Kempe Engineering Hit by RansomHub: 4 TB Data Breach Analysis

Incident Date:

August 7, 2024

World map

Overview

Title

Kempe Engineering Hit by RansomHub: 4 TB Data Breach Analysis

Victim

Kempe Engineering Pty Ltd

Attacker

Ransomhub

Location

Geelong, Australia

, Australia

First Reported

August 7, 2024

RansomHub Ransomware Attack on Kempe Engineering Pty Ltd: A Detailed Analysis

Kempe Engineering Pty Ltd, a prominent engineering firm based in Geelong, Victoria, Australia, has recently fallen victim to a ransomware attack orchestrated by the RansomHub group. This cyber assault has resulted in the exfiltration of a substantial 4 TB of sensitive data, including financial records, customer data, internal communications, and proprietary business information.

About Kempe Engineering Pty Ltd

Kempe Engineering Pty Ltd specializes in maintenance, modernization, and the provision of process equipment products and services. The company operates primarily in sectors such as mining, oil and gas, and industrial manufacturing. With a workforce of approximately 84 employees and an annual revenue of around $79.2 million, Kempe Engineering is recognized for its commitment to developing long-term client relationships and delivering high-quality, custom-designed engineering solutions.

The company's in-house global delivery model allows it to source materials and expertise from emerging markets, enhancing the efficiency and cost-effectiveness of its projects. Kempe Engineering's emphasis on safety, innovative methodologies, and sustainability further distinguishes it in the industry.

Attack Overview

The ransomware attack on Kempe Engineering was claimed by the RansomHub group via their dark web leak site. The cybercriminals have reportedly exfiltrated 4 TB of sensitive data, which includes financial records, customer data, internal mail, and proprietary business information. This breach has significant implications for the company's operations and data security, underscoring the critical need for effective cybersecurity measures.

About RansomHub

RansomHub is a relatively new ransomware group that has emerged in the cyber threat landscape. Believed to have roots in Russia, RansomHub operates as a Ransomware-as-a-Service (RaaS) group, with affiliates receiving 90% of the ransom money and the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, without following a specific pattern.

RansomHub's ransomware strains are written in Golang, a language choice that is becoming increasingly popular among ransomware developers. This trend may indicate a shift towards more sophisticated and resilient ransomware attacks in the future.

Penetration and Vulnerabilities

While the exact method of penetration used by RansomHub in the Kempe Engineering attack is not publicly disclosed, common vulnerabilities that could have been exploited include weak passwords, unpatched software, and phishing attacks. The use of Golang in their ransomware strains suggests a level of sophistication that could bypass traditional security measures.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.