hiveleak attacks Weidmueller

Incident Date:

July 27, 2022

World map

Overview

Title

hiveleak attacks Weidmueller

Victim

Weidmueller

Attacker

Hiveleak

Location

Rio de Janeiro - RJ, Brazil

Rio de Janeiro - RJ, Brazil

First Reported

July 27, 2022

Weidmueller Suffers Ransomware Attack by Hiveleak Group

Company Overview

Weidmueller, a Brazilian company, specializes in industrial connectivity solutions, offering a diverse portfolio that includes TI applications, PCB solutions, and identification systems. Detailed information about their offerings and history can be found on their official website.

Company Size and Industry Standing

While specific details regarding Weidmueller's size are not readily available, it is known that the company plays a significant role in the manufacturing sector. This industry is particularly vulnerable to ransomware attacks due to the high potential for operational disruptions and financial repercussions.

Vulnerabilities and Targeting

Ransomware groups, such as Hiveleak, frequently exploit weaknesses in enterprise security, targeting companies utilizing widely used products from vendors like Citrix or VMware. Hiveleak has demonstrated capabilities to compromise networks through single-factor RDP, VPN, and other remote access protocols. Notably, they have also managed to circumvent multi-factor authentication, exploiting vulnerabilities such as CVE-2020-12812 to infiltrate FortiOS servers.

Response and Mitigation

In response to the ransomware attack, Weidmueller has initiated a review and enhancement of their security and protection policies. Furthermore, the Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the Federal Bureau of Investigation (FBI) and the Department of Health and Human Services (HHS), has issued a joint alert regarding the Hive ransomware group. This alert highlights the group's focus on a broad spectrum of sectors, including Government Facilities, Communications, Critical Manufacturing, Information Technology, and notably, Healthcare and Public Health.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.