Engineering (Includes Industrial Construction)

Industry

Cyberattack at Max Wild GmbH takes IT Systems Offline

April 25, 2024

Cyberattack on Max Wild GmbH. The company website reports:
Cyber criminals managed to break through IT security barriers and existing protection systems and penetrate our IT systems. The attack was detected on April 25 and then immediately stopped.

In order to be able to fully examine the IT systems and avert further attacks, many of our IT systems are currently switched off. restrictions in digital communication and telephone accessibility possible

read more

8Base Leaked Data from German Engineering Company

March 25, 2024

Ringhoffer Verzahnungstechnik was the victim of a ransomware attack on March 25, 2024. The blackmail group 8BASE was able to steal the company’s data during the attack. The stolen data includes financial data, employment contracts and other confidential documents. The blackmailers have since published these.

read more

Operations Down at Water & Complex Waste Waste Plant Manufacturer Wehrle

May 11, 2024

The Emmendingen plant manufacturer Wehrle has fallen victim to hackers.

According to the Badische Zeitung, the attack was carried out on May 11. Since then, the company’s production and communication have been severely restricted. The company announced yesterday Tuesday that it was working intensively to restore the affected systems and resume full operations.

read more

Databreach at Upstream Engineering Firm, Netherland, Sewell & Associates, Inc. (NSAI)

July 10, 2024

Dallas, Texas-based upstream engineering provider, Netherland, Sewell & Associates, Inc. (NSAI) discovered on or around August 16, 2024 they suffered a ransomware attack in July. Personal information that may have been obtained, the company said. It added there has been no indications attackers are using that information at present. The current count of victims in the attack is at 537, the company said.

read more

Control Room Provider, Activu, Hit In Cyberattack

August 30, 2024

Control room visualization technology provider, Activu Corporation, suffered a cyberattack this past August and is now informing victims of the attack.
“On or about, August 30, 2024, Activu became aware of suspicious activity on our computer network,” the Rockaway, New Jersey-based company said in an advisory. “We promptly took steps to secure our systems and began an investigation to determine the full nature and scope of the event.
“Our investigation determined that an unknown actor gained accessed certain Activu systems on August 30, 2024, and accessed and/or acquired certain files from those systems.”

read more

CRB Engineering Discloses December 2023 Data Breach

December 25, 2023

CRB Engineering suffered a cyberattack back in December through January and released an update providing a few more details.
The cyberattack affected 1,198 victims. On May 20, the company completed its initial review and it then worked to locate accurate address information in order to inform victims of pertinent information. The company completed its address review May 29. It then sent out letters dated August 21.

read more

Remote Control Malware Targets South Korean Company’s Large Machine & Equipment Design Files

April 15, 2024

In April 2024, the North Korean hacking organization Andariel exploited vulnerabilities of the VPN information security software used by targeted construction and machinery companies to replace update files in their systems with malware.

In addition to the VPN products, Andariel also exploited vulnerabilities in server security products. The threat actors were able to distribute remote control malware DoraRAT with the aim of using it to transfer large machine and equipment-related design files to the C2 server, according to South Korean intelligence.

read more

North Korean hackers attack South Korea’s construction sector

January 15, 2024

The Kimsuky hacker group distributed malware through the website of a professional association in the construction sector, according to the South Korean intelligence.

The malware was hidden in the security authentication software used to log into the website. As a result, the personal computers of local government, public institutions, and construction company staff who accessed the website were infected.

It is believed that the attackers exploited a file upload vulnerability on the professional association’s website to alter the security authentication software in a “meticulously” planned operation. “It is presumed that the hackers aimed to use the compromised credentials of officials in the construction sector as a foothold to steal critical information about major construction projects and technical data from companies involved,” the KCIC said.

read more

Ransomware Attack at Engineering and Construction Company Hiap Seng Industries

July 3, 2024

Hiap Seng Industries, a prominent engineering and construction company, has fallen victim to a ransomware attack that compromised its servers. The company has swiftly taken measures to contain the breach and ensure the continuity of its business operations.

Hiap Seng Industries reported that there has been no material impact on its business operations due to the incident.

read more

McKim & Creed Engineering Firm Suffers Cyberattack

February 11, 2024

Raleigh, North Carolina-based McKim & Creed suffered a cyberattack on its network that disrupted some business aspects.
“On February 11, 2024, McKim & Creed discovered suspicious activity on certain computer systems, resulting in the disruption of certain business functions,” the company said in an advisory last week. “McKim & Creed immediately responded and launched an investigation with outside cybersecurity specialists to confirm the nature and scope of the incident and restore impacted computer systems to full, secure operability.
“Through the investigation, McKim & Creed learned that an unauthorized actor accessed its systems and may have viewed or acquired business data containing certain employee information between December 15, 2023 to February 11, 2024. McKim & Creed conducted a review of the data that was potentially viewed or acquired to determine whether it contained any sensitive information.
“While the review was ongoing, McKim & Creed notified certain impacted individuals of the incident on February 28, 2024. On May 3, 2024, McKim & Creed determined what personal information related to employees and dependents was included in the potentially impacted data set. After determining the scope of information in the potentially impacted files, McKim & Creed undertook efforts to locate address information for the affected individuals, put resources in place to assist, and provide direct notice.”

read more