alphv attacks ThreeSixty Sourcing

Incident Date:

February 18, 2022

World map



alphv attacks ThreeSixty Sourcing


ThreeSixty Sourcing




Lam Chak, China

Hongkong, China

First Reported

February 18, 2022

ThreeSixty Sourcing Ransomware Attack

ThreeSixty Sourcing, a global organization behind renowned brands such as Sharper Image, FAO Schwarz, and Vornado, has recently fallen victim to a ransomware attack orchestrated by the group Alphv. This incident was disclosed on a dark web leak site, highlighting the ongoing vulnerability of prominent entities in the retail sector to sophisticated cyber threats.

With a vast operational footprint, ThreeSixty Sourcing's influence spans over 30 countries, boasting more than 75,000 global offices. The company's portfolio, known for its high-quality offerings in everyday play, technology, health and wellness, and premium home comfort, underscores the significant impact of this security breach.

The attack on ThreeSixty Sourcing reflects a growing trend where ransomware syndicates increasingly target the manufacturing sector. Notably, subsectors such as metal components, automotive, and plastics/technology have emerged as prime targets, with groups like Conti and Lockbit 2.0 accounting for 51% of all ransomware incidents in 2021.

Manufacturers, including ThreeSixty Sourcing, often grapple with cybersecurity challenges that heighten their risk of ransomware attacks. These challenges include limited oversight of operational technology (OT) systems, inadequate network perimeters, exposure due to external connectivity in OT systems, and the problematic practice of using shared credentials.

The attack methodology employed against ThreeSixty Sourcing likely encompasses a multi-extortion strategy. This approach not only involves the encryption of data but also data exfiltration, service disruption, and direct ransom demands to third-party associates, amplifying the attack's impact.

To mitigate the threat of ransomware, it is imperative for manufacturers to enhance the security posture of both their IT and OT environments. Developing and implementing a comprehensive ransomware incident response plan is crucial in safeguarding against such cyber threats, ensuring operational resilience and security assurance for stakeholders.


Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.