lorenz attacks Biz Retek

Incident Date:

March 29, 2022

World map

Overview

Title

lorenz attacks Biz Retek

Victim

Biz Retek

Attacker

Lorenz

Location

Batavia, USA

Illinois, USA

First Reported

March 29, 2022

Biz ReTek: A Target for Ransomware Attacks

Biz ReTek, a prominent IT technology solutions provider located in Batavia, IL, has recently fallen victim to a ransomware attack perpetrated by the Lorenz group. The incident was disclosed on a dark web leak site. Specializing in comprehensive IT strategy and support services, Biz ReTek caters to the needs of small to mid-sized businesses. Their services are particularly focused on Point of Sale (POS) systems, Payment Card Industry (PCI) compliance, IT consulting, and system integration.

The company's approach to technology is business-centric, distinguishing it from other IT service providers. Biz ReTek advocates for the use of technology to fulfill the unique requirements of a business, rather than allowing technology to dictate business operations. It provides a full spectrum of technology services, including IT infrastructure management, server and computer system support, and enhancing brand identity through logo and web design services.

Biz ReTek's proficiency in POS systems and PCI compliance stems from years of dedicated experience in these areas, serving a variety of businesses. The company ensures that its IT solutions are cost-effective for businesses by aligning with their goals, budgetary limitations, and technological needs.

The ransomware attack on Biz ReTek serves as a stark reminder of the vulnerabilities faced by small to mid-sized businesses in the IT sector. Such attacks can severely disrupt operations and inflict substantial financial harm, particularly during critical business periods. To counteract these risks, it is imperative for businesses to focus on updating and fortifying remote desktop protocol (RDP) credentials, implementing two-factor authentication, and either changing the RDP port to a non-standard one or completely disabling RDP access.

Despite possessing significant IT resources and expertise in IT strategy and support, companies like Biz ReTek are not immune to cyber threats. This incident highlights the critical need for robust cybersecurity measures within the IT sector.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.