Attack Overview
VICTIM
Incegroup LLC
INDUSTRY
Energy, Utilities & Waste
LOCATION
Saint Vincent and the Grenadines
ATTACKER
Lockbit
FIRST REPORTED
May 9, 2024

Ransomware Attack on INCEGROUP by LockBit 3.0

Victim Profile

INCEGROUP LLC, based in Saint Vincent and the Grenadines, is a leading engineering and database solutions company operating in the Caribbean. They specialize in generator installation, solar renewable energy, electrical design and installation, and database consultancy. The company also offers services for automating work lines to increase production efficiency and provides maintenance contracts for generators. With a professional staff of 200-500 and a commitment to innovation, it focuses on client satisfaction and adapting to market demands.

Vulnerabilities and Targeting

The company's involvement in critical infrastructure projects and their use of advanced technologies make them an attractive target for threat actors like the LockBit 3.0 ransomware group. The company's wide range of services and client base could have made them vulnerable to a ransomware attack, as cybercriminals seek to exploit weaknesses in their systems for financial gain.

Attack Details

The ransomware attack on INCEGROUP by LockBit 3.0 involved a demand for ransom with a deadline of May 23rd. Specific details about the ransom demand, exfiltrated data, and leaked data were not provided, but the urgency of the deadline indicates potential consequences for non-compliance.

LockBit 3.0 is considered one of the most dangerous ransomware threats due to its advanced features and capabilities, including lateral movement through networks and data deletion to cover tracks.

LockBit May Attacks

This is part of the May 2024 attacks by LockBit 3.0, a cybercriminal group that resurfaced with vigor following the disruption of its infrastructure during "Operation Cronos," a collaborative effort by international law enforcement agencies. Despite arrests and the dismantling of its data leak site, LockBit swiftly returned, targeting over 50 victims within hours of reactivating its platform. LockBit's recent activities targeted diverse industries globally, with manufacturing companies, professional services, and the ICT sector being the most affected.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.