RansomHub Strikes Wulff & Co. Leaks 32GB of Sensitive Data

Incident Date: Nov 19, 2024

Attack Overview
VICTIM
Wulff & Co
INDUSTRY
Manufacturing
LOCATION
Norway
ATTACKER
Ransomhub
FIRST REPORTED
November 19, 2024

RansomHub Ransomware Attack on Wulff & Co.

On November 20, Wulff & Co., a prominent player in the automotive and food supply sectors, became the latest victim of a ransomware attack by the notorious RansomHub group. This attack resulted in the leak of 32GB of sensitive data, potentially jeopardizing the company's long-standing relationships with its clients and suppliers.

About Wulff & Co.

Wulff & Co., headquartered in Norderstedt, Germany, has over 30 years of experience in exporting high-quality spare parts for trucks, passenger cars, and construction machinery. The company is known for its commitment to quality and reliability, offering parts from renowned manufacturers like Mercedes-Benz and BMW. Additionally, Wulff & Co. operates in the food sector through its Norwegian division, supplying meat products to the HORECA market. This diverse portfolio underscores the company's dedication to quality and customer satisfaction.

Attack Overview

The ransomware attack on Wulff & Co. was executed by RansomHub, a Ransomware-as-a-Service group known for its aggressive tactics. The attack led to the exposure of various files, including sensitive documents from business partners, which were leaked as proof of the breach.

RansomHub's Modus Operandi

RansomHub distinguishes itself through its sophisticated and adaptable affiliate model. Emerging in February, the group has quickly gained notoriety for its double extortion tactics, combining data encryption with exfiltration to pressure victims into paying ransoms. RansomHub's operations are characterized by their speed and efficiency, often exploiting vulnerabilities in unpatched systems and using advanced data exfiltration techniques.

Potential Vulnerabilities

Wulff & Co.'s extensive operations across multiple sectors make it an attractive target for ransomware groups like RansomHub. The company's reliance on digital infrastructure for managing its supply chains and customer relationships could have been a potential entry point for the attackers. RansomHub's use of phishing campaigns and vulnerability exploitation suggests that Wulff & Co. may have been targeted through similar vectors, underscoring the importance of effective cybersecurity measures.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.