Miller Service Company Faces Ransomware Threat from SafePay

Incident Date: Nov 19, 2024

Attack Overview
VICTIM
Miller Service Company
INDUSTRY
Construction
LOCATION
USA
ATTACKER
SafePay
FIRST REPORTED
November 19, 2024

Ransomware Attack on Miller Service Company by SafePay

On November 21, Miller Service Company, a family-owned HVAC service provider based in Murfreesboro, Tennessee, became the latest victim of a ransomware attack by the cybercriminal group SafePay. This incident highlights the growing threat of ransomware attacks on small to medium-sized enterprises, particularly those in the construction and HVAC sectors.

About Miller Service Company

Miller Service Company specializes in providing comprehensive HVAC services, including air conditioning installation, maintenance, and repair, as well as heating services and ductwork solutions. The company is known for its commitment to energy-efficient solutions, such as Energy Star® rated systems and geothermal heating options. Despite its small size, with around four employees, Miller Service Company has established a reputation for high-quality service and customer satisfaction in the Murfreesboro area.

Details of the Attack

The ransomware attack resulted in the unauthorized access and potential leak of approximately 70GB of sensitive data. While the specifics of the compromised information have not been fully disclosed, the breach could significantly impact the company's operations and its clients. SafePay, known for its double-extortion tactics, has not publicly commented on the incident. Miller Service Company is likely working with cybersecurity experts to assess the damage and mitigate further risks.

SafePay Ransomware Group

SafePay is a relatively new player in the ransomware landscape, utilizing ransomware-as-a-service (RaaS) tactics and LockBit source code. The group employs a double-extortion strategy, encrypting files and threatening to release stolen data if ransom demands are not met. SafePay typically gains access to victim networks through valid credentials, often acquired via VPN gateways, which suggests a stealthy approach to infiltration.

Potential Vulnerabilities

Small businesses like Miller Service Company are often targeted by ransomware groups due to their limited cybersecurity resources. The company's reliance on digital systems for operations and client management may have made it vulnerable to such attacks. The HVAC sector's increasing adoption of smart technologies and IoT devices could also present additional entry points for cybercriminals.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.