blackbyte attacks GEBE

Incident Date:

March 30, 2022

World map

Overview

Title

blackbyte attacks GEBE

Victim

GEBE

Attacker

Blackbyte

Location

Philipsburg, Netherlands Antilles

Philipsburg, Netherlands Antilles

First Reported

March 30, 2022

Ransomware Attack on NV GEBE

On March 17, 2022, the ransomware group Black Byte claimed responsibility for an attack on NV GEBE, a utility company operating in the Energy, Utilities & Waste sector in Sint Maarten. NV GEBE is a vital organization that provides essential services, including power generation, water supply, and waste management.

Company Size and Industry Standing

NV GEBE is a significant player in the energy sector of Sint Maarten, providing essential services to the local community. The company's operations, including power plants, water tanks, and roadside work, are showcased on its website.

Vulnerabilities and Attack Circumstances

The attack on NV GEBE was facilitated by a lack of management and security measures. A report revealed that GEBE's network was compromised due to outdated and unsecured IT systems. The company's IT department used the same local administrator account and password on all computers, and there was no security awareness training for staff. Additionally, GEBE provided staff with computers for personal use, which had full administrative privileges and allowed for the installation of any software.

Black Byte targeted NV GEBE due to its outdated and unsecured IT infrastructure. The ransomware group specifically targeted servers and workstations, including the enterprise resource planning system and the Microsoft Data Protection Manager.

Response and Aftermath

NV GEBE made the cyber attack public and refused to pay the ransom. In retaliation, Black Byte published samples of GEBE-data on its Tor.Onion auction website. Aurora, a cybersecurity firm, was hired to help GEBE recover from the attack. They installed monitoring software and discovered that 93 GEBE-employees' credentials had been exposed on the dark web.

Since the attack, Aurora has implemented a layered security approach, using various tools monitored around the clock by its Security Operations Centers. These SOCs have detected more than one million threats to GEBE's network and hunted down 778 threats.

The attack on NV GEBE underscores the critical importance of robust cybersecurity measures in protecting critical infrastructure sectors. The company's lack of management and security measures allowed Black Byte to successfully exploit its outdated and unsecured IT infrastructure. It is imperative for organizations to prioritize cybersecurity to safeguard their operations and the communities they serve from the devastating consequences of ransomware attacks.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.