Ransomware Attack on Matadero de Gijón: A Cybersecurity Threat

Incident Date: May 21, 2024

Attack Overview
VICTIM
Matadero de Gijón
INDUSTRY
Hospitality
LOCATION
Spain
ATTACKER
Ransomhub
FIRST REPORTED
May 21, 2024

Ransomware Attack on Matadero de Gijón by RansomHub

Victim Overview

Matadero de Gijón, a meat processing company based in Spain, was targeted in a ransomware attack by the cybercrime group RansomHub in May 2024. The company, Sociedad de Explotación del Matadero de Gijón SL, is dedicated to the slaughter and processing of various types of livestock, as well as the sale of meat and related products. Located in Gijón, Asturias, Spain, the company operates as a cultural center promoting contemporary art and culture through exhibitions, performances, workshops, and events.

Company Profile

The company's standout services include the slaughter and processing of various types of livestock, including beef, pork, and sheep. Matadero de Gijón stands out in the meat processing and distribution industry in Spain by providing high-quality meat products and services.

Attack Overview

RansomHub attackers exfiltrated 400 GB of critical data from Matadero de Gijón, gaining access to the company's SCADA control system and encrypting backups. The attackers have leaked a sample of the compromised data, although the ransom demand details have not been disclosed. This incident highlights the vulnerability of industrial control systems to cyberattacks, posing significant risks to operational integrity and data security.

Ransomware Group - RansomHub

RansomHub is a new ransomware group that has emerged in the cyber threat landscape, distinguishing itself by making claims and backing them up with data leaks. The group operates as a Ransomware-as-a-Service (RaaS) group, with affiliates receiving 90% of the ransom money and the remaining 10% going to the main group. RansomHub has targeted various countries without following a specific pattern, including the US, Brazil, Indonesia, and Vietnam.

How the Attack Happened

The group's ransomware strains are written in Golang, a relatively new trend in the ransomware world. The choice of this language may indicate a step towards future trends in ransomware attacks. The attackers could have penetrated Matadero de Gijón's systems through vulnerabilities in their network security or through social engineering tactics to gain unauthorized access to their SCADA control system.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.