lockbit2 attacks Sobotram

Incident Date:

February 21, 2022

World map

Overview

Title

lockbit2 attacks Sobotram

Victim

Sobotram

Attacker

Lockbit2

Location

Paul Sabatier, France

crissey, France

First Reported

February 21, 2022

Sobotram, a Transportation Company, Suffers a Ransomware Attack by Lockbit2

Company Overview

Sobotram, a French transportation and logistics company, has been targeted by the ransomware group Lockbit2, as announced on the group's dark web leak site. The company, part of the Groupe Blondel since early 2023, specializes in the transport and logistics of general goods and hazardous materials both in France and internationally. With strategic locations at major transportation hubs, Sobotram operates a SEVESO high-risk site in Chalon sur Saône (71).

Industry Vulnerabilities

The transportation sector is frequently targeted by ransomware attacks due to its critical nature and the potential for significant operational disruptions. Such attacks can result in considerable financial losses, operational setbacks, and reputational damage for the companies involved.

Attack Vector

Lockbit2, the group behind this attack, typically exploits unpatched vulnerabilities to infiltrate target networks. The group's strategy includes the use of zero-day vulnerabilities and one-day flaws, enabling them to circumvent traditional security measures. Once inside, they can encrypt or exfiltrate sensitive data for extortion purposes.

Mitigation Strategies

To reduce the risk of ransomware attacks, organizations are advised to promptly patch newly disclosed vulnerabilities and ensure they have robust backup and restoration processes in place. The implementation of multi-factor authentication (MFA) and the promotion of good security practices, such as phishing training and password hygiene among employees, are also crucial in mitigating the risk of social engineering or brute-force attacks.

The ransomware attack on Sobotram by Lockbit2 underscores the persistent threat of ransomware within the transportation sector. It is imperative for companies within this industry to stay vigilant and prioritize cybersecurity measures to safeguard against such attacks.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.