IncRansom Cyberattack Disrupts Kito Canada's Operations and Data Security

Incident Date:

June 13, 2024

World map

Overview

Title

IncRansom Cyberattack Disrupts Kito Canada's Operations and Data Security

Victim

Kito Canada

Attacker

Inc Ransom

Location

Burnaby, Canada

, Canada

First Reported

June 13, 2024

Ransomware Attack on Kito Canada by IncRansom

Overview of Kito Canada

Kito Canada Inc., a subsidiary of the global Kito Corporation, specializes in manufacturing and distributing high-quality hoists, cranes, and related lifting equipment. With over 80 years of experience, the company is a significant player in the material handling industry, known for its commitment to safety, performance, and durability. Kito Canada serves various sectors, including construction, manufacturing, mining, and logistics, providing products like electric chain hoists, manual chain hoists, and cranes.

Details of the Attack

The ransomware group IncRansom has claimed responsibility for a cyberattack on Kito Canada. The breach resulted in the encryption of critical data, severely disrupting operations and compromising sensitive information. IncRansom demanded a substantial ransom in cryptocurrency for the decryption key. Kito Canada has not disclosed whether the ransom was paid, highlighting the increasing threat of ransomware to businesses.

About IncRansom

IncRansom is a sophisticated cybercriminal group known for targeted ransomware attacks on corporate and organizational networks. The group employs advanced techniques, including spear-phishing campaigns and exploiting vulnerabilities like CVE-2023-3519 in Citrix NetScaler. IncRansom's attacks involve double extortion, encrypting data and threatening to release it publicly to pressure victims into paying the ransom. Active since 2023, the group has targeted various industries, including healthcare, education, and technology.

Penetration and Vulnerabilities

IncRansom likely penetrated Kito Canada's systems through a combination of spear-phishing and exploiting known vulnerabilities. The group's use of both Commercial Off-The-Shelf (COTS) software and legitimate system tools for reconnaissance and lateral movement within networks makes them particularly dangerous. Kito Canada's reliance on digital systems for operations and data management made it a prime target for such a sophisticated attack.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.