Medusa Ransomware Strikes BELL DATA in Major Cyberattack
Incident Date:
September 30, 2024
Overview
Title
Medusa Ransomware Strikes BELL DATA in Major Cyberattack
Victim
BELL DATA, Inc
Attacker
Medusa
Location
First Reported
September 30, 2024
Medusa Ransomware Group Targets BELL DATA, Inc.
The Medusa ransomware group has claimed responsibility for a significant cyberattack on BELL DATA, Inc., a Japanese company known for its IT infrastructure solutions. This attack underscores the growing threat of ransomware groups targeting critical sectors worldwide.
About BELL DATA, Inc.
BELL DATA, Inc. is a medium-sized enterprise with 271 employees, including 139 engineers, and reported a turnover of approximately $72 million USD as of September 2023. Established in 1991, the company specializes in providing IT infrastructure solutions, including hardware and software sales, data center services, and cloud outsourcing. Their Power-Cloud service for AS/400 systems is particularly notable. BELL DATA's commitment to high standards is reflected in its numerous certifications, including IBM and Cisco credentials.
Attack Overview
The Medusa ransomware group has listed BELL DATA on its dark web leak site, demanding a ransom of $300,000. The attackers claim to have accessed sensitive company data and have threatened to release it if their demands are not met by October 9. BELL DATA confirmed the breach on September 19, indicating that some systems were compromised. This attack highlights the vulnerabilities that even well-established IT companies face in the current cyber threat landscape.
Medusa Ransomware Group Profile
Emerging in late 2022, Medusa operates as a Ransomware-as-a-Service platform, allowing affiliates to launch attacks using its sophisticated ransomware. The group has been involved in high-profile attacks across various sectors, including education and healthcare. Medusa's ransomware is known for disabling applications and shadow copies, making recovery efforts challenging. Their global reach and aggressive tactics distinguish them from other ransomware groups.
Potential Vulnerabilities
BELL DATA's focus on cloud-based solutions and IT infrastructure makes it a lucrative target for ransomware groups like Medusa. The company's extensive data handling and integration services could have been exploited through vulnerabilities in their network or cloud systems. The attack on BELL DATA serves as a stark reminder of the importance of cybersecurity measures, especially for companies handling sensitive data.
Sources
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.