RansomHouse Strikes Gantan Beauty Industry

Incident Date: May 17, 2024

Attack Overview
VICTIM
Gantan Beauty Industry
INDUSTRY
Manufacturing
LOCATION
Japan
ATTACKER
Ransomhouse
FIRST REPORTED
May 17, 2024

Ransomware Attack on Gantan Beauty Industry by RansomHouse

Victim Overview

A Japanese company specializing in metal roofing solutions, Gantan Beauty Industry, fell victim to a ransomware attack orchestrated by the cybercriminal group RansomHouse. The company has been a pioneer in the field for over 50 years, known for its innovative technology, commitment to environmental sustainability, and high-quality roofing products.

Company Profile

Gantan Beauty Industry focuses on developing environmentally friendly construction materials, including photovoltaic power generation roofs and natural lighting solutions. They are recognized for their advanced technology in metal roofing and their dedication to creating durable and sustainable roofing solutions.

Attack Overview

The ransomware attack on Gantan Beauty Industry resulted in the exfiltration of 400 GB of data by RansomHouse. The attackers successfully infiltrated the company's systems, although specific details about the ransom demand were not disclosed. A sample of the exfiltrated data was leaked as part of the aftermath of the attack.

Ransomware Group - RansomHouse

RansomHouse is a unique data extortion group that emerged in late 2021. Unlike traditional ransomware groups, RansomHouse focuses on stealing sensitive data from victims and threatening to publicly release it if a ransom is not paid. The group distinguishes itself by not encrypting the stolen data, making the attacks stealthier and potentially allowing for a longer dwell time before detection.

Penetration and Vulnerabilities

The ransomware group likely penetrated Gantan Beauty Industry's systems through vulnerabilities in their cybersecurity defenses. The company's high-profile status in the manufacturing sector and their valuable data on roofing solutions and patents made them an attractive target for threat actors. The lack of robust security measures may have facilitated the successful exfiltration of a significant amount of data by RansomHouse.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.