Osaka Motorcycle Business Cooperative Hit by 8Base Ransomware

Incident Date:

May 27, 2024

World map

Overview

Title

Osaka Motorcycle Business Cooperative Hit by 8Base Ransomware

Victim

Osaka Motorcycle Business Cooperative

Attacker

8base

Location

Higashiosaka, Japan

, Japan

First Reported

May 27, 2024

Ransomware Attack on Osaka Motorcycle Business Cooperative

Company Profile

The Osaka Motorcycle Business Cooperative, also known as AJ Osaka, is a motorcycle business cooperative located in Osaka, Japan. They provide a wide range of services related to motorcycles, including registration, group purchases, loan management, and the publication of industry-related magazines and newspapers.

Company Standout

AJ Osaka is notable for its comprehensive services related to motorcycles and its active role in organizing events and contests to promote motorcycle safety and community engagement.

Vulnerabilities

As a cooperative that handles sensitive data such as registration information, financial transactions, and personal files, AJ Osaka is particularly vulnerable to cyber attacks, especially from threat actors like ransomware groups.

Ransomware Attack Overview

The 8Base ransomware group targeted the Osaka Motorcycle Business Cooperative, resulting in the leak of sensitive documents including receipts, accounting documents, employment contracts, and personal files. This attack has exposed the cooperative to potential financial and reputational damage.

Ransomware Group Profile

The 8Base ransomware group has gained notoriety for its aggressive tactics, targeting small and medium-sized businesses across various sectors. They are known for their double-extortion methods, where they encrypt files and threaten to release stolen data if the ransom is not paid.

Group Distinguishing Factors

8Base distinguishes itself through its use of customized ransomware strains, such as the Phobos variant with a ".8base" extension. They have been particularly active in recent months, positioning themselves as a top-performing ransom group.

Penetration Methods

8Base is believed to spread through phishing emails, exploit kits, and drive-by downloads. Their use of double-extortion tactics adds pressure on victims to comply with ransom demands.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.