Edizioni Dottrinari Targeted by Funksec Ransomware Attack

Incident Date: Dec 05, 2024

Attack Overview
VICTIM
Edizioni Dottrinari
INDUSTRY
Education
LOCATION
Italy
ATTACKER
Funksec
FIRST REPORTED
December 5, 2024

Ransomware Attack on Edizioni Dottrinari: A Closer Look at Funksec's Latest Breach

Edizioni Dottrinari, a well-established publishing house in Salerno, Italy, has recently fallen victim to a ransomware attack allegedly orchestrated by the cybercrime group Funksec. This incident highlights the vulnerabilities faced by small to medium-sized enterprises (SMEs) in the education sector, particularly those with a significant online presence.

About Edizioni Dottrinari

Founded in 1964, Edizioni Dottrinari is a prominent publishing house dedicated to catechesis and pastoral care. The company specializes in religious texts and educational materials, serving a niche market within the Catholic community. With an employee count ranging from 10 to 50, Edizioni Dottrinari is classified as an SME, generating estimated annual revenues between €1 million and €5 million. Its commitment to quality and specialized offerings has established a loyal customer base and a strong reputation in its field.

Attack Overview

The ransomware attack on Edizioni Dottrinari involved the exfiltration and encryption of sensitive data, including user identification information, Gmail messages, and phone numbers. Funksec, the group behind the attack, allegedly released the compromised database online, making it available for free download. This breach underscores the susceptibility of online retail platforms to cyber threats, particularly those handling sensitive customer information.

Funksec: A Rising Threat

Funksec is an emerging ransomware group first observed in December 2024. Known for its double extortion tactics, the group combines data exfiltration with encryption to pressure victims. Funksec operates a Tor-based data-leak site, where it hosts breach announcements and offers a free DDoS tool. The group's activities suggest potential operations as a data broker, diversifying its extortion methods and raising its profile in the cybercrime landscape.

Potential Vulnerabilities

Edizioni Dottrinari's vulnerabilities may stem from its reliance on online platforms for book sales and customer interactions. As a smaller enterprise, it may lack the cybersecurity infrastructure necessary to fend off sophisticated attacks. Funksec could have exploited these weaknesses through phishing, exploiting unpatched software, or leveraging weak access controls to penetrate the company's systems.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.