Ransomware Hits Fashion Firm By Design LLC Exposing Data

Incident Date: Oct 23, 2024

Attack Overview
VICTIM
By Design LLC
INDUSTRY
Retail
LOCATION
USA
ATTACKER
Meow
FIRST REPORTED
October 23, 2024

Ransomware Attack on By Design LLC: A Detailed Analysis

By Design LLC, a prominent player in the fashion and apparel industry, has recently fallen victim to a ransomware attack orchestrated by the Meow Ransomware group. This incident highlights the vulnerabilities faced by mid-sized companies in the retail sector, particularly those with significant digital assets and sensitive data.

About By Design LLC

Founded in 1994, By Design LLC is a New York-based apparel company specializing in women's fashion. The company is known for its commitment to inclusivity, offering a diverse range of sizes and styles. With a workforce of 51 to 200 employees, By Design LLC generates an annual revenue of approximately $17.2 million. The company's focus on ethical production and sustainable fashion practices sets it apart in the competitive apparel market.

Details of the Ransomware Attack

The Meow Ransomware group claims to have infiltrated By Design LLC's systems, accessing around 550 GB of sensitive data. This data includes employee records, client details, financial documents, and personal information such as dates of birth and driver's license scans. The attackers have posted sample screenshots of the stolen data on their dark web portal, pressuring the company to respond to the breach.

Profile of Meow Ransomware Group

Emerging in late 2022, the Meow Ransomware group is associated with the Conti v2 ransomware variant. Known for targeting industries with sensitive data, the group employs various infection methods, including phishing emails and exploiting RDP vulnerabilities. They use a combination of ChaCha20 and RSA-4096 algorithms to encrypt data, leaving a ransom note instructing victims to contact them for decryption.

Potential Vulnerabilities and Attack Vector

By Design LLC's reliance on digital systems for managing sensitive data may have made it an attractive target for the Meow Ransomware group. The attack could have been facilitated through phishing emails or exploiting vulnerabilities in remote access protocols. The company's mid-sized operation, while allowing for personalized service, may also mean limited resources for comprehensive cybersecurity measures, increasing susceptibility to such attacks.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.