conti attacks NORDEX FOOD

Incident Date:

March 18, 2022

World map



conti attacks NORDEX FOOD






Dronninglund, Denmark

Dronninglund, Denmark

First Reported

March 18, 2022

Conti Ransomware Attacks Nordex Food

The Conti ransomware group has claimed responsibility for an attack on Nordex Food, a Danish company specializing in white cheese production. Nordex Food operates in the manufacturing sector and has a significant presence in Europe, with production facilities in Denmark, Austria, and Romania. The company has an omsætning (revenue) of 2.7 billion krone (approximately 350 million euros).

Nordex Food is known for its egenproduktion (own production), which allows the company to cater to unique customer needs and preferences. The company's products include salatost, madlavningsost, grillost, Feta, and Halloumi, as well as a range of other cheese and dairy products. Nordex Food's distribution network covers the detail, foodservice, and industri segments, and the company has a global reach, serving customers in over 70 countries.

The Conti ransomware attack on Nordex Food was not the first time the company has faced such an incident. In 2022, another wind turbine manufacturer, Vestas, suffered a ransomware attack by the LockBit group.

Understanding Conti Ransomware

Conti ransomware is a private Ransomware-as-a-Service (RaaS) operation believed to be controlled by a Russian-based cybercrime group tracked as Wizard Spider. The group often gains initial access to networks through spearphishing campaigns, malicious attachments, stolen or weak Remote Desktop Protocol (RDP) credentials, fake software, and common vulnerabilities in external assets.

To mitigate the risk of ransomware attacks, organizations should implement multi-factor authentication, network segmentation, vulnerability scanning, endpoint detection and response tools, and limit access to resources over the network, especially by restricting RDP.

Nordex Food has not disclosed the extent of the damage caused by the Conti ransomware attack or whether any data was stolen during the incident. The company has not yet responded to requests for comment on the attack.


Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.