Edizioni Dottrinari Targeted by Funksec Ransomware Attack
Ransomware Attack on Edizioni Dottrinari: A Closer Look at Funksec's Latest Breach
Edizioni Dottrinari, a well-established publishing house in Salerno, Italy, has recently fallen victim to a ransomware attack allegedly orchestrated by the cybercrime group Funksec. This incident highlights the vulnerabilities faced by small to medium-sized enterprises (SMEs) in the education sector, particularly those with a significant online presence.
About Edizioni Dottrinari
Founded in 1964, Edizioni Dottrinari is a prominent publishing house dedicated to catechesis and pastoral care. The company specializes in religious texts and educational materials, serving a niche market within the Catholic community. With an employee count ranging from 10 to 50, Edizioni Dottrinari is classified as an SME, generating estimated annual revenues between €1 million and €5 million. Its commitment to quality and specialized offerings has established a loyal customer base and a strong reputation in its field.
Attack Overview
The ransomware attack on Edizioni Dottrinari involved the exfiltration and encryption of sensitive data, including user identification information, Gmail messages, and phone numbers. Funksec, the group behind the attack, allegedly released the compromised database online, making it available for free download. This breach underscores the susceptibility of online retail platforms to cyber threats, particularly those handling sensitive customer information.
Funksec: A Rising Threat
Funksec is an emerging ransomware group first observed in December 2024. Known for its double extortion tactics, the group combines data exfiltration with encryption to pressure victims. Funksec operates a Tor-based data-leak site, where it hosts breach announcements and offers a free DDoS tool. The group's activities suggest potential operations as a data broker, diversifying its extortion methods and raising its profile in the cybercrime landscape.
Potential Vulnerabilities
Edizioni Dottrinari's vulnerabilities may stem from its reliance on online platforms for book sales and customer interactions. As a smaller enterprise, it may lack the cybersecurity infrastructure necessary to fend off sophisticated attacks. Funksec could have exploited these weaknesses through phishing, exploiting unpatched software, or leveraging weak access controls to penetrate the company's systems.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!