RansomHub Ransomware Attack on ERMA Srl: 350GB of Sensitive Data Stolen

Incident Date: Jul 18, 2024

Attack Overview
VICTIM
ERMA Srl
INDUSTRY
Manufacturing
LOCATION
Italy
ATTACKER
Ransomhub
FIRST REPORTED
July 18, 2024

RansomHub Ransomware Attack on ERMA Srl

Overview of ERMA Srl

ERMA Srl, also known as ERMA-RTMO, is a prominent Italian company specializing in the production, distribution, and sale of aftermarket components and spare parts for earthmoving machines and agricultural equipment. Founded in 1943 by Pio Martini, ERMA has established itself as a leader in the industry. The company offers a wide range of products, including components for major brands such as Caterpillar, Komatsu, Liebherr, and Volvo. ERMA's extensive catalog and well-equipped workshop enable it to provide high-quality original spare parts and alternative options, catering to diverse customer needs.

Details of the Ransomware Attack

On July 19, 2024, ERMA Srl fell victim to a ransomware attack orchestrated by the cybercriminal group RansomHub. The attack resulted in a significant data breach, with 350GB of sensitive information being exfiltrated. RansomHub claims to have been embedded within ERMA's network for an extended period, meticulously studying the company's operations. The group has threatened to notify ERMA's customers about the data leak and publicly release the stolen information if their demands are not met, potentially causing severe reputational and financial damage.

About RansomHub

RansomHub is a relatively new ransomware group that has recently emerged in the cyber threat landscape. Believed to have roots in Russia, RansomHub operates as a Ransomware-as-a-Service (RaaS) group, with affiliates receiving 90% of the ransom money and the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, without following a specific pattern. RansomHub's ransomware strains are written in Golang, a language choice that may indicate future trends in ransomware development.

Penetration and Vulnerabilities

RansomHub's ability to penetrate ERMA's systems likely involved exploiting vulnerabilities within the company's network. The group's meticulous study of ERMA's operations suggests a sophisticated approach, possibly involving phishing attacks, exploiting software vulnerabilities, or leveraging weak security protocols. The extended period of undetected presence within the network indicates a high level of stealth and expertise in avoiding detection by traditional security measures.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.