LockBit3 Ransomware Attack on B&S Group Limited

Incident Date:

May 27, 2024

World map



LockBit3 Ransomware Attack on B&S Group Limited


B&S Group Limited




London, United Kingdom

, United Kingdom

First Reported

May 27, 2024

Ransomware Attack on B&S Group Limited by LockBit3

Company Overview

B&S Group Limited, operating in the Healthcare Services sector, is one of the largest short-line pharmaceutical distributors in the UK. They serve over 5,000 customers daily, providing a comprehensive range of pharmaceutical products and exceptional services to community pharmacies throughout the country. The company is dedicated to quality, safety, and regulatory compliance, with state-of-the-art warehousing facilities and a knowledgeable team supporting their operations.

Company Standout

B&S Group distinguishes itself in the industry through its commitment to customer satisfaction, quality, and sustainability. They offer a diverse range of products and services, including healthcare products, unlicensed medicines, and consumer health products. The company has received certifications such as ISO 9001 and collaborates with organizations promoting responsible practices.

Company Vulnerabilities

Despite its strong reputation and commitment to quality, B&S Group's expansive network and strategic alliances may have made it a target for threat actors like the LockBit3 ransomware group. The company's large customer base and critical role in the healthcare supply chain could have attracted cybercriminals seeking to disrupt operations and extort ransom payments.

Attack Overview

B&S Group Limited fell victim to a ransomware attack by the LockBit3 group. The attackers successfully penetrated the company's systems, leading to the exposure of sample data. The ransomware group, known for its advanced capabilities and evasive tactics, encrypted files, modified filenames, and dropped a ransom note on the victim's desktop.

Ransomware Group Details

The LockBit3 ransomware group, an evolution of the LockBit group, operates under a Ransomware-as-a-Service (RaaS) model. LockBit3, also known as LockBit Black, is considered one of the most dangerous and disruptive ransomware threats currently active. The group actively recruits affiliates and targets a wide range of businesses and critical infrastructure organizations globally.

How the Attack Occurred

LockBit3's advanced features, including the ability to move laterally through a network and cover its tracks, likely enabled the ransomware group to infiltrate B&S Group's systems. The heavily obfuscated nature of LockBit3 makes it challenging for security researchers to analyze and defend against, allowing the group to persist in its malicious activities and target high-profile organizations like B&S Group.


Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.