blackbasta attacks Montrose Environmental Group, Inc.

Incident Date:

August 6, 2022

World map

Overview

Title

blackbasta attacks Montrose Environmental Group, Inc.

Victim

Montrose Environmental Group, Inc.

Attacker

Blackbasta

Location

Irvine, USA

California, USA

First Reported

August 6, 2022

Analysis of the Ransomware Attack on Montrose Environmental Group by BlackBasta

Overview of the Incident

On June 14, 2022, Montrose Environmental Group, Inc., a prominent provider of environmental solutions, announced it had fallen victim to a ransomware attack orchestrated by the BlackBasta group. The company, which operates extensively within the Energy, Utilities & Waste sector, offers a wide range of environmental services across the United States. Its services span across various operational segments including Assessment, Permitting and Response; Measurement and Analysis; and Remediation and Reuse.

With a global presence through 80 locations and catering to sectors such as manufacturing, oil and gas, and government services, Montrose Environmental Group delivers critical services like leak detection and repair, soil and groundwater remediation, biogas solutions, and environmental advisory services. The company also runs 11 environmental testing laboratories in the US, focusing on analyzing air, soil, water, and other substances for toxicity and pollutants.

Impact of the Attack

The ransomware attack specifically targeted the computers and servers within the Enthalpy Analytical laboratory network of Montrose, leading to delays in certain lab results. In response, Montrose suspended the affected systems, engaged law enforcement, and initiated remediation efforts with the assistance of both internal and external IT and cybersecurity experts.

Despite the attack, Montrose has stated that its backup data and cloud-based enterprise systems, including email, remain unaffected. The company is actively working towards restoring the impacted systems and has communicated that it does not expect significant disruptions to its other services. Montrose is also in the process of informing its clients about any potential delays or impacts resulting from the attack.

Analysis of Target Vulnerability

While Montrose Environmental Group has not publicly disclosed specific vulnerabilities that may have led to the ransomware attack, the company's reliance on technology for its environmental testing and analysis services underscores a potential area of risk. The sophistication of the attack, as described by Montrose, highlights the evolving threat landscape and the need for robust cybersecurity measures, especially for companies operating within critical infrastructure sectors.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.