Olson Steel Inc. Targeted in Ransomware Attack by Black Basta
Incident Date:
May 5, 2024
Overview
Title
Olson Steel Inc. Targeted in Ransomware Attack by Black Basta
Victim
Olson Steel Inc.
Attacker
Blackbasta
Location
First Reported
May 5, 2024
Ransomware Attack on Olson Steel by Black Basta
Company Profile: Olson Steel Inc.
Olson & Co Steel Inc. is a prominent player in the construction sector, specializing in steel fabrication and erection. Founded in 2002, the company is headquartered in San Leandro, California. With a workforce of 251-500 employees, Olson Steel boasts annual revenues between $100 million and $250 million. The company stands out in its industry due to its integration of technology in detailing, fabrication, and erection processes, aiming for continuous improvement and innovation.
Details of the Cyber Attack
The ransomware group Black Basta, known for its sophisticated cyber attacks, has recently targeted Olson Steel. During the attack, approximately 900 GB of sensitive data was exfiltrated, including HR and accounting records, employee details, and confidential project files such as CAD drawings. This breach not only highlights the vulnerability of Olson Steel's cybersecurity defenses but also underscores the persistent threat posed by organized cybercriminal groups.
Black Basta Ransomware Group
Emerging in early 2022, Black Basta has quickly become notorious in the cybercrime arena. The group is known for its double extortion tactics, involving data encryption and threats of public data leakage. Black Basta uses the XChaCha20 encryption algorithm and has connections with other major cybercriminal groups, suggesting a high level of sophistication and strategic cybercriminal alliances.
Potential Vulnerabilities and Attack Vectors
While specific details of the intrusion vector used in the Olson Steel attack remain undisclosed, common entry points for such attacks include phishing, exploitation of unpatched systems, or compromised credentials. Olson Steel's significant data repository and its critical role in construction projects make it an attractive target for ransomware groups seeking substantial ransom payouts.
Sources
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.