Ransomware Attack on PBC Companies: 300GB Data Stolen by BianLian

Incident Date: Aug 18, 2024

Attack Overview
VICTIM
PBC Companies
INDUSTRY
Construction
LOCATION
USA
ATTACKER
Bianlian
FIRST REPORTED
August 18, 2024

Ransomware Attack on PBC Companies by BianLian

PBC Companies, a construction firm specializing in concrete, masonry, and paver projects, has recently fallen victim to a ransomware attack by the notorious BianLian group. The attackers claim to have exfiltrated 300GB of sensitive data, including crucial project information, from the company's systems.

About PBC Companies

PBC Companies operates primarily in California, with offices in Anaheim, Escondido, and Pacoima. The firm is known for its expertise in hardscaping and outdoor construction projects, having completed notable installations such as the San Clemente Plaza and the Elevon Campus. The company's specialization in concrete, masonry, and paver work has established it as a reputable player in the construction industry.

Attack Overview

The BianLian ransomware group has claimed responsibility for the attack on PBC Companies via their dark web leak site. The group asserts that they have accessed and exfiltrated 300GB of sensitive organizational data. This breach could have significant financial and reputational consequences for PBC Companies, given the nature of the data involved.

About BianLian Ransomware Group

BianLian is a sophisticated ransomware group that has evolved from targeting individual users to launching high-profile attacks on various sectors, including construction. Initially functioning as a banking trojan, BianLian transitioned into advanced ransomware operations, focusing on exfiltration-based extortion. The group is known for its ability to gain initial access through compromised Remote Desktop Protocol (RDP) credentials and implant custom backdoors specific to each victim.

Penetration Tactics

BianLian employs a range of tactics to penetrate company systems. These include using PowerShell and Windows Command Shell for defense evasion and employing various tools for discovery, lateral movement, collection, exfiltration, and impact. The group's shift towards exfiltration-based extortion underscores the evolving threat landscape posed by ransomware groups.

Vulnerabilities and Impact

PBC Companies' vulnerabilities likely stem from inadequate cybersecurity measures, such as weak RDP credentials and insufficient endpoint detection and response solutions. The attack highlights the urgent need for enhanced cybersecurity measures to protect against sophisticated ransomware groups like BianLian.

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.