RansomHub Ransomware Hits Dutch Retailer NRcollecties.nl, 8GB Data Compromised

Incident Date:

August 17, 2024

World map

Overview

Title

RansomHub Ransomware Hits Dutch Retailer NRcollecties.nl, 8GB Data Compromised

Victim

NRcollecties.nl

Attacker

Ransomhub

Location

Hilversum, Netherlands

, Netherlands

First Reported

August 17, 2024

RansomHub Ransomware Attack on NRcollecties.nl

NRcollecties.nl, an online retail platform based in the Netherlands, has recently fallen victim to a ransomware attack orchestrated by the notorious RansomHub group. The attack has resulted in the compromise of over 8GB of sensitive data, including documents, databases, and source code. The attackers have threatened to release this information within a week if their demands are not met.

About NRcollecties.nl

Established in 2014, NRcollecties.nl specializes in the sale of Indian jewelry, women's bags, and candle holders, catering to customers in the Netherlands and Belgium. The company prides itself on offering a diverse range of products that blend traditional Indian designs with European aesthetics. The platform operates primarily through its e-commerce site, emphasizing customer satisfaction and community engagement through review platforms.

Company Vulnerabilities

NRcollecties.nl's reliance on its e-commerce platform makes it particularly vulnerable to cyberattacks. The company's focus on customer satisfaction and community engagement means that any data breach could severely impact its reputation and customer trust. The lack of publicly available information about the company's size and revenue further complicates its ability to defend against sophisticated cyber threats.

Attack Overview

The ransomware attack on NRcollecties.nl was claimed by RansomHub via their dark web leak site. The attackers have obtained over 8GB of sensitive data and are threatening to release it unless their demands are met. This incident highlights the growing threat of ransomware attacks on small to medium-sized enterprises in the retail sector.

About RansomHub

RansomHub is a relatively new player in the ransomware landscape, believed to have roots in Russia. Operating as a Ransomware-as-a-Service (RaaS) group, RansomHub affiliates receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries and sectors, including healthcare and retail, without following a specific pattern. Their ransomware strains are written in Golang, a trend that is becoming increasingly popular among ransomware developers.

Penetration Methods

While the exact method of penetration in the NRcollecties.nl attack is not publicly known, common tactics include phishing emails, exploiting unpatched software vulnerabilities, and leveraging weak security protocols. The use of Golang in their ransomware strains suggests a sophisticated approach, potentially making it harder for traditional security measures to detect and mitigate the attack.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.