Incident Date:

April 9, 2024

Montreal, Canada

, Canada

April 9, 2024

Ransomware Attack on Homeocan by BlackSuit Group

Company Profile and Ransomware Attack

Established in 1987 by Michèle Boisvert, Homeocan specializes in natural and alternative medicine, particularly focusing on homeopathy. This Montreal-based company has ascended to a leadership position in Canada's natural products sector, offering a diverse array of homeopathic remedies tailored for both adults and children. Its international footprint extends across multiple countries, where it also serves as a supplier for prominent drugstore chains. Nevertheless, on April 24, the company fell victim to a devastating ransomware attack orchestrated by the cybercriminal group BlackSuit, shaking the foundations of its digital infrastructure and threatening the security of its sensitive data.

Company Size and Industry Standing

Homeocan's annual revenue is estimated to be less than 1 million CAD. Despite its modest financial scale, the company has cemented its status through its natural products and homeopathy. With a legacy spanning over three decades, it has cultivated a good reputation for delivering natural, gluten-free, and sugar-free solutions to its clientele.

Vulnerabilities and Targeting by Threat Actors

The distinctive focus of Homeocan on natural and alternative medicine, coupled with its global reach, likely rendered it an appealing target for threat actors such as the BlackSuit ransomware group. Its dependence on digital infrastructure for operational and distribution functions might have exposed vulnerabilities that were skillfully exploited by these attackers. Furthermore, the inherent sensitivity of healthcare data and intellectual property concerning homeopathic remedies could have constituted prime targets for extortion.

The BlackSuit ransomware group, renowned for its indiscriminate targeting across sectors encompassing healthcare, education, and retail, has been actively operational since early 2023. Employing sophisticated tactics, including encryption and exfiltration of victim data, they coerce organizations into giving into their ransom demands. Their expert handling of software and open-source tools during ransomware operations, alongside their affiliations with the Royal ransomware family, highlight the sophisticated nature of their attacks.


