Hunters International Strikes: Rocky Mountain Sales Inc. Under Siege
Incident Date:
April 26, 2024
Overview
Title
Hunters International Strikes: Rocky Mountain Sales Inc. Under Siege
Victim
Rocky Mountain Sales
Attacker
Hunters International
Location
First Reported
April 26, 2024
Ransomware Attack on Rocky Mountain Sales by Hunters International
Overview of the Attack
Rocky Mountain Sales Inc., a U.S.-based outsourced sales and service organization, recently fell victim to a significant cyberattack. The attack was carried out by Hunters International, a notorious cybercrime group. This incident involved the exfiltration of approximately 301.1 GB of data, encompassing 293,308 files from the company's primary operational site
Company Profile
Founded in 1971 and based in Golden, Colorado, Rocky Mountain Sales Inc. specializes in providing customer service support and driving revenue for its strategic partners and the brands it represents. The company, with an annual revenue of around $3 million, employs 14 individuals and operates primarily in the wholesale building materials industry. Their services are critical in large projects across multiple states including Colorado, Wyoming, and Montana.
Significance in the Industry
The company is distinguished by its extensive experience and specialization in plumbing sales, marketing, customer service, specifications, and job quotes. Their involvement in significant projects like Montage Big Sky and Parq on Speer underlines their pivotal role in large-scale developments within their operational regions.
Vulnerabilities and Target Profile
The victim's relatively small size and the extensive amount of sensitive data managed through their systems make them an attractive target for cybercriminals like Hunters International. The nature of their business requires storing substantial client information, project details, and financial data, which are valuable for ransomware attackers seeking leverage through data exfiltration.
Sources
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.