LockBit3 Ransomware Attack on B&S Group Limited

Incident Date: May 27, 2024

Attack Overview
VICTIM
B&S Group Limited
INDUSTRY
Healthcare Services
LOCATION
United Kingdom
ATTACKER
Lockbit
FIRST REPORTED
May 27, 2024

Ransomware Attack on B&S Group Limited by LockBit3

Company Overview

B&S Group Limited, operating in the Healthcare Services sector, is one of the largest short-line pharmaceutical distributors in the UK. They serve over 5,000 customers daily, providing a comprehensive range of pharmaceutical products and exceptional services to community pharmacies throughout the country. The company is dedicated to quality, safety, and regulatory compliance, with state-of-the-art warehousing facilities and a knowledgeable team supporting their operations.

Company Standout

B&S Group distinguishes itself in the industry through its commitment to customer satisfaction, quality, and sustainability. They offer a diverse range of products and services, including healthcare products, unlicensed medicines, and consumer health products. The company has received certifications such as ISO 9001 and collaborates with organizations promoting responsible practices.

Company Vulnerabilities

Despite its strong reputation and commitment to quality, B&S Group's expansive network and strategic alliances may have made it a target for threat actors like the LockBit3 ransomware group. The company's large customer base and critical role in the healthcare supply chain could have attracted cybercriminals seeking to disrupt operations and extort ransom payments.

Attack Overview

B&S Group Limited fell victim to a ransomware attack by the LockBit3 group. The attackers successfully penetrated the company's systems, leading to the exposure of sample data. The ransomware group, known for its advanced capabilities and evasive tactics, encrypted files, modified filenames, and dropped a ransom note on the victim's desktop.

Ransomware Group Details

The LockBit3 ransomware group, an evolution of the LockBit group, operates under a Ransomware-as-a-Service (RaaS) model. LockBit3, also known as LockBit Black, is considered one of the most dangerous and disruptive ransomware threats currently active. The group actively recruits affiliates and targets a wide range of businesses and critical infrastructure organizations globally.

How the Attack Occurred

LockBit3's advanced features, including the ability to move laterally through a network and cover its tracks, likely enabled the ransomware group to infiltrate B&S Group's systems. The heavily obfuscated nature of LockBit3 makes it challenging for security researchers to analyze and defend against, allowing the group to persist in its malicious activities and target high-profile organizations like B&S Group.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.