Ransomware Attack on London Drugs by LockBit 3.0

Incident Date: May 23, 2024

Attack Overview
VICTIM
London Drugs
INDUSTRY
Retail
LOCATION
Canada
ATTACKER
Lockbit
FIRST REPORTED
May 23, 2024

Ransomware Attack on London Drugs by LockBit 3.0

Victim Overview

London Drugs, a Canadian retail store chain, was targeted by the LockBit 3.0 ransomware group. The company offers a diverse range of products including pharmaceuticals, cosmetics, electronics, and housewares. With a revenue of $1.69 billion in 2024, London Drugs is a significant player in the retail sector. The company is known for being 100% Canadian owned, prioritizing local customer satisfaction, and providing an exceptional shopping experience through innovation and community involvement.

Attack Details

The ransomware attack on London Drugs involved the LockBit 3.0 group demanding a ransom. Despite the company's financial strength, the pharmaceutical sector of London Drugs was only willing to pay $8 million of the demanded ransom. The threat actors are now seeking an additional $17 million to prevent the release of stolen data within 48 hours. A sample of the compromised data has already been leaked, indicating the severity of the breach.

Ransomware Group Overview

The LockBit 3.0 ransomware group is an evolution of the LockBit group, known for its advanced and dangerous ransomware tactics. LockBit 3.0 operates under a Ransomware-as-a-Service (RaaS) model, allowing other cybercriminals to utilize their malware for attacks. The group is highly sophisticated, encrypting files, modifying filenames, changing desktop wallpapers, and dropping ransom notes on victims' desktops. LockBit 3.0 is designed to be evasive and difficult to analyze, making it a formidable threat in the cybersecurity landscape.

Company Vulnerabilities

London Drugs' prominence in the retail sector and its extensive customer base make it an attractive target for threat actors like LockBit 3.0. The company's wide range of products and services, including pharmaceuticals, electronics, and photo printing, may contain sensitive data that can be exploited by ransomware groups. Additionally, the company's substantial revenue and reputation could make it more likely to be targeted for large ransom demands.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.