LockBit 3.0 Ransomware Attack on SRG Apparel PLC

Incident Date:

May 8, 2024

World map

Overview

Title

LockBit 3.0 Ransomware Attack on SRG Apparel PLC

Victim

SRG Apparel Plc

Attacker

Lockbit3

Location

Manchester, United Kingdom

, United Kingdom

First Reported

May 8, 2024

Ransomware Attack on SRG Apparel PLC by LockBit 3.0

Victim Profile

SRG Apparel PLC, a company based in Lancashire, United Kingdom, with a revenue of $26.1 million, specializes in developing fashion apparel for men and women. They supply private label and SRG branded products to retailers worldwide. With over 40 years of experience in manufacturing, SRG Apparel is known for its innovative approach to fashion, using global market intelligence to develop on-trend and commercially viable products.

Industry Standing

The company operates in the Manufacturing sector, specifically focusing on men's and women's fashion apparel. They offer a range of products including accessories, denim, jackets, jerseywear, knitwear, and wovens. Their commitment to quality and trendsetting designs has made them a market-leading supplier to retailers and wholesalers globally.

Attack and Vulnerabilities

The cyberattack on SRG Apparel by the LockBit 3.0 ransomware group involved the encryption of the company's data, rendering it inaccessible to authorized users.

As a prominent player in the fashion apparel industry, SRG Apparel PLC may have been targeted by threat actors due to the sensitive nature of their data and the potential financial gain from a successful ransomware attack. The company's extensive network of retailers and wholesalers could also make them an attractive target for cybercriminals seeking to disrupt supply chains.

Ransomware Group Tactics

The LockBit 3.0 ransomware group, an evolution of the LockBit group, is known for its advanced encryption techniques and obfuscation methods. By encrypting files, modifying filenames, changing desktop wallpapers, and dropping ransom notes, LockBit 3.0 creates a sense of urgency and pressure on victims to pay the ransom for data recovery.

LockBit May Attacks

The ransomware group resurfaced in May 2024 following the disruption of its infrastructure during "Operation Cronos." Despite law enforcement efforts, LockBit swiftly returned, targeting over 50 victims within hours of reactivating its platform. The group's adaptability and global reach showcase the challenges in combating cybercrime effectively. Cybersecurity experts emphasize the need for proactive measures, collaborative intelligence sharing, and international cooperation to counter LockBit's resurgence and safeguard digital ecosystems against evolving threats.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.