LockBit 3.0 Strikes CloudMinds: A Cyber Attack Story

Incident Date:

May 9, 2024

World map

Overview

Title

LockBit 3.0 Strikes CloudMinds: A Cyber Attack Story

Victim

CloudMinds

Attacker

Lockbit3

Location

Irvine, USA

California, USA

First Reported

May 9, 2024

Ransomware Attack on CloudMinds by LockBit 3.0

Victim Company Profile: CloudMinds

CloudMinds, established in 2015, is a pioneering force in cloud robot systems and services. Operating as "CloudMinds Technology Inc." from Irvine, California, it stands as a privately held company with a significant workforce ranging between 501-1,000 employees. With a focus on building and operating cloud robot systems and services, the company aims to lead in technological advancements. CloudMinds develops humanoid robots for enterprise and households

Within the Manufacturing sector, specifically in CloudMinds Robotics, the company's cloud robots tackle dull, dirty, dangerous, or demeaning work, enhancing people's lives. Holding more than 1633 patent applications, it ranks first globally in cloud robotics. Its products and solutions cater to various fields, including smart city infrastructure, community services, elderly care, agriculture, education, and health.

LockBit 3.0's Penetration of CloudMinds

LockBit 3.0, a variant of the notorious LockBit ransomware, executed a cyber attack on CloudMinds, affecting their website, with ransomware. This likely entailed encrypting sensitive data and extorting payment for decryption keys, potentially causing operational disruptions and data loss. LockBit 3.0 is notorious for file encryption, filename alterations, desktop wallpaper changes, and ransom note deployment. It can propagate through networks via group policy updates and erase traces of its activity.

LockBit's Resurgence

These attacks occurred in May 2024 by LockBit 3.0, a cybercriminal group that resurfaced with renewed vigor following the disruption of its infrastructure during "Operation Cronos." Despite arrests and the dismantling of its data leak site, LockBit swiftly returned, targeting over 50 victims within hours of reactivating its platform. These assaults spanned various sectors and countries, showcasing LockBit's global reach and adaptability. The group's resurgence underscores the need for enhanced international cooperation to effectively combat such syndicates.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.