ransomexx attacks Bombardier Recreational Products (BRP) - BONUS CONTENT (!!!)

Incident Date:

August 24, 2022

World map

Overview

Title

ransomexx attacks Bombardier Recreational Products (BRP) - BONUS CONTENT (!!!)

Victim

Bombardier Recreational Products (BRP) - BONUS CONTENT (!!!)

Attacker

Ransomexx

Location

Québec, Canada

Ontario, Canada

First Reported

August 24, 2022

RansomEXX Ransomware Targets Bombardier Recreational Products

Overview of the Attack

Bombardier Recreational Products (BRP), a leading entity in the powersports vehicles and propulsion systems industry, recently fell victim to a cyberattack by the RansomEXX ransomware group. This incident has put a spotlight on the vulnerabilities within the Manufacturing sector. BRP's portfolio includes renowned brands like Ski-Doo and Lynx snowmobiles, Sea-Doo watercraft and pontoons, Can-Am vehicles, Alumacraft and Quintrex boats, Manitou pontoons, and Rotax marine propulsion systems. The company boasts a workforce of over 20,000 employees and reports annual sales reaching CA$7.6 billion.

Details of the Cyberattack

The RansomEXX ransomware group, known for its human-operated attacks, infiltrated BRP's systems and exfiltrated 29.9GB of sensitive files. The stolen data encompassed non-disclosure agreements, passports, IDs, contracts, and supply agreements. Notably, the breach did not compromise customer data but did expose employee login credentials. In response, BRP has directed its employees to update their passwords to mitigate further risks.

The cyberattack prompted a temporary cessation of BRP's operations, potentially affecting transactions with customers and suppliers. Nevertheless, the company managed to resume production at its facilities in Valcourt (Canada), Rovaniemi (Finland), Sturtevant (USA), and Gunskirchen (Austria) after a week-long interruption. BRP has initiated a recovery plan aimed at minimizing the financial fallout from the cyberattack and maintains that it will not affect its year-end financial projections.

Company's Response and Cybersecurity Measures

In the aftermath of the attack, BRP has refrained from publicly discussing any interactions or possible negotiations with the cybercriminals, including the topic of ransom payments. The company has adopted a cautious stance, focusing on the significance of cybersecurity and the dedication of its expert team to safeguard the integrity of its systems and data.

The incident involving BRP underscores the persistent threat of ransomware facing businesses across various sectors. It highlights the critical importance of implementing robust cybersecurity defenses and adopting a proactive stance to counteract these risks effectively.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.