LockBit 3.0 Ransomware Attack on Hotel Ostella

Incident Date:

May 9, 2024

World map

Overview

Title

LockBit 3.0 Ransomware Attack on Hotel Ostella

Victim

Hotel Ostella

Attacker

Lockbit3

Location

Bastia, France

, France

First Reported

May 9, 2024

Ransomware Attack on Hotel Ostella by LockBit 3.0

Victim Profile

Hotel Ostella, a 4-star luxury hotel located in Bastia, Corsica Island, France, became a target of the cybercrime group LockBit 3.0. The hotel celebrated its 50th anniversary in 2019 and offers 50 comfortable rooms, two luxury suites, a 450m² wellness center, a restaurant serving modern cuisine, a lounge bar area, and a terrace for dining.

With 52 guest rooms, 3 meeting rooms, and a total event space of 120 sq m, Hotel Ostella caters to both leisure and business travelers. Its year-round availability and commitment to providing a relaxing stay on the Isle of Beauty have made it a standout in the hospitality industry.

Attack Details

LockBit 3.0 targeted Hotel Ostella with ransomware, exfiltrating 88 GB of sensitive data, including marketing data, financial documents, PII, and more. The attack highlighted vulnerabilities in the hotel's cybersecurity defenses, potentially stemming from inadequate security measures or lack of employee training.

Ransomware Group Profile

LockBit 3.0, also known as LockBit Black, distinguishes itself as a highly dangerous ransomware variant with advanced encryption capabilities and obfuscation techniques. The cybercriminal likely penetrated Hotel Ostella's systems through phishing emails, unpatched software vulnerabilities, or weak remote desktop protocol (RDP) configurations. The ransomware's ability to move laterally through networks and cover its tracks poses significant challenges for cybersecurity professionals.

LockBit May Attacks

This ransomware attack on Hotel Ostella is part of the May 2024 attacks by LockBit 3.0. Following the disruption of its infrastructure in February during "Operation Cronos," LockBit swiftly resurfaced and targeted over 50 victims within hours of reactivating its platform. The group's adaptability and global reach highlight the challenges faced by law enforcement in combating cybercrime effectively. LockBit's resurgence emphasizes the need for proactive measures, collaborative intelligence sharing, and enhanced international cooperation to counter such syndicates and safeguard digital ecosystems against evolving threats.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.