RansomHub Targets ALL Construction Group in Major Data Breach
RansomHub Ransomware Attack on ALL Construction Group
In a recent cyberattack, the ransomware group RansomHub has targeted ALL Construction Group, a prominent general contracting firm based in Cicero, Illinois. The attack, discovered on November 19, has resulted in the exfiltration of 122 GB of sensitive data, with the threat of public release looming within a week.
About ALL Construction Group
ALL Construction Group is a family-owned business established in 1959, recognized as the largest masonry contractor in the Chicagoland area. The company specializes in a wide array of construction services, including general contracting, masonry, carpentry, and concrete restoration. With a workforce of 201 to 500 employees, the firm operates across both private and public sectors, handling projects in aviation, healthcare, education, and more. Their commitment to safety, environmental responsibility, and high-quality standards has earned them numerous awards and a strong reputation in the industry.
Attack Overview
The ransomware attack on ALL Construction Group was executed by RansomHub, a Ransomware-as-a-Service (RaaS) group known for its aggressive tactics. The group claims to have obtained 122 GB of data from the company, with sample files already leaked as proof. The attack has affected the company's website, allconstructiongroupwv.com, disrupting their online operations and potentially compromising client interactions.
RansomHub's Distinctive Approach
RansomHub emerged in February 2024, quickly establishing itself in the ransomware landscape through its adaptable affiliate model. The group is known for its double extortion tactics, encrypting data while exfiltrating sensitive information to increase ransom demands. RansomHub's ransomware is optimized for speed and efficiency, targeting cross-platform systems and exploiting vulnerabilities in unpatched systems. Their operations are characterized by intermittent encryption, modular architecture, and advanced data exfiltration techniques.
Potential Vulnerabilities
ALL Construction Group's extensive operations across various sectors make it an attractive target for ransomware groups like RansomHub. The company's reliance on digital systems for project management and client interactions could have been exploited through phishing campaigns or vulnerability exploitation. The construction sector's critical data and operational importance further increase the impact of such attacks, emphasizing the need for enhanced cybersecurity measures.
Sources:
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!