Ondozabal Group Hit by LockBit 3.0 Ransomware

Incident Date:

May 9, 2024

World map

Overview

Title

Ondozabal Group Hit by LockBit 3.0 Ransomware

Victim

Ondozabal Group

Attacker

Lockbit3

Location

Aia, Spain

, Spain

First Reported

May 9, 2024

Ransomware Attack on Ondozabal Group by LockBit 3.0

Attack Details

During the ransomware attack on ondozabal.com, LockBit 3.0 managed to exfiltrate 181 GB of data, including sensitive information like confidential agreements, personal data, and contracts. The attackers demanded a ransom, although the specific amount was not disclosed. The leaked data sample underscored the severity and extent of the breach, highlighting the impact on Ondozabal Group's operations and reputation.

Victim Profile

The victim of a recent cyberattack was the Ondozabal Group, a Spanish machinery company specializing in high-precision industrial mechanics and large-scale machining. With over 80 years of experience, the company offers integrated services such as CNC machining, metalworking, and machining of extra-large parts weighing up to 50 tons.

Company Size and Industry Standing

The Ondozabal Group falls within the range of 51-200 employees, showcasing its status as a mid-sized enterprise in the manufacturing sector. The company has diversified its activities across key sectors like aerospace, wind energy, steel, presses, and oil & gas, positioning itself as a versatile player in the industry.

Vulnerabilities and Targeting

Due to its advanced operations and use of sophisticated software like NX Siemens CAM and SolidWorks, Ondozabal Group's interconnected systems, including ERP & MRP and industrial communication software, presented vulnerabilities that were exploited by threat actors. The company's extensive data connectivity and control over production processes made it an attractive target for cybercriminals seeking to disrupt operations and extort ransom.

LockBit 3.0 Ransomware Group

The LockBit 3.0 ransomware group, also known as LockBit Black, is a Ransomware-as-a-Service (RaaS) entity that has evolved from previous LockBit versions. Notable for its advanced encryption techniques, obfuscation, and lateral movement capabilities within networks, LockBit 3.0 has targeted a wide range of organizations globally, including major companies like Boeing and ICBC.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.