Medusa Ransomware Strikes BELL DATA in Major Cyberattack

Incident Date: Sep 30, 2024

Attack Overview
VICTIM
BELL DATA, Inc
INDUSTRY
Software
LOCATION
Japan
ATTACKER
Medusa
FIRST REPORTED
September 30, 2024

Medusa Ransomware Group Targets BELL DATA, Inc.

The Medusa ransomware group has claimed responsibility for a significant cyberattack on BELL DATA, Inc., a Japanese company known for its IT infrastructure solutions. This attack underscores the growing threat of ransomware groups targeting critical sectors worldwide.

About BELL DATA, Inc.

BELL DATA, Inc. is a medium-sized enterprise with 271 employees, including 139 engineers, and reported a turnover of approximately $72 million USD as of September 2023. Established in 1991, the company specializes in providing IT infrastructure solutions, including hardware and software sales, data center services, and cloud outsourcing. Their Power-Cloud service for AS/400 systems is particularly notable. BELL DATA's commitment to high standards is reflected in its numerous certifications, including IBM and Cisco credentials.

Attack Overview

The Medusa ransomware group has listed BELL DATA on its dark web leak site, demanding a ransom of $300,000. The attackers claim to have accessed sensitive company data and have threatened to release it if their demands are not met by October 9. BELL DATA confirmed the breach on September 19, indicating that some systems were compromised. This attack highlights the vulnerabilities that even well-established IT companies face in the current cyber threat landscape.

Medusa Ransomware Group Profile

Emerging in late 2022, Medusa operates as a Ransomware-as-a-Service platform, allowing affiliates to launch attacks using its sophisticated ransomware. The group has been involved in high-profile attacks across various sectors, including education and healthcare. Medusa's ransomware is known for disabling applications and shadow copies, making recovery efforts challenging. Their global reach and aggressive tactics distinguish them from other ransomware groups.

Potential Vulnerabilities

BELL DATA's focus on cloud-based solutions and IT infrastructure makes it a lucrative target for ransomware groups like Medusa. The company's extensive data handling and integration services could have been exploited through vulnerabilities in their network or cloud systems. The attack on BELL DATA serves as a stark reminder of the importance of cybersecurity measures, especially for companies handling sensitive data.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.