Engineering (Includes Industrial Construction)

Industry

Cyberattack at VA Engineering Firm

January 14, 2025

Roanoke, Virginia-based construction engineering firm, The Branch Group, Inc., suffered a cyberattack in January and is now letting employee victims know their personally identifiable information ended up stolen in the hack.
“On or about January 14, 2025, we detected a network security incident, in which an unauthorized third-party attempted to access our network environment,” the company said in a letter to victims. “We immediately engaged third-party forensic specialists to assist us with securing the network environment and investigating the extent of any unauthorized activity.”
The investigation concluded on August 22 and the company found an unauthorized third party acquired certain individual personal information during this incident.

read more

Outage at Mathworks, a leading US Simulation Software Co.

May 27, 2025

MathWorks, a leading developer of mathematical computing and simulation software, has revealed that a recent ransomware attack is behind an ongoing service outage. Online applications and internal systems became unavailable. Customers experienced issues preventing them from creating new accounts, while others who haven’t signed in since 11 October 2024 were not able to log in at all. No ransomware gang has claimed the breach, suggesting that MathWorks has either paid the ransom demanded by the attackers or is still negotiating.

read more

Cyberattack Disrupts Tata Technologies’ IT Systems

January 31, 2025

Tata Technologies reported a security breach by ransomware actors disrupting parts of its IT systems. The company stated operational impact was minimal and client delivery services were not affected. Hunters International ransomware gang claimed responsibility for the attack claiming they stole 1.4TB of data. The hacker group did not post any samples of the stolen files or elaborate on what kind of documents they hold.

read more

Cyberattack Hits Schwerte’s Municipal Utilities

March 5, 2025

A municipality in North Rhine-Westphalia has fallen victim to a cyberattack. The city of Schwerte has “taken comprehensive security precautions,” according to the Ruhr Nachrichten newspaper. The city’s digital connection to the utility company has been interrupted. The Schwerte city administration’s systems were fully operational again on March 10. Local newspaper Ruhr News reports that stolen data, including personal data, has been published on the dark web on April 30.

read more

Security Breach at British Engineering Firm IMI

February 6, 2025

British-based engineering firm IMI plc has disclosed a security breach after unknown attackers hacked into the company’s systems. An IMI spokesperson declined to comment when asked by BleepingComputer provide more details about the attack, such as the date it was detected, whether it impacted its operations, and whether the threat actors stole company or customer information from compromised systems.

read more

Cyberattack at UK Engineering Firm Smiths Group

January 28, 2025

U.K. engineering firm Smiths Group — whose operations span 50 countries across a range of sectors — has detected “unauthorised access” in its systems, the company informed the London Stock Exchange on Tuesday. Smiths Group said it “rapidly isolated affected systems and activated business continuity plans” after it detected the activity.

read more

Ivanti Flaw Exploited in MITRE Corporation Cyberattack

April 19, 2024

MITRE’s unclassified collaborative research and development network — where prototyping and other work is housed — was compromised by a foreign nation-state threat actor. MITRE’s work supports a variety of government agencies. MITRE is working to restore operational alternatives for collaboration in an expedited and secure manner.

The company said unidentified threat actors performed reconnaissance on its networks by exploiting one of its VPNs through two vulnerabilities in Ivanti Connect Secure. At the time, Ivanti said the two vulnerabilities — CVE-2023-46805 and CVE-2024-21887 — were used in attacks on at least 10 of its customers.

read more

Widespread Fallout after Ransomware Attack at Service Provider for Customer Communication in the Netherlands

May 5, 2024

AddComm’s systems were recently hit by a ransomware attack. The hack took place between May 5 and May 17. On May 17, the security incident became known to AddComm because the systems were encrypted by the cybercriminals.

=ABN Amro reports that it will no longer use Addcomm’s services for the time being, but says that it is in close contact with AddComm.
=Energy Suppliers Essent en Vattenfall energy companies warn customers of dataleak at AddComm.
=The Hague housing corporation Staedion; Waterbedrijf Groningen; the Drenthe drinking water company WMD; the Regional Tax Group (RBG); Hoogheemraadschap Hollands Noorderkwartier (HHNK) ; and the Amsterdam housing corporation Eigen Haard also issued warnings .

read more

Cyberattack on Engineering Firm in Germany

November 1, 2024

The engineering office Fritz Spieth Beratende Ingenieure GmbH has fallen victim to a targeted hacker attack by criminals.

Immediately after discovering the attack, our management informed the authorities and filed a complaint. At the same time, all IT systems were shut down or isolated to protect our customers, suppliers and employees.

By consistently implementing an emergency protocol and IT emergency plan, our company has returned to normal operations. In the future, we will have a compromise assessment carried out by independent experts on a continuous basis to further increase our IT security level and go beyond our previous standards.

According to the assessment of independent IT experts, there is currently no evidence that the portals we use and the emails we send pose an increased risk.

read more