Attack Overview
VICTIM
Uppco
INDUSTRY
Energy, Utilities & Waste
LOCATION
USA
ATTACKER
Lorenz
FIRST REPORTED
July 11, 2022

UPPCO Ransomware Attack by Lorenz Group

Company Overview

Upper Peninsula Power Company (UPPCO), a Michigan-based energy utility company, has been targeted by the Lorenz ransomware group, as announced on the group's dark web leak site. The company operates in the Energy, Utilities & Waste sector and has been affected by the attack, which has been linked to the exploitation of a vulnerability in Mitel's VoIP systems.

UPPCO is a utility company that provides electricity to customers in the Upper Peninsula of Michigan. The company's website features news updates and information about energy usage and conservation. UPPCO is part of the energy sector, which is a critical infrastructure industry that is often targeted by threat actors due to the potential for widespread disruption and financial gain.

Vulnerabilities and Targeting

The Lorenz ransomware group has been observed exploiting a vulnerability in Mitel's VoIP systems, specifically CVE-2022-29499, to gain initial access to targeted networks. This vulnerability allows an attacker to execute arbitrary code on the affected system, potentially leading to a ransomware attack. The group is known for using a double-extortion model, where they steal data before encrypting victims' devices, holding both the data and systems to ransom.

Mitigation Strategies

To mitigate the risk of ransomware attacks, organizations should implement a multi-layered security approach that includes regular software updates, employee training, and network segmentation. Additionally, monitoring all externally facing devices, including VoIP and IoT devices, can help detect and prevent unauthorized access.

The ransomware attack on UPPCO by the Lorenz group highlights the importance of maintaining a robust cybersecurity posture, particularly in critical infrastructure sectors. By implementing best practices and staying informed about emerging threats, organizations can reduce their risk of falling victim to ransomware attacks.

Sources

  • UPPCO Homepage
  • An In-Depth Look at Lorenz Ransomware - URL not available
  • Arctic Wolf Labs Assesses Lorenz Ransomware Group - URL not available
  • Ransomware Tracker 2024 - URL not available
  • Lorenz Ransomware Group Leaks Details - URL not available
  • The State of Ransomware in 2022 - BlackFog

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.