alphv attacks ThreeSixty Sourcing

Incident Date: Feb 18, 2022

Attack Overview
VICTIM
ThreeSixty Sourcing
INDUSTRY
Retail
LOCATION
China
ATTACKER
Alphv
FIRST REPORTED
February 18, 2022

ThreeSixty Sourcing Ransomware Attack

ThreeSixty Sourcing, a global organization behind renowned brands such as Sharper Image, FAO Schwarz, and Vornado, has recently fallen victim to a ransomware attack orchestrated by the group Alphv. This incident was disclosed on a dark web leak site, highlighting the ongoing vulnerability of prominent entities in the retail sector to sophisticated cyber threats.

With a vast operational footprint, ThreeSixty Sourcing's influence spans over 30 countries, boasting more than 75,000 global offices. The company's portfolio, known for its high-quality offerings in everyday play, technology, health and wellness, and premium home comfort, underscores the significant impact of this security breach.

The attack on ThreeSixty Sourcing reflects a growing trend where ransomware syndicates increasingly target the manufacturing sector. Notably, subsectors such as metal components, automotive, and plastics/technology have emerged as prime targets, with groups like Conti and Lockbit 2.0 accounting for 51% of all ransomware incidents in 2021.

Manufacturers, including ThreeSixty Sourcing, often grapple with cybersecurity challenges that heighten their risk of ransomware attacks. These challenges include limited oversight of operational technology (OT) systems, inadequate network perimeters, exposure due to external connectivity in OT systems, and the problematic practice of using shared credentials.

The attack methodology employed against ThreeSixty Sourcing likely encompasses a multi-extortion strategy. This approach not only involves the encryption of data but also data exfiltration, service disruption, and direct ransom demands to third-party associates, amplifying the attack's impact.

To mitigate the threat of ransomware, it is imperative for manufacturers to enhance the security posture of both their IT and OT environments. Developing and implementing a comprehensive ransomware incident response plan is crucial in safeguarding against such cyber threats, ensuring operational resilience and security assurance for stakeholders.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.