LockBit Ransomware Hits UK's Largest Lubricants Manufacturer

Incident Date:

August 11, 2024

World map

Overview

Title

LockBit Ransomware Hits UK's Largest Lubricants Manufacturer

Victim

Exol Lubricants Limited

Attacker

Lockbit3

Location

Wednesbury, United Kingdom

, United Kingdom

First Reported

August 11, 2024

LockBit Ransomware Attack on Exol Lubricants Limited

Exol Lubricants Limited, the largest independent lubricants manufacturer in the UK, has recently fallen victim to a ransomware attack orchestrated by the notorious LockBit group. The breach was discovered on August 12, raising significant concerns about the security of the company's sensitive information.

Company Overview

Founded in 1984, Exol Lubricants Limited specializes in the production and supply of a diverse range of lubricants and related products tailored for various sectors, including industry, agriculture, transport, automotive, and garage services. The company operates two primary manufacturing sites in Birmingham and Rotherham, with research and development activities conducted at its headquarters in the Midlands. Exol is recognized for its commitment to quality management, innovation, and exceptional customer service, positioning itself as a leader in the lubricants manufacturing sector.

Attack Overview

The ransomware attack on Exol Lubricants Limited was claimed by the LockBit group via their dark web leak site. While the exact size of the data leak remains unknown, the incident underscores the growing threat of ransomware attacks on industrial and manufacturing sectors. The attack has raised significant concerns about the security of the company's sensitive information, including proprietary product formulations, customer data, and operational details.

About LockBit Ransomware Group

LockBit is a highly sophisticated ransomware-as-a-service (RaaS) group that has been active since September 2019. It has become the most active ransomware group, responsible for over one-third of all ransomware attacks in the latter half of 2022 and the first quarter of 2023. LockBit employs "double extortion" tactics, exfiltrating sensitive data and threatening to release it publicly if the ransom is not paid. The ransomware uses a combination of RSA-2048 and AES-256 encryption algorithms to encrypt victims' files, making it extremely difficult to decrypt without paying the ransom.

Potential Vulnerabilities

Exol Lubricants Limited, like many companies in the manufacturing sector, may have been targeted due to potential vulnerabilities in their cybersecurity infrastructure. LockBit is known to exploit vulnerabilities in Remote Desktop Protocol (RDP) services and unsecured network shares to spread quickly across a network. The attack on Exol highlights the critical need for regular software updates, network segmentation, and comprehensive employee training to mitigate social engineering tactics.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.