RansomHub Ransomware Hits Golfoy India: Key Details and Impact
RansomHub Ransomware Attack on Golfoy India: A Detailed Analysis
Golfoy India, a prominent online retailer of golf equipment and accessories, has recently fallen victim to a ransomware attack orchestrated by the notorious group RansomHub. This attack has significant implications for the company's operations and data security.
About Golfoy India
Founded in 2020, Golfoy India has quickly established itself as a leading online retailer in the golf industry. The company offers a wide range of golf clubs, balls, apparel, shoes, bags, and other gear from top brands. Headquartered in New Delhi, Golfoy is known for its exceptional customer service and seamless shopping experience. The company's website, Golfoy, is user-friendly and caters to both professional and amateur golfers.
Attack Overview
RansomHub, a ransomware group believed to have roots in Russia, has claimed responsibility for the attack on Golfoy India. The attackers infiltrated Golfoy's systems, gaining access to all files and webmails. They encrypted and exfiltrated sensitive information from the company's servers. RansomHub is demanding a ransom payment, threatening to publicly leak private documents, databases, webmails, and source code if their demands are not met. This breach poses a significant risk to Golfoy's operations and data security.
About RansomHub
RansomHub is a relatively new player in the ransomware landscape, distinguishing itself by making claims and backing them up with data leaks. Operating as a Ransomware-as-a-Service (RaaS) group, RansomHub's affiliates receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, without following a specific pattern. Their ransomware strains are written in Golang, a language choice that is becoming increasingly popular among ransomware developers.
Potential Vulnerabilities
Golfoy India's rapid growth and strong online presence may have made it an attractive target for threat actors like RansomHub. The company's reliance on digital infrastructure for its operations and customer interactions could have exposed vulnerabilities that the attackers exploited. The use of advanced ransomware strains written in Golang suggests that RansomHub is leveraging cutting-edge techniques to penetrate and compromise systems.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!