Widdop & Co Targeted by Rhysida Ransomware Attack

Incident Date: May 18, 2024

Attack Overview
VICTIM
Widdop and Co.
INDUSTRY
Manufacturing
LOCATION
United Kingdom
ATTACKER
Rhysida
FIRST REPORTED
May 18, 2024

Ransomware Attack on Widdop & Co by Rhysida

Victim Overview

Widdop & Co, a leading UK-based giftware and home decor supplier, was targeted by the Rhysida ransomware group in a recent cyberattack. The company, established in 1883, offers a wide range of products for various occasions and events, with a strong focus on design, innovation, and quality. Widdop & Co stands out in the industry for its 140-year history, diverse product portfolio, and commitment to customer service.

Attack Overview

The attackers demanded a ransom of 10 BTC (approximately $670,000) from Widdop & Co after compromising sensitive information within the company's SQL databases. This data included details of suppliers, buyers, financial transactions, and proprietary algorithms related to discounts and profit margins. The attackers exfiltrated an undisclosed amount of data and made a sample of the leaked information available.

Rhysida Ransomware Group

The Rhysida ransomware group is known for its double extortion technique, stealing data before encrypting it and threatening to publish it on the dark web unless a ransom is paid. The group targets various sectors, including manufacturing, healthcare, education, and government, and primarily operates through phishing campaigns and network infiltration. Rhysida distinguishes itself by using the ChaCha20 encryption algorithm and generating ransom notes as PDF documents.

Company Vulnerabilities

Widdop & Co may have been targeted by threat actors due to its extensive network connections, including field-based territory managers and an export team serving over 75 countries. The company's reliance on digital systems for managing product information, financial data, and customer details could have made it susceptible to ransomware attacks. Additionally, the use of valid credentials and VPN connections for network access may have provided an entry point for the attackers.

Sources:

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.