LockBit 3.0 Ransomware Attack on Alian Plastics SA
Ransomware Attack on Alian Plastics SA by LockBit 3.0
Victim Company Profile
Alian Plastics SA, based in Monterrey, Mexico, is a private entity with over 25 years of experience in providing comprehensive solutions globally through plastic injection molding and secondary operations. They are well-equipped to supply plastic components and assembly needs. Alian Plastics SA is part of Al Kathiri Holding Company, which is involved in managing subsidiaries, owning industrial property rights, and increasing its capital over the years. The CEO of Al Kathiri Holding Company is Meshal Mohammed Nasser Al Kathiri, who holds a Bachelor's degree in Marine and Military Sciences.
Ransomware Attack Details
Alian Plastics fell victim to a cyberattack perpetrated by the LockBit 3.0 ransomware group. The attackers employed ransomware techniques to compromise Alian's systems, resulting in the exfiltration of 166 GB of sensitive data, including invoices, banking, financial data, and more. While the specific ransom demand was not disclosed, the attackers leaked a sample of the exfiltrated data.
LockBit 3.0 Ransomware Group
The LockBit 3.0 ransomware group is an evolution of the LockBit group, known for its Ransomware-as-a-Service (RaaS) model. LockBit 3.0, also known as LockBit Black, is considered one of the most dangerous and disruptive ransomware threats currently active. It encrypts files, modifies their filenames, changes the desktop wallpaper, and drops a ransom note on the victim's desktop. The ransomware is heavily obfuscated and protected against analysis, making it difficult for security researchers to study.
LockBit May Attacks
In May 2024, Alian Plastics fell victim to a cyberattack orchestrated by the LockBit 3.0 ransomware group. Utilizing sophisticated ransomware tactics, the attackers breached the company's systems, compromising 166 GB of crucial data encompassing invoices, banking details, and financial records. Though the specific ransom demand remained undisclosed, the attackers issued a warning by releasing a portion of the pilfered information.
Sources:
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!