German Bakery Schäfer Faces Major Ransomware Cyberattack

Incident Date:

September 26, 2024

World map

Overview

Title

German Bakery Schäfer Faces Major Ransomware Cyberattack

Victim

Schäfer, dein BäckerGmbH & Co. KG

Attacker

Akira

Location

Limburg, Germany

, Germany

First Reported

September 26, 2024

Ransomware Attack on Schäfer, dein Bäcker: A Detailed Analysis

Schäfer, dein Bäcker GmbH & Co. KG, a renowned German bakery chain, has recently fallen victim to a ransomware attack orchestrated by the Akira group. This incident highlights the increasing vulnerability of the food production sector to cyber threats.

Company Profile

Established in 1920, Schäfer, dein Bäcker is a family-owned business that has grown to operate over 160 retail locations, employing approximately 1,700 staff members. The company is a significant player in the German bakery industry, known for its high-quality baked goods, including fresh rolls, breads, pastries, and cakes. Their commitment to traditional baking methods and sustainability has earned them numerous accolades and a loyal customer base.

Attack Overview

The Akira ransomware group claims to have exfiltrated 14 GB of sensitive data from Schäfer, dein Bäcker. The compromised data reportedly includes personal information of employees, financial records, and details of business partners. The breach occurred at the company's Langer Kornweg location, underscoring the growing threat of ransomware attacks on the food production sector.

About Akira Ransomware Group

Akira emerged in March 2023 and quickly gained notoriety for its sophisticated attack methods. The group employs a hybrid encryption scheme and utilizes a double-extortion model, threatening to publish stolen data if ransoms are not paid. Akira's operations are characterized by their focus on larger organizations across various sectors, including education, finance, and healthcare.

Potential Vulnerabilities

Schäfer, dein Bäcker's extensive operations and reliance on digital systems for managing their business processes may have made them an attractive target for Akira. The ransomware group is known for exploiting vulnerabilities in VPN software and using compromised login credentials to gain unauthorized access. The bakery's commitment to expanding its market presence could have inadvertently increased its exposure to cyber threats.

Penetration Tactics

Akira likely penetrated Schäfer, dein Bäcker's systems through vulnerabilities in their network infrastructure or by exploiting weak security protocols. The group's use of "living off the land" techniques, which involve using legitimate system tools for malicious purposes, may have facilitated the attack while evading detection.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.