Medusa Ransomware Strikes BELL DATA in Major Cyberattack

Incident Date:

September 30, 2024

World map

Overview

Title

Medusa Ransomware Strikes BELL DATA in Major Cyberattack

Victim

BELL DATA, Inc

Attacker

Medusa

Location

Tokyo, Japan

, Japan

First Reported

September 30, 2024

Medusa Ransomware Group Targets BELL DATA, Inc.

The Medusa ransomware group has claimed responsibility for a significant cyberattack on BELL DATA, Inc., a Japanese company known for its IT infrastructure solutions. This attack underscores the growing threat of ransomware groups targeting critical sectors worldwide.

About BELL DATA, Inc.

BELL DATA, Inc. is a medium-sized enterprise with 271 employees, including 139 engineers, and reported a turnover of approximately $72 million USD as of September 2023. Established in 1991, the company specializes in providing IT infrastructure solutions, including hardware and software sales, data center services, and cloud outsourcing. Their Power-Cloud service for AS/400 systems is particularly notable. BELL DATA's commitment to high standards is reflected in its numerous certifications, including IBM and Cisco credentials.

Attack Overview

The Medusa ransomware group has listed BELL DATA on its dark web leak site, demanding a ransom of $300,000. The attackers claim to have accessed sensitive company data and have threatened to release it if their demands are not met by October 9. BELL DATA confirmed the breach on September 19, indicating that some systems were compromised. This attack highlights the vulnerabilities that even well-established IT companies face in the current cyber threat landscape.

Medusa Ransomware Group Profile

Emerging in late 2022, Medusa operates as a Ransomware-as-a-Service platform, allowing affiliates to launch attacks using its sophisticated ransomware. The group has been involved in high-profile attacks across various sectors, including education and healthcare. Medusa's ransomware is known for disabling applications and shadow copies, making recovery efforts challenging. Their global reach and aggressive tactics distinguish them from other ransomware groups.

Potential Vulnerabilities

BELL DATA's focus on cloud-based solutions and IT infrastructure makes it a lucrative target for ransomware groups like Medusa. The company's extensive data handling and integration services could have been exploited through vulnerabilities in their network or cloud systems. The attack on BELL DATA serves as a stark reminder of the importance of cybersecurity measures, especially for companies handling sensitive data.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.