LockBit 3.0 Strikes gammaRenax AG: A Cybersecurity Threat to a Multinational Company

Incident Date:

May 7, 2024

World map

Overview

Title

LockBit 3.0 Strikes gammaRenax AG: A Cybersecurity Threat to a Multinational Company

Victim

gammaRenax AG

Attacker

Lockbit3

Location

Dübendorf, Switzerland

, Switzerland

First Reported

May 7, 2024

Ransomware Attack on gammaRenax AG by LockBit 3.0

Victim Profile

GammaRenax AG is a company specializing in facility services, offering a broad range of services such as general cleaning, building services, garden maintenance, and administration. The company prides itself on a multicultural and multifaceted working environment, employing staff from around 63 countries of origin. They emphasize fair working conditions, correct remuneration, targeted training, and compliance with labor laws, safety, and health requirements.

Company Standout

The Swiss company stands out for its commitment to professional advancement, particularly focusing on training apprentices in various fields such as commercial clerks, building cleaners, and maintenance specialists. They offer recognized apprenticeships with practical training, highlighting a dedication to nurturing young talent and providing them with a solid foundation for their future careers.

Company Size

The attacked company has over 1800 employees, showcasing its substantial workforce and operational scale. It has grown significantly since its establishment in 1985 and remains family-owned, now in its second generation of leadership.

Ransomware Attack Details

Recently, Gammarenax was the target of a cyberattack by the LockBit 3.0 ransomware group. LockBit 3.0, also known as LockBit Black, is a new variant of the LockBit ransomware that emerged in 2022. It is considered one of the most dangerous and disruptive ransomware threats currently active.

Vulnerabilities

Being a company with a substantial workforce and a focus on customer satisfaction, Gammarenax may have been targeted by threat actors due to the sensitive nature of the data they handle. The company's commitment to quality and customer satisfaction, as well as its certifications in various management systems, could have made it an attractive target for cybercriminals seeking to disrupt operations and extort ransom payments.

LockBit May Attacks:

This is part of the May 2024 attacks by LockBit3.0, a cybercriminal group, resurfaced with vigor following the disruption of its infrastructure during "Operation Cronos," a collaborative effort by international law enforcement agencies. Despite arrests and the dismantling of its data leak site, LockBit swiftly returned, targeting over 50 victims within hours of reactivating its platform, with subsequent attacks adding to the tally. These assaults spanned various sectors and countries, showcasing LockBit's global reach and adaptability.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.