blackbasta attacks Willemen Group

Incident Date: Oct 05, 2022

Attack Overview
VICTIM
Willemen Group
INDUSTRY
Construction
LOCATION
Netherlands
ATTACKER
Blackbasta
FIRST REPORTED
October 5, 2022

Willemen Group Suffers Ransomware Attack

Company Overview

Willemen Group is a construction sector company that emphasizes quality, innovation, and sustainability. The company brings together various competencies and knowledge in enthusiastic teams to shape the future of construction projects. They are committed to digitization and sustainability, aligning with the United Nations Sustainable Development Goals and preparing for the European Green Deal. The company employs 2,100 people and has a strong focus on safety, with a goal of ensuring that everyone, including employees, subcontractors, suppliers, and partners, returns home safely every day.

Vulnerabilities and Attack Vectors

Ransomware attacks typically exploit vulnerabilities in software, use brute-force credential attacks, employ social engineering tactics, leverage previously compromised credentials, or abuse trust opportunities. The 2022 Unit 42 Incident Response Report identified that 48% of ransomware cases began with software vulnerabilities, and 32% of ransomware attacks experienced by survey respondents in the past year started with an exploited vulnerability.

In the case of Willemen Group, the attack vector is not explicitly stated. However, it is mentioned that the attackers are using multiextortion techniques, which can include copying and exfiltrating unencrypted data, shaming the victim on social media, threatening additional attacks like DDoS, or leaking the stolen information to clients or on the dark web.

Industry Vulnerabilities

The construction sector is known for its use of older technologies that are more prone to security gaps, and patches may not be available for legacy and end-of-life solutions. Additionally, the larger the environment, the greater the challenge in understanding the attack surface and maintaining the necessary tools and technologies.

Mitigation Strategies

To mitigate ransomware attacks, organizations should focus on understanding the attack vectors used by threat actors and implementing platforms for EDR, SOAR, and active ASM to reduce the risk of infection. Good security practices, such as phishing training and password hygiene among employees, can also help reduce the likelihood of social engineering or brute-force attacks. Streamlined offboarding for ex-employees can prevent insider attacks.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.