Raffmetal Spa Hit by DragonForce Ransomware Attack: 149GB Data Compromised

Incident Date:

July 8, 2024

World map

Overview

Title

Raffmetal Spa Hit by DragonForce Ransomware Attack: 149GB Data Compromised

Victim

Raffmetal Spa

Attacker

Dragonforce

Location

Casto, Italy

, Italy

First Reported

July 8, 2024

Raffmetal Spa Targeted by DragonForce Ransomware Attack

Overview of Raffmetal Spa

Raffmetal Spa, headquartered in Valsabbia, Italy, is Europe's largest producer of aluminum alloys for remelting. Established in 1976 and part of the Silmar Group, the company operates several advanced production facilities covering approximately 145,000 square meters. Raffmetal specializes in recycling aluminum scrap into high-quality secondary alloys, with a strong commitment to sustainability and innovation. Their SILVAL aluminum alloys, derived from recycled materials, are particularly popular in the automotive sector for their low carbon footprint.

Details of the Attack

The ransomware group DragonForce has claimed responsibility for a recent cyberattack on Raffmetal Spa. The attackers reportedly compromised around 149.71 GB of sensitive data and are threatening to release this information publicly if their demands are not met within 11 days. The breach is currently under investigation, and Raffmetal is working to mitigate the effects and strengthen its cybersecurity measures.

About DragonForce Ransomware Group

DragonForce is a relatively new ransomware group that emerged in late 2023. They are known for using double extortion tactics, encrypting victims' data and exfiltrating sensitive information, which they threaten to release publicly if the ransom is not paid. The group has claimed several high-profile attacks across various industries and countries. Their ransomware code is based on a leaked builder from the infamous LockBit ransomware group, suggesting a sophisticated approach to their operations.

Potential Vulnerabilities

Raffmetal's advanced technological infrastructure, while a strength, may also present vulnerabilities that can be exploited by sophisticated threat actors like DragonForce. The company's extensive use of continuous casting technology and rigorous scrap treatment processes require robust cybersecurity measures to protect against potential breaches. The attack underscores the importance of continuous improvement in cybersecurity practices, especially for companies operating in critical sectors like manufacturing and recycling.

Conclusion

The ransomware attack on Raffmetal Spa by DragonForce highlights the growing threat of cyberattacks on critical industries. As Raffmetal works to address the breach and enhance its cybersecurity, the incident serves as a stark reminder of the need for vigilance and robust security measures in the face of evolving cyber threats.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.