RansomHub Strikes Solarium Revestimentos in Major Data Breach

Incident Date: Jan 16, 2025

Attack Overview
VICTIM
Solarium Revestimentos
INDUSTRY
Construction
LOCATION
Brazil
ATTACKER
Ransomhub
FIRST REPORTED
January 16, 2025

RansomHub Ransomware Attack on Solarium Revestimentos

Solarium Revestimentos, a prominent Brazilian company in the construction sector, has allegedly fallen victim to a ransomware attack orchestrated by the notorious RansomHub group. This incident underscores the vulnerabilities faced by companies in the construction materials industry, particularly those with a strong digital presence and innovative product lines.

Company Profile and Industry Standing

Founded in 1997 and headquartered in Porto Alegre, Solarium Revestimentos specializes in cementitious coatings for floors and walls. The company is recognized for its commitment to sustainability and innovative design, offering products like cobogós, which are decorative concrete blocks that provide ventilation and light while maintaining privacy. Solarium employs approximately 110 direct employees and has a network of 160 representatives across Brazil. The company's focus on sustainable production methods and its collaborations with renowned architects have positioned it as a leader in the Brazilian cement floor market.

Attack Overview

The RansomHub group claims to have exfiltrated 293 GB of data from Solarium Revestimentos, threatening to release it publicly within 14 to 15 days. The attackers have shared several files as evidence of the breach, highlighting the severity of the situation. This attack exemplifies the growing threat of ransomware to companies with valuable intellectual property and critical operational data.

RansomHub's Modus Operandi

RansomHub, a Ransomware-as-a-Service (RaaS) group, emerged in February 2024 and quickly established itself as a formidable player in the ransomware landscape. Known for its aggressive affiliate model and double extortion tactics, RansomHub encrypts victims' data while exfiltrating sensitive information to increase leverage in ransom negotiations. The group is affiliated with former Knight ransomware actors and operates through cybercrime forums like RAMP.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.