SafePay Ransomware Strikes Onnicar Srl Leaking 127GB Data
Ransomware Attack on Onnicar S.r.l. by SafePay
On November 21, Onnicar S.r.l., an Italian company specializing in the conversion of commercial vehicles, became the latest victim of a ransomware attack orchestrated by the SafePay group. This incident resulted in the compromise and leak of 127GB of sensitive data, significantly impacting the company's operations.
About Onnicar S.r.l.
Founded in 1969 and headquartered in Vezza d'Alba, Cuneo, Italy, Onnicar S.r.l. is renowned for its innovative solutions in vehicle conversions, particularly using lightweight aluminum structures. The company focuses on enhancing the functionality of commercial vehicles through customized conversions and reliable support services. Onnicar's reputation for quality and innovation has made it a leader in the automotive sector, particularly in vehicle body repair and conversions.
Vulnerabilities and Targeting
Onnicar's specialization in commercial vehicle conversions and its reliance on digital systems for operations and customer data management made it a lucrative target for cybercriminals. The company's extensive use of technology to manage its services, including vehicle reception, insured storage, and delivery, may have presented vulnerabilities that SafePay exploited. The attack underscores the growing threat to manufacturing and automotive sectors, which are increasingly targeted by ransomware groups due to their critical operational dependencies on digital infrastructure.
Attack Overview
The SafePay ransomware group, known for its double-extortion tactics, claimed responsibility for the attack on Onnicar. The group typically encrypts files and threatens to release stolen data unless a ransom is paid. In this case, SafePay managed to exfiltrate 127GB of data, potentially including sensitive customer and operational information. The attack highlights the group's ability to infiltrate networks stealthily, often using valid credentials obtained through compromised VPN gateways or portals.
SafePay Ransomware Group
SafePay is a relatively new player in the ransomware landscape, utilizing ransomware-as-a-service (RaaS) tactics and leveraging LockBit source code. The group distinguishes itself through its operational security and a double-extortion strategy, which adds pressure on victims to comply with ransom demands. SafePay's presence on the dark web, where it lists victims and details stolen data, further emphasizes its threat to organizations across various sectors.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!