LockBit 3.0 Ransomware Attack on Ajuntament de Calvià Mallorca

Incident Date: May 09, 2024

Attack Overview
VICTIM
Ajuntament de Calvia Mallorca
INDUSTRY
Hospitality
LOCATION
Spain
ATTACKER
Lockbit
FIRST REPORTED
May 9, 2024

Ransomware Attack on Ajuntament de Calvià Mallorca by LockBit 3.0

Victim Profile

The Ajuntament de Calvià, Marrorca, also known as the Calvia Town Hall, is a local government administration. They operate in the Government sector, aiming to provide information about tourist attractions, events, accommodations, and services in the Calvià area.

Their website stands out for its comprehensive website that offers visitors the opportunity to plan their trip to Calvià and explore the offerings of the area. The town hall aims to promote tourism and provide valuable information to tourists and locals alike.

Attack Details

The cyber attack on Ajuntament de Calvià Mallorca was orchestrated by LockBit 3.0, using ransomware to target the company's website. The attack likely involved encrypting files, modifying filenames, changing desktop wallpapers, and dropping ransom notes on the victim's desktop.

Vulnerabilities

Being in the Hospitality sector, Ajuntament de Calvià Mallorca may have been targeted by threat actors due to the sensitive nature of the information they handle, including visitor data and potentially financial transactions. Additionally, the company's website may have vulnerabilities that could be exploited by cybercriminals to gain unauthorized access to their systems.

Ransomware Group: LockBit 3.0

LockBit 3.0, also known as LockBit Black, is a Ransomware-as-a-Service (RaaS) group that has been actively recruiting affiliates and targeting businesses and critical infrastructure organizations. The group distinguishes itself by its advanced encryption capabilities, obfuscation techniques, and the ability to move laterally through networks to cover its tracks.

LockBit May Attacks

This ransomware attack on Ajuntament de Calvià Mallorca is part of the May 2024 attacks by LockBit 3.0. Following the disruption of its infrastructure during "Operation Cronos," LockBit swiftly resurfaced and targeted over 50 victims within hours of reactivating its platform. The group's adaptability and global reach highlight the challenges faced by law enforcement agencies in combating cybercrime effectively. LockBit's resurgence underscores the need for enhanced international cooperation and proactive measures to address evolving threats in the cybersecurity landscape.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.