LockBit 3.0 Ransomware Attack on Hotel Ostella
Ransomware Attack on Hotel Ostella by LockBit 3.0
Victim Profile
Hotel Ostella, a 4-star luxury hotel located in Bastia, Corsica Island, France, became a target of the cybercrime group LockBit 3.0. The hotel celebrated its 50th anniversary in 2019 and offers 50 comfortable rooms, two luxury suites, a 450m² wellness center, a restaurant serving modern cuisine, a lounge bar area, and a terrace for dining.
With 52 guest rooms, 3 meeting rooms, and a total event space of 120 sq m, Hotel Ostella caters to both leisure and business travelers. Its year-round availability and commitment to providing a relaxing stay on the Isle of Beauty have made it a standout in the hospitality industry.
Attack Details
LockBit 3.0 targeted Hotel Ostella with ransomware, exfiltrating 88 GB of sensitive data, including marketing data, financial documents, PII, and more. The attack highlighted vulnerabilities in the hotel's cybersecurity defenses, potentially stemming from inadequate security measures or lack of employee training.
Ransomware Group Profile
LockBit 3.0, also known as LockBit Black, distinguishes itself as a highly dangerous ransomware variant with advanced encryption capabilities and obfuscation techniques. The cybercriminal likely penetrated Hotel Ostella's systems through phishing emails, unpatched software vulnerabilities, or weak remote desktop protocol (RDP) configurations. The ransomware's ability to move laterally through networks and cover its tracks poses significant challenges for cybersecurity professionals.
LockBit May Attacks
This ransomware attack on Hotel Ostella is part of the May 2024 attacks by LockBit 3.0. Following the disruption of its infrastructure in February during "Operation Cronos," LockBit swiftly resurfaced and targeted over 50 victims within hours of reactivating its platform. The group's adaptability and global reach highlight the challenges faced by law enforcement in combating cybercrime effectively. LockBit's resurgence emphasizes the need for proactive measures, collaborative intelligence sharing, and enhanced international cooperation to counter such syndicates and safeguard digital ecosystems against evolving threats.
Sources:
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!