Ransomware Attack on W.I.S. Sicherheit-Service by 8Base

Incident Date: May 13, 2024

Attack Overview
VICTIM
W.I.S. Sicherheit
INDUSTRY
Business Services
LOCATION
Germany
ATTACKER
8base
FIRST REPORTED
May 13, 2024

Ransomware Attack on W.I.S. Sicherheit-Service by 8Base

Victim Overview

W.I.S. Sicherheit-Service GmbH & Co. KG, a German security services company headquartered in Cologne, North Rhine-Westphalia, was targeted in a ransomware attack by the cybercrime group 8Base. Founded in 1901 as the "Kölner Wach- und Schließgesellschaft," W.I.S. Sicherheit has grown to become one of the largest security service providers in Germany, with over 4,000 employees and annual revenue exceeding 141 million euros. The company offers security technology, personnel security, and 24/7 monitoring through its security center, providing comprehensive security solutions to businesses and individuals.

Company Profile

The company stands out in the industry for its over 100 years of experience and expertise in the security field, as well as its nationwide presence with multiple branches across Germany. The company's "Security-as-a-Service" model combines experienced personnel and modern technology to deliver effective security solutions at a fixed monthly price, catering to the needs of its clients.

Attack Details

During the cyberattack, sensitive information such as invoices, receipts, accounting documents, personal data, certificates, employment contracts, confidentiality agreements, and personal files were compromised. The leaked data was fully published, posing significant risks to the privacy and security of the company and its stakeholders.

Ransomware Group 8Base

The 8Base ransomware group, active since April 2022, has gained notoriety for its aggressive tactics, primarily targeting small and medium-sized businesses across various sectors. 8Base distinguishes itself through its double-extortion tactics, where they encrypt files and steal data, threatening to publicly release it if the ransom is not paid. The group uses ransomware strains like Phobos and spreads through phishing emails, exploit kits, and drive-by downloads.

Penetration and Vulnerabilities

It is believed that 8Base could have penetrated W.I.S. Sicherheit's systems through phishing emails or exploit kits, taking advantage of potential vulnerabilities in the company's cybersecurity defenses. The use of double-extortion tactics by 8Base highlights the importance of robust cybersecurity measures to protect against ransomware attacks and safeguard sensitive data.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.