blackbasta attacks IMA Schelling Group

Incident Date:

April 26, 2022

World map

Overview

Title

blackbasta attacks IMA Schelling Group

Victim

IMA Schelling Group

Attacker

Blackbasta

Location

morrisville, USA

north carolina, USA

First Reported

April 26, 2022

IMA Schelling Group Suffers Ransomware Attack

IMA Schelling Group, a leading system provider to the woodworking and board industries, has been targeted by the ransomware group BlackBasta. The attack was announced on the group's dark web leak site, and the victim's website is currently under threat. The company operates in the Manufacturing sector and is renowned for its sales and after-sales support of IMA and Schelling products for the woodworking, metalworking, and plastics industries.

Company Overview

IMA Schelling Group is a system provider that specializes in the woodworking and board industries. They have been recognized for their work in the woodworking industry, with Roseburg Forest Products selecting them for their new state-of-the-art MDF plant in Dillard, OR. The company is also a Platinum Sponsor for the 2023 Executive Briefing Conference (EBC).

Vulnerabilities and Impact

Ransomware attacks can have significant impacts on organizations, including financial losses, reputational damage, and the loss of sensitive or proprietary information. The potential impact of a ransomware attack on IMA Schelling Group could include:

  • Financial Losses: The company may face significant financial losses due to the ransom payment, remediation costs, insurance deductibles, attorney fees, and litigation.
  • Reputational Damage: The attack could negatively impact the company's reputation, as customers may view the successful attack as an indication of weak security practices.
  • Data Loss: Encrypted files may be permanently locked, requiring the company to regenerate the information if a ransom is not paid.

Mitigation Strategies

To mitigate the risk of ransomware attacks, organizations should implement a comprehensive incident response plan that focuses on attack mitigation and remediation. This includes isolating infected systems, powering down aspects of the system to prevent the spread, and identifying the source of the attack. Additionally, contacting Federal Law Enforcement may aid with available decryptions and launch an investigation into the attack.

The ransomware attack on IMA Schelling Group underscores the importance of proactive cybersecurity measures. By implementing robust security controls and educating employees on potential threats, companies can diminish their risk of being targeted by threat actors.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.