cuba attacks STM

Incident Date:

July 7, 2022

World map

Overview

Title

cuba attacks STM

Victim

STM

Attacker

Cuba

Location

Kaohsiung, Taiwan

Gangshan, Taiwan

First Reported

July 7, 2022

STM Ransomware Attack: A Cybersecurity Perspective

Company Overview

STM, also known as 信盛精工股份有限公司, is a Taiwanese company that has been in operation for over 50 years. They are known for their commitment to active research and development in connectors, materials, products, and molds, as well as their one-stop service that caters to diverse customer needs and high-quality requirements. In the past two decades, STM has imported advanced automatic connector assembly technology and equipment from advanced countries, ensuring their quality and control meet international standards. They have a significant presence in the technology, information, and electronics industries, leading the way in the supply chain of these sectors.

Attack Details

The ransomware attack on STM was carried out using a highly sophisticated variant of the RansomExx computer virus, which included a high level of automation. The attack affected 600 out of a total of 1,600 critical servers, and the STM was able to isolate its systems within four hours and restore the affected servers. The investigation revealed that the attack did not affect bus and métro service at any time.

Vulnerabilities and Mitigation

The STM's investigation showed that the attack was made through the desktop or trash can on certain equipments. This suggests that the company may have had insufficient endpoint security measures in place, allowing the ransomware to enter through these entry points. Additionally, the attack resulted in the exfiltration of some low sensitivity personal information from 24 of their 11,000 employees and 72 of their 645,000 customers. This highlights the importance of robust data protection measures, particularly in handling sensitive information.

To mitigate the risks of ransomware attacks, companies should invest in advanced endpoint security solutions, regularly update their software and systems, and implement strong data protection policies. Regular employee training on cybersecurity best practices is also crucial in preventing such attacks.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.