RansomHub Ransomware Breach Exposes Sensitive Data at Banham Poultry Ltd

Incident Date:

August 21, 2024

World map

Overview

Title

RansomHub Ransomware Breach Exposes Sensitive Data at Banham Poultry Ltd

Victim

Banham Poultry Ltd

Attacker

Ransomhub

Location

Attleborough, United Kingdom

, United Kingdom

First Reported

August 21, 2024

RansomHub Ransomware Attack on Banham Poultry Ltd

Banham Poultry Ltd, a prominent British poultry producer based in Attleborough, Norfolk, has recently fallen victim to a ransomware attack orchestrated by the RansomHub group. The attack, which occurred on August 18, 2024, has compromised 50 GB of sensitive data, including National Insurance numbers, passport copies, and bank details of staff members.

About Banham Poultry Ltd

Banham Poultry Ltd is a significant player in the UK poultry market, accounting for approximately 7% of the total production. The company specializes in the processing and supply of chicken products primarily for the fresh retail sector. With an annual turnover estimated at around £100 million, Banham Poultry employs over 1,000 individuals. The company operates a comprehensive supply chain, including its own hatchery, and adheres to stringent standards such as the Assured Chicken Production Scheme, ensuring high-quality and welfare standards.

Attack Overview

The ransomware attack by RansomHub resulted in the theft of sensitive personal information from Banham Poultry's systems. The group has threatened to publish the stolen data within the next 3-4 days. In response, Banham Poultry promptly shut down its systems and enlisted external forensic specialists to investigate the breach. Despite the attack, factory operations remain unaffected, and employees are receiving their pay as usual. The company is advising its staff on credit monitoring and fraud detection and has reported the incident to the Information Commissioner's Office (ICO).

About RansomHub

RansomHub is a relatively new ransomware group believed to have roots in Russia. Operating as a Ransomware-as-a-Service (RaaS) group, RansomHub's affiliates receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, and has a history of targeting healthcare-related institutions. RansomHub's ransomware strains are written in Golang, a language choice that is becoming increasingly popular among ransomware developers.

Potential Vulnerabilities

Banham Poultry's significant size and the sensitive nature of the data it handles make it an attractive target for ransomware groups like RansomHub. The company's comprehensive supply chain and large workforce mean that any disruption could have widespread implications. The attack highlights the importance of stringent cybersecurity measures, particularly for companies handling sensitive personal information.

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.