Supply Technologies Hit by BlackSuit Ransomware Attack

Incident Date: Nov 11, 2024

Attack Overview
VICTIM
Supply Technologies
INDUSTRY
Manufacturing
LOCATION
USA
ATTACKER
Black Suit
FIRST REPORTED
November 11, 2024

Ransomware Attack on Supply Technologies by BlackSuit Group

Supply Technologies, a subsidiary of Park Ohio Holdings Corp., has recently been targeted by the BlackSuit ransomware group. This attack highlights the vulnerabilities within the manufacturing sector, particularly for companies specializing in supply chain management and logistics. Supply Technologies, founded in 1995 and headquartered in Cleveland, Ohio, is renowned for its Total Supply Management (TSM) approach, which enhances manufacturing efficiencies through tailored solutions. With an annual revenue of approximately $158.1 million and a workforce of around 557 employees, the company plays a significant role in the logistics and supply chain industry.

Attack Overview

The BlackSuit ransomware group, known for its double extortion tactics, has claimed responsibility for the attack on Supply Technologies. This group typically gains access to networks through phishing emails, compromised Remote Desktop Protocol (RDP) credentials, and exploitation of public-facing applications. Once inside, they employ privilege escalation and data exfiltration techniques before encrypting files. The attack on Supply Technologies underscores the risks faced by companies in the manufacturing sector, where the flow of parts and materials is critical to operations.

About BlackSuit Ransomware Group

Emerging in 2023, BlackSuit ransomware is linked to the Royal ransomware group, indicating a continuation of sophisticated cybercrime tactics. The group distinguishes itself through its rapid encryption process and the use of both Windows and Linux payloads. BlackSuit's focus on high-value targets, such as healthcare, education, and manufacturing, makes it a formidable threat in the cybersecurity landscape. The group's ability to disable system recovery options and employ obfuscation techniques further complicates recovery efforts for victims.

Vulnerabilities and Impact

Supply Technologies' role in managing the flow of products for manufacturers makes it an attractive target for ransomware groups like BlackSuit. The company's reliance on digital systems for procurement, inventory control, and logistics services presents potential vulnerabilities that threat actors can exploit. The attack not only disrupts operations but also poses a risk to sensitive data, which can be exfiltrated and used to pressure victims into paying ransoms. This incident serves as a reminder of the importance of effective cybersecurity measures in protecting critical supply chain functions.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.