queries running from the account, but someone else had executed the queries. That discovery of the database queries soon led Anthem to realize it was under attack from an advanced cyber espionage group.
Victim: United Airlines
United, the world’s second-largest airline, detected an incursion into its computer systems in May or early June, said several people familiar with the probe.
Incident: German Nuke Infected with Malware
A nuclear power plant in Germany suffered from an infection of computer viruses, but they appear not to have posed a threat to the facility’s operations, the station’s operator said April 26.
The Gundremmingen plant, located about 120 km (75 miles) northwest of Munich, is run by the German utility RWE.
The viruses, which include W32.Ramnit and Conficker, ended up discovered at Gundremmingen’s B unit in a computer system retrofitted in 2008 with data visualization software associated with equipment for moving nuclear fuel rods, RWE said. The operating system ended up saved because it was not connected to the Internet.
Malware was also on 18 removable data drives, mainly USB sticks, in office computers maintained separately from the plant’s operating systems. RWE said it increased cyber security measures as a result.
Reference: German Nuke Infected With Malware
Malware: W32.Ramnit
W32.Ramnit steals files from infected computers and targets Microsoft Windows software, according to the security firm Symantec. First discovered in 2010, it ends up distributed through data sticks, among other methods, and can give an attacker remote control over a system when there is a connection to the Internet.
Malware: Conficker
Conficker has infected millions of Windows computers worldwide since it first came to light in 2008. It is able to spread through networks and by copying itself onto removable data drives.
Victim: Gundremmingen plant run by the German utility RWE.
The viruses, which include W32.Ramnit and Conficker, ended up discovered at Gundremmingen’s B unit in a computer system retrofitted in 2008 with data visualization software associated with equipment for moving nuclear fuel rods, RWE said. The operating system ended up saved because it was not connected to the Internet.
Incident: Gas Supplier Hit In Ransomware Attack
Toronto, Canada-based Superior Plus Corp. revealed the company suffered a ransomware attack Sunday, which had an impact on the firm’s computer systems.
Upon learning of the incident, the company said it took steps to secure its systems and mitigate the impact on its data and operations. Superior retained independent cybersecurity experts to help deal with the matter in accordance with industry best practices.
Superior temporarily disabled certain computer systems and applications as it investigates this incident and is in the process of bringing these systems back online.
Reference: Gas Supplier Hit In Ransomware Attack
Victim: Superior Plus Corp.
Superior is a North American distributor and marketer of propane and distillates and related products and services, servicing over 780,000 locations in the U.S. and Canada.
Incident: Cloud Provider Hit in Ransomware Attack
The Kronos Private Cloud (KPC), a human resources platform used by multiple organizations and industries, was hit with a ransomware attack over the weekend.
The attack forced parent company UKG to tell its customers it may take several weeks to restore service. UKG, which resulted from the merger of Kronos and Ultimate Software last year, to customers to implement an alternative business continuity protocol in the interim.
Reference: Cloud Provider Hit In Ransomware Attack
Victim: Kronos Private Cloud (KPC)
A ransomware incident affecting the Kronos Private Cloud – the portion of our business where UKG Workforce Central, UKG TeleStaff, Healthcare Extensions, and Banking Scheduling Solutions are deployed.
Tesla, the city of Cleveland, Clemson University and Temple University use the KPC platform.
Incident: Security Firm Hacked
Bit9, a security firm that provides software reputation, application control and whitelisting services suffered a breach that left three of its customers infected with malware.
“Due to an operational oversight within Bit9, we failed to install our own product on a handful of computers within our network. As a result, a malicious third party was able to illegally gain temporary access to one of our digital code-signing certificates that they then used to illegitimately sign malware,” said Bit9 Chief Executive Patrick Morley.
This was a supply chain attack.
Reference: Security Firm Hacked
Victim: Bit9
Bit9 is a security firm that provides software reputation, application control and whitelisting services.
Incident: FL Utility Suffers DDoS
The website of Jacksonville, FL-based JEA, a not-for-profit community-owned utility company that serves one million people, suffered a distributed denial-of-service (DDOS) attack.
The company notified customers the attack, which disrupted its website and its automatic phone system, started February 17, 2013.
Reference: FL Utility Suffers DDoS
Victim: JEA
Jacksonville, FL-based JEA is a not-for-profit community-owned utility company that serves one million people.
Incident: Poughkeepsie, NY, Utility Hacked
Hackers gained entry to as many as 110,000 customer accounts at Poughkeepsie, NY-based Central Hudson Gas and Electric.
Employees detected the computer system intrusion Feb. 20, 2013. The attack occurred over a weekend, and as a result of regular control procedures, employees found the attack and reported it, the utility said.
Reference: Poughkeepsie, NY, Utility Hacked
Victim: Central Hudson Gas & Electric
Poughkeepsie, NY-based Central Hudson Gas and Electric is a gas and electric utility.
Editorial: Aussie Electric Utility Hit in Ransomware Attack
Incident: CS Energy Hit In Ransomware Attack
The incident occurred Nov. 27 on CS Energy’s corporate network and did not have an impact on electricity generation at the Callide and Kogan Creek power stations, officials said. Those stations are continuing to generate and dispatch electricity into the National Electricity Market.
Reference: Ransomware attack on Australian utility claimed by Russian-speaking criminals
Reference: Aussie Electric Utility Hit In Ransomware Attack
Victim: CS Energy
Queensland, Australia, government-owned energy generator CS Energy continued to generate electricity and feed it into the grid since the November 27 ransomware attack and has “systems and safeguards [with] layers of separation and protection, which enabled it to contain and protect its critical infrastructure.”
The incident occurred on CS Energy’s corporate network and did not have an impact on electricity generation at the Callide and Kogan Creek power stations, officials said. Those stations are continuing to generate and dispatch electricity into the National Electricity Market.
Editorial: Cyber Attack Damages CO Utility
Incident: Cyber Attack Damages CO Utility
Montrose, Colorado-based Delta-Montrose Electric Association (DMEA) should be up and running within a week and completely operational by the end of the year after the utility fell victim to a “sophisticated and malicious” cyber attack in early November.
DMEA Chief Executive, Alyssa Clemsen Roberts confirmed the attack the utility discovered November 7 to the board of directors this past Tuesday (Nov. 30).
“We are a victim of a malicious cyber security attack,” Clemsen Roberts said in a report in the Montrose Daily Press. “In the middle of an investigation, that is as far as I’m willing to go. In the process about 90 percent of our internal controls and systems were corrupted or broken or disabled. And we lost the majority of our historical data for the last 20-25 years. Since then we have been slowly rebuilding our network.”
Reference: Cyberattack Causes Significant Disruption at Colorado Electric Utility
Reference: Cyber Attack Damages CO Utility
Victim: Delta-Montrose Electric Association (DMEA)
In November, the Montrose, Colorado-based cooperative said there was a “targeted attempt” on its internal network, which took some operations offline, including SmartHub and electronic bill-pay options. DMEA hired an outside organization to conduct an analysis.
The attack affected phones, email, and data such as forms, documents, spreadsheets and historical data. DMEA was unable to take or make payments, but, Clemsen Roberts said the power grid and fiber network were not affected.
The co-op is still dealing with limited functionality of internal systems and working to fully restore the system this week while the investigation continues and DMEA takes “significant measures” to boost network security.
Incident: Panasonic Breached in Attack
Osaka, Japan-based Panasonic Corporation confirmed its network was illegally accessed by a third party on November 11 and data ended up accessed in the breach, officials said.
As soon as the electronics giant discovered the breach, it initiated an internal investigation and discovered some data on a file server had been accessed during the intrusion. Panasonic spokesperson Dannea DeLisser said the breach began on June 22 and ended on November 3 — and the unauthorized access was first detected on November 11.
Reference: Panasonic discloses data breach after network hack
Reference: Panasonic Breached in Attack
Victim: Panasonic
As soon as the electronics giant discovered the breach, it initiated an internal investigation and discovered some data on a file server had been accessed during the intrusion. Panasonic spokesperson Dannea DeLisser said the breach began on June 22 and ended on November 3 — and the unauthorized access was first detected on November 11.
After detecting the unauthorized access, the company immediately reported the incident to the relevant authorities and implemented security countermeasures, including steps to prevent external access to the network, according to a Panasonic advisory.
Incident: Supernus Pharma Hit in Ransomware Attack
Rockville, Maryland-based Supernus Pharmaceuticals, Inc., a biopharmaceutical company, said Wednesday it was a target of a ransomware attack.
The attack, which started November 14, had no significant impact on the business and did not cause any serious disruption to the company’s operations, officials said in an advisory. The company added it continues to operate without interruption and does not currently anticipate paying any ransom amounts to any criminal ransomware group.
Reference: Ransomware Operators Threaten to Leak 1.5TB of Supernus Pharmaceuticals Data
Reference: Supernus Pharma Hit In Ransomware Attack
Threat Actor: Hive Ransomware Group
Hive ransomware uses multiple mechanisms to compromise business networks, including phishing emails with malicious attachments to gain access and Remote Desktop Protocol (RDP) to move laterally once on the network, according to the report.
After compromising a victim network, Hive ransomware actors exfiltrate data and encrypt files on the network. The actors leave a ransom note in each affected directory within a victim’s system, which provides instructions on how to purchase the decryption software. The ransom note also threatens to leak exfiltrated victim data on the Tor site, “HiveLeaks.”
Hive ransomware seeks processes related to backups, anti-virus/anti-spyware, and file copying and terminates them to facilitate file encryption, according to the report. The encrypted files commonly end with a .hive extension. The Hive ransomware then drops a hive.bat script into the directory, which enforces an execution timeout delay of one second in order to perform cleanup after the encryption is finished by deleting the Hive executable and the hive.bat script.
Victim: Supernus Pharmaceuticals, Inc.
Supernus Pharmaceuticals focuses on developing and commercializing products for the treatment of central nervous system (CNS) diseases. Its portfolio includes approved treatments for epilepsy, migraine, ADHD, hypomobility in Parkinson’s disease, cervical dystonia and chronic sialorrhea.
Editorial: Wind Turbine Maker Hit in Cyber Attack
Incident: Wind Turbine Maker Hit in Cyber Attack
One of the world’s biggest wind turbine makers, Aarhus, Denmark-based Vestas Wind Systems A/S, shut down computer systems across several locations Saturday to deal with a cyber security incident.
Vestas discovered a cyber security incident Friday and has since then, together with external partners, worked to contain the situation and re-establish the integrity of its IT systems.
The company’s preliminary findings indicate the incident had an impact on parts of Vestas’ internal IT infrastructure and data has suffered compromise.
Reference: Vestas recovers from cyber attack and data breach
Reference: Wind Turbine Maker Hit in Cyber Attack
Victim: Vestas Wind Systems A/S,
One of the world’s biggest wind turbine makers, Aarhus, Denmark-based Vestas Wind Systems A/S.
Vestas’ manufacturing, construction and service teams have been able to continue operations, although several operational IT systems have been shut down as a precaution. Vestas has already initiated a gradual and controlled reopening of all IT systems.
Editorial: Ransomware Attacks Focus on ‘Small Failures’
Incident: Automotive Group Hit in Ransomware Attack
A U.S.-based automotive group of dealerships fell victim to a new ransomware attack group threatening to drop 200 GB of exfiltrated data unless the group pays $400,000.
The attack is a variant of ransomware called Colossus that affects machines running Microsoft Windows operating systems, according to a report by the ZeroFox Threat Intelligence team. The sample has features including binary packing via Themida and sandbox evasion capabilities. The ransomware has a support website for setting up communications with victims, which most likely launched September 20.
Reference: Flash Report: Colossus Ransomware
Reference: Automotive Group Hit in Ransomware Attack
Malware: Colossus
Ransomware called Colossus affects machines running Microsoft Windows operating systems.
Victim: U.S.-based automotive group
A representative of this U.S.-based automotive group with the anonymous username “USER912058085” appears to have entered the chat room and initiated negotiations, according to ZeroFox.
Incident: Acer Hit in Cyber Attack
After attackers infiltrated Acer’s servers in India, the company’s Taiwan office fell victim to a breach this past weekend.
On October 16, Desorden hackers said they obtained login details belonging to employees of Acer’s Taiwanese branch. That came three days after the attack group breached Acer India’s servers. The attack group apparently found vulnerabilities on Acer’s Malaysian and Indonesian network as well, according to a report with Privacy Affairs.
Reference: Acer Confirms Third Cyberattack in 2021 – Employee Information Shared on Hacker Forum
Reference: Acer Hit In Cyber Attack
Threat Actor: Desorden
Desorden described themselves as former associates of Chaos. In one report they said they reformed ourselves as Desorden Group which stands for Chaos & Disorder. Their targets are supply chain networks and public services. Desorden attacks on supply chains create higher level of disorder and chaos affecting many parties rather than the victim itself. If victim fails to pay, Desorden sells the data on black market in a few days.
Victim: Acer
Acer Inc. is a Taiwanese multinational hardware and electronics corporation specializing in advanced electronics technology, headquartered in Xizhi, New Taipei City.
Incident: Weir Group Ransomware Incident
Weir Group is currently managing the consequences of a sophisticated attempted ransomware attack that occurred in the second half of September. Weir’s cybersecurity systems and controls responded quickly to the threat and took robust action. This included isolating and shutting down IT systems including core Enterprise Resource Planning (ERP) and engineering applications. These applications are now restored on a partial basis, and other applications are being brought back online in a progressive manner in order of business priority. The above actions have led to a number of ongoing but temporary disruptions including engineering, manufacturing and shipment rephasing, which has resulted in revenue deferrals and overhead under-recoveries. Effective capabilities are being progressively restored in the coming weeks but the consequences of the operational disruption and associated inefficiencies are expected to continue into the fourth quarter.
Reference: Industrial Engineering Group Hit In Ransomware Attack
Reference: Q3 trading update and cybersecurity incident
Victim: Weir Group
Weir Group employs 11,500 people in over 50 countries serving mining, infrastructure and oil and gas markets.
Editorial: Ransomware: Trusting the Attackers
Incident: French Container Operator Hit By Attack
French container operator, CMA CGM S.A. suffered a cyberattack with unknown hackers leaking part of its customer information, officials said Monday.
The world’s third biggest boxship operator said the “limited customer information” leak includes names, positions, emails and phone numbers.
Reference: French Container Operator CMA CGM Hit By Cyberattack
Reference: French Container Operator Hit By Attack
Victim: CMA CGM S.A.
CMA CGM is the world’s third largest liner – the top four, which include Maersk, MSC and Cosco, have all suffered hacks in recent years, leading to massive losses.
Threat Actor: BlackMatter
BlackMatter threatened to publish a terabyte of the cooperative’s data, including invoices, research and development documents, and the source code to its soil-mapping technology, if it did not receive the ransom payment in cryptocurrency by Sept. 25.
Incident: IA Ag Cooperative Hit In Ransomware Attack
An Iowa agricultural business, New Cooperative, suffered a ransomware attack and the criminal gang is demanding a $5.9 million ransom. And while the victim and the attacker quibble over if the organization is considered critical infrastructure or not, a vital system is shut down.
New Cooperative confirmed it had been hit with a cyberattack either late Friday or early Saturday and shut down its systems in response. Researchers are saying the cyber gang called BlackMatter, which has Russian ties, perpetrated the assault.
New Cooperative contained the breach and developed a workaround to continue accepting grain shipments and distributing feed.
The cooperative took its computer network offline to isolate the incursion and stopped its soil-mapping software — a master-control system that optimizes irrigation and fertilization — as a precaution.
Reference: Russian hackers target Iowa grain co-op in $5.9 million ransomware attack
Reference: IA Ag Cooperative Hit In Ransomware Attack
Victim: New Cooperative
Fort Dodge, Iowa-based New Cooperative is a member-owned alliance of farmers that sells corn and soy products.
Threat Actor: Security consultant
A security consultant was scanning the food companies business and process networks for vulnerabilities. Probe packets containing deliberately malformed entered the Ethernet-based process control network and caused all PLCs to hard fault. The packets contained malformed ICMP Redirects messages with a subcode of 4 or greater.
Incident: Olympus Hit by Ransomware Attack
Olympus is now investigating the ransomware attack, and the company said the incident occurred in the Europe, the Middle East, and Africa (EMEA) regions, and it happened September 8.
Reference: Technology giant Olympus hit by BlackMatter ransomware
Reference: Olympus Hit By Ransomware Attack
Malware: BlackMatter
BlackMatter is a ransomware-as-a-service group founded as a successor to several ransomware groups, including DarkSide, which appeared to attack the Colonial Pipeline, and REvil, which went silent for months after the Kaseya attack flooded hundreds of companies with ransomware.
Victim: Olympus
Technology multi-national, Olympus, confirmed it suffered a ransomware attack last week and the threat group behind it has been identified as "BlackMatter."
Olympus is now investigating the ransomware attack, and the company said the incident occurred in the Europe, the Middle East, and Africa (EMEA) regions, and it happened September 8.
Incident: Ransomware Attack on Holiday at ME Wastewater Plant
In northern Maine, Limestone Water and Sewer District was hit on the Fourth of July holiday. Limestone Water and Sewer District Superintendent Jim Leighton said the ransomware attack impaired control computers at two plants necessitating both to revert to manual operations. The control computers were responsible for alarming on equipment damage (pumps over-heating) and operational errors (tanks over-filling).
Reference: Ransomware Attacks At 2 ME Wastewater Plants
Victim: Limestone Water and Sewer District
The facility was using a Windows 7 computer which was well past its end of life date and was due to be replaced anyway, said Limestone Water and Sewer District Superintendent Jim Leighton. In the end, it may have been a good thing because it caught the attention of water and sewage district operators in Aroostook County, he said.
“We said enough of that, it’s not worth paying a ransom for,” Leighton said. “We had to update it anyway.”
Incident: Ransomware Attacks At ME Wastewater Plant
The April attack occurred in the town of Mount Desert on Mount Desert Island, Maine.
In Mount Desert Island, officials said the attack took computers offline for three days, but treatment plants were not affected because they are controlled manually.
Ed Montague, superintendent for Mount Desert Wastewater, said, “The office computers were down for approximately three working days… Our treatment plants were not affected as they are manually controlled with no automated inputs.” No ransom was paid and no personal information was compromised, Montague said, and town and IT professionals were notified.
Reference: Ransomware Attacks At 2 ME Wastewater Plants
Victim: Mount Desert Wastewater
Office computers were down for three working days. Treatment plants were not affected as they are manually controlled with no automated inputs.
Incident: Ransomware Hits MO City
A ransomware attack shut down the city of Joplin, MO, government’s computer system in early July, city officials said last week.
While the debate on whether to pay the ransom rages, an insurer paid $320,000 to someone not identified, to keep any sensitive information obtained as a result of the cyberattack from being exposed, City Manager Nick Edwards said in the statement.
Reference: Ransomware Hits MO City
Victim: City of Joplin, MO
A ransomware attack shut down the city of Joplin, MO, government’s computer system in early July.
Incident: Accenture Back Up After Ransomware Attack Report
Accenture said it has fully restored certain affected systems, after a hacker group attacked the consulting firm using LockBit ransomware and threatened to release the data in several hours.
“Through our security controls and protocols, we identified irregular activity in one of our environments. We immediately contained the matter and isolated the affected servers,” Accenture said in a Wednesday statement. “We fully restored our affected systems from backup, and there was no impact on Accenture’s operations, or on our clients’ systems.”
Reference: Accenture Responds Following LockBit Ransomware Attack
Reference: Ransomware group threatening to leak stolen data
Reference: Accenture Back Up After Ransomware Attack Report
Threat Actor: LockBit
The LockBit ransomware gang first emerged in September 2019. LockBit, like many other ransomware gangs, leases its malicious software to third-party criminal affiliates who then receive a cut of ransoms in exchange for planting the code onto victim networks.
On February 19 2024 authorities took down LockBit's infrastructure, which included 34 servers hosting the data leak website and its mirrors, data stolen from the victims, cryptocurrency addresses, decryption keys, and the affiliate panel. This disruption was part of an international law enforcement operation called Operation Cronos. Five days later, LockBit relaunched with new infrastructure and threatened to focus more of its attacks on the government sector. However, the ransomware gang was never able to return to its previous prominence, with its affiliates moving to other ransomware operations. Over the past year, law enforcement has continued to target LockBit, identifying and charging seven LockBit ransomware members.
Malware: LockBit
The LockBit ransomware gang first emerged in September 2019. LockBit, like many other ransomware gangs, leases its malicious software to third-party criminal affiliates who then receive a cut of ransoms in exchange for planting the code onto victim networks.
Victim: Accenture
Global technology consulting firm
Incident: Attacks Shuts South Africa Port Ops
Transnet, a state-owned South African rail, port and pipeline company, suffered a cyberattack July 22.and has been forced to halt operations. Transnet declared force majeure at 4 container terminals. Container shipment processing was delayed for 7 days.
Transnet said ports at Durban, Ngqura, Port Elizabeth and Cape Town were affected.
Reference: South Africa Port Operator Declares Force Majeure Over Cyber Attack
Reference: Attacks Shuts South Africa Port Ops
Victim: Transnet
Transnet, a state-owned South African rail, port and pipeline company, suffered a cyberattack July 22 and has been forced to halt operations.
The logistics firm stopped operations at container terminals in Durban, Ngqura, Port Elizabeth and Cape Town, South Africa.
“Transnet, including Transnet Port Terminals, experienced an act of cyberattack, security intrusion and sabotage, which resulted in the disruption of TPT normal processes and functions or the destruction or damage of equipment or information,” Bloomberg reported on a note Transnet sent to customers.
Incident: Saudi Aramco Data Breach
Saudi Aramco, the state oil company of Saudi Arabia, was the focus of a $50 million data breach.
Aramco is describing the attack as an indirect release of a limited amount of company data held by third-party contractors. Saudi Aramco said there was no breach of its systems and said the attack had no impact on its operations. However, it became aware of the indirect release of a limited amount of company data which was held by third-party contractors.
A listing for the stolen data was posted on June 23.
Reference: Saudi Aramco Suffers Data Breach
Reference: Saudi Aramco data breach sees 1 TB stolen data for sale
Threat Actor: ZeroX
A group called ZeroX is taking credit for the attack. ZeroX said it holds 1 terabyte of data from the company and is threatening to release the stolen data if the ransom is not paid.
Victim: Saudi Aramco
Saudi Aramco, officially the Saudi Arabian Oil Company, is a Saudi Arabian public petroleum and natural gas company based in Dhahran.
Threat Actor: ZeroX
A group called ZeroX is taking credit for the attack. ZeroX said it holds 1 terabyte of data from the company and is threatening to release the stolen data if the ransom is not paid.
Victim: Saudi Aramco
Saudi Aramco, officially the Saudi Arabian Oil Company, is a Saudi Arabian public petroleum and natural gas company based in Dhahran.
Incident: AL Utility Hit In Ransomware Attack
A ransomware attack hit Wiregrass Electric Cooperative (WEC) in Hartford, Alabama, this weekend, officials said. However, there was no compromise of data. In addition, this attack was not connected to the Kaseya supply-chain attack.
Reference: AL Utility Hit In Ransomware Attack
Victim: Wiregrass Electric Cooperative
Wiregrass Electric Cooperative, which serves about 22,000 members, said in a statement: “A ransomware attack was made against Wiregrass Electric Cooperative this weekend. While no data was compromised, we will be conducting system maintenance out of an abundance of caution. During this maintenance, all account access and payment systems will be unavailable. Disconnects will be suspended during this time, as well. We will restore all systems when we feel it is safe to do so.”
Incident: Supply Chain Attack Guidance Released
While the supply-chain ransomware attack Friday leveraging a vulnerability in Kaseya VSA software against multiple managed service providers (MSPs) and their customers remains under investigation, small- to midsize manufacturing companies could feel the impact.
Reference: ‘Turn off your heart’: Kaseya VSA ransomware hits MSPs in a vital organ
Reference: Supply Chain Attack Guidance Released
Threat Actor: REvil
REvil (Ransomware Evil, also known as Sodinokibi) is a private ransomware-as-a-service (RaaS) operation. After an attack, REvil would threaten to publish the information on their page 'Happy Blog' unless the ransom is received.
Incident: Hacker Accessed CA Water Treatment System
A hacker was easily able to get in to a San Francisco Bay Area water treatment facility in mid-January and delete programs used to treat drinking water, a senior intelligence official said Thursday. The hacker used a former plant employee’s username and password to gain entry to the unidentified Bay Area water treatment facility Jan. 15, according to a NBC News report.
Reference: Hacker Accessed CA Water Treatment System
Victim: San Francisco Bay Area Water Facility
The hacker used a former plant employee’s username and password to gain entry to the unidentified Bay Area water treatment facility Jan. 15, according to a NBC News report.
Confirming the attack, Michael Sena, executive director of the Northern California Regional Intelligence Center – which works with the Department of Homeland Security and the FBI to track suspicious activity – declined to say where it occurred or who carried it out.
Incident: DoE Nuclear Subcontractor Suffers Cyber Attack
A subcontractor for the Department of Energy (DoE) that conducts nuclear weapons-related work, said it fell victim to a security breach.
Sol Oriens is the name of the consulting firm working with DoE’s National Nuclear Security Administration, the federal agency which has a mission of enhancing and securing U.S. nuclear stockpiles. Sol Orien’s work with the nuclear agency remain unclear to the public at this point.
Reference: Contractor that does nuclear weapons-related works for Energy Department hit by ransomware
Reference: DoE Nuclear Subcontractor Suffers Cyber Attack
Victim: Sol Oriens
Sol Oriens is the name of the consulting firm working with DoE’s National Nuclear Security Administration, the federal agency which has a mission of enhancing and securing U.S. nuclear stockpiles. Sol Orien’s work with the nuclear agency remain unclear to the public at this point.
Incident: South Korea’s Atomic Agency Suffers Hack Attack
The intrusion took place in May by what is believed to be an attack group operating out of North Korea, said a KAERI spokesperson. The incident occurred May 14 and the attackers got in through a vulnerability in a virtual private network (VPN) server. KAERI is the government organization that conducts research on nuclear power and nuclear fuel technology.
Reference: North Korean hackers breach South Korea’s atomic research agency through VPN bug
Reference: South Korea’s Atomic Agency Suffers Hack Attack
Threat Actor: Kimsuky
Kimsuky is a North Korean state-backed hacker group (also known as Velvet Chollima, Black Banshee, THALLIUM, or Emerald Sleet), an advanced persistent threat that targets South Korean think tanks, industry, nuclear power operators, and the South Korean Ministry of Unification for espionage purposes.
Kimsuky and Andariel are some of the North Korean hacker groups whose activities focus on espionage and attacks on the cryptocurrency industry.
In recent years Kimsuky has expanded its operations to target states such as Russia, the United States, and European nations.
Victim: South Korean Atomic Energy Research Institute (KAERI)
Attackers breached a vulnerability in a virtual private network (VPN) server of the South Korean Atomic Energy Research Institute (KAERI), officials said Friday.
The intrusion took place in May by what is believed to be an attack group operating out of North Korea, said a KAERI spokesperson. The incident occurred May 14 and the attackers got in through a vulnerability in a virtual private network (VPN) server. KAERI is the government organization that conducts research on nuclear power and nuclear fuel technology.
Malware: Ransomware – Unknown group or variant
Unknown attack group or variant.
Incident: Fujifilm Now Operating after Ransomware Attack
Japan’s major film provider, Fujifilm, finally restored operations on June 14, following a ransomware attack earlier this month.
On June 4, Fujifilm said it fell victim to a ransomware attack on June 1 which forced the company to shut down its network and servers across the globe. Beyond the shutdown, there were order processing delays. While most regions were able to get back up and running fairly quickly, Japan suffered the biggest impact.
Fujifilm manufactures a wide variety of products, including rapid COVID19 test kits.
Reference: Fujifilm Restores Services Following Ransomware Attack
Reference: Fujifilm Now Operating After Ransomware Attack
Victim: Fujifilm
On June 4, Fujifilm said it fell victim to a ransomware attack on June 1 which forced the company to shut down its network and servers across the globe. While most regions were able to get back up and running fairly quickly, Japan suffered the biggest impact.
However, this Monday Fujifilm said it had restored all operations.
The Tokyo-based company also said it did not end up paying any ransom, but instead restored operations using backups, with its computer systems in the U.S., Europe, the Middle East and Africa.
Reference: Volkswagen hack: 3 million customers have had their information stolen
Reference: VW, Audi Hit In Cyber Attack
Victim: Volkswagen
More than 3 million customers or shoppers had at least basic contact information stolen from an outside company that worked with the automakers, VW officials said. That data included phone numbers, email addresses, postal mailing addresses and, in some cases, vehicle identification numbers.
Incident: VW, Audi Hit In Cyber Attack
Volkswagen and Audi, VW’s luxury brand, suffered a a data breach that exposed contact information and, in some cases, personal details, like driver license numbers, of customers in the United States and Canada.
Editorial: Think Security Not Just Ransomware
Incident: Ransomware Hits MA Ferry Service
A ransomware attack hit The Steamship Authority of Massachusetts affecting ticketing, reservations, credit card payment and other IT systems. Customers were unable to book or change reservations online or by phone. There was no impact on physical operations, as the issue did not affect radar or GPS functionality, and the operator was able to revert to manual operations and cash payments. Delays possible related to the ticketing process.
The ferry service operates between mainland Massachusetts and the islands of Martha’s Vineyard and Nantucket.
Reference: Ransomware Hits MA Ferry Service
Victim: Woods Hole, Martha’s Vineyard and Nantucket Steamship Authority
“The Woods Hole, Martha’s Vineyard and Nantucket Steamship Authority has been the target of a ransomware attack that is affecting operations as of Wednesday morning. As a result, customers traveling with us today may experience delays,” the Steamship Authority said on Twitter.
“A team of IT professionals is currently assessing the impact of the attack. Additional information will be provided upon completion of the initial assessment,” the agency said.
Incident: Attack Shuts Operations of Global Meat Provider
Australian and North American units of the world’s largest meat works, Brazil’s JBS SA, suffered a cyberattack over the weekend by an assault on its information systems, effectively shutting down at least 9 plants in the USA, one in Canada and one in Australia. Shutdowns lasted 2 days.
JBS produces 23% of America's meat.
Reference: Attack Shuts Operations Of Global Meat Provider
Victim: JBS SA
Australian and North American units of the world’s largest meat works, Brazil’s JBS SA, suffered a cyberattack over the weekend by an assault on its information systems, effectively shutting down operations in some regions, company officials said.
Incident: Tulsa cybersecurity attack similar to pipeline attack
A cybersecurity attack on the city of Tulsa’s computer system was similar to an attack on the Colonial Pipeline and that the hacker is known.
Reference: https://abcnews.go.com/US/wireStory/tulsa-cybersecurity-attack-similar-pipeline-attack-77811164
Victim: City of Tulsa, Oklahoma
Tulsa’s computer security system identified the attack and shut down the system before it was infiltrated.
The attack, discovered earlier this month, was similar to the ransomware attack that shut down the Colonial Pipeline for days, according to Tulsa Chief Information Officer Michael Dellinger.
Incident: Air India: Hack Leaked Passengers’ Data
Personal data of an unspecified number of travelers has been compromised after a company that serves India’s national carrier was hacked, Air India said.
The hackers were able to access 10 years’ worth of data including names, passport and credit card details from the Atlanta-based SITA Passenger Service System, Air India said in a statement Friday.
Reference: India’s National Carrier Says Hack Leaked Passengers’ Data
Victim: Air India
The breach that happened in late February had compromised the data of some major global airlines, too. SITA at that time had said that Singapore Airlines, New Zealand Air and Lufthansa were among those affected.
Air India said almost 4.5 million passengers globally were affected in the “highly sophisticated” attack but did not specify how many of them were its travelers.
Editorial: Executive Order’s Impact on ICS Industry
Incident: EU Packaging Maker, Ardagh Group Hit By Cyberattack
European glass and metal packaging manufacturer Ardagh Group shut down some of its systems as a precautionary measure after the company suffered from a cyberattack, officials said Monday.
In an effort to deal with the attack, the Dublin-Ireland-based company said it initiated defense and containment procedures, and was working with external security experts to deal with the incident.
Supply chain operations have been affected, and alternative solutions, including manual workarounds, have been implemented. While products have continued to be shipped to customers, shipping delays were reported
“We are progressively bringing key systems back online securely, in a phased manner. This is proceeding according to plan and is expected to be substantially achieved by the end of this month,” Ardagh said in a statement.
Reference: Packaging vendor Ardagh admits cyber-attack disrupted operations
Reference: EU Packaging Maker Hit By Cyberattack
Victim: Ardagh Group
European glass and metal packaging manufacturer Ardagh Group shut down some of its systems as a precautionary measure after the company suffered from a cyberattack, officials said Monday.
In an effort to deal with the attack, the Dublin-Ireland-based company said it initiated defense and containment procedures, and was working with external security experts to deal with the incident.
Incident: Toshiba Hit In DarkSide Ransomware Attack
Toshiba Tec Corp. fell victim late last week to a ransomware attack by the same organization that hit Colonial Pipeline, only this assault had an impact in Europe.
Japan-based Toshiba Tec Corp operates through two business segments, the retail solutions segment and the Printing Solutions segment where manufacture products including barcode scanners, Point-of-Sale (PoS) systems, printers, and other electrical equipment. The target in the attack appears to be the company’s French subsidiary.
Reference: Toshiba unit struck by DarkSide ransomware group
Reference: Toshiba Hit In DarkSide Ransomware Attack
Malware: DarkSide
DarkSide is a ransomware-as-a-service (RaaS) outfit that provides ransomware to affiliates within its network in return for a cut of any profits made by extorting victim organizations.
DarkSide affiliates employ a double-extortion tactic, in which companies first receive a demand for payment in return for a decryption key to unlock systems infected with DarkSide ransomware. If they refuse, they are then threatened with the public release of confidential data and records stolen during initial access on a leak site.
Victim: Toshiba Tec Corp.
Operates through two business segments, the retail solutions segment and the Printing Solutions segment where manufacture products including barcode scanners, Point-of-Sale (PoS) systems, printers, and other electrical equipment. The target in the attack appears to be the company’s French subsidiary.
Reference: Insurance Carrier Suffers Ransomware Attack
Victim: AXA Partners
This ransomware attack hit information technology operations in Thailand, Malaysia, Hong Kong and the Philippines, the AXA statement said. “As a result, certain data processed by Inter Partners Asia (IPA) in Thailand has been accessed,” it said.
Malware: Avaddon
Russian-speaking attackers used a ransomware variant called Avaddon.
Incident: Insurance Carrier Suffers Ransomware Attack
AXA Partners, the international subsidiary of AXA insurance group, ended up hit by ransomware attacks in four countries, company officials said.
The attack comes on the heels of AXA, among Europe’s top five insurers, saying it will stop writing cyber-insurance policies in France that reimburse customers for extortion payments made to ransomware criminals. The Paris-based group said it was suspending the option in France only in response to growing concern that such reimbursements encourage cyber criminals to demand ransom from companies they prey on, crippling them with malware. Once victims of ransomware pay up, criminals provide software keys to decode the data.
Editorial: Pipeline Ops Shut Down after Ransomware Attack
Reference: Pipeline Ops Shut Down After Ransomware Attack
Threat Actor: DarkSide
Criminal gang known as DarkSide that cultivates a Robin Hood image of stealing from corporations and giving a cut to charity.
It is among ransomware gangs that have "professionalized" a criminal industry that has cost Western nations tens of billions of dollars in losses in the past three years.
DarkSide claims it does not attack hospitals and nursing homes, educational or government targets and that it donates a portion of its take to charity. It has been active since August and, typical of the most potent ransomware gangs, is known to avoid targeting organizations in former Soviet bloc nations.
DarkSide announced its closure in the aftermath of the Colonial Pipeline assault.
Victim: Colonial Pipeline
Colonial Pipeline said the ransomware attack Friday affected some of its information technology systems and the company moved proactively to take certain systems offline, halting pipeline operations, according to a report by The Associated Press. The company said it delivers roughly 45 percent of all fuel consumed on the East Coast.
In an earlier statement, it said it was “taking steps to understand and resolve this issue” with an eye toward returning to normal operations.
The Alpharetta, Georgia-based company transports gasoline, diesel, jet fuel and home heating oil from refineries primarily located on the Gulf Coast through pipelines running from Texas to New Jersey. Its pipeline system spans more than 5,500 miles, transporting more than 100 million gallon a day.
Incident: Colonial Pipeline Ops Shut Down after Ransomware Attack
Colonial Pipeline, which operates a major pipeline system that transports fuel across the East Coast, fell victim to a ransomware attack Friday and halted all pipeline operations while it dealt with the incident, company officials said. Colonial Pipeline did not say what was demanded or who made the demand. Ransomware attacks are typically carried out by criminal hackers who seize data and demand a large payment in order to release it.
UPDATE: The FBI has established that the DarkSide is to blame for the assaults. The DarkSide appears to be unaffiliated with any nation-states, claiming in a statement that "our purpose is to generate money [not to create] issues for society" and that it is apolitical. DarkSide announced its closure in the aftermath of the pipeline assault.
Reference: DigitalOcean says customer billing data accessed in data breach
Reference: Cloud Provider, DigitalOcean, Suffers Data Breach
Victim: DigitalOcean
DigitalOcean is a cloud infrastructure company.
Incident: Cloud Provider, DigitalOcean, Suffers Data Breach
DigitalOcean suffered a breach involving customers’ billing data.
The cloud infrastructure company sent out an email to customers Wednesday saying it “confirmed an unauthorized exposure of details associated with the billing profile on your DigitalOcean account.”
Malware: Ransomware (target: Gyrodata)
The attacker gained access to certain systems and related data within the Gyrodata environment at various times from approximately January 16 to February 22.
The data potentially obtained by the unauthorized actor may have contained personal information of current and former Gyrodata employees, including names, addresses, dates of birth, drivers’ license numbers, Social Security numbers, passport numbers, W-2 tax forms, and information related to health plan enrollment.
Incident: Oil Drilling Company, Gyrodata, Hit By Ransomware
On February 21, Gyrodata discovered it was the target of a ransomware attack. In response, the company immediately took steps to secure its systems, launched an investigation, and a cybersecurity firm was engaged to assist with its investigation.
Reference: US Drilling Giant Gyrodata Reveals Employee Data Breach
Reference: Oil Drilling Company Hit By Ransomware
Victim: Gyrodata
A Houston, Texas-based oil drilling specialist suffered a ransomware attack which may have led to the compromise of data belonging to current and former employees.
Gyrodata Inc. provided notice of a data security where it identified and addressed a attack involving personal information of some current and former Gyrodata employees.
Incident: Data Leak At New England Energy Supplier, Eversource
New England’s energy provider Eversource suffered a data leak in March that compromised the personal information of thousands of customers.
Eversource Energy, which provides service to 4.3 million electricity, natural gas and water users, sent across notifications to its customers to notify them about the breach.
Reference: Private Data of 11,000 Eversource Customers in Eastern Mass Exposed
Reference: Data Leak At New England Energy Supplier
Victim: Eversource
New England’s energy provider Eversource suffered a data leak in March that compromised the personal information of thousands of customers.
Eversource Energy, which provides service to 4.3 million electricity, natural gas and water users, sent across notifications to its customers to notify them about the breach.
According to the notification sent out by Eversource, the company identified misconfigured cloud storage on March 16 that exposed the personal information of customers, such as their names, addresses, phone numbers, social security numbers, service addresses, and account numbers. Further investigation revealed the leaked data belonged to customers residing in eastern Massachusetts.
The data leak was detected and fixed on the same day and the company’s security team confirmed the exposed data wasn’t used illegally or stolen or misused by unauthorized third parties. CyberScout, the cybersecurity company handling customer services on behalf of Eversource, published a document with additional details about the security incident, stating the exposed files were created in August 2019 and included personal information of 11,000 Eversource customers residing in eastern Massachusetts.
Incident: Ransomware Attack: Automation Supplier, Pilz, Down
Automation product supplier, Pilz, remains down after a week because of a ransomware attack.
Germany-based Pilz reached out to the prosecutor’s office and Federal Office for Security in Information Technology after suffering a targeted cyber-attack Oct. 13. Despite setting up an incident response team to locate the source of the attack and resolve the disruption, it warned that outages will continue for several more days.
Reference: Ransomware Attack: Automation Supplier, Pilz, Down
Victim: Pilz
Pilz operates in over 70 countries around the world, across Europe, Asia Pacific and the Americas.
The company supplies electronic control and monitoring devices, programmable logic controllers. Other products and services include sensor technology, bus and industrial wireless systems, risk assessments and training courses on machinery safety.
Incident: India Nuke Hit By Malware
A day after officials at Kudankulam Nuclear Power Plant (KKNPP) in Tamil Nadu, India, denied a cyberattack on its systems, the Nuclear Power Corporation of India Limited (NPCIL), the administrative governing body for nuclear power plants in the country, said “malware” was in one of their systems.
The NPCIL said Wednesday only an administrative system was infected by malware and the plant’s control systems were not affected. But others are saying there was domain controller level access achieved and mission critical targets hit.
Reference: India Nuke Hit By Malware
Victim: Kudankulam Nuclear Power Plant (KKNPP)
A day after officials at Kudankulam Nuclear Power Plant (KKNPP) in Tamil Nadu, India, denied a cyberattack on its systems, the Nuclear Power Corporation of India Limited (NPCIL), the administrative governing body for nuclear power plants in the country, said “malware” was in one of their systems.
The NPCIL said Wednesday only an administrative system was infected by malware and the plant’s control systems were not affected. But others are saying there was domain controller level access achieved and mission critical targets hit.
Incident: Airline Hit By Cyber Attack, Cancels Flights
After a cyber attack on its computer network, RavnAir was forced to cancel at least a half-dozen flights in Alaska Dec. 22, 2019.
While the airline itself is not a huge carrier, the cancellations affected around 260 passengers, said company spokeswoman Debbie Reinwand.
The regional carrier canceled all flights involving its Dash 8 aircraft until noon “because the cyber attack forced us to disconnect our Dash 8 maintenance system and its back-up,” the company said. The airline serves more than 100 communities in Alaska, many of which are not accessible by road.
Reference: Airline Hit By Cyber Attack, Cancels Flights
Victim: RavnAir
The regional carrier canceled all flights involving its Dash 8 aircraft until noon “because the cyber attack forced us to disconnect our Dash 8 maintenance system and its back-up,” the company said. The airline serves more than 100 communities in Alaska, many of which are not accessible by road.
Incident: Ransomware Takes Down Maritime Facility
There was a ransomware intrusion at a Maritime Transportation Security Act (MTSA) regulated facility, said officials at the U.S. Coast Guard (USCG).
The virus, identified as Ryuk ransomware, may have entered the network of the MTSA facility via an email phishing campaign, officials said.
Reference: Ransomware Takes Down Maritime Facility
Victim: Maritime Transportation Security Act (MTSA) regulated facility
The facility suffered a disruption of the entire corporate IT network (beyond the footprint of the facility), disruption of camera and physical access control systems, and loss of critical process control monitoring systems. These combined effects required the company to shut down the primary operations of the facility for over 30 hours while a cyber-incident response was conducted.
Incident: Ransomware Hits Trucking Firm
Teams restored most major desktop services and continue working to bring critical systems back online, including mobile services, said officials at Truckstop.com after a ransomware attack caused at least a weeklong outage that affected its sites, including its load board, online carrier safety vetting, and payment services.
Reference: Ransomware Hits Trucking Firm
Malware: Ransomware [Target: AU Prison]
Ransomware attack caused at least a weeklong outage that affected its sites, including its load board, online carrier safety vetting, and payment services.
Victim: Truckstop.com
Truckstop.com handles about 500,000 loads per day and has 200,000 active users. he New Plymouth, Idaho-based company said there is no evidence that any customer information was compromised, and systems are being continuously monitored for irregular activity. As of Dec. 26 they had major desktop services and were still working to restore other critical systems.
The outage hit at least seven sites owned by Truckstop.com. The affected services include the app-based load board, factoring, carrier onboarding, RFP tool, real-time freight monitoring, SaferWatch and ShipperMate. Most of the major services are up and running, the company said.
Editorial: NBA’s Houston Rockets Hit By Ransomware
Reference: KS Man Charged In Water Plant Attack
Threat Actor: Wyatt A. Travnichek
Wyatt A. Travnichek, 22, of Ellsworth County, Kansas ended up charged Wednesday with one count of tampering with a public water system and one count of reckless damage to a protected computer during unauthorized access.
The indictment said on March 27, 2019, Travnichek accessed the Ellsworth County Rural Water District’s protected computer system without authorization.
Victim: Ellsworth County Rural Water District
Wyatt Travnichek is charged with performing activities that shut down the processes at the facility which affect the facilities cleaning and disinfecting procedures with the intention of harming the Ellsworth Rural Water District No. 1, also known as Post Rock Rural Water District.
Incident: Ellsworth County, KS Rural Water District Attacked
Wyatt A. Travnichek, 22, of Ellsworth County, Kansas ended up charged with one count of tampering with a public water system and one count of reckless damage to a protected computer during unauthorized access.
Reference: University of California victim of ransomware attack
Reference: University Hit By Accellion-Based Ransomware
Malware: Related to Accellion File Transfer Appliance (FTA)
UC added officials do not believe university’s systems or networks ended up compromised as a result. The school system said it reported the incident to federal law enforcement, took measures to contain it and has begun an investigation.
Victim: University of California
The state university system its institution, along with several other government agencies, private companies and other schools have been involved in an Accellion-centric attack.
“An unauthorized individual appears to have copied and transferred UC files by exploiting a vulnerability in Accellion’s file transfer service,” according to an UC advisory.
UC added officials do not believe university’s systems or networks ended up compromised as a result. The school system said it reported the incident to federal law enforcement, took measures to contain it and has begun an investigation.
Incident: University of California Hit By Accellion-Based Ransomware
The University of California (UC) was the victim of a ransomware attack via the Accellion Secure File Transfer Appliance (FTA).
The state university system its institution, along with several other government agencies, private companies and other schools have been involved in an Accellion-centric attack.
Editorial: Water Plant Modernizes, Secures Assets
Incident: Turbomachinery manufacturer attacked with ransomware
On February 15, 2021, a defect was detected in internal system of the Elliott head office and confirmed an attack by ransomware on the mail system and certain servers. As the damage from the ransomware attack, some problems were confirmed in production or ordering systems at Elliott plants. Upon detection, Ebara Corporation, the Group’s Headquarters in Japan, and the Elliott Group in the United States immediately undertook a robust forensic investigation to determine the extent of the defect, its impact and potential consequences.
As of this writing, Nefilim Ransomware group has posted teaser files, one 6GB and 1 549KB in size as proof of data breach.
Threat Actor: Nempty Ransomware group
Nempty Ransomware group, also known as Nefilim Ransomware employs tactic called Double Extortion. where they steal data from then encrypt victims machines and threaten the victim with releasing the data to the public if the ransom is not paid.
Threat Actor: Nefilim Ransomware group
Nefilim Ransomware group, also known as Nempty Ransomware employs tactic called Double Extortion. where they steal data from then encrypt victims machines and threaten the victim with releasing the data to the public if the ransom is not paid.
Nefilim ransomware uses a combination of AES-128 and RSA-2048 algorithms to encrypt the victims’ files. First the files are encrypted using AES-128 encryption and AES encryption key is further encrypted using the RSA-2048 public key. This key is then embedded in the executable file of the ransomware. The file extension name .NEFILIM is appended at the end of each encrypted file name along with a NEFILIM file marker for all encrypted files. This is how the ransomware gets its name.
On successfully encrypting all files, the ransomware plants a ransom note ‘NEFILIM-DECRYPT.txt’ that instructs the victim on how to recover their files. The ransom note contains different contact emails for contacting its operators. It also includes a line that warns victims of leaking their data if the ransom is not paid within seven days.
Malware: Nefilim Ransomware
Nefilim Ransomware group publishes teaser files and threatens to release victims stolen data to the public if ransom is not paid.
Victim: Elliott Group
“Commonly known as Elliott Group and formerly known as Elliott Turbomachinery, the Ebara subsidiary designs, manufactures, and services turbomachinery for the petrochemical, refining, oil and gas, power, and process industries around the world. Its primary products are centrifugal and axial compressors, steam turbines, and lubrication systems for rotating equipment. Elliott Group also provides repair services, spare parts supply, turbine remanufacturing, and upgrades through a global network of service facilities”
Reference: Users Learning, But Ransomware Still A Problem
Victim: AW North Carolina
Durham, NC-based 2,200-worker transmission factory.
Incident: AW North Carolina Hit in Ransomware Attack
August 2016 at the Durham, NC-based 2,200-worker transmission factory, AW North Carolina, a computer virus flowed through the plant’s network like a raging river, flooding machines with data and stopping production for about four hours, said John Peterson, the plant’s information technology manager. Add the cost of downtime at $270,000 an hour that adds up to $1.08 million for a four-hour shut down.
Data on some laptops was lost, but the malicious ransomware ended up blocked by a firewall when it tried to exit the plant’s network and put the hackers’ lock on the plant’s computer network.
The plant was hit again in April 2017, this time different bad guys used an alternative type of ransomware, Peterson said. Learning from the previous attack, the attack ended up contained before affecting production. No ransom was paid to either group, he said.
Reference: WestRock ransomware attack caused production, shipping slowdowns
Reference: Packaging Giant WestRock Says Ransomware Attack Hit Production
Incident: ‘Sophisticated’ Attack Hits Cyber Insurance Provider
Insurance provider Chicago, IL-based CNA Financial ended up hit by what it called a “sophisticated” cybersecurity attack on Sunday, company officials said.
“On March 21, 2021, CNA determined that it sustained a sophisticated cybersecurity attack. The attack caused a network disruption and impacted certain CNA systems, including corporate email,” the company said in an advisory.
The Chicago-based company paid the hackers about two weeks after a trove of company data was stolen, and CNA officials were locked out of their network, according to two people familiar with the attack who asked not to be named because they weren’t authorized to discuss the matter publicly.
Reference: CNA confirms ‘sophisticated’ cyber attack on systems
Reference: ‘Sophisticated’ Attack Hits Cyber Insurance Provider
Victim: CNA Financial
CNA offers an entire portfolio of insurance products, including a suite of cyber insurance and risk control resources for businesses of all sizes.
Reference: Honeywell Says Malware Disrupted IT Systems
Reference: Honeywell IT Systems Hit in Cyberattack
Victim: Honeywell
Industrial giant Honeywell is a technology supplier to multiple industries.
Incident: Honeywell IT Systems Hit in Cyberattack
Industrial giant Honeywell, which is a technology supplier to multiple industries, fell victim to a cyberattack on its information technology systems, the company said Tuesday.
“We recently detected a malware intrusion that disrupted a limited number of our information technology systems,” the company said in an advisory. “At this time, we do not expect this incident will have a material impact on Honeywell. We promptly took steps to address the incident, including partnering with Microsoft to assess and remediate the situation.
Reference: Ransomware attack shuts down Sierra Wireless IoT maker
Reference: Sierra Wireless Hit by Ransomware Attack
Victim: Sierra Wireless
Sierra Wireless is an IoT solution provider
Incident: Sierra Wireless Hit by Ransomware Attack
Manufacturing shut down for IoT solution provider, Sierra Wireless, as the company fell victim to a ransomware attack on its internal IT systems Saturday, company officials said.
Once the company learned of the attack, its IT and operations teams immediately implemented measures to counter the attack in accordance with established cybersecurity procedures and policies that were developed in collaboration with third-party advisors.
Reference: Energy giant Shell discloses data breach after Accellion hack
Reference: Shell Says Personal, Corporate Data Stolen in Accellion Security Incident
Reference: Shell a Victim in Accellion Incident
Victim: Royal Dutch Shell
In a statement the oil and gas giant said, “Upon learning of the incident, Shell addressed the vulnerabilities with its service provider and cyber security team, and started an investigation to better understand the nature and extent of the incident. There is no evidence of any impact to Shell’s core IT systems as the file transfer service is isolated from the rest of Shell’s digital infrastructure.
Incident: Shell A Victim In Accellion Incident
Shell is the latest company to fall victim in a data security incident involving Accellion’s File Transfer Appliance (FTA). Like other companies within the manufacturing automation sector, Shell said in an advisory it published March 16 it uses the FTA appliance to securely transfer large data files.
Incident: Navy Radar Shuts Down SCADA Systems
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Flaw Makes Water Undrinkable
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Flood Warning System Failure Causes Flooding
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Puget Sound Sewage Spill
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Faulty Water Level Alarm Cause of Sewage Spill
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Wastewater pumped into Jones Falls
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Faulty Software Causes Torrens Lake Drain
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Glitch Floods Neighborhood
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Lightning Strikes Cause Sewage Pump Station Overflow
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Glitch Causes 7 Water Mains to Break
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Switch Malfunction Causes Sewage Spill
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: SCADA Communictions Problems Cause Breakdown in Water Supply
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Sewage Spill Shuts Down a Cornish Shellfishery
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Glitch Causes Overflowing Water Tower
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: California Canal System Hack
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Pennsylvania Water Company Hack
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Routine Audit of SCADA Laptop Identifies Virus
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Attempted Cover-Up of Sewage Spillage
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Trojan Backdoor on Water SCADA System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Proposed Hack of UK Water Systems
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Baseline Audit Uncovers Virus in Water Control System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Maroochy Shire Sewage Spill
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Worcester Air Traffic Communications System Hack
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Oakland Air-Traffic Control Center Outage
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Software Faults May Have Caused Chinook Helicopter Crash
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Paperless Chart Recorder Software Hacked
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Unauthorized Connection Permits Sasser Infection
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Korgo Worm Infects 20 Workstations
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Spybot Infection
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Date Triggered Code Found on PLC
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Malformed Packet Causes PLC Crash
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Hackers gain unauthorized access to a modular hybrid controller
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Ethernet Storm Wipes PLC’s Processor Memory
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Malfunction Blamed for Major Sewage Spill
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Wastewater Treatment District Hacked
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Water Utility Hack Destroys Pump
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: South Houston Water Treatment Plant Hack
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Water plant shut down by computer glitch
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Power Failure Leads to Sewage Spill in Washington
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Glitch Causes Water Outage
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: SCADA Water System Fails
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Glitch Causes Sewage Spill
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: SCADA System Collapse Leads to Tunnel Closure
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: SCADA System Failure Causes Shut down of Dublin Port Tunnel
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Problems Causes Flight Delays
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Tunnel Shutdown after Fault in Control System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Schoolboy Hacks into Polish Tram System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Software failure contributes to rail car fire
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Engineers Hack into Los Angeles Traffic Signal Computer
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Remote Software Upgrade Causes Loss of Control & View
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Errant AntiVirus Definition Brings Down Railway LANs
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Air Traffic Radar System in Palmdale California Crashes
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Sasser Worm Hits British Airways
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Error Grounds Japanese Flights
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Virus Shuts Down AC Jazz Airline Flight Planning Computer
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Nacchi Virus Infects Air Canada Check-In System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Sobig Virus Strikes CSX Train Signalling System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: UK Air Traffic Control Computers Fail
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Runaway Remote Control Train
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Ski Gondola Worker Shutdown Control System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: DoS Attack Shuts Down Port of Houston
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Korean Air Line B747 CFIT Accident in Guam
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Malfunction Causes Train Delays
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Trains Shut Down Due to Computer Malfunction
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Glitch Stops Trains
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Glitch Causes Shutdown of Airport People Mover
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Control system failure causes bridge delays
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer glitch causes BART train service shutdown
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Glitch Causes Ride Shutdown
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer glitch causes delayed and canceled flights
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer glitch blamed for train signalling failure
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Emergency flight landing caused by computer glitch
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Faulty Signaling Software Causes Train Delays
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Malware a Factor in Spanair Plane Crash
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Faulty Train Signal Sends Train on Collision Course
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Glitch Causes Monongahela Incline Shut Down
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer glitch caused plane’s altitude to drop
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Error Causes Flight Delays
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Failure Causes Jet Crash
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Washington DC Metro Accident
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Texas Road Sign Hack
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Glitch Causes Airplane Plunge
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Power Industry Slammer #1
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Hackers Target Cal – ISO System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Utility SCADA System Attacked
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Y2K Test Crashes Reactor Computer
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Power Outages and Other Service Interruptions
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Hackers Attack NZ & Aust for Joining Gulf Taskforce
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Salt River Project Hack
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Sabotage at Nuclear Power Plant
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Error at Sellafield Nuclear Plant in UK
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Virus Impacts Paper Machine HMI
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Paper Company Control System Hit By Blaster
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: DCS Console Reprogramming Causes Gateway Fault
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Broadcast Storm Shuts Down DCS Consoles
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Duplicate IP Address Prevents Machine Startup
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: PLC Password Change
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: U-2 spy plane caused widespread shutdown of U.S. flights: report2014
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Signal problems cause train delays
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Virus shuts down county highway department network
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Cascade of Computer Crashes Causes Metro System Shutdown
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Limerick Nuclear Reactor 1 Shut Down
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Blackout in Florida
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Georgia Nuclear Power Plant Shutdown
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Energy Company Exposed to Hackers by a Phishing Attack
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Glitch Causes Major Power Outage
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Power Network Survives Virus Attack
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Browns Ferry Nuclear Plant Scrammed (Shut Down)
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Power Plant Security Information Leaked Onto Internet
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Offsite Fiber Cable Cut Causes Loss of Communications
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: E-Tag Incident
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Japanese Nuclear Company Virus Attack
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Taum Sauk Water Storage Dam Failure
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Theft of Relay Programming Laptops
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: SCADA Workstation Infected by W32/Korgo Worm
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Iranian Hackers Attempt to Disrupt Israel Power System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: SCADA/EMS Alarm System Failure Contributes to Blackout
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Virus Attacks a European Utility
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: London August 2003 Power Blackout
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Slammer Impact on Ohio Nuclear Plant
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Power Industry Slammer #2
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Oil Company SCADA System Impacted by RF Interference
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: CIA Trojan Causes Siberian Gas Pipeline Explosion
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Hacker froze operations at pharmaceutical company
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Ethernet Network Storm Zaps Multiple PLC5’s
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Russian-Based Dragonfly Group Attacks Energy Industry
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Public utility compromised after brute-force hack attack, says Homeland Security
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: U. S. Electric Utility Virus Infection
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: U. S. Power Plant Infected With Malware
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Glitch Leads to Shutdown of Nuclear Reactor
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Circuit card shuts down nuclear plant
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Control system failure causes shutdown of liquified natural gas terminal
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Gas Leak Caused by Computer Malfunction
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: San Bruno Pipeline Explosion
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Malware Targets Uranium Enrichment Facility
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Cyber Attack on Texas Electricity Provider
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: SCADAlalarm & PCAnywhere compatibility
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Wrong Signal Shuts Down Cooling Systems
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Energy Company Virus Attack
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Texas Power Company Hack
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Failed Sensor on Wind Turbine Caused Shower of Ice Shards
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Telco Shuts Off Critical SCADA Comms
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Slammer Infected Laptop Shuts Down DCS
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Slammer Impacts Offshore Platforms
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: SQL Slammer Impacts Drill Site
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Welchia Worm Infects Automation Network
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: MUMU Infection of Leak Detection System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: MUMU Infection of Fiscal Metering System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: MUMU Infection of Operator Training System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Virus/Worm Infects New Oil Platform
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Blaster Infects Onshore Oil Production Control System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Control System Infected with SQLslammer Worm
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Whitehat Takeover of DCS Consoles
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Electronic Sabatoge of Venezuela Oil Operations
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Virus Infection of Operator Training Simulator
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Anti-Virus Software Prevents Boiler Safety Shutdown
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Electronic Sabotage of Petroleum Company’s Gas Processing Plant2001
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Code Red Worm Defaces Automation Web Pages
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Accidental Remote Uploading of PLC Program
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Hacker Takes Over Russian Gas System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Olympic Pipeline Rupture and Subsequent Fire
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Instability of the OSI Layer-2 Bridging
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Sasser Infection from the Enterprise Network
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Change of Network Service Stopped OSI Layer-2 Communication
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Penetration Test Locks-Up Gas Utility SCADA System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Ping Sweep Causes PCS System to Hang
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Ping Sweep Causes Inappropriate Control of a 9 Foot Robotic Arm
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Iranian Oil Terminal offline after malware attack
Iran has been forced to disconnect key oil facilities after suffering a malware attack on Sunday, say reports. The computer virus is believed to have hit the internal computer systems at Iran's oil ministry and its national oil company. Equipment on the Kharg island and at other Iranian oil plants has been disconnected from the net as a precaution. Oil production had not been affected by the attack, said the Mehr news agency.
Deletion of data from Iranian oil ministry, facilities last month led to discovery of advanced attack code, says expert.
Incident: Shamoon virus knocks out computers at Qatari gas firm RasGas
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Process Control Network Infected with a Virus
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Gas Company Virus Infection
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Virus Targets Saudi Arabian Oil Company
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Glitch Prevents Return of Gas Service
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Trans-Alaska pipeline spill
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Refinery Explosion and Fire Caused by Non-Functioning Computerized Level Monitoring System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Hacker Disabled Offshore Oil Platforms
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Baku-Tbilisi-Ceyhan Pipeline explosion
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Ping Sweep Caused DOS on PCN Firewall
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Two Viruses Cause Near Miss With Process Control Networks (PCN) in Africa
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Sasser Worm Infection in Process Control System.
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Worm attack on Drilling Control system
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Steel plant infected with Conficker
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Steel Plant infection with Ahack Worm
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Blaster Impacts HMI Stations in Smelter
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: 11 Ethernet PLCs Fail At Once
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Glitch Causes Roller Coaster Malfunction
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Industrial Control System Hacked Using Backdoor Posted Online
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Glitch Causes shutdown of 2 Amusement Park Rides
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Malware Shuts Down Hospital
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Virus Strikes Two Scottish Hospitals
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Hospital HVAC Hack
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Environmental Southland Target of Cyber Vandals
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Computer Virus Infects Three London Hospitals
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Hacker Activates Emergency Sirens
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Automated Antiaircraft Cannon Malfunctions, Kills 9, Wounds 14
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Cancer Treatment Delayed by Virus
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: UK Maritime and Coastguard Agency Hit by Sasser Worm
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Blockage of 12 Out Of 13 PLC Systems
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Weekly Connection Loss to PLCs
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Omega Engineering Sabotage
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: PLC Crash In Food Plant
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Software Vendor Patch Crashes SCADA System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Partial Loss of PLC Program
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Coors Brewing Shutdown
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Loss of Network Traffic on PCN
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Infected Laptop Infects SCADA Network
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Nimda Impact on Manufacturing System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Windows Compiler Causes PLC Code to Crash PLC
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Virus Infection On DCS
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Wrong Code Downloaded to PLC Causes Plant to Shutdown
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: New Serial Communications Line Disrupts Network
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Software Manufacturing Company Firewall Breach
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Malware Shuts Down Milling Factory
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Former System Administrator Sentenced for Wrecking Corporate Servers
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Trojan Found on SCADA Server
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Single PLC Lost For Unknown Reason
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Accidental Remote Control
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Auto Manufacturer Hacked
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Disgruntled Employee Remotely Disables Cars using the Webtech Plus System
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Car Manufacturer Infected with Computer Virus
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Zotob, PnP Worms Hit 13 Automotive Manufacturing Plants
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Slammer Worm Hits Major US Auto Manufacturer
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Control system failure caused phosphine leak
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: PC_SALITY.EN Virus Infects DCS Servers and Historians
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Chemical Plant Explosion
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Sasser Worm Causes Loss of View in Chemicals Plant
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Nachi Worm on Advanced Process Control Servers
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Contractor Accidentally Connects to Remote PLC
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Infected New HMI Infects Chemical Plant DCS
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Blaster Worm Infects Chemical Plant
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: IP Address Change Shuts Down Chemical Plant
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Hacker Changes Chemical Plant Set Points via Modem
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: SCADA Attack on Production Plant of Global Chemical Company
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Union Carbide Chemical Leak West Virginia
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Backdoor Trojan Attack on Manufacturing Lab
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Reverse Osmosis System PLC Attacked
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Hackers Crash Controller via Web Service
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Incident: Safety Instrumented System Disabled by Triton Malware
Triton, which has been called the Worlds 1st murderous malware was discovered in 2017. In December 2017, it was reported that the safety systems of an unidentified petrochemical plant in Saudi Arabia were compromised when the Triconex industrial safety technology made by Schneider Electric SE was targeted in what is believed to have been a state sponsored attack. The computer security company Symantec claimed that the malware, known as "Triton", exploited a vulnerability in computers running the Microsoft Windows operating system. The intention of Triton was to disable the safety instrumented systems, thus earning the name of the 1st murderous malware.
Reference: Russian Lab Linked to Malware That Attacks Industrial Plants
Reference: TRITON Attribution: Russian Government-Owned Lab Most Likely Built Custom Intrusion Tools for TRITON Attackers
Reference: Russian Research Institute Was Actively Involved In TRITON ICS Attack Activity
Reference: US Treasury sanctions Russian research institute behind Triton malware
Threat Actor: Central Scientific Research Institute of Chemistry and Mechanics (CNIIHM), Russia
A laboratory run by the Russian government.
Malware: Triton
Triton is malware first discovered at a Saudi Arabian petrochemical plant in 2017.[1][2] It can disable safety instrumented systems, which can then contribute to a plant disaster. It has been called "the world's most murderous malware."[3]
In December 2017, it was reported that the safety systems of an unidentified power station, believed to be in Saudi Arabia, were compromised when the Triconex industrial safety technology made by Schneider Electric SE was targeted in what is believed to have been a state sponsored attack. The computer security company Symantec claimed that the malware, known as "Triton", exploited a vulnerability in computers running the Microsoft Windows operating system.[2]
In 2018, FireEye, a company that researches cyber-security, reported that the malware most likely came from the Central Scientific Research Institute of Chemistry and Mechanics (CNIIHM), a research entity in Russia.[4]
Incident: Hackers cause power outages to close to 1/4 million people
On December 23, 2015, the Ukrainian Kyivoblenergo, a regional electricity distribution company, reported service outages to customers. The outages were due to a remote individual who took control of the operator workstation and opened breakers at 30 substations. At approximately 3:35 p.m local time, seven 110 kV and 23 35 kV substations were disconnected for three hours. The cyber attack impacted additional portions of the distribution grid and forced operators to switch to manual mode. The outages were originally thought to have affected approximately 80,000 customers, based on the Kyivoblenergo’s update to customers. However, later it was revealed that three different distribution oblenergos (a term used to describe an energy company) were attacked, resulting in several outages that caused approximately 225,000 customers to lose power across various areas. Shortly after the attack, Ukrainian government officials claimed the outages were caused by a cyber attack, and that Russian security services were responsible for the incidents.
Reference: Ukraine Power Grid Cyberattack and US Susceptibility: Cybersecurity Implications of Smart Grid Advancements in the US
Reference: Analysis of the Cyber Attack on the Ukrainian Power Grid
Reference: December 2015 Ukraine power grid cyberattack
Reference: Cyber Autopsy Series: Ukrainian Power Grid Attack Makes History
Threat Actor: Russian Security Services
The Federal Security Service of the Russian Federation (FSB RF; Russian: Федеральная служба безопасности Российской Федерации (ФСБ), tr. Federal'naya sluzhba bezopasnosti Rossiyskoy Federatsii, IPA: [fʲɪdʲɪˈralʲnəjə ˈsluʐbə bʲɪzɐˈpasnəstʲɪ rɐˈsʲijskəj fʲɪdʲɪˈratsɨjɪ]) is the principal security agency of Russia and the main successor agency to the Soviet Union's KGB ('Committee for State Securityʼ). Its main responsibilities are within the country and include counter-intelligence, internal and border security, counter-terrorism, and surveillance as well as investigating some other types of grave crimes and federal law violations. It is headquartered in Lubyanka Square, Moscow's center, in the main building of the former KGB. According to the 1995 Federal Law "On the Federal Security Service", direction of the FSB is executed by the president of Russia, who appoints the Director of the FSB.[1]
Victim: Ukrainian Kyivoblenergo
A regional electricity distribution company.
Incident: Cyber attack at German Steel Mill damages equipment
A German steel mill was targeted with malware that gave the attackers access to the business network and then to the SCADA/ICS network. The event was confirmed by the German government's Federal Office for Information Security (BSI) in an IT security report. Attackers that appeared to particularly target industrial plant personnel, caused plant control components to fail, resulting in an uncontrolled furnace, which eventually caused physical damage to the steel factory.
According to a study issued by the SANS Institute, the hackers used spear-phishing attempts to obtain access to the steel mill network. The email most likely contained an attached document that, when opened, activated the malicious malware onto the system. The malware then constructed a remote connection point to establish a bridge between the attackers and the targeted industrial network by exploiting vulnerabilities in a targeted operating system. The hackers were able to modify the programmable logic controllers (PLCs) at this stage, jeopardizing the furnace's operations, which further lead to its own physical damage.
Incident: 30,000 Hard drives wiped by virus
Saudi Arabia’s national oil company, Aramco, said that a cyber attack damaged approximately, 30,000 computers. The attack was aimed at stopping oil and gas production in Saudi Arabia. The company shut down its main internal network for more than a week. The computer virus, Shamoon, spread through Amarco’s network and wiped computers’ hard drives clean. Fortunately, the damage was limited to office computers and didn't affect control systems software that would impact technical operations.
Reference: Compromise of Saudi Aramco and RasGas
Reference: The inside story of the biggest hack in history
Reference: Oil giant Saudi Aramco back online after 30,000 workstations hit by malware
Threat Actor: Cutting Sword of Justice
Not much known - just claimed responsibility for Saudi Aramco attack.
Malware: Shamoon
Shamoon, also known as W32.DistTrack, is a modular computer virus that was discovered in 2012, targeting then-recent 32-bit NT kernel versions of Microsoft Windows. The virus was notable due to the destructive nature of the attack and the cost of recovery. Shamoon can spread from an infected machine to other computers on the network. Once a system is infected, the virus continues to compile a list of files from specific locations on the system, upload them to the attacker, and erase them. Finally the virus overwrites the master boot record of the infected computer, making it unusable.
Victim: Saudi Aramco
Saudi Aramco, officially the Saudi Arabian Oil Company (formerly Arabian-American Oil Company), is a Saudi Arabian public petroleum and natural gas company based in Dhahran.
As of 2020, it is one of the largest companies in the world by revenue. Saudi Aramco has both the world's second-largest proven crude oil reserves, at more than 270 billion barrels (43 billion cubic metres), and largest daily oil production of all oil producing companies.
Saudi Aramco operates the world's largest single hydrocarbon network, the Master Gas System. Its 2013 crude oil production total was 3.4 billion barrels (540 million cubic metres), and it manages over one hundred oil and gas fields in Saudi Arabia, including 288.4 trillion standard cubic feet (scf) of natural gas reserves. Saudi Aramco operates the Ghawar Field, the world's largest onshore oil field, and the Safaniya Field, the world's largest offshore oil field.
Incident: Stuxnet Malware Targets Uranium Enrichment Facility
Stuxnet reportedly compromised Iranian PLCs, collecting information on from the industrial systems then downloaded a configuration to the controllers that caused the fast-spinning Uranium enriching centrifuges to tear themselves apart. Stuxnet has 3 major components; A worm module, A link file and a rootkit module. The worm propagates across the network, scanning for Siemens Step7 software on computers controlling a PLC. In the absence of either criterion, Stuxnet becomes dormant inside the computer. If both the conditions are fulfilled, Stuxnet introduces the infected rootkit onto the PLC and Step7 software, modifying the code and giving unexpected commands to the PLC while returning a loop of normal operation system values back to the users. Iranian sources confirmed that the Stuxnet malworm shut down uranium enrichment at Natanz for a week from Nov. 16 to 22, 2010.
Reference: Richard Clarke on Who Was Behind the Stuxnet Attack
Reference: Stuxnet Worm Attack on Iranian Nuclear Facilities
Reference: An Unprecedented Look at Stuxnet, the World’s First Digital Weapon
Threat Actor: United States
Mostly directed toward Iran.
Malware: Stuxnet
Stuxnet is a malicious computer worm first uncovered in 2010 and thought to have been in development since at least 2005. Stuxnet targets supervisory control and data acquisition (SCADA) systems and is believed to be responsible for causing substantial damage to the nuclear program of Iran. Although neither country has openly admitted responsibility, the worm is widely understood to be a cyberweapon built jointly by the United States and Israel in a collaborative effort known as the "Olympic Games".[2][3][4]
Victim: Natanz Nuclear Facility
Natanz is a hardened Fuel Enrichment Plant (FEP) covering 100,000 square meters that is built 8 meters underground and protected by a concrete wall 2.5 meters thick, itself protected by another concrete wall. It is located at Natanz, the capital city of Natanz County, Isfahan Province, Iran. In 2004, the roof was hardened with reinforced concrete and covered with 22 meters of earth. The complex consists of two 25,000 square meter halls and a number of administrative buildings. This once secret site was one of the two exposed by Alireza Jafarzadeh in August, 2002.
Incident: Cyber worm shuts down 13 Auto plants in US
The Zotob worm 13 shuts down US auto plants. Despite having professionally installed firewalls separating the Internet, the company network and the control network, the Zotob worm had made its way into the control system (probably via a laptop). Once in the control system, it was able to travel from plant to plant in seconds. Approximately 50,000 assembly line workers had to cease work during the outages.
Reference: Virus shuts down 13 plants: loss estimated at $14 million
Reference: Zotob, PnP Worms Slam 13 DaimlerChrysler Plants
Malware: Zotob Worm
Zotob is a computer worm which exploits security vulnerabilities in Microsoft operating systems like Windows 2000, including the MS05-039 plug-and-play vulnerability. This worm has been known to spread on Microsoft-ds or TCP port 445.
It was declared that the Zotob worms cost an average of $97,000 as well as 80 hours of cleanup per company affected.[1]
Victim: Daimler Chrysler
The company was renamed DaimlerChrysler upon acquiring the American automobile manufacturer Chrysler Corporation in 1998, and was again renamed Daimler AG upon divestment of Chrysler to Cerberus Capital Management in 2007 (Chrysler is currently owned by Stellantis).
Reference: Protecting Drinking Water Utilities from Cyber Threats
Reference: Cyberterrorism: fear factor
Reference: Malicious Control System Cyber Security Attack Case Study– Maroochy Water Services, Australia1
Reference: Maroochy Water Breach – Slideshow
Reference: Cybersafety Analysis of the Maroochy Shire Sewage Spill
Incident: Disgruntled ex-employee dumps raw sewage
Vitek Boden, worked for Hunter Watertech, an Australian firm that installed SCADA radio-controlled sewage equipment for the Maroochy Shire Council in Queensland, Australia. Boden was having a “strained relationship” with Hunter Watertech and left the company. He then applied for a job with the Maroochy Shire Council. The Council did not hire him, so he decided to get even with both the Council and Hunter Watertech. He loaded his car with radio equipment attached to a configuration computer and drove around the area on at least 46 occasions from February 28 to April 23, 2000, issuing radio commands to the sewage equipment that he (probably) helped install. He caused 800,000 liters of raw sewage to spill out into local parks, rivers and even the grounds of a Hyatt Regency hotel. A representative of the Australian Environmental Protection Agency representative stated that the creek water had turned black, Marine life died, and the stench was unbearable for residents. Boden got caught when a policeman pulled him over for a traffic violation after one of his attacks. He was sentenced to two years in jail and ordered him to reimburse the Council for cleanup.
Reference: Classic Hacker Case – Maroochy
Threat Actor: Former Employee
Someone who used to work for one of the parties involved
Victim: Maroochy Shire Council
The Shire of Maroochy was a local government area about 100 kilometres (62 mi) north of Brisbane in the Sunshine Coast region of South East Queensland, Australia. The shire covered an area of 1,162.7 square kilometres (448.9 sq mi), and existed as a local government entity from 1890 until 2008, when it amalgamated with its neighbours to the north and south to form the Sunshine Coast Region.
Page: Submit an Incident
Page: Contact Us
Reference: World’s leading dairy group Lactalis hit by cyberattack
Victim: Lactalis Group
Lactalis (short for Lactalis Group) has 85,000 employees in 51 countries, and it exports dairy products to over 100 countries around the world.
The dairy group controls multiple leading international brands, including Président, Galbani, Lactel, Santal, and Parmalat.
Incident: World’s leading dairy group Lactalis hit by cyberattack
Lactalis, the world's leading dairy group, has disclosed a cyberattack after unknown threat actors have breached some of the company's systems.
Incident: DoppelPaymer ransomware group claims plastics engineering and manufacturing company as victim
Dopplepaymer ransomware group claims the Ensinger company as a victim of the Dopplepaymer ransomware. They posted an image and an example file on their website with the claim. Ensinger is headquartered in Pennsylvania with multiple facilities in the US and abroad.
Ensinger is a global supplier of high performance thermoplastics as well as offering multiple fabrication solutions throughout the U.S. and the world. No information from Ensinger has been made available to date.
Editorial: Major Brewer Hit By Cyberattack
Reference: Cyberattack Against Molson Coors Impacts Brewery Operations, Production, and Shipments
Reference: Major Brewer Hit By Cyberattack
Victim: Molson Coors Beverage Compay
Molson Coors carries the Coors, Miller, Molson Canadian, Blue Moon, Peroni, Killian’s, and Foster’s beer brands.
Incident: Major Brewer, Molson Coors, Hit By Cyberattack Costing Millions
On March 11, 2021, Molson Coors Beverage Company (the “Company”) announced that it experienced a systems outage that was caused by a cybersecurity incident. Production was reportedly halted up to one week at some plants. The Company has engaged leading forensic information technology firms and legal counsel to assist the Company’s investigation into the incident. This cybersecurity incident has caused and may continue to cause a delay or disruption to parts of the Company’s business, including its brewery operations, production, and shipments.
Update: Production of 1.8 million hectolitres delayed from Q1 to later in the year, delaying 120-140 m$ earnings to later in the year.
Editorial: Security Cameras’ Data Breached
Incident: Spear-phishing attacks on Middle Eastern Oil & Gas companies
Information stealing malware such as Agent Tesla, Formbook, Masslogger and Matriex as well as AZORult trojan were delivered via Spear-phishing attacks to Oil & Gas companies in the Middle East
Malware: Matriex
Information stealing malware
Malware: Masslogger
Information stealing malware
Malware: Formbook
information stealing malware
Malware: Agent Tesla
Information stealing malware
Victim: Unknown Oil and Gas companies in the Middle East
multiple Oil & Gas companies.
Editorial: Guidance on Protective DNS
Reference: UK Airline Attacked; 9M Records Lost
Victim: easyJet
Hacking tools and techniques used to access the travel records of millions of customers of Britain’s easyJet point to a group of suspected Chinese hackers.
Incident: UK Airline, easyJet, Attacked; 9M Records Lost
Budget airline, easyJet, said hackers had accessed the email and travel details of around nine million customers, as well as the credit card details of more than 2,000 of them, in a “highly sophisticated” attack.
Reference: Florence, AL, Hit By Ransomware, Decides To Pay
Victim: Florence, Alabama
Florence, Alabama, paid just under $300,000 to attackers to recover data encrypted in a ransomware attack. Florence became a victim of the DoppelPaymer ransomware attack on June 5 that shut down the city’s email system. The gang demanded 38 bitcoin, equivalent to USD $378,000, and threatened to publish or sell data stolen from Florence if the city didn’t pay up.
Incident: Florence, AL, Hit By Ransomware, Decides To Pay
Florence, Alabama, became a victim of the DoppelPaymer ransomware attack on June 5 that shut down the city’s email system.
Reference: Knoxville Hit By Ransomware Attack
Victim: City of Knoxville, Tennessee
The city’s website was unreachable in the morning. By evening, access to the site was restored after city employees moved it from its normal domain — www.knoxvilletn.gov — to an ad hoc domain cityofknoxville.hosted.civiclive.com. Officials said the fire and police departments were operating as normal.
Incident: Knoxville Hit By Ransomware Attack
The city of Knoxville, Tennessee, appears to be back up after shutting down part of its computer network Thursday as a result of a ransomware attack.
The attack was first noticed by members of the Knoxville Fire Department around 4:30 a.m. Thursday, according to a report in the Knoxville News Sentinel.
Reference: Hit By Ransomware, University Decides To Pay
Victim: University of Utah
On July 19, the Information Security Office (ISO) notified the university’s College of Social and Behavioral Science (CSBS) that ransomware had infected some of its servers.
ISO responded by isolating the CSBS servers from the rest of the university’s network, notifying law enforcem
Incident: Hit By Ransomware, University of Utah Decides To Pay
ecurity experts say never pay a ransom if a system ends up taken over by ransomware. However, that is often easier said than done as the University of Utah paid over $450,000 to attackers after they infected a portion of its servers with ransomware.
Incident: Security Provider, Stormshield, Hit In Cyber Attack
Security provider Stormshield revealed a security incident that resulted in unauthorized access to a technical portal and a “leakage” of some parts of the SNS (Stormshield Network Security) source code.
Reference: Security firm Stormshield loses source code in cyber attack
Reference: Security Provider Hit In Cyber Attack
Victim: Stormshield
Stormshield is a wholly-owned subsidiary of France-based cybersecurity company Airbus CyberSecurity, and it provides network security, endpoint security and data security solutions.
Incident: Ransomware Attack on WestRock
WestRock, an Atlanta, GA-based company that involves in paper based packaging solutions, has been hit by a ransomware attack that disrupted its operations and information technology systems. Attack was highly sophisticated where hackers stole a portion of data from the servers and locked it down from access.
Upon discovering the incident, WestRock immediately began proactively shutting down certain systems in an abundance of caution, as well as taking steps to supplement existing security monitoring, scanning and protective measures. The Company is now systematically bringing its information systems back online in a controlled, phased approach.
The company reported packaging production through February 4 was approximately 85,000 tons lower than plan.
Reference: Ransomware Hits OT Systems at Packaging Giant
Reference: Ransomware Attack on WestRock
Victim: WestRock
A paper-based packaging solution provider.
Reference: Asian Food Distribution Giant JFC International Hit by Ransomware
Victim: JFC International (Europe)
JFC International (Europe) was recently subject to a ransomware attack that briefly disrupted its IT systems.
Incident: JFC International Ransomware Attack
JFC International (Europe) was recently subject to a ransomware attack that briefly disrupted its IT systems. A full forensic investigation by in- house specialists together with external cyber experts was immediately started and is underway.
Reference: Groupe Beneteau Hacked
Reference: French Boat Maker Hit By Cyberattack
Victim: Beneteau
Beneteau is a French sail and motor boat manufacturer, with production facilities in France and in the United States.
Incident: French Boat Maker, Beneteau, Hit By Cyberattack
French boat manufacturer Beneteau SA suffered a cyberattack which is now resulting in the company slowing down or stopping some of its production. The company first noticed the attack, which it is calling a malware intrusion, during the night of Feb. 18 to Feb. 19. The company quickly disconnected its information systems to prevent a further spread.
May '21 update on consequences of cyber attack:
3-4 weeks production shutdown at several plants; OT systems such as numerical control machines impaired; "Almost all of the year's growth evaporated in this ordeal"
Editorial: French Boat Maker Hit by Cyberattack
Threat Actor: Clop (or Cl0p) ransomware gang
Multiple Accellion FTA customers suffered attacks from UNC2546 and have received extortion emails threatening to publish stolen data on the “CL0P^_- LEAKS” .onion website.
The Clop ransomware gang are behind the 2023 MOVEit Transfer data-theft attacks.
Threat Actor: FIN11
FIN11, a financially-motivated hacker group with a history starting since at least 2016, has adapted malicious email campaigns to transition to ransomware as the main monetization method, according to a Bleeping Computer report. The group runs high-volume operations, lately targeting companies primarily in North America and Europe from almost every industry sector to steal data and to deploy Clop ransomware.
Reference: Airplane maker Bombardier data posted on ransomware leak site following FTA hack
Reference: Jet Maker Victim In Accellion Attack
Threat Actor: UNC2546
Mandiant identified UNC2546 as the criminal hacker behind the cyberattacks and data theft involving Accellion’s legacy File Transfer Appliance product. Multiple Accellion FTA customers suffered attacks from UNC2546 and have received extortion emails threatening to publish stolen data on the “CL0P^_- LEAKS” .onion website. Some of the published victim data appears to have been stolen using the DEWMODE web shell.
Victim: Bombardier
Bombardier is a global aviation provider. Headquartered in Montréal, Canada, Bombardier is present in than 12 countries including its production/engineering sites and its customer support network. The Corporation supports a worldwide fleet of 4,900 aircraft in service with a wide variety of multinational corporations, charter and fractional ownership providers, governments and private individuals.
Incident: Jet Maker, Bombardier, Victim In Accellion Attack
Global aircraft producer, Bombardier, fell victim to a cybersecurity breach where an attacker accessed and extracted data by exploiting a vulnerability affecting a third-party file-transfer application.
Upon learning of the attack, Montreal, Canada-based Bombardier initiated its response protocol and as a part of its investigation, Bombardier brought in cybersecurity and forensic professionals.
Editorial: Jet Maker Victim in Accellion Attack
Editorial: Critical Infrastructure Risk At All-Time High: Report
Incident: Bolpegas attacked by Ragnar Locker Ransomware
Ragnar Locker Ransomware blog site has claimed that Bolpegas is a victim of their ransomware. No information has yet been released by Bolpegas (the victim).
Reference: Australia Toll Group suffers Nefilim ransomware attack
Reference: Nefilim Hits Whirlpool with Ransomware, Publishes Some Stolen Data
Reference: Home appliance giant Whirlpool hit in Nefilim ransomware attack
Victim: Whirlpool
Benton Charter Township, Michigan-based Whirlpool is one of the world's largest home application makers with appliances under its name and KitchenAid, Maytag, Brastemp, Consul, Hotpoint, Indesit, and Bauknecht. Whirlpool employs 77,000 people at 59 manufacturing & technology research centers worldwide and generated approximately $20 billion in revenue for 2019.
Incident: Home appliance giant Whirlpool hit in Nefilim ransomware attack
Home appliances giant Whirlpool suffered a ransomware attack by the Nefilim ransomware gang who stole data before encrypting devices.
Nefilim ransomware gang published files stolen from Whirlpool during a ransomware attack. The leaked data included documents related to employee benefits, accommodation requests, medical information requests, background checks, and more.
Victim: Prototron Circuits
Printed Circuit Board Manufacturer
Victim: International Maritime Organization
The International Maritime Organization is a specialised agency of the United Nations responsible for regulating shipping. The IMO was established following agreement at a UN conference held in Geneva in 1948 and the IMO came into existence ten years later, meeting for the first time in 1959.
Victim: CMA CGM
CMA CGM S.A. is a French container transportation and shipping company. It is a leading worldwide shipping group, using 200 shipping routes between 420 ports in 150 different countries, ranking fourth behind Maersk Line, MSC and COSCO Shipping Lines.
Victim: Braskem
Braskem is a Brazilian petrochemical company headquartered in São Paulo. The company is the largest petrochemical company in Latin America and has become a major player in the international petrochemical market.
Victim: Adif Transportation
Adif, the Administrator of Railway Infrastructures, is a state-owned company that answers to the Ministerio de de Transportes, Movilidad y Agenda Urbana. Adif plays a leading role in promoting the railway sector, working towards converting it into the ideal mode of transport and facilitating access to the infrastructure under fair conditions.
Victim: Mediterranean Shipping Company (MSC)
Mediterranean Shipping Company S.A. is a Swiss-Italian international shipping line. The company operates in all major ports of the world. It is the world's second-largest shipping line in terms of container vessel capacity.
Victim: Austal
Austal is an Australian-based global ship building company and defence prime contractor that specialises in the design, construction and support of defence and commercial vessels.
Its American subsidiary, Austal USA, is under contract for multiple programs that include building Independence class littoral combat ships for the U.S. Navy, which are 127-meter-long vessels at a cost of $360 million per unit. Austal also has an active $3.3 billion contract for building 11 patrol cutters for the U.S. Coast Guard.
Threat Actor: Netwalker Group
Netwalker is a strain of ransomware discovered in September 2019, but its timestamp dates it back to late August. Initially believed to be a threat of the Mailto persuasion, it has since been established that it is an updated version of it. Mailto was discovered by independent cybersecurity researcher and Twitter user GrujaRS.
Victim: Onslow Water and Sewer Authority (ONWASA)
Water utility company in Jacksonville, North Carolina
Victim: BASF
BASF SE is a German multinational chemical company and the largest chemical producer in the world. The BASF Group comprises subsidiaries and joint ventures in more than 80 countries and operates six integrated production sites and 390 other production sites in Europe, Asia, Australia, the Americas and Africa.
Victim: Seimens
Siemens AG is a German multinational conglomerate company headquartered in Munich and the largest industrial manufacturing company in Europe with branch offices abroad.
Victim: Henkel
Henkel AG & Co. KGaA is a German chemical and consumer goods company headquartered in Düsseldorf, Germany. It is a multinational company active both in the consumer and industrial sector.
Victim: Roche
F. Hoffmann-La Roche AG is a Swiss multinational healthcare company that operates worldwide under two divisions: Pharmaceuticals and Diagnostics. Its holding company, Roche Holding AG, has bearer shares listed on the SIX Swiss Exchange. The company headquarters are located in Basel.
Victim: Shin-Etsu
Shin-Etsu Chemical Co., Ltd. is the largest chemical company in Japan, ranked No. 9 in Forbes Global 2000 for chemical sector. Shin-Etsu has the largest global market share for polyvinyl chloride, semiconductor silicon, and photomask substrates.
Victim: Sumitomo
Japanese business group that crosses multiple industries.
Victim: Lion Air
Airline from Southeast Asia
Victim: Marriott
Hospitality Company
Victim: Valve
Valve is a software company. https://www.valvesoftware.com/en/
Incident: Winnti attack on Marriott
Marriott hotels suffered a breach which exposed the personal information of 5.2 million guests.
Consequences not disclosed. ARD, a public broadcaster reported that company had been attacked by a group associated with Chinese government with malware which allows attackers to access victims network remotely.
Incident: Winnti attack on Valve
Consequences not disclosed. ARD, a public broadcaster reported that company had been attacked by a group associated with Chinese government with malware which allows attackers to access victims network remotely.
Incident: Ryuk causes facility shutdown
Loss of view and control resulting in shutdown of facility for over 30 hours
Incident: Toll Group has large portion of IT infrastructre taken out by ransomeware attack
Australian-based global logistics company suffered a targeted ransomware attack. Large part of its IT infrastructure was taken out. Company has publicly declared that it will not pay ransom
Incident: Ransomware takes out Multiple PC Board facilities
Someone in Redmond got onto the internet and accidentally clicked on some links. The Redmond site was infiltrated and with ransomware which branched out to the Tucson facility, infecting multiple pcs and infrastructure there as well. Prototron shut everything down and did a complete rebuild, reinstalling operating systems and complete infrastructure rebuild. Affected sites in Redmond, WA & Tuscon AZ
Incident: Global Transportation company has multiple servers and intranet taken down by attack
A number of IMO web-based services were unavailable and the breach affected its public website and internal systems. Spokesperson stated their website and intranet had been disabled by a sophisticated cyber-attack and its IT specialists had shut down key systems to prevent further damage.
Incident: CMA CGM SA shutdown after attack with ransomeware
They shut down some of their technology systems as they coped with a cyberattack at two of their Asia-Pacific subsidiaries. As of Oct. 2nd, they were still working on restoring access to all information systems and their worldwide agency network was gradually being reconnected. They claim that the malware had not compromised any of its communications, including email, transmitted files and electronic data interfaces. People involved in the matter said the carrier was investigating an encryption malware attack and that it had been contacted by someone claiming to be a hacker who asked for ransom in return for a decryption key.
Incident: Personal Information stolen and extortion attempt to Brasken facility
Revil operators obtained 874 GB of data and threatened to publish it. As of morning of Oct 16, the Sao Paulo Braskem website was inaccessible possibly indicating that all of the network issues were still not resolved.
Incident: Personal Information stolen and extortion attempt to Adif Transportation
800GB of personal information, correspondence, contracts and other accounting figures was obtained by hackers who threatened to publish in public domain if demands not met
Incident: Ransomware affects container shipments of global operations company
Ransomware affected some servers in Geneva as well as some machines on the container vessels. Official website was down for numerous days disrupting the self service tools for making and managing bookings of MSC ships.
Incident: Personal Information stolen and extortion attempt to Austal Transportation
Cyber security breach and extortion attempt was made by hackers who accessed some staff email and mobile phone numbers. It was reported that the hackers got access to, or stole, drawings and designs of its ships although the company said there was "no evidence to date that information affecting national security has been stolen".
Incident: Energy company loses 5TB of data from encryption of ransomeware
Netwalker Group accessed and encrypted nearly 5 TB of data and was demanding a $14 Million ransom or they would look for interesting data and start publishing it. This was 2nd ransomware attack on Enel Group this year.
Incident: NC Water authority hit with Ryuk Ransomware
ONWASA (North Carolina) was hit with Ryuk ransomware in middle of night of Oct 10 attacking the utility's servers and personal computers. This attack is following the spread of the "polymorphic" EMOTET that spread through their networks beginning on Oct 4. ONWASA CEO said that they experienced a catastrophic loss inside their computer network. ONWASA vowed not to pay any ransom and to instead “undertake the painstaking process of rebuilding its databases and computer systems from the ground up.”
Incident: Agriculture water pumps attacked
Water pumps were attacked in Mateh Yehuda province in Israel. These were specific, small drainage installations in the agriculture sector that were immediately and independently repaired by the locals, causing no harm or any real-world effects," the Water Authority said in a statement.
Incident: Winnti attack on Covestro
Not disclosed. Covestro discovered Winnti on multiple systems in June of 2019.but believes it was present on the systems since 2018
Incident: Winnti attack on BASF
Consequences not disclosed. ARD, a public broadcaster reported that company had been attacked by a group associated with Chinese government with malware which allows attackers to access victims network remotely.
Incident: Winnti attack on Siemens
Consequences not disclosed. ARD, a public broadcaster reported that company had been attacked by a group associated with Chinese government with malware which allows attackers to access victims network remotely.
Incident: Winnti attack on Henkel
Consequences not disclosed. ARD, a public broadcaster reported that company had been attacked by a group associated with Chinese government with malware which allows attackers to access victims network remotely.
Incident: Winnti attack on Roche
Consequences not disclosed. ARD, a public broadcaster reported that company had been attacked by a group associated with Chinese government with malware which allows attackers to access victims network remotely.
Incident: Winnti attack on Shin-Etsu
Consequences not disclosed. ARD, a public broadcaster reported that company had been attacked by a group associated with Chinese government with malware which allows attackers to access victims network remotely.
Incident: Winnti attack on Sumitomo
Consequences not disclosed. ARD, a public broadcaster reported that company had been attacked by a group associated with Chinese government with malware which allows attackers to access victims network remotely.
Incident: Winnti attack on Lion Air
Consequences not disclosed. ARD, a public broadcaster reported that company had been attacked by a group associated with Chinese government with malware which allows attackers to access victims network remotely.
Reference: Kia Motors America suffers ransomware attack, $20 million ransom
Reference: Kia Motors Hit by Ransomware Attack
Victim: Kia Motors America
Irvine, CA-based KMA has nearly 800 dealers in the USA with cars and SUVs manufactured out of West Point, Georgia.
Incident: Kia Motors Hit by Ransomware Attack
DoppelPaymer gang wants $20 million from Kia Motors America (KMA) for a decryptor or else it will leak data it stole from the California-based subsidiary of the South Korean-based auto giant.
Kia Motors America was hit by an attack nationwide on Saturday through its IT enterprise affecting their mobile UVO Link apps, phone services, payment systems, owner's portal, and internal sites used by dealerships, according to a report in Bleeping Computer.
Irvine, CA-based KMA has nearly 800 dealers in the USA with cars and SUVs manufactured out of West Point, Georgia. When visiting their sites, users are met with a message saying Kia is "experiencing an IT service outage that has impacted some internal networks."
Victim: Israel Water Authority, Upper Galilee, Israel
Agricultural water authority for Upper Galilee, Israel
Editorial: Remote Access Leads To FL Water Supply Tampering
Reference: Someone tried to poison Oldsmar’s water supply during hack, sheriff says
Reference: Remote Access Leads To FL Water Supply Tampering
Victim: Oldsmar, Pinellas County, Florida – water department
Oldsmar provides water directly to its businesses and 15,000 residents, Gualtieri said. The computer system at the water treatment plant was set up to allow authorized users to remotely access it for troubleshooting.
Incident: Remote Access Leads To FL Water Supply Tampering
A quick thinking worker watched and quickly fixed an attack as a hacker using a Florida water treatment plant’s remote access capabilities broke in Friday and increased the amount of sodium hydroxide, or lye, to extremely dangerous levels.
In these times of increased work from home, questions remain as to how secure are company’s remote access capabilities, and how vigilant are those providers in seeing what is going on? In this case, it appears the water company’s remote access was not secure, but worker vigilance was on target.
The investigation into the hack is continuing after the attempted poisoning of the city of Oldsmar, Florida’s water supply, said Pinellas County Sheriff Bob Gualtieri said. Someone remotely accessed a computer for the city’s water treatment system and briefly increased the amount of sodium hydroxide by a factor of more than 100, Gualtieri said at a news conference.
Reference: Defence contractor Visser targeted using DoppelPaymer ransomware
Reference: Visser, a parts manufacturer for Tesla and SpaceX, confirms data breach
Victim: Visser Precision
Visser Precision, a Denver, Colorado-based manufacturer, makes custom parts for a number of industries, including automotive and aeronautics.
Incident: Visser, a parts manufacturer for Tesla and SpaceX, confirms data breach
A precision parts maker for space and defense contractors has confirmed a “cybersecurity incident,” which TechCrunch has learned was likely caused by ransomware. Visser Precision, a Denver, Colorado-based manufacturer, makes custom parts for a number of industries, including automotive and aeronautics. In a brief statement, the company confirmed it was “the recent target of a criminal cybersecurity incident, including access to or theft of data.”
Reference: OT Pipeline Attack Shuts Down Compression Facility
Victim: Unnamed natural gas compression facility
An attacker used a spearphishing link to obtain initial access to the organization’s information technology (IT) network before pivoting to its OT network, according to a report from Cybersecurity and Infrastructure Security Agency (CISA).
Incident: OT Pipeline Attack Shuts Down Compression Facility
A cyberattack hit the control and communication assets on the operational technology (OT) network of a natural gas compression facility forcing it to shut down for two days.
An attacker used a spearphishing link to obtain initial access to the organization’s information technology (IT) network before pivoting to its OT network, according to a report from Cybersecurity and Infrastructure Security Agency (CISA). The attacker then deployed commodity ransomware to encrypt data for impact on both networks. Specific assets experiencing a loss of availability on the OT network included human machine interfaces (HMIs), data historians, and polling servers.
Reference: Ransomware Hits U.S. Electric Utility
Reference: MA Utility Hit By Ransomware
Victim: Reading Municipal Light Department (RMLD)
RMLD has been operating for 125 years, and is serving more than 29,000 residential and commercial customers.
Incident: MA Utility, Reading Municipal Light Department, Hit By Ransomware
A Massachusetts electric utility was a ransomware attack victim late last month.
The Reading Municipal Light Department (RMLD) suffered a ransomware infection Feb. 21, the Reading, MA-based electric utility said in a statement. RMLD did not disclose the details on how their system was infected or the demands of the group behind the malware. There was also no indication of plans to pay ransom to the threat actors.
RMLD has been operating for 125 years, and is serving more than 29,000 residential and commercial customers.
Reference: Defense Contractor, CPI, Knocked Offline by Ransomware Attack
Malware: unknown ransomware, but unsegmented domain
According to the source, a “domain admin” — a user with the highest level of privileges on the network — clicked on a malicious link while they were logged in, which triggered the file-encrypting malware, according to Tech Crunch report. Because the thousands of computers on the network were on the same, unsegmented domain, the ransomware quickly spread to every CPI office, including its on-site backups, the source said.
Reference: Ransomware Bites Defense Manufacturer
Victim: Communications & Power Industries (CPI)
California-based Communications & Power Industries (CPI) makes components for military devices and equipment, like radar, missile seekers and electronic warfare technology. The company works with the U.S. Department of Defense and its advanced research unit DARPA.
Incident: Ransomware Bites Defense Manufacturer, Communications & Power Industries
An unsegmented domain appears to be a key aspect into the downfall of a defense industry manufacturer that suffered a ransomware attack.
A source with knowledge of the incident said the defense contractor paid a ransom of about $500,000 shortly after the incident in mid-January, but the company was not yet fully operational, according to a report with TechCrunch.com.
California-based Communications & Power Industries (CPI) makes components for military devices and equipment, like radar, missile seekers and electronic warfare technology. The company works with the U.S. Department of Defense and its advanced research unit DARPA.
Victim: Blackbaud
Cloud service provider
Reference: JSE company Omnia hit by cyber attack
Reference: Chemical Group Suffers Cyber Attack
Victim: Omnia Holdings
Omnia Holding Limited is a holding company for a group of companies that produces and supplies fertilizer to the agricultural industry, explosives to the mining industry and industrial chemical products.
Incident: Chemical Company, Omnia Holdings, Suffered Cyber Attack
Chemical company, Omnia Holdings, suffered a cyber attack on its IT infrastructure, officials said.
Omnia Holding Limited is a holding company for a group of companies that produces and supplies fertilizer to the agricultural industry, explosives to the mining industry and industrial chemical products. The group’s operations are located in South Africa, Ghana, Kenya, Mauritius, Tanzania, Zimbabwe and Zambia. The company is listed on the Johannesburg Stock Exchange (JSE)
The company said it was alerted to abnormal activity on its network on March 12 and specialist teams promptly began investigating the incident.
Reference: Lessons Learned from Honda Ransomware Attack
Reference: Attack Hits Honda Networks, Hurts Production
Reference: Power company Enel Group suffers Snake Ransomware attack
Reference: Ransomware Hits Italian Energy Giant
Reference: Aussie Brewer’s Production Hit After Ransomware Attack
Reference: Lion warns of beer shortages following ransomware attack
Victim: Lion
Australian beverages company Lion, is a maker of beers and other beverages.
The company also produces and distributes milk and other dairy items such as yoghurt, as well as juice and soy, Lion said some parts of its Dairy & Drinks business customer service continue to be impacted, with some of its manufacturing sites currently offline.
Incident: Aussie Brewer, Lion, Production Hit After Ransomware Attack
One week after an Australian beverages company Lion ended up hit by a ransomware attack, production continues to suffer.
Lion, a maker of beers and other beverages, suffered a ransomware attack last Monday which shut down their IT systems, causing some disruption to our suppliers and customers.
“Our investigations have shown that a partial IT system outage at Lion is a result of a ransomware attack,” the company said on its web site June 15. “In response, we immediately shut down key systems as a precaution. Our IT teams and expert cyber advisors have continued working throughout the weekend to investigate this incident, working to bring systems back online safely.
Reference: Making Sense of the Blackbaud Ransomware Attack
Reference: Cloud Provider Hit By Ransomware Then Pays
Incident: Cloud software provider, Blackbaud, falls victim to ransomware attack
Cloud software provider, Blackbaud, fell victim to a ransomware attack and decided to pay to avoid a release of data information.
The summary of the incident detailed by Charleston, SC-based Blackbaud started in May when the company said it discovered and stopped a ransomware attack. Blackbaud describes itself as a provider of cloud software, services, expertise, and data intelligence that empower and connect people to drive impact for social good.
After discovering the attack, Blackbaud’s security team, along with independent forensics experts and law enforcement, successfully prevented attackers from fully encrypting files.
Reference: U.S. spirits and wine giant hit by cyberattack, 1TB of data stolen
Reference: Ransomware Hits Alcohol Beverage Maker
Editorial: Tool to Help Defend Against APTs
Reference: Steelcase furniture giant down for 2 weeks after ransomware attack
Threat Actor: Ryuk ransomware gang
Ryuk ransomware gang was the one responsible for the attack.
Reference: Ransomware Shuts Furniture Maker
Malware: Ryuk ransomware
Ryuk ransomware has been an ongoing issue across all industries. Once an attacker gets in through any means possible — the enterprise, the physical security network, building automation, outside vendors and contractors, or the operational technology network — it can pivot and start its attack to take over and own whatever network it wants to control.
Victim: Steelcase
Steelcase is the world’s largest office furniture manufacturer, with 13,000 employees and $3.7 billion in revenue in 2020. It also has a network of 800 dealers.
Grand Rapids, Michigan-based Steelcase produces office furniture, architectural and technology products for office environments and the education, health care and retail industries. It has facilities, offices, and factories in the Americas, Europe, Asia, the Middle East, Australia and Africa.
Incident: Ransomware Shuts Furniture Maker
Office furniture giant Steelcase suffered a Ryuk ransomware attack late last month that forced them to shut down global operations for two weeks.
Reference: Biotech Firm Back Up After Malware Attack
Malware: Unknown malware attack
Various parts of the company ended up halted because of a malware attack.
Victim: Miltenyi Biotec
“During the last two weeks, there have been isolated cases where order processing was impaired by malware in parts of our global IT infrastructure. Rest assured, all necessary measures have now been taken to contain the issue and recover all affected systems,” the company said in a statement.
It then added there were no indications the attack did not go out to any of its customers or partners along its supply chain.
Incident: Biotech Firm Back Up After Malware Attack
Miltenyi Biotec is back up and running after a malware attack hit parts of its global infrastructure.
The company said in a note on its website: “Miltenyi Biotec is happy to announce that we are again fully operational.” Miltenyi Biotec started up in 1989 in Bergisch Gladbach, Germany. The company offers solutions for cell and therapy research, including COVID-19-related products. It has facilities in 28 countries and has over 3,000 workers.
Over the past two weeks, various parts of the company ended up halted because of a malware attack.
Reference: Toy Maker Hit By Ransomware Attack
Reference: Toy manufacturer Mattel suffers ransomware attack
Malware: Unknown ransomware variant
Threat actors targeted Mattel with an unnamed ransomware variant, which impacted some of its business functions in July 2020. However, the company stated that attackers did not exfiltrate any data. This incident highlights the continued threat of ransomware for large organizations.
Victim: Mattel
U.S. toymaker Mattel was the victim of a ransomware attack on its information technology systems that caused data on a number of systems to end up encrypted this past July, the company said in its quarterly report filed with the Securities Exchange Commission (SEC).
Mattel contained the attack and, although some business functions were temporarily impacted, it restored its operations, according to the report.
A forensic investigation of the July 28 incident concluded, and no exfiltration of any sensitive business data or retail customer, supplier, consumer, or employee data ended up identified, the company said in the report. The company noted there has been no material impact to Mattel’s operations or financial condition as a result of the incident.
Incident: Mattel Hit By Ransomware Attack
U.S. toymaker Mattel was the victim of a ransomware attack on its information technology systems that caused data on a number of systems to end up encrypted this past July, the company said in its quarterly report filed with the Securities Exchange Commission (SEC).
Mattel contained the attack and, although some business functions were temporarily impacted, it restored its operations, according to the report.
Reference: Networking equipment vendor Belden discloses data breach
Reference: OT Networking, Security Supplier Attacked
Victim: Belden Inc.
Belden Inc. is a supplier of specialty networking solutions and cybersecurity products.
Incident: OT Networking, Security Supplier, Belden, Attacked
Belden Inc., a supplier of specialty networking solutions and cybersecurity products, is investigating the cause of a cyberattack that led to unauthorized access and copying of some current and former employee data, as well as limited company information regarding some business partners.
Belden IT professionals detected unusual activity involving certain company servers, the company said in a release. Upon detection, the company immediately activated its cybersecurity incident response plan, deployed teams of internal IT specialists, and engaged leading third-party cybersecurity forensic experts and other advisors to identify and mitigate the impact of this incident.
Threat Actor: Nation State Actor
“Red team tools” were stolen as part of a highly sophisticated, likely “nation-state” hacking operation.
Reference: FireEye Shares Details of Recent Cyber Attack, Actions to Protect Community
Reference: Security Provider FireEye Hit By Cyber Attack
Victim: FireEye
From CEO Kevin Mandia: FireEye is on the front lines defending companies and critical infrastructure globally from cyber threats. We witness the growing threat firsthand, and we know that cyber threats are always evolving. Recently, we were attacked by a highly sophisticated threat actor, one whose discipline, operational security, and techniques lead us to believe it was a state-sponsored attack. Our number one priority is working to strengthen the security of our customers and the broader community. We hope that by sharing the details of our investigation, the entire community will be better equipped to fight and defeat cyber attacks.
Incident: FireEye Hit by Cyber Attack
FireEye said its own systems ended up attacked by what it called “a nation with top-tier offensive capabilities.”
The FireEye breach ended up disclosed in a blog post authored by Chief Executive Kevin Mandia. The post said “red team tools” were stolen as part of a highly sophisticated, likely “nation-state” hacking operation. It is not clear exactly when the hack initially took place.
Reference: Egregor Ransomware Strikes Metro Vancouver’s TransLink
Reference: Ransomware Hits Vancouver’s TransLink
Reference: test
Reference: Foxconn Electronics Giant Hit by Ransomware, $34 Million Ransom
Reference: Electronics Maker Hit by Ransomware
Reference: Pemex Ransomware Attack
Threat Actor: DoppelPaymer Ransomware Gang
Group responsible for DoppelPaymer ransomware
Victim: Foxconn
Foxconn is a multinational electronics contract manufacturer established in 1974 with headquarters in Tucheng District, New Taipei City, Taiwan. It manufactures electronic products for major American, Canadian, Chinese, Finnish, and Japanese companies.
Incident: Foxconn Hit By Ransomware
Electronics giant Foxconn suffered a ransomware attack at a Mexican facility over the Thanksgiving weekend.Foxconn is the largest electronics manufacturing company globally, with revenue of $172 billion in 2019 and over 800,000 employees worldwide. Foxconn subsidiaries include Sharp Corporation, Innolux, FIH Mobile, and Belkin.
Malware: Egregor
Egregor is one ransomware operation that maintains a data leaks site for publishing non-compliant victims’ stolen information. These portals enable digital attackers to double-extort their victims: Once for the decryption key and again for the deletion of their stolen information.
Victim: Translink
TransLink is the authority responsible for managing Metro Vancouver’s transportation network, Attack affected its phones, online services and payment systems.
Incident: Ransomware Hits Vancouver’s TransLink
TransLink December 1 said certain issues were affecting its phones, online services and payment systems. It later it had suffered a ransomware attack and those responsible for the infection had used its printers to deliver their ransom note, according to a report with Tripwire. Officials also believe the attack started via a phishing email.
Incident: Austria Crane Maker Under Attack
Austria-based Palfinger Group is undergoing a global cyber attack with its IT infrastructure disrupted including sending and receiving emails and its ERP systems. A large proportion of the group’s worldwide locations are suffering from the attack. It is not possible to estimate the precise extent and duration of the attack or its consequences at this time, the company said.
Reference: Austria Crane Maker Under Attack
Victim: Palfinger Group
Austria-based crane and lifting manufacturer
Reference: Jet Maker Hit By Cyber Attack
Victim: Embraer S.A.
Brazil-based aircraft maker
Victim: Covestro
Germany-based Covestro
Threat Actor: Winnti
Group of professional hackers believed to be controlled by China. Since at least 2011, these hackers have been using malware to spy on corporate networks. Their mode of operation is to collect information on the organizational charts of companies, on cooperating departments, on the IT systems of individual business units, and on trade secrets. Targets are primarily German-based companies (Siemens, Bayer, Roche, BASF, Covestro).
Malware: Winnti
Winnti is a trojan typically used by a Chinese advanced persistent threat (APT) group of the same name. The Winnti trojan was first identified in 2011. An indication that Winnti has compromised a computer system is the presence of “tmpCCD.tmp” in the Windows temporary folder and the files “ServiceAdobe.dll” and “ksadobe.dat.” When working, the RAT (remote access Trojan) also uses a service pretending to be from Adobe (Adobe Service).
Incident: Winnti malware infection
Covestro discovered Winnti malware on multiple systems.
Reference: What happened in ransomware attack on Port of San Diego
Malware: Conti Ransomware
Conti Ransomware
Victim: Advantech
Advantech is an automation supplier.
Incident: Jet Maker Hit By Cyber Attack
Brazilian jet maker Embraer S.A. suffered a cyber attack of its IT systems which resulted in the disclosure of data.
Reference: Advantech Hit By Ransomware
Incident: Advantech Hit By Ransomware
Ransomware attack hit Taiwan-based Advantech Co. in November, 2020 and the hackers sought 750 bitcoin or $13.8 million in exchange for the decryption key.
Editorial: Ransomware Alert from FBI
Editorial: Microsoft Code Safe after Attackers View
Reference: Hack Hits Kawasaki Heavy
Incident: Hack on Kawasaki Heavy
Kawasaki Heavy Industries Ltd. discovered a data breach last June that may have occurred the previous September, company officials said Monday.
Kawasaki Heavy said it found fraudulent server access via a company unit in Thailand during a system audit on June 11 this year, and confirmed the possibility of data breach. The administrator identification and password of the company’s domestic system had been stolen, Kawasaki Heavy said.
Victim: Kawasaki Heavy
Page: Collaborator: Add New Information
Reference: Test
Editorial: Ransomware Hits MA Laser Maker
Incident: Ransomware Attack Disrupting Operations
PG Photonics, an Oxford-Massachusetts-based developer of fiber lasers for cutting, welding, medical use, and laser weaponry suffered a ransomware attack that disrupted operations.
Victim: IPG Photonics
Malware: AndroidOC/MalLocker.B
Mobile ransomware targeting Android devices
Editorial: Android Ransomware Shows New Twist
Page: Incidents
Reference: Why the Norsk Hydro attack is a ‘blueprint’ for disruptive hacking operations
Reference: Ransomware Behind Norsk Hydro Attack Takes On Wiper-Like Capabilities
Reference: Long Beach Port terminal hit by ransomware attack
Reference: Iran reports failed cyber-attack on Strait of Hormuz port
Reference: Port Kembla steelworks hit by BlueScope cyber attack
Reference: Energy Giant EDP Hit With €10 Million Ransomware Threat
Reference: Officials: Israel linked to a disruptive cyberattack on Iranian port facility
Reference: Ragnar Locker’s well-conceived ransomware attack on Energias de Portugal
Reference: Steel miner and manufacturer EVRAZ hit by a Ransomware Attack
Incident: Natural Gas Compression Facility Spearfishing
CISA responded to a cyberattack affecting control and communication assets on the operational technology (OT) network of a natural gas compression facility. A cyber threat actor used a Spearphishing Link [T1192] to obtain initial access to the organization’s information technology (IT) network before pivoting to its OT network. The threat actor then deployed commodity ransomware to Encrypt Data for Impact [T1486] on both networks. Specific assets experiencing a Loss of Availability [T826] on the OT network included human machine interfaces (HMIs), data historians, and polling servers. Impacted assets were no longer able to read and aggregate real-time operational data reported from low-level OT devices, resulting in a partial Loss of View [T829] for human operators. The attack did not impact any programmable logic controllers (PLCs) and at no point did the victim lose control of operations. Although the victim’s emergency response plan did not specifically consider cyberattacks, the decision was made to implement a deliberate and controlled shutdown to operations. This lasted approximately two days, resulting in a Loss of Productivity and Revenue [T828], after which normal operations resumed. CISA is providing this Alert to help administrators and network defenders protect their organizations against this and similar ransomware attacks.
Reference: Alert (AA20-049A) Ransomware Impacting Pipeline Operations
Victim: Undisclosed – Oil & Gas
A victim in the oil and gas industry that does not wish to be disclosed.
Reference: Pemex Workers Barred From Computers After Unexpected Shutdown
Reference: Hackers demand $5 million from Mexico’s Pemex in cyberattack
Incident: Brown-Forman Cyber Attack
Brown-Forman, a manufacturer of alcoholic beverages including Jack Daniel’s and Finlandia, said it was hit by a cyber-attack in which some information, including employee data, may have been impacted. The threat actors managed to copy 1TB of confidential data which they had decided to sell to the highest bidder the most important info and leak the rest. The data stolen includes confidential information about employees, company agreements, contracts, financial statements, and internal correspondence. Louisville, KY.
Incident: Carnival Data Breach
Threat actors accessed and encrypted a portion of one brand’s information technology systems. They also downloaded files from the company’s network. Carnival upon preliminary assessment of the incident, stated that the attackers might have attained access to some guest and employees’ personal data.
Incident: Honda Manufacturing Attack
A ransomware attack took down portions of Honda Motor Co. this week, locking up systems and halting vital manufacturing operations in several countries.
Incident: Enel Group Internal IT Network Disruption
Its internal IT network was disrupted due to a ransomware attack. Their antivirus caught the malware before it could spread although corporate network was isolated for a time to eliminate any residual risk.
Incident: Fresenius Kabi Computer Virus
A computer virus infected at least one of its businesses’ IT systems. The corporation said the security incident had hampered some production in its pharmaceutical business, which makes everything from nutritional products and infusion therapies to pain relievers that are in high demand during the coronavirus pandemic
Incident: Yashma Wind Park Spear Phishing Attack
Spear phishing attack led to Data theft. Reported by Cisco Talos
Incident: Emcor IT Systems Attack
EMCOR said that not all of its systems were impacted and only "certain IT systems" were affected, which it promptly shut down to contain the infection. The company said it was restoring services, but did not specify if it paid the ransom demand or if it was restoring from backups.
Incident: INA Group Cyber Attack
A notice on the company website states: “The INA Group is under cyber-attack, which began around 10 pm on February 14, 2020, causing problems in the operation of certain IT systems, which can occasionally affect normal operation, such as issuing mobile phone vouchers, electronic vignettes, paying utility bills.”
Incident: Railworks Data Breach
Data Breach exposed various forms of personally identifiable information (PII) – names, addresses, driver’s license numbers, government-issued IDs, Social Security numbers, dates of birth, and dates of hire/termination and/or retirement. Those affected include both past and present employees, independent contractors, as well as their beneficiaries and dependents.
Incident: Hexion/Momentive Global IT Outage
The incident caused a global IT outage that forced the company to order hundreds of new computers and give some employees new email accounts as their old ones had become inaccessible.
Incident: sPower CyberAttack
The cyberattack briefly cut off communications between sPower’s control centers and a dozen remote wind and solar farms that served as its power generation stations. Lara Hamsher, government relations and communications manager at sPower, provided the following statement: “sPower is a generator owner and generator operator of wind and solar generation assets that are operated from a 24/7/365 control center in Salt Lake City, Utah. On March 5, 2019 sPower’s Control Center observed a brief (five minutes or less) communication interruptions between the control center and 12 generation sites. These interruptions had no impact to generation and did not cause electrical system separation. After investigation and in accordance with sPower’s commitment to continuous improvement, processes and systems were improved to help ensure as much uptime as possible.”
Incident: Altran Technologies IT Shutdown
Shut down IT Network and Aplications
Incident: Nyrstar Ransomware Attack
Nyrstar said that its metals processing and mining operations were not damaged by the attack.
Incident: Roadrunner Transportation Systems
Private information of Roadrunner employees was stolen. Started as a Phishing attack. Ransom was not paid and company recovered on its own.
Incident: Mondelez Ransomware Attack
Mondelez International, owner of U.K. chocolate maker Cadbury, estimated the cost of the attack at just over $150 million in lost sales and incremental expenses. The company, whose sales, distribution and financial networks were impacted by the malware, expects the recovery process to continue into the second half of 2017.
Mondelez filed $100 million claim from Zurich Insurance, claiming permanent damage to 1,700 of its servers and 24,000 laptops, inflicted by NotPetya, plus the theft of thousands of user credentials, unfulfilled customer orders and other losses.
The NotPetya ransomware attack crippled computer systems of firms operating across the globe. Building Systems unit with over 1700 servers and 24,000 laptops rendered malfunctional.
Incident: Merck Ransomware Attack
Crippled more than 40,000 laptop and desktop computers, as well as 7,500 servers,. Crippled Merck’s production facilities. Cost the company $1.3Billion.
Incident: Maersk Ransomware Attack
A NotPetya attack disrupted operations for two weeks, blocking access to systems the company relied on to operate shipping terminals. The incident temporarily shut down the Port of Los Angeles’ largest cargo terminal. The company lost $300 million in business disruption and equipment damage. Maersk had to undertake an almost complete infrastructure overhaul. They reinstalled 4,000 servers, 45,000 PCs and 2,500 applications over the course of ten days, a process that would normally have taken six months to implement.
Victim: German Steel Mill
Victim: sPower
Victim: Railworks of North America
Victim: INA Group
Victim: Honda
Victim: Hexion / Momentive
Victim: Enel Group
Victim: Emcor
Victim: Carnival Corporation
Victim: Brown-Forman
Incident: Pemex Ransomware Attack
Pemex said that its oil and gas operations were not disrupted and storage was unaffected but some employees disagreed.
Malware: SamSam
Also known as MSIL/Samas.A. Specifically, this product shares analysis of vulnerabilities that cyber actors exploited to deploy this ransomware. In addition, this report provides recommendations for prevention and mitigation.
The SamSam actors targeted multiple industries, including some within critical infrastructure. Victims were located predominately in the United States, but also internationally. Network-wide infections against organizations are far more likely to garner large ransom payments than infections of individual systems. Organizations that provide essential functions have a critical need to resume operations quickly and are more likely to pay larger ransoms.
Malware: REvil
The REvil (also known as Sodinokibi) ransomware was first identified on April 17, 2019. It is used by the financially motivated GOLD SOUTHFIELD threat group, which distributes ransomware via exploit kits, scan-and-exploit techniques, RDP servers, and backdoored software installers. Secureworks Counter Threat Unit (CTU) analysis suggests that REvil is likely associated with the GandCrab ransomware due to similar code and the emergence of REvil as GandCrab activity declined. CTU researchers attribute GandCrab to the GOLD GARDEN threat group.
Malware: Nemty
For those unfamiliar with this malware operation, Nemty is a classic RaaS (Ransomware-as-a-Service). It launched in the summer of 2019 and has been heavily advertised on underground Russian-speaking hacking forums.
Malware: NetWalker
Also known as MailTo
Malware: CLOP
Clop is a ransomware-type virus discovered by Jakub Kroustek. This malware is designed to encrypt data and rename each file by appending the ".Clop" extension. For instance, "sample.jpg" is renamed to "sample.jpg.Clop". Following successful encryption, Clop generates a text file ("ClopReadMe.txt") and places a copy in every existing folder. The text file contains a ransom-demand message.
Threat Actor: Ragnarok Group
A hacking group called Ragnarok, known for using the custom Ragnar Locker ransomware that has been hitting managed service providers since late 2019.
Incident: China Ocean Shipping Company Terminal Maritime Incident
COSCO Shipping Lines confirmed that it has been hit by a cyber attack impacting its internet connection within its offices in America.
Incident: Shahid Rajaee Port Terminal Maratime Attack
Computers that regulate the flow of vessels, trucks and goods all crashed at once, creating massive backups on waterways and roads leading to the facility,” the Post reported, adding that it had seen satellite photos showing miles-long traffic jams leading to the port and ships still waiting to offload several days later.
Incident: Toll Group Cyber Attack #2
Logistics giant Toll Group says it suffered a second major cyber attack this year, revealing it has closed numerous internal and customer-facing systems after being infected by a new form of ransomware.
The company faced over a month of costly disruptions to its operations earlier this year when its systems were compromised by Russia-based hackers, who unsuccessfully sought a hefty ransom to unlock Toll's
Incident: EDP Ransom Attack
10TB of sensitive data stolen and threatened to publish. Requested ransom of 1,580 BTC (Bitcoin – a value of €9.9MM)
Incident: EVRAZ Infection Affects Steel Production Plants Across Canada and the US
A cyberattack late Wednesday night has shut down Evraz North America's information technology systems across the United States and Canada, a company spokesperson confirmed on Thursday. The company also confirmed that temporary layoff notices have been issued as a result.
"At this point, there has been no indication of any breach of confidential or personal customer or employee information," said Patrick Waldron, spokesperson for the company. Waldron said there is currently no timeline for resolution of the situation but it has affected internal infrastructure such as the company's email system.
Incident: Port of San Diego Maritime Event
The Barcelona cyber-attack was followed by another one this week, this time against the Port of San Diego, a medium-sized cargo port on the US west coast.
"Port employees are currently at work but have limited functionality, which may have temporary impacts on service to the public, especially in the areas of park permits, public records requests, and business services," said Randa Coniglio, Chief Executive Officer for the Port of San Diego in a statement released a day after the attack.
Incident: Port of Barcelona Maritime Incident
The Port of Barcelona the target of a cyberattack that affected some of its servers and systems, forcing the organization to launch the contingency plan designed specifically for these incidents.
Malware: DoppelPaymer
DoppelPaymer is an emerging type of ransomware that not only locks companies out of their own computer systems by encrypting files—the hallmark of typical ransomware—but also can exfiltrate company data and use it as collateral.
Malware: Lockergoga
Once installed, LockerGoga modifies the user accounts in the infected system by changing their passwords. It also tries to log off users logged in to the system. It would then relocate itself into a temp folder then rename itself using the command line (cmd). The command-line parameter used does not contain the file paths of the files targeted for encryption.
Malware: Netfilim
Netfilim uses AES-128 encryption to encrypt victim’s files. An RSA-2048 embedded in the ransomware executable will then encrypt the AES encryption key. The encrypted AES key will then be added to every encrypted key. The ransomware also adds a “NEFILIM” string as a file marker to all encrypted files. The encrypted files will have .NEFILIM appended to their file names (for example, a file called 1.doc would be named 1.doc.NEFILIM).
Malware: NotPetya
This ransomware targets Microsoft Windows-based systems, infecting the master boot record to execute a payload that encrypts a hard drive's file system table and prevents Windows from booting. It subsequently demands that the user make a payment in Bitcoin in order to regain access to the system.'
Malware: SNAKE
Like most ransomware, Snake doesn’t touch your operating system files and programs, so your computer will still boot up, log in, and let you open your favourite apps, so that in purely technical terms you have a working system…
…but all your important data files, such as documents, spreadsheets, photos, videos, music, tax returns, business plans, accounts payable and accounts receivable, are scrambled with a randomly chosen encryption key.
Malware: Mirai
Mirai is a malware that turns networked devices running Linux into remotely controlled bots that can be used as part of a botnet in large-scale network attacks. It primarily targets online consumer devices such as IP cameras and home routers.
Malware: Mailto
Also known as NetWalker
Malware: EKANS
EKANS ransomware emerged in mid-December 2019. While relatively straightforward as a ransomware sample in terms of encrypting files and displaying a ransom note, EKANS featured additional functionality to forcibly stop a number of processes, including multiple items related to ICS operations. While all indications at present show a relatively primitive attack mechanism on control system networks, the specificity of processes listed in a static “kill list” shows a level of intentionality previously absent from ransomware targeting the industrial space.
Malware: Ragnar Locker
A new ransomware attack method takes defense evasion to a new level—deploying as a full virtual machine on each targeted device to hide the ransomware from view. In a recently detected attack, Ragnar Locker ransomware was deployed inside an Oracle VirtualBox Windows XP virtual machine. The attack payload was a 122 MB installer with a 282 MB virtual image inside—all to conceal a 49 kB ransomware executable.
Reference: https://news.sophos.com/en-us/2020/05/21/ragnar-locker-ransomware-deploys-virtual-machine-to-dodge-security/
Threat Actor: Joseph Atkins
An unknown hacker who uses the name “Joseph Atkins” in an email address — almost surely a pseudonym.
Threat Actor: Infected Mouse
Attackers plant an infected mouse at a company to start a ransomware attack.
Threat Actor: STIBNITE
Biohackers.
Threat Actor: Iran
A threat apparently originating in Iran.
Threat Actor: Russia
A threat apparently originating in Russia.
Threat Actor: Russian Main Intelligence Directorate (GRU)
The Directorate is reputedly Russia's largest foreign-intelligence agency.
Threat Actor: Jerusalem Electronic Army
An Islamic hacktivist group active on social media. Named the Jerusalem Electronic Army (J.E.Army), the group has a presence on all major social networks, such as Facebook, Instagram, WhatsApp, Twitter, and Telegram, where it often posts screenshots from targets they claim to have hacked.
Threat Actor: Isreal
A threat apparently originating in Israel.
Threat Actor: Wizard Spider
WIZARD SPIDER is a sophisticated eCrime group that has been operating the Ryuk ransomware since August 2018, targeting large organizations for a high-ransom return. This methodology, known as “big game hunting,” signals a shift in operations for WIZARD SPIDER. This actor is a Russia-based criminal group known for the operation of the TrickBot banking malware that had focused primarily on wire fraud in the past.
Victim: Pemex
Victim: EVRAZ
Victim: EDP
Victim: Toll Group
Victim: Shahid Rajaee Port Terminal
Victim: Port of San Diego
Victim: Port of Barcelona
Victim: Nyrstar
Victim: Maersk
Victim: Merck
Victim: Roadrunner Transportation Systems
Victim: Fresenius Kabi
Victim: Altran Technologies
Victim: Yashma Wind Park
Victim: Mondelez
Victim: China Ocean Shipping Company Terminal
Incident: Attack on deep-draft vessel bound for the Port of New York
Deep draft vessel bound for the Port of New York
Victim: Port of New York
Incident: Norsk Hydro Production lines stopped
Production lines had stopped at some of its 170 plants.
The ransomware LockerGoga blocked the company’s systems, forcing a switch to manual operations and workarounds. The Extruded Solutions unit, which makes components for car manufacturing, construction and other industries, reduced its output by 50%. Administrative systems, such as reporting, billing and invoicing, suffered delays. It took Norsk Hydro several weeks to bring operations back to normal.
Victim: Norsk Hydro
Victim: Bluescope
Incident: Bluescope Shutdown of Operations
Worldwide shut down of operations after cyberattack. The ransomware infection was discovered yesterday morning in one of Bluescope Steel's United States-based businesses. The company had reverted to manual operations where possible, but some processes such as steel despatches were continuing as normal. Steelmaking at Port Kembla, Australia was continuing, however the hot strip mill was temporarily disrupted.
