lockbit2 attacks Sobotram

Incident Date: Feb 21, 2022

Attack Overview
VICTIM
Sobotram
INDUSTRY
Transportation
LOCATION
France
ATTACKER
Lockbit
FIRST REPORTED
February 21, 2022

Sobotram, a Transportation Company, Suffers a Ransomware Attack by Lockbit2

Company Overview

Sobotram, a French transportation and logistics company, has been targeted by the ransomware group Lockbit2, as announced on the group's dark web leak site. The company, part of the Groupe Blondel since early 2023, specializes in the transport and logistics of general goods and hazardous materials both in France and internationally. With strategic locations at major transportation hubs, Sobotram operates a SEVESO high-risk site in Chalon sur Saône (71).

Industry Vulnerabilities

The transportation sector is frequently targeted by ransomware attacks due to its critical nature and the potential for significant operational disruptions. Such attacks can result in considerable financial losses, operational setbacks, and reputational damage for the companies involved.

Attack Vector

Lockbit2, the group behind this attack, typically exploits unpatched vulnerabilities to infiltrate target networks. The group's strategy includes the use of zero-day vulnerabilities and one-day flaws, enabling them to circumvent traditional security measures. Once inside, they can encrypt or exfiltrate sensitive data for extortion purposes.

Mitigation Strategies

To reduce the risk of ransomware attacks, organizations are advised to promptly patch newly disclosed vulnerabilities and ensure they have robust backup and restoration processes in place. The implementation of multi-factor authentication (MFA) and the promotion of good security practices, such as phishing training and password hygiene among employees, are also crucial in mitigating the risk of social engineering or brute-force attacks.

The ransomware attack on Sobotram by Lockbit2 underscores the persistent threat of ransomware within the transportation sector. It is imperative for companies within this industry to stay vigilant and prioritize cybersecurity measures to safeguard against such attacks.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.