conti attacks NORDEX FOOD

Incident Date: Mar 18, 2022

Attack Overview
VICTIM
NORDEX FOOD
INDUSTRY
Manufacturing
LOCATION
Denmark
ATTACKER
Conti
FIRST REPORTED
March 18, 2022

Conti Ransomware Attacks Nordex Food

The Conti ransomware group has claimed responsibility for an attack on Nordex Food, a Danish company specializing in white cheese production. Nordex Food operates in the manufacturing sector and has a significant presence in Europe, with production facilities in Denmark, Austria, and Romania. The company has an omsætning (revenue) of 2.7 billion krone (approximately 350 million euros).

Nordex Food is known for its egenproduktion (own production), which allows the company to cater to unique customer needs and preferences. The company's products include salatost, madlavningsost, grillost, Feta, and Halloumi, as well as a range of other cheese and dairy products. Nordex Food's distribution network covers the detail, foodservice, and industri segments, and the company has a global reach, serving customers in over 70 countries.

The Conti ransomware attack on Nordex Food was not the first time the company has faced such an incident. In 2022, another wind turbine manufacturer, Vestas, suffered a ransomware attack by the LockBit group.

Understanding Conti Ransomware

Conti ransomware is a private Ransomware-as-a-Service (RaaS) operation believed to be controlled by a Russian-based cybercrime group tracked as Wizard Spider. The group often gains initial access to networks through spearphishing campaigns, malicious attachments, stolen or weak Remote Desktop Protocol (RDP) credentials, fake software, and common vulnerabilities in external assets.

To mitigate the risk of ransomware attacks, organizations should implement multi-factor authentication, network segmentation, vulnerability scanning, endpoint detection and response tools, and limit access to resources over the network, especially by restricting RDP.

Nordex Food has not disclosed the extent of the damage caused by the Conti ransomware attack or whether any data was stolen during the incident. The company has not yet responded to requests for comment on the attack.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.