cuba attacks STM

Incident Date: Jul 07, 2022

Attack Overview
VICTIM
STM
INDUSTRY
Organizations
LOCATION
Taiwan
ATTACKER
Cuba
FIRST REPORTED
July 7, 2022

STM Ransomware Attack: A Cybersecurity Perspective

Company Overview

STM, also known as 信盛精工股份有限公司, is a Taiwanese company that has been in operation for over 50 years. They are known for their commitment to active research and development in connectors, materials, products, and molds, as well as their one-stop service that caters to diverse customer needs and high-quality requirements. In the past two decades, STM has imported advanced automatic connector assembly technology and equipment from advanced countries, ensuring their quality and control meet international standards. They have a significant presence in the technology, information, and electronics industries, leading the way in the supply chain of these sectors.

Attack Details

The ransomware attack on STM was carried out using a highly sophisticated variant of the RansomExx computer virus, which included a high level of automation. The attack affected 600 out of a total of 1,600 critical servers, and the STM was able to isolate its systems within four hours and restore the affected servers. The investigation revealed that the attack did not affect bus and métro service at any time.

Vulnerabilities and Mitigation

The STM's investigation showed that the attack was made through the desktop or trash can on certain equipments. This suggests that the company may have had insufficient endpoint security measures in place, allowing the ransomware to enter through these entry points. Additionally, the attack resulted in the exfiltration of some low sensitivity personal information from 24 of their 11,000 employees and 72 of their 645,000 customers. This highlights the importance of robust data protection measures, particularly in handling sensitive information.

To mitigate the risks of ransomware attacks, companies should invest in advanced endpoint security solutions, regularly update their software and systems, and implement strong data protection policies. Regular employee training on cybersecurity best practices is also crucial in preventing such attacks.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.