lockbit2 attacks wiegaarden

Incident Date:

April 3, 2022

World map

Overview

Title

lockbit2 attacks wiegaarden

Victim

wiegaarden

Attacker

Lockbit2

Location

Hobro, Denmark

Hobro, Denmark

First Reported

April 3, 2022

Wiegaarden: A Danish Media Company Targeted by Lockbit2 Ransomware

Overview of the Incident

Wiegaarden, a Danish media company, has recently fallen victim to the Lockbit2 ransomware group, as disclosed on their dark web leak site. Operating within the agriculture sector, Wiegaarden offers a broad spectrum of services, including graphic design, text and magazines, and multimedia design, catering to a diverse clientele that spans insurance, forensics, and hosting providers.

Company Profile and Vulnerability Analysis

Although the exact size of Wiegaarden is not detailed, indications from their official website suggest a medium-sized enterprise with a dedicated team specializing in various domains such as graphic design and multimedia design. The specific vulnerabilities exploited by the Lockbit2 ransomware group in this attack remain undisclosed. However, the incident involving Danish hosting providers CloudNordic and AzeroCloud, which led to significant data loss for their customers, implies that the ransomware group might have leveraged weaknesses within the hosting services, possibly during a data center migration or similar operations.

Lockbit2 Ransomware Group's Modus Operandi

The Lockbit2 ransomware group is notorious for its widespread attacks across different sectors worldwide. Their operations typically involve encrypting the victim's data and demanding a ransom for its release. Despite the growing threat posed by this group, Wiegaarden and the affected Danish hosting providers have opted not to pay the ransom, focusing instead on data recovery efforts. The current status of these efforts is mixed, with some servers restored but the majority of customer data irretrievably lost.

This incident underscores the critical need for comprehensive cybersecurity measures, especially during vulnerable periods such as system migrations or updates. It highlights the necessity for organizations to invest in advanced cybersecurity solutions that can detect and thwart malicious activities, implement regular data backups, establish clear response protocols, and conduct ongoing staff training to effectively manage and mitigate the impact of ransomware attacks.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.