SafePay Ransomware Strikes Onnicar Srl Leaking 127GB Data

Incident Date: Nov 19, 2024

Attack Overview
VICTIM
Omnicar S.r.l
INDUSTRY
Manufacturing
LOCATION
Italy
ATTACKER
SafePay
FIRST REPORTED
November 19, 2024

Ransomware Attack on Onnicar S.r.l. by SafePay

On November 21, Onnicar S.r.l., an Italian company specializing in the conversion of commercial vehicles, became the latest victim of a ransomware attack orchestrated by the SafePay group. This incident resulted in the compromise and leak of 127GB of sensitive data, significantly impacting the company's operations.

About Onnicar S.r.l.

Founded in 1969 and headquartered in Vezza d'Alba, Cuneo, Italy, Onnicar S.r.l. is renowned for its innovative solutions in vehicle conversions, particularly using lightweight aluminum structures. The company focuses on enhancing the functionality of commercial vehicles through customized conversions and reliable support services. Onnicar's reputation for quality and innovation has made it a leader in the automotive sector, particularly in vehicle body repair and conversions.

Vulnerabilities and Targeting

Onnicar's specialization in commercial vehicle conversions and its reliance on digital systems for operations and customer data management made it a lucrative target for cybercriminals. The company's extensive use of technology to manage its services, including vehicle reception, insured storage, and delivery, may have presented vulnerabilities that SafePay exploited. The attack underscores the growing threat to manufacturing and automotive sectors, which are increasingly targeted by ransomware groups due to their critical operational dependencies on digital infrastructure.

Attack Overview

The SafePay ransomware group, known for its double-extortion tactics, claimed responsibility for the attack on Onnicar. The group typically encrypts files and threatens to release stolen data unless a ransom is paid. In this case, SafePay managed to exfiltrate 127GB of data, potentially including sensitive customer and operational information. The attack highlights the group's ability to infiltrate networks stealthily, often using valid credentials obtained through compromised VPN gateways or portals.

SafePay Ransomware Group

SafePay is a relatively new player in the ransomware landscape, utilizing ransomware-as-a-service (RaaS) tactics and leveraging LockBit source code. The group distinguishes itself through its operational security and a double-extortion strategy, which adds pressure on victims to comply with ransom demands. SafePay's presence on the dark web, where it lists victims and details stolen data, further emphasizes its threat to organizations across various sectors.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.