lockbit2 attacks bbst-clp

Incident Date:

March 20, 2022

World map

Overview

Title

lockbit2 attacks bbst-clp

Victim

bbst-clp

Attacker

Lockbit2

Location

Lankumer Feldweg 1, Germany

1 Cloppenburg, Germany

First Reported

March 20, 2022

Ransomware Attack on Berufsbildende Schulen Technik Cloppenburg (BBST-CLP)

Company Information

Berufsbildende Schulen Technik Cloppenburg (BBST-CLP), a vocational school located in Cloppenburg, Germany, has recently fallen victim to a ransomware attack. The institution, which specializes in various technical courses, emphasizes sustainable future development. Its premises are situated at Lankumer Feldweg 1, 49661 Cloppenburg, operating within the Education sector.

Vulnerabilities

The attack on BBST-CLP did not specify the vulnerabilities exploited by the attackers. However, the Lockbit2 ransomware group, responsible for this incident, is known for its comprehensive approach to network compromise. Typically, the group gains initial access through the Active Directory (AD) server, allowing them to map the network and plan their attack meticulously. This preparatory phase includes reconnaissance, lateral movement, and data exfiltration, culminating in the ransomware deployment.

Ransomware Group

Lockbit2, the group behind this attack, distinguishes itself by appending the “.ClOP” extension to encrypted files. Renowned for its adaptive tactics, techniques, and procedures (TTPs), Lockbit2 remains at the forefront of cybercriminal innovation. The group employs a combination of negotiation attempts and threats, including the potential public release and auctioning of stolen data on their leak site, to pressure victims into complying with their demands.

Response and Mitigation

While specific details regarding BBST-CLP's response to the ransomware attack are not disclosed, it underscores the necessity for organizations to implement comprehensive cybersecurity measures. Essential strategies include the regular application of updates and patches, conducting cybersecurity awareness training for employees, and establishing effective incident response protocols.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.