RansomHub Ransomware Hits Allium Interiors: Key Details & Impact

Incident Date:

August 11, 2024

World map

Overview

Title

RansomHub Ransomware Hits Allium Interiors: Key Details & Impact

Victim

Allium Interiors

Attacker

Ransomhub

Location

Auckland, New Zealand

, New Zealand

First Reported

August 11, 2024

RansomHub Ransomware Attack on Allium Interiors: A Detailed Analysis

Allium Interiors, a prominent interior design and home decor company based in Auckland, New Zealand, has recently fallen victim to a ransomware attack orchestrated by the cybercriminal group RansomHub. The attack, which was announced on August 9, has put the company in a precarious position, with significant operational and reputational risks.

Overview of Allium Interiors

Established in 2000, Allium Interiors operates both a physical store in Newmarket and an online platform. The company specializes in sourcing unique and high-quality furnishings, fabrics, wallpapers, bed linen, furniture, and home accessories from Europe, America, Australia, and New Zealand. Co-founded by Suzanne Barber and Jo Burrell, Allium Interiors is known for its innovative and inspiring design solutions, making it a standout in the interior design industry.

Details of the Ransomware Attack

RansomHub claimed responsibility for the attack via their dark web leak site, stating that they had successfully infiltrated Allium Interiors' systems. The cybercriminals exfiltrated and encrypted 31 gigabytes of data, including sensitive documents, databases, webmails, and source code. They have threatened to leak this information if a ransom is not paid within eight days. The specific ransom amount remains undisclosed, and no sample data has been released to substantiate their claims.

About RansomHub

RansomHub is a relatively new player in the ransomware landscape, believed to have roots in Russia. Operating as a Ransomware-as-a-Service (RaaS) group, RansomHub's affiliates receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, without following a specific pattern. Their ransomware strains are written in Golang, a language choice that is becoming increasingly popular among ransomware developers.

Potential Vulnerabilities and Penetration Methods

While the exact method of penetration remains unclear, common vulnerabilities that could have been exploited include outdated software, weak passwords, and lack of employee training on phishing attacks. Given RansomHub's use of Golang, it is possible that they leveraged sophisticated techniques to bypass traditional security measures. The attack on Allium Interiors highlights the importance of vigilant cybersecurity practices, especially for companies handling sensitive customer data and operating online platforms.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.