Medusa Ransomware Hits Belgian IT Firm Prosolit in Major Data Breach

Incident Date:

September 7, 2024

World map

Overview

Title

Medusa Ransomware Hits Belgian IT Firm Prosolit in Major Data Breach

Victim

Prosolit

Attacker

Medusa

Location

Urmond, Netherlands

, Netherlands

First Reported

September 7, 2024

Medusa Ransomware Group Targets Prosolit in Belgium

Prosolit, a Belgium-based IT services company, has recently fallen victim to a ransomware attack orchestrated by the notorious Medusa group. The attack has resulted in a significant data breach, compromising 13.07 GB of sensitive information.

About Prosolit

Established in 2004, Prosolit specializes in a variety of IT services aimed at enhancing business operations and digital presence. With over 20 years of experience, the company offers tailored solutions in custom software development, e-commerce website creation, IT infrastructure management, and maintenance services. One of their standout offerings is the proprietary Gescom software, a comprehensive commercial management tool designed to streamline business operations.

Company Size and Industry Position

Prosolit is a small to medium-sized enterprise with an estimated annual revenue of approximately $200,000. The company is headquartered in Erpent, Wallonia, Belgium, and has a presence in Urmond, Limburg, Netherlands. Despite its modest size, Prosolit has carved out a niche in the IT services sector by offering a diverse range of services, from custom software solutions to machine park management.

Vulnerabilities and Attack Overview

Prosolit's extensive involvement in custom software development and IT infrastructure management makes it a lucrative target for ransomware groups. The company's reliance on proprietary software and the handling of sensitive client data present significant vulnerabilities. The Medusa group exploited these weaknesses, leading to a substantial data breach.

About the Medusa Ransomware Group

Medusa is a ransomware group that emerged in late 2022 and operates as a Ransomware-as-a-Service (RaaS) platform. The group has been involved in various high-profile attacks across multiple sectors globally. Medusa's ransomware is designed to disable numerous applications and services, making detection and mitigation challenging. The group often demands substantial ransoms, with recent demands ranging from hundreds of thousands to millions of dollars.

Penetration Tactics

While specific details about how Medusa penetrated Prosolit's systems are not publicly available, common tactics include phishing attacks, exploiting unpatched vulnerabilities, and leveraging weak security protocols. Given Prosolit's focus on custom software and IT infrastructure, any lapses in cybersecurity measures could have provided an entry point for the attackers.

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.