Hunters International Strikes: Rocky Mountain Sales Inc. Under Siege

Incident Date:

April 26, 2024

World map

Overview

Title

Hunters International Strikes: Rocky Mountain Sales Inc. Under Siege

Victim

Rocky Mountain Sales

Attacker

Hunters International

Location

Golden, USA

Colorado, USA

First Reported

April 26, 2024

Ransomware Attack on Rocky Mountain Sales by Hunters International

Overview of the Attack

Rocky Mountain Sales Inc., a U.S.-based outsourced sales and service organization, recently fell victim to a significant cyberattack. The attack was carried out by Hunters International, a notorious cybercrime group. This incident involved the exfiltration of approximately 301.1 GB of data, encompassing 293,308 files from the company's primary operational site

Company Profile

Founded in 1971 and based in Golden, Colorado, Rocky Mountain Sales Inc. specializes in providing customer service support and driving revenue for its strategic partners and the brands it represents. The company, with an annual revenue of around $3 million, employs 14 individuals and operates primarily in the wholesale building materials industry. Their services are critical in large projects across multiple states including Colorado, Wyoming, and Montana.

Significance in the Industry

The company is distinguished by its extensive experience and specialization in plumbing sales, marketing, customer service, specifications, and job quotes. Their involvement in significant projects like Montage Big Sky and Parq on Speer underlines their pivotal role in large-scale developments within their operational regions.

Vulnerabilities and Target Profile

The victim's relatively small size and the extensive amount of sensitive data managed through their systems make them an attractive target for cybercriminals like Hunters International. The nature of their business requires storing substantial client information, project details, and financial data, which are valuable for ransomware attackers seeking leverage through data exfiltration.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.