RansomHub Ransomware Hits Olanocorp in Major Cyber Attack

Incident Date: Oct 25, 2024

Attack Overview
VICTIM
Olanocorp
INDUSTRY
Construction
LOCATION
Peru
ATTACKER
Ransomhub
FIRST REPORTED
October 25, 2024

RansomHub Ransomware Attack on Olanocorp: A Detailed Analysis

Olanocorp, officially known as Distribuciones Olano S.A.C., a prominent player in Peru's construction sector, has recently fallen victim to a ransomware attack by the notorious RansomHub group. This incident highlights the vulnerabilities faced by companies in the construction supply chain, especially those heavily reliant on digital operations and international trade.

Company Profile: Olanocorp

Olanocorp is a Peruvian company engaged in the import and distribution of construction materials. With a diverse product catalog that includes ceramics, tiles, plumbing supplies, and specialized items like biodigesters and electrobombas, Olanocorp serves a wide range of clients from builders to individual consumers. The company has recorded over 5,200 import transactions valued at approximately $42 million over the past five years, primarily sourcing from China, India, and Turkey. This extensive import activity underscores their reliance on international suppliers, positioning them as a key player in the Peruvian market.

Attack Overview

The RansomHub ransomware group claims to have infiltrated Olanocorp's systems, exfiltrating 343 GB of sensitive data. The attackers have threatened to release this information publicly within a week if their demands are not met. This attack not only jeopardizes Olanocorp's operational integrity but also risks exposing confidential business and client information.

RansomHub: A Formidable Threat

RansomHub, emerging in February 2024, has quickly established itself as a significant player in the ransomware landscape. Known for its aggressive affiliate model and double extortion tactics, the group combines data encryption with exfiltration to maximize pressure on victims. RansomHub's operations are characterized by their speed and efficiency, often exploiting vulnerabilities in unpatched systems and leveraging phishing campaigns to gain initial access.

Potential Vulnerabilities

Olanocorp's extensive digital operations and reliance on international trade may have made it an attractive target for RansomHub. The company's interactive online catalog and significant import activities suggest a digital infrastructure, which, if not adequately secured, could be vulnerable to sophisticated cyber threats. Additionally, the construction sector's increasing digitization and reliance on data-driven processes further expose companies like Olanocorp to ransomware attacks.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.