Homeocan: A Leader in Natural Medicine Under Attack

Incident Date:

April 9, 2024

World map

Overview

Title

Homeocan: A Leader in Natural Medicine Under Attack

Victim

Homeocan

Attacker

Black Suit

Location

Montreal, Canada

, Canada

First Reported

April 9, 2024

Ransomware Attack on Homeocan by BlackSuit Group

Company Profile and Ransomware Attack

Established in 1987 by Michèle Boisvert, Homeocan specializes in natural and alternative medicine, particularly focusing on homeopathy. This Montreal-based company has ascended to a leadership position in Canada's natural products sector, offering a diverse array of homeopathic remedies tailored for both adults and children. Its international footprint extends across multiple countries, where it also serves as a supplier for prominent drugstore chains. Nevertheless, on April 24, the company fell victim to a devastating ransomware attack orchestrated by the cybercriminal group BlackSuit, shaking the foundations of its digital infrastructure and threatening the security of its sensitive data.

Company Size and Industry Standing

Homeocan's annual revenue is estimated to be less than 1 million CAD. Despite its modest financial scale, the company has cemented its status through its natural products and homeopathy. With a legacy spanning over three decades, it has cultivated a good reputation for delivering natural, gluten-free, and sugar-free solutions to its clientele.

Vulnerabilities and Targeting by Threat Actors

The distinctive focus of Homeocan on natural and alternative medicine, coupled with its global reach, likely rendered it an appealing target for threat actors such as the BlackSuit ransomware group. Its dependence on digital infrastructure for operational and distribution functions might have exposed vulnerabilities that were skillfully exploited by these attackers. Furthermore, the inherent sensitivity of healthcare data and intellectual property concerning homeopathic remedies could have constituted prime targets for extortion.

The BlackSuit ransomware group, renowned for its indiscriminate targeting across sectors encompassing healthcare, education, and retail, has been actively operational since early 2023. Employing sophisticated tactics, including encryption and exfiltration of victim data, they coerce organizations into giving into their ransom demands. Their expert handling of software and open-source tools during ransomware operations, alongside their affiliations with the Royal ransomware family, highlight the sophisticated nature of their attacks.

Sources:

Homeocan Website

SentinelOne - BlackSuit Ransomware

HIPAA Journal - BlackSuit Ransomware Threat

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.