RansomHub Ransomware Attack Disrupts Operations at Metalfrio Solutions S.A.

Incident Date:

July 18, 2024

World map

Overview

Title

RansomHub Ransomware Attack Disrupts Operations at Metalfrio Solutions S.A.

Victim

Metalfrio Solutions S.A.

Attacker

Ransomhub

Location

São Paulo, Brazil

, Brazil

First Reported

July 18, 2024

RansomHub Ransomware Attack on Metalfrio Solutions S.A.

Overview of Metalfrio Solutions S.A.

Metalfrio Solutions S.A. is a prominent Brazilian company specializing in commercial refrigeration solutions. The company manufactures and distributes refrigeration equipment for beverages, ice cream, and frozen goods. Metalfrio operates globally, with significant manufacturing facilities in Turkey and Mexico, producing hundreds of thousands of units annually. The company is known for its innovative products, robust manufacturing capabilities, and commitment to sustainability.

Details of the Ransomware Attack

On July 14, 2024, Metalfrio Solutions S.A. reported a ransomware attack orchestrated by the ransomware group RansomHub. The attack affected parts of Metalfrio's systems in both Brazil and Mexico, causing significant operational disruptions. Metalfrio promptly activated its security protocols, isolating its systems to prevent further damage. Fortunately, there has been no evidence of data breaches involving customer, supplier, or personal information. The company is currently focused on restoring normal operations and ensuring the security of its systems.

About RansomHub

RansomHub is a relatively new ransomware group that has quickly made a name for itself in the cyber threat landscape. Believed to have roots in Russia, RansomHub operates as a Ransomware-as-a-Service (RaaS) group, with affiliates receiving 90% of the ransom money. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, and is known for its ransomware strains written in Golang, a trend in the ransomware world.

Potential Vulnerabilities

Metalfrio's extensive global operations and reliance on interconnected systems may have made it a target for RansomHub. The company's significant manufacturing facilities and comprehensive service network could present multiple entry points for cyber attackers. RansomHub's sophisticated tactics, including exploiting vulnerabilities and leveraging data leaks, likely played a role in penetrating Metalfrio's defenses.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.