conti attacks TIG

Incident Date: Mar 18, 2022

Attack Overview
VICTIM
TIG
INDUSTRY
Manufacturing
LOCATION
USA
ATTACKER
Conti
FIRST REPORTED
March 18, 2022

Gesswein Manufacturing Company Suffers Ransomware Attack

Gesswein, a family-owned and operated company in the manufacturing sector, has been targeted by the ransomware group Conti. The attack was announced on the group's dark web leak site. The company, which has been in operation for over 100 years, specializes in mold polishing and offers a comprehensive product line of over 15,000 innovative tools and equipment.

Company Size and Industry Standout

Gesswein is a mid-sized business with reported revenues of up to $50 million, making it a common target for ransomware attacks. In the manufacturing sector, the company stands out for its extensive product line and long-standing industry expertise.

Vulnerabilities and Attack Vectors

The attack on Gesswein highlights the importance of addressing vulnerabilities in software and applications used by the business. According to a 2022 Unit 42 Incident Response Report, 48% of ransomware cases began with software vulnerabilities. In 2023, threat actors increasingly exploited unknown and day-one vulnerabilities in their attacks, with some ransomware operators focusing solely on stealing sensitive data and extorting victims by threatening to sell or leak the data.

The attack on Gesswein underscores the need for organizations to prioritize patching of newly disclosed vulnerabilities and to understand the adversary, threat surfaces, techniques used, and the products, processes, and people required to stop a modern ransomware attack.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.