lorenz attacks Laddawn Inc

Incident Date:

September 16, 2022

World map

Overview

Title

lorenz attacks Laddawn Inc

Victim

Laddawn Inc

Attacker

Lorenz

Location

Sterling, USA

Massachusets, USA

First Reported

September 16, 2022

Laddawn Inc. Suffers Ransomware Attack by Lorenz Group

Laddawn Inc., a subsidiary of Berry Global Company, recently fell victim to a ransomware attack orchestrated by the Lorenz group. This entity has been operational since 1996, boasting ISO 9001 registration and a reputation for precision and philanthropy, notably donating $1 for every online order exceeding $100.

The Lorenz ransomware group, active since February 2021, predominantly preys on small and medium-sized businesses (SMBs) within the United States, though it has also targeted entities in China and Mexico. This group employs a double-extortion scheme, initially exfiltrating data before encrypting the victim's systems and subsequently threatening to sell or publicly release the data unless a ransom is paid.

This incident underscores a growing trend among ransomware groups to target less conspicuous or monitored assets, thereby evading detection. In Laddawn's case, the attackers exploited a vulnerability in the Mitel MiVoice VoIP appliance (CVE-2022-29499) to facilitate initial access.

To counteract the threat of ransomware, it is imperative for organizations to adopt a comprehensive security strategy. This includes deploying anti-malware solutions, conducting regular security audits, educating employees on cybersecurity best practices, and establishing a solid backup and recovery protocol.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.