RansomHub Ransomware Hits Lowe-Martin Group, 2TB Data Stolen

Incident Date: Aug 10, 2024

Attack Overview
VICTIM
Lowe-Martin Group
INDUSTRY
Business Services
LOCATION
Canada
ATTACKER
Ransomhub
FIRST REPORTED
August 10, 2024

RansomHub Ransomware Attack on Lowe-Martin Group

The Lowe-Martin Group, a prominent Canadian business services company specializing in printing, fulfillment, and e-commerce solutions, has fallen victim to a significant ransomware attack. The attack, claimed by the ransomware group RansomHub, has resulted in the theft of over 2 terabytes of confidential client data.

About Lowe-Martin Group

Established in 1908, Lowe-Martin Group operates primarily out of Ottawa and Toronto, providing a wide range of services including digital printing, offset printing, large format printing, warehousing, inventory management, and order processing. The company is recognized for its commitment to quality and environmentally progressive practices, employing advanced technologies like HP Latex Printing Technologies. With approximately 193 employees and an annual revenue of $78.8 million, Lowe-Martin Group is a key player in the Canadian market.

Attack Overview

The ransomware attack occurred on July 14, 2024, and was orchestrated by RansomHub. Following the breach, RansomHub released a statement on the dark web, criticizing Lowe-Martin's cyber insurance provider, Boxx Insurance, for failing to provide the expected compensation and support. The insurance company allegedly refused to honor the claim, citing minor technicalities, leaving Lowe-Martin struggling to manage the financial fallout and address the damage caused to their clients.

RansomHub: The Ransomware Group

RansomHub is a relatively new ransomware group believed to have roots in Russia. Operating as a Ransomware-as-a-Service (RaaS) group, RansomHub's affiliates receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, and has been known to target healthcare-related institutions. RansomHub's ransomware strains are written in Golang, a language choice that is becoming increasingly popular among ransomware developers.

Penetration and Vulnerabilities

While the exact method of penetration remains unclear, it is likely that RansomHub exploited vulnerabilities in Lowe-Martin's cybersecurity infrastructure. The group's use of Golang-written ransomware strains suggests a sophisticated approach, potentially bypassing traditional security measures. The incident highlights the importance of vigilant cybersecurity practices and the potential pitfalls of relying solely on cyber insurance for protection.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.