Hunters International Ransomware Hits WheelerShip
Incident Date:
July 2, 2024
Overview
Title
Hunters International Ransomware Hits WheelerShip
Victim
WheelerShip
Attacker
Hunters International
Location
First Reported
July 2, 2024
Ransomware Attack on WheelerShip by Hunters International
Company Profile: WheelerShip
WheelerShip, officially known as The Wheelership LLC, is a prominent e-commerce retailer headquartered in Carlstadt, New Jersey. Specializing in the distribution of replacement wheels and accessories for cars, trucks, and SUVs, the company has carved a niche in the automotive parts industry. WheelerShip stands out due to its extensive inventory that includes both OEM and replica wheels, catering to a diverse clientele ranging from car enthusiasts to average drivers seeking quality and affordability. Their commitment to customer service and a user-friendly online shopping experience on wheelership.com enhances their industry standing.
Details of the Ransomware Attack
The cyberattack on WheelerShip was orchestrated by the ransomware group known as Hunters International. This group, which surfaced in the cybercrime arena in 2023, has claimed responsibility for infiltrating WheelerShip's network and exfiltrating 9.5GB of data. According to their statements on a dark web leak site, they intend to publish the stolen data if their demands are not met within the next 5-6 days. This type of cyber extortion is typical of ransomware operations, where victim data is held hostage to leverage ransom payments.
Profile of Hunters International
Hunters International is a Ransomware-as-a-Service (RaaS) group with significant technical similarities to the previously dismantled Hive ransomware group. Emerging in the aftermath of Hive's disruption by law enforcement, Hunters International has quickly established itself by targeting a variety of sectors globally. The group's operations are marked by the exfiltration of sensitive data followed by ransom demands, employing tactics that suggest a sophisticated understanding of cybersecurity vulnerabilities.
Potential Vulnerabilities and Attack Vectors
While specific details of the breach vector used in the WheelerShip attack remain undisclosed, common entry points for such attacks include phishing, exploitation of unpatched software, and compromised credentials. Given the nature of WheelerShip's business, which relies heavily on digital transactions and data storage, it is plausible that Hunters International exploited weaknesses in the company’s cybersecurity defenses. These could include inadequate endpoint protection, insufficient employee cybersecurity training, or vulnerabilities in their web applications.
Sources:
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.