Funksec Targets Aquamaná ESP in Major Ransomware Breach

Incident Date: Jan 17, 2025

Attack Overview
VICTIM
Aquamaná ESP
INDUSTRY
Energy, Utilities & Waste
LOCATION
Colombia
ATTACKER
Funksec
FIRST REPORTED
January 17, 2025

Ransomware Attack on Aquamaná ESP: A Closer Look at Funksec's Latest Target

The ransomware group Funksec has recently claimed responsibility for a cyberattack on Aquamaná ESP, a municipal public utility company based in Villamaría, Caldas, Colombia. This incident, discovered on January 20, 2025, underscores the vulnerabilities faced by public service entities in the digital age.

About Aquamaná ESP

Aquamaná ESP is a key player in the Energy, Utilities & Waste sector, providing essential services such as water supply, sewage management, and waste disposal to the local community. Established in 1996, the company has a mission to ensure quality, continuity, and coverage of public services while preserving natural resources. With a proactive approach to environmental challenges, Aquamaná ESP stands out for its commitment to technological innovation and sustainable financial efficiency. Despite its significant role, the company’s digital infrastructure appears to have been vulnerable to cyber threats, as evidenced by the recent breach.

Details of the Attack

The attack on Aquamaná ESP involved the defacement of its website and potential data exfiltration, although the full extent of the data leak remains unspecified. Funksec, known for its double extortion tactics, likely used a combination of data encryption and exfiltration to pressure the company. This incident highlights the critical need for enhanced cybersecurity measures in public utility companies, which are increasingly becoming targets for cybercriminals.

Funksec: An Emerging Threat

Funksec is a relatively new ransomware group that emerged in late 2024. It distinguishes itself through a combination of technical sophistication and political motivations, often targeting organizations across various sectors, including media, IT, and public services. The group employs a double extortion strategy, encrypting files and threatening to leak exfiltrated data. Funksec's operations are facilitated through a Tor-based data-leak site, where they also offer free DDoS tools, indicating a broader attack capability.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.