RansomHub Ransomware Hits Lowe-Martin Group, 2TB Data Stolen
RansomHub Ransomware Attack on Lowe-Martin Group
The Lowe-Martin Group, a prominent Canadian business services company specializing in printing, fulfillment, and e-commerce solutions, has fallen victim to a significant ransomware attack. The attack, claimed by the ransomware group RansomHub, has resulted in the theft of over 2 terabytes of confidential client data.
About Lowe-Martin Group
Established in 1908, Lowe-Martin Group operates primarily out of Ottawa and Toronto, providing a wide range of services including digital printing, offset printing, large format printing, warehousing, inventory management, and order processing. The company is recognized for its commitment to quality and environmentally progressive practices, employing advanced technologies like HP Latex Printing Technologies. With approximately 193 employees and an annual revenue of $78.8 million, Lowe-Martin Group is a key player in the Canadian market.
Attack Overview
The ransomware attack occurred on July 14, 2024, and was orchestrated by RansomHub. Following the breach, RansomHub released a statement on the dark web, criticizing Lowe-Martin's cyber insurance provider, Boxx Insurance, for failing to provide the expected compensation and support. The insurance company allegedly refused to honor the claim, citing minor technicalities, leaving Lowe-Martin struggling to manage the financial fallout and address the damage caused to their clients.
RansomHub: The Ransomware Group
RansomHub is a relatively new ransomware group believed to have roots in Russia. Operating as a Ransomware-as-a-Service (RaaS) group, RansomHub's affiliates receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, and has been known to target healthcare-related institutions. RansomHub's ransomware strains are written in Golang, a language choice that is becoming increasingly popular among ransomware developers.
Penetration and Vulnerabilities
While the exact method of penetration remains unclear, it is likely that RansomHub exploited vulnerabilities in Lowe-Martin's cybersecurity infrastructure. The group's use of Golang-written ransomware strains suggests a sophisticated approach, potentially bypassing traditional security measures. The incident highlights the importance of vigilant cybersecurity practices and the potential pitfalls of relying solely on cyber insurance for protection.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!