Jonti-Craft Faces Major Data Breach by Black Basta

Incident Date: Nov 19, 2024

Attack Overview
VICTIM
Jonti-Craft Inc.
INDUSTRY
Manufacturing
LOCATION
USA
ATTACKER
Blackbasta
FIRST REPORTED
November 19, 2024

Ransomware Attack on Jonti-Craft: A Detailed Analysis

Jonti-Craft Inc., a leading manufacturer of children's furniture based in Wabasso, Minnesota, has recently been targeted by the ransomware group Black Basta. This attack has compromised approximately 700GB of sensitive data, including financial, personal, and engineering information. The breach highlights the vulnerabilities faced by companies in the manufacturing sector, particularly those with significant operational dependencies and data protection requirements.

Company Profile: Jonti-Craft Inc.

Established in 1979, Jonti-Craft is a family-owned business renowned for its high-quality, durable furniture designed for educational and childcare environments. With a workforce of approximately 76 employees, the company generates an estimated revenue of $71 million. Jonti-Craft's commitment to sustainable design and craftsmanship has made it a trusted name among educators and caregivers. Their extensive product catalog, exceeding 4,000 items, caters to preschools, daycare centers, and other child-centric spaces, emphasizing safety and environmental responsibility.

Attack Overview

The ransomware attack on Jonti-Craft involved the encryption and exfiltration of critical data, leveraging Black Basta's sophisticated techniques. The compromised data spans various domains, including payroll, human resources, and departmental information. This breach underscores the challenges faced by manufacturing companies in safeguarding their digital assets against increasingly sophisticated cyber threats.

Black Basta Ransomware Group

Emerging in April 2022, Black Basta operates as a Ransomware-as-a-Service (RaaS) provider, employing double extortion tactics. The group is known for its closed affiliate model, where affiliates execute attacks while core members manage infrastructure and ransom negotiations. The group's ability to bypass conventional defenses and maintain persistent access highlights the need for comprehensive cybersecurity measures. Jonti-Craft's reliance on digital infrastructure for operational efficiency may have inadvertently exposed them to such targeted attacks.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.