Miller Edge Ransomware Breach Exposes 600GB of Sensitive Data

Incident Date: Oct 21, 2024

Attack Overview
VICTIM
Miller Edge
INDUSTRY
Manufacturing
LOCATION
USA
ATTACKER
Blackbasta
FIRST REPORTED
October 21, 2024

Ransomware Attack on Miller Edge: A Detailed Analysis

Miller Edge, a well-established North American manufacturer known for its safety solutions for motorized doors and automated gate systems, has recently fallen victim to a ransomware attack by the notorious Black Basta group. This incident has compromised approximately 600GB of sensitive data, posing significant risks to the company's operations and reputation.

About Miller Edge

Founded in 1936, Miller Edge is a prominent player in the manufacturing sector, specializing in safety devices such as sensing edges, photoelectric sensors, and light curtains. These products are crucial for preventing accidents in high-traffic areas where automated doors operate. The company is recognized for its commitment to safety standards, particularly UL 325, and operates as a privately held family business headquartered in West Grove, Pennsylvania. Despite being a small to medium-sized enterprise, Miller Edge has established itself as a leader in its niche market.

Attack Overview

The ransomware attack orchestrated by Black Basta has compromised a wide range of sensitive data, including personal information of employees, corporate data such as human resources, financial, tax, and payroll records, as well as accounting and engineering data. Customer information and contracts have also been affected. This breach highlights the vulnerabilities that even well-established companies face in the digital age, particularly those with critical data integral to their business functions and customer trust.

About Black Basta

Black Basta is a ransomware group that emerged in early 2022, believed to have connections to the defunct Conti group. Known for its targeted attacks, Black Basta employs a double extortion tactic, encrypting victims' data and threatening to publish it if the ransom is not paid. The group uses sophisticated methods to gain initial access, such as spear-phishing and buying network access, and employs tools like QakBot and Cobalt Strike for lateral movement and command and control.

Potential Vulnerabilities

Miller Edge's reliance on digital systems for managing sensitive data may have made it an attractive target for Black Basta. The group's ability to exploit vulnerabilities and employ advanced tools for data exfiltration and encryption underscores the importance of effective cybersecurity measures. The attack on Miller Edge serves as a stark reminder of the evolving threat landscape and the need for continuous vigilance in protecting critical infrastructure.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.