Hunters International Ransomware Hits WheelerShip

Incident Date:

July 2, 2024

World map

Overview

Title

Hunters International Ransomware Hits WheelerShip

Victim

WheelerShip

Attacker

Hunters International

Location

Melville, USA

New York, USA

First Reported

July 2, 2024

Ransomware Attack on WheelerShip by Hunters International

Company Profile: WheelerShip

WheelerShip, officially known as The Wheelership LLC, is a prominent e-commerce retailer headquartered in Carlstadt, New Jersey. Specializing in the distribution of replacement wheels and accessories for cars, trucks, and SUVs, the company has carved a niche in the automotive parts industry. WheelerShip stands out due to its extensive inventory that includes both OEM and replica wheels, catering to a diverse clientele ranging from car enthusiasts to average drivers seeking quality and affordability. Their commitment to customer service and a user-friendly online shopping experience on wheelership.com enhances their industry standing.

Details of the Ransomware Attack

The cyberattack on WheelerShip was orchestrated by the ransomware group known as Hunters International. This group, which surfaced in the cybercrime arena in 2023, has claimed responsibility for infiltrating WheelerShip's network and exfiltrating 9.5GB of data. According to their statements on a dark web leak site, they intend to publish the stolen data if their demands are not met within the next 5-6 days. This type of cyber extortion is typical of ransomware operations, where victim data is held hostage to leverage ransom payments.

Profile of Hunters International

Hunters International is a Ransomware-as-a-Service (RaaS) group with significant technical similarities to the previously dismantled Hive ransomware group. Emerging in the aftermath of Hive's disruption by law enforcement, Hunters International has quickly established itself by targeting a variety of sectors globally. The group's operations are marked by the exfiltration of sensitive data followed by ransom demands, employing tactics that suggest a sophisticated understanding of cybersecurity vulnerabilities.

Potential Vulnerabilities and Attack Vectors

While specific details of the breach vector used in the WheelerShip attack remain undisclosed, common entry points for such attacks include phishing, exploitation of unpatched software, and compromised credentials. Given the nature of WheelerShip's business, which relies heavily on digital transactions and data storage, it is plausible that Hunters International exploited weaknesses in the company’s cybersecurity defenses. These could include inadequate endpoint protection, insufficient employee cybersecurity training, or vulnerabilities in their web applications.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.