Ransomware Attack on Pier Foundry & Pattern Shop, Inc.

Incident Date: May 15, 2024

Attack Overview
VICTIM
Pier Foundry & Pattern Shop, Inc.
INDUSTRY
Manufacturing
LOCATION
USA
ATTACKER
Black Suit
FIRST REPORTED
May 15, 2024

Ransomware Attack on Pier Foundry & Pattern Shop, Inc.

Victim Overview

Pier Foundry & Pattern Shop, Inc. is a manufacturing company based in St. Paul, MN, specializing in producing high-quality gray and ductile iron castings for various industries such as agriculture, construction, and industrial equipment. They also offer pattern making services to create custom molds for casting production. The company has 134 years of manufacturing experience and is ISO certified.

Company Profile

The company is known for its commitment to providing high-level service, support, and value to its customers. They offer assistance in design and castability from concept through production and have made significant investments in new technology, including a new M14 Tumble Blast System, mold machines, green sand controls system, 3D printer technology, and ergonomic workbenches. The company has also been recognized for its safety record, winning awards from the American Foundry Society.

Attack Details

The cybercrime group Black Suit targeted Pier Foundry & Pattern Shop, Inc. with ransomware, compromising the company's website. The attack resulted in the exfiltration of employees' and partners' data, some of which has been fully published, posing significant risks to individuals' privacy and security.

Ransomware Group Profile

Black Suit is a new ransomware family closely related to the notorious Royal ransomware group. The group targets both Windows and Linux systems, including critical VMware ESXi infrastructure. Black Suit appends the .blacksuit extension to encrypted files and provides a ransom note for victims to contact the operators. The ransomware group has significant similarities in code and functionality with the Royal ransomware, indicating a potential connection between the two groups.

Vulnerabilities

The company may have been targeted by threat actors due to the sensitive nature of the data they handle, including employees' and partners' information. Additionally, the company's investment in new technology could have provided avenues for cybercriminals to exploit vulnerabilities in their systems.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.