ElDorado Ransomware Strikes Lindostar: Data Breach Threat

Incident Date:

June 6, 2024

World map

Overview

Title

ElDorado Ransomware Strikes Lindostar: Data Breach Threat

Victim

Lindostar

Attacker

ElDorado

Location

Casalecchio di Reno, Italy

, Italy

First Reported

June 6, 2024

ElDorado Ransomware Attack on Lindostar

Overview of Lindostar

Lindostar S.r.l., based in Zola Predosa, Bologna, is an Italian company specializing in high-quality lighting solutions. Founded in 2007, the company employs between 11-50 people and focuses on the design, production, and distribution of innovative lighting fixtures. Their product range includes chandeliers, pendant lights, wall sconces, floor lamps, and table lamps. Lindostar is known for combining advanced technology with elegant design, emphasizing sustainability and energy efficiency through the use of LED technology.

Details of the Attack

Recently, the ransomware group ElDorado has claimed responsibility for an attack on Lindostar, resulting in the exfiltration of 2.7GB of data. The stolen data has been put up for sale on ElDorado's dark web leak site. The attack has significantly impacted Lindostar, a company that prides itself on innovation and customer satisfaction.

About ElDorado

ElDorado is a ransomware group that emerged in 2024, known for its double-extortion tactics. They encrypt victims' files and exfiltrate sensitive data, threatening to release it publicly if ransom demands are not met. Over the past seven months, ElDorado has claimed 15 victims, showcasing their aggressive and sophisticated approach. Their attacks are marked by meticulous targeting and the use of robust encryption algorithms, making it difficult for victims to recover without paying the ransom.

Penetration Methods

To infiltrate systems, ElDorado employs various tactics, including phishing attacks, exploiting unpatched vulnerabilities, and weaknesses in Remote Desktop Protocol (RDP) configurations. They often use legitimate system administration tools for malicious purposes, blending in with normal operations to avoid detection. The group exfiltrates sensitive data before encryption, adding pressure on victims to comply with ransom demands.

Vulnerabilities and Impact

Given Lindostar's relatively small size and potential lack of cybersecurity defenses, it was a vulnerable target for ElDorado. The attack has not only disrupted their operations but also poses a significant threat to their reputation and customer trust. The exfiltration and potential sale of sensitive data could have long-term consequences for the company and its clients.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.