DezineCorp Hit by BlackSuit Ransomware Attack

Incident Date: Nov 11, 2024

Attack Overview
VICTIM
DezineCorp
INDUSTRY
Manufacturing
LOCATION
Canada
ATTACKER
Black Suit
FIRST REPORTED
November 11, 2024

Ransomware Attack on DezineCorp by BlackSuit Group

On November 12, DezineCorp, a Canadian company specializing in promotional products, became the latest victim of a ransomware attack by the BlackSuit group. Based in Mississauga, Ontario, DezineCorp is a family-owned business known for its high-quality corporate gifts and promotional merchandise. Founded by Paul Bami, the company has been operational since 1991 and is recognized for its commitment to community and diversity, being a member of the Canadian Aboriginal and Minority Supplier Council.

DezineCorp stands out in the manufacturing sector by offering over 2,000 items, including premium brands like Stanley and Riedel. Their in-house production capabilities, such as engraving and printing, ensure quality control and quick delivery. Despite its small size, with approximately nine employees, the company has an estimated revenue of $6.2 million, highlighting its significant impact in the industry.

The BlackSuit ransomware group, known for its double extortion tactics, claimed responsibility for the attack. This group emerged in 2023 and has been linked to the Royal ransomware syndicate. BlackSuit typically gains access through phishing emails, compromised RDP credentials, or exploiting vulnerable applications. Once inside, they escalate privileges, exfiltrate data, and deploy ransomware, encrypting files and demanding a ransom for decryption.

Details about the DezineCorp attack remain sparse, with the extent of the data breach and the method of infiltration undisclosed. However, the attack underscores the vulnerabilities faced by small to medium-sized enterprises in the manufacturing sector. DezineCorp's reliance on digital systems for production and client management may have made it an attractive target for BlackSuit, which has a history of targeting industries with valuable data.

BlackSuit distinguishes itself by its rapid encryption process and the use of both Windows and Linux payloads. The group often disables system recovery options to hinder victim recovery efforts. The attack on DezineCorp highlights the ongoing threat posed by ransomware groups and the need for effective cybersecurity measures, especially for companies with significant digital operations.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.