RansomHub Ransomware Disrupts Inglenorth Contracting Operations

Incident Date:

September 5, 2024

World map

Overview

Title

RansomHub Ransomware Disrupts Inglenorth Contracting Operations

Victim

Inglenorth Contracting

Attacker

Ransomhub

Location

Wigan, United Kingdom

, United Kingdom

First Reported

September 5, 2024

RansomHub Ransomware Attack on Inglenorth Contracting

Inglenorth Contracting, a UK-based specialist in demolition and related services, has recently fallen victim to a ransomware attack orchestrated by the cybercriminal group RansomHub. This attack has potentially compromised their operational capabilities and client data, posing significant risks to their business continuity and reputation.

About Inglenorth Contracting

Established in 1999, Inglenorth Contracting Limited operates from its headquarters in Wigan, Lancashire. The company offers a comprehensive range of services, including stand-alone demolition, site clearance, recycling, and remediation. They are particularly noted for their expertise in nuclear decommissioning and asbestos removal. Inglenorth is accredited with several quality management standards, including ISO 9001:2015, ISO 14001:2015, and ISO 45001:2018, and is a member of the National Federation of Demolition Contractors (NFDC).

Attack Overview

The ransomware attack on Inglenorth Contracting was claimed by RansomHub via their dark web leak site. The attack has disrupted the company's operations, which include critical services such as nuclear site decommissioning and asbestos removal. The breach has raised concerns about the safety and compliance of their ongoing projects, given the sensitive nature of their work.

About RansomHub

RansomHub, a Ransomware-as-a-Service (RaaS) group, emerged in February 2024. Known for its aggressive affiliate model and double extortion tactics, RansomHub encrypts victims' data and exfiltrates sensitive information to leverage ransom demands. The group has quickly gained notoriety for its speed and efficiency, targeting high-value sectors such as healthcare, financial services, and government.

Penetration and Impact

RansomHub likely penetrated Inglenorth's systems through phishing campaigns, vulnerability exploitation, or password spraying. The group's ransomware is optimized to encrypt large datasets quickly, targeting cross-platform systems including Windows, Linux, and ESXi. The attack has not only disrupted Inglenorth's operations but also exposed sensitive client data, which could have severe implications for their business relationships and compliance with industry regulations.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.