RansomHub Targets Sundt Construction in Major Ransomware Attack

Incident Date: Nov 05, 2024

Attack Overview
VICTIM
Sundt Construction
INDUSTRY
Construction
LOCATION
USA
ATTACKER
Ransomhub
FIRST REPORTED
November 5, 2024

RansomHub Ransomware Attack on Sundt Construction: A Detailed Analysis

Sundt Construction, a leading general contractor in the United States, has fallen victim to a ransomware attack orchestrated by the notorious RansomHub group. This breach highlights the vulnerabilities faced by large enterprises in the construction sector, particularly those with extensive digital operations and valuable data assets.

About Sundt Construction

Founded in 1890, Sundt Construction is a prominent player in the U.S. construction industry, employing approximately 2,115 individuals. The company is renowned for its expertise in infrastructure, site development, transportation, industrial, and renewable energy projects. Sundt's commitment to quality and innovation, coupled with its employee-ownership model, distinguishes it in the competitive construction landscape. However, its extensive digital footprint and valuable data make it an attractive target for cybercriminals.

Attack Overview

The RansomHub group claims to have exfiltrated a significant amount of sensitive data from Sundt Construction. This includes financial reports, sales documents, accounting data, and personal information of investors and clients. The breach also reportedly involves confidential internal correspondence, passwords, credentials, and SQL databases. Such a comprehensive data compromise poses severe risks to Sundt's operations and reputation.

RansomHub's Modus Operandi

RansomHub, a Ransomware-as-a-Service (RaaS) group, emerged in February 2024 and quickly established itself as a formidable threat in the cyber landscape. Known for its aggressive affiliate model and double extortion tactics, RansomHub encrypts victims' data while exfiltrating sensitive information to increase ransom leverage. The group is adept at exploiting vulnerabilities in unpatched systems and employs advanced data exfiltration techniques.

Potential Vulnerabilities

Sundt Construction's extensive use of digital technologies and data-driven operations may have contributed to its vulnerability. RansomHub likely penetrated the company's systems through phishing campaigns or exploiting unpatched vulnerabilities, such as those in Citrix ADC or FortiOS. The construction sector's reliance on critical data and the potential for operational disruption make it a lucrative target for ransomware groups like RansomHub.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.