RansomHub Ransomware Hits Allium Interiors: Key Details & Impact

Incident Date: Aug 11, 2024

Attack Overview
VICTIM
Allium Interiors
INDUSTRY
Retail
LOCATION
New Zealand
ATTACKER
Ransomhub
FIRST REPORTED
August 11, 2024

RansomHub Ransomware Attack on Allium Interiors: A Detailed Analysis

Allium Interiors, a prominent interior design and home decor company based in Auckland, New Zealand, has recently fallen victim to a ransomware attack orchestrated by the cybercriminal group RansomHub. The attack, which was announced on August 9, has put the company in a precarious position, with significant operational and reputational risks.

Overview of Allium Interiors

Established in 2000, Allium Interiors operates both a physical store in Newmarket and an online platform. The company specializes in sourcing unique and high-quality furnishings, fabrics, wallpapers, bed linen, furniture, and home accessories from Europe, America, Australia, and New Zealand. Co-founded by Suzanne Barber and Jo Burrell, Allium Interiors is known for its innovative and inspiring design solutions, making it a standout in the interior design industry.

Details of the Ransomware Attack

RansomHub claimed responsibility for the attack via their dark web leak site, stating that they had successfully infiltrated Allium Interiors' systems. The cybercriminals exfiltrated and encrypted 31 gigabytes of data, including sensitive documents, databases, webmails, and source code. They have threatened to leak this information if a ransom is not paid within eight days. The specific ransom amount remains undisclosed, and no sample data has been released to substantiate their claims.

About RansomHub

RansomHub is a relatively new player in the ransomware landscape, believed to have roots in Russia. Operating as a Ransomware-as-a-Service (RaaS) group, RansomHub's affiliates receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, without following a specific pattern. Their ransomware strains are written in Golang, a language choice that is becoming increasingly popular among ransomware developers.

Potential Vulnerabilities and Penetration Methods

While the exact method of penetration remains unclear, common vulnerabilities that could have been exploited include outdated software, weak passwords, and lack of employee training on phishing attacks. Given RansomHub's use of Golang, it is possible that they leveraged sophisticated techniques to bypass traditional security measures. The attack on Allium Interiors highlights the importance of vigilant cybersecurity practices, especially for companies handling sensitive customer data and operating online platforms.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.