RansomHub Ransomware Hits Major Auto Supplier Yorozu

Incident Date: Oct 21, 2024

Attack Overview
VICTIM
Yorozu Corporation
INDUSTRY
Manufacturing
LOCATION
India
ATTACKER
Ransomhub
FIRST REPORTED
October 21, 2024

RansomHub Ransomware Attack on Yorozu Corporation

Yorozu Corporation, a leading Japanese manufacturer of automotive components, has become the latest victim of a ransomware attack by the notorious RansomHub group. The attack, confirmed on October 14, resulted in the encryption of files across multiple servers, with the attackers demanding a ransom by October 31.

Yorozu Corporation: A Key Player in Automotive Manufacturing

Established in 1948, Yorozu Corporation is headquartered in Yokohama, Japan, and employs approximately 5,726 people. The company specializes in the design, development, and production of automotive parts, including mechanical components, body parts, and engine components. Yorozu's significant market presence is underscored by its major clients, such as Nissan, Honda, and Toyota, with Nissan accounting for 65.7% of its sales. The company's commitment to innovation and sustainability is evident in its recent green energy initiatives.

RansomHub: A Formidable Ransomware Group

RansomHub emerged in February 2024 as a Ransomware-as-a-Service (RaaS) group, quickly gaining notoriety for its aggressive affiliate model and double extortion tactics. The group is known for its speed and efficiency, leveraging advanced data exfiltration techniques and targeting high-value sectors. RansomHub's operations are characterized by their use of intermittent encryption and Curve 25519 elliptic curve encryption, making them a formidable threat.

Details of the Attack

The RansomHub group claims to have exfiltrated 849 GB of sensitive data from Yorozu Corporation, including confidential documents and contracts with major car manufacturers, technical documentation, budget reports, and HR files. The attack has rendered critical files inaccessible, severely impacting Yorozu's operations. The attackers have set a ransom deadline, adding pressure on the company to comply with their demands.

Potential Vulnerabilities and Penetration Methods

Yorozu Corporation's extensive network and reliance on critical data make it a prime target for ransomware groups like RansomHub. The attackers likely exploited vulnerabilities in Yorozu's systems, potentially through phishing campaigns or unpatched software. RansomHub's sophisticated techniques, including lateral movement and data exfiltration, highlight the challenges faced by organizations in safeguarding their digital assets.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.