Olson Steel Inc. Targeted in Ransomware Attack by Black Basta

Incident Date:

May 5, 2024

World map

Overview

Title

Olson Steel Inc. Targeted in Ransomware Attack by Black Basta

Victim

Olson Steel Inc.

Attacker

Blackbasta

Location

San Leandro, USA

California, USA

First Reported

May 5, 2024

Ransomware Attack on Olson Steel by Black Basta

Company Profile: Olson Steel Inc.

Olson & Co Steel Inc. is a prominent player in the construction sector, specializing in steel fabrication and erection. Founded in 2002, the company is headquartered in San Leandro, California. With a workforce of 251-500 employees, Olson Steel boasts annual revenues between $100 million and $250 million. The company stands out in its industry due to its integration of technology in detailing, fabrication, and erection processes, aiming for continuous improvement and innovation.

Details of the Cyber Attack

The ransomware group Black Basta, known for its sophisticated cyber attacks, has recently targeted Olson Steel. During the attack, approximately 900 GB of sensitive data was exfiltrated, including HR and accounting records, employee details, and confidential project files such as CAD drawings. This breach not only highlights the vulnerability of Olson Steel's cybersecurity defenses but also underscores the persistent threat posed by organized cybercriminal groups.

Black Basta Ransomware Group

Emerging in early 2022, Black Basta has quickly become notorious in the cybercrime arena. The group is known for its double extortion tactics, involving data encryption and threats of public data leakage. Black Basta uses the XChaCha20 encryption algorithm and has connections with other major cybercriminal groups, suggesting a high level of sophistication and strategic cybercriminal alliances.

Potential Vulnerabilities and Attack Vectors

While specific details of the intrusion vector used in the Olson Steel attack remain undisclosed, common entry points for such attacks include phishing, exploitation of unpatched systems, or compromised credentials. Olson Steel's significant data repository and its critical role in construction projects make it an attractive target for ransomware groups seeking substantial ransom payouts.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.