VBÜ Zrt Hit by INC Ransom: Major Ransomware Breach in Hungary

Incident Date: Nov 08, 2024

Attack Overview
VICTIM
VBÜ Zrt
INDUSTRY
Business Services
LOCATION
Hungary
ATTACKER
Inc Ransom
FIRST REPORTED
November 8, 2024

Ransomware Attack on VBÜ Zrt: A Critical Breach in Hungary's Defense Procurement Sector

VBÜ Zrt, officially known as Védelmi Beszerzési Ügynökség Zártkörűen Működő Részvénytársaság, has recently fallen victim to a ransomware attack by the notorious INC Ransom group. This Hungarian company, established in 2019, specializes in business and management consultancy with a focus on defense and public procurement. Operating from Budapest, VBÜ Zrt employs approximately 97 individuals and has positioned itself as a key player in enhancing public sector efficiency and compliance.

Company Profile and Industry Standing

VBÜ Zrt is recognized for its strategic consulting services in public procurement processes, compliance, and contract management. The company's expertise in navigating complex public sector procurement laws has made it a significant contributor to governmental and defense-related projects in Hungary. Despite being a relatively new entity, VBÜ Zrt has demonstrated stable financial performance, reporting a net revenue of approximately 28.61 million HUF for 2023.

Details of the Ransomware Attack

The INC Ransom group has claimed responsibility for the attack on VBÜ Zrt, asserting that they have accessed sensitive data related to the company's defense procurement activities. The group has released sample screenshots of the compromised data on their dark web portal, raising serious concerns about potential national security implications.

Profile of the INC Ransom Group

INC Ransom is a sophisticated cybercriminal group known for its targeted ransomware attacks across various industries, including healthcare, education, and government entities. The group employs advanced techniques such as spear-phishing and exploiting known vulnerabilities like CVE-2023-3519 in Citrix NetScaler. Their modus operandi involves double extortion, where they encrypt and steal data, threatening to release it publicly to pressure victims into paying ransoms.

Potential Vulnerabilities and Attack Vectors

VBÜ Zrt's involvement in defense procurement makes it an attractive target for ransomware groups like INC Ransom. The company's reliance on digital systems for managing sensitive procurement data could have been exploited through vulnerabilities in their network infrastructure. The use of legitimate system tools for reconnaissance and lateral movement within the network is a common tactic employed by INC Ransom, emphasizing the need for effective cybersecurity measures.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.