RansomHub Strikes City West Commercials in Major Data Breach

Incident Date: Nov 19, 2024

Attack Overview
VICTIM
City West Commercials
INDUSTRY
Transportation
LOCATION
United Kingdom
ATTACKER
Ransomhub
FIRST REPORTED
November 19, 2024

RansomHub Ransomware Attack on City West Commercials

On November 20, City West Commercials, a leading authorized dealer of Mercedes-Benz commercial vehicles, became the latest victim of a ransomware attack orchestrated by the notorious RansomHub group. This incident resulted in a significant data breach, with 12GB of sensitive information being exfiltrated from the company's systems.

About City West Commercials

City West Commercials is a prominent player in the transportation sector, specializing in the sale and servicing of Mercedes-Benz trucks and vans, as well as FUSO vehicles. The company operates from four strategic locations in the South West of England, including Avonmouth, Highbridge, Exeter, and Roche. With approximately 95 employees, City West Commercials has demonstrated significant growth, reporting a turnover of £46.52 million for the year ending December 31, 2023. The company's focus on both new and used vehicle sales, alongside comprehensive after-sales services, positions it as a reliable partner for businesses requiring commercial transportation solutions.

RansomHub Overview

RansomHub, a Ransomware-as-a-Service (RaaS) group, emerged in February 2024 and quickly established itself as a formidable player in the ransomware landscape. Known for its aggressive affiliate model, RansomHub employs double extortion tactics, encrypting victims' data while exfiltrating sensitive information to increase leverage in ransom demands.

The attack on City West Commercials highlights the vulnerabilities that can be exploited by sophisticated threat actors like RansomHub. The group is known for its speed and efficiency, utilizing advanced data exfiltration techniques and targeting cross-platform systems. Potential entry points for the attack could include phishing campaigns, vulnerability exploitation, or password spraying, all of which are common tactics employed by RansomHub affiliates..

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.