RansomHub Ransomware Hits Golfoy India: Key Details and Impact

Incident Date:

August 9, 2024

World map

Overview

Title

RansomHub Ransomware Hits Golfoy India: Key Details and Impact

Victim

Golfoy India

Attacker

Ransomhub

Location

Chandigarh, India

, India

First Reported

August 9, 2024

RansomHub Ransomware Attack on Golfoy India: A Detailed Analysis

Golfoy India, a prominent online retailer of golf equipment and accessories, has recently fallen victim to a ransomware attack orchestrated by the notorious group RansomHub. This attack has significant implications for the company's operations and data security.

About Golfoy India

Founded in 2020, Golfoy India has quickly established itself as a leading online retailer in the golf industry. The company offers a wide range of golf clubs, balls, apparel, shoes, bags, and other gear from top brands. Headquartered in New Delhi, Golfoy is known for its exceptional customer service and seamless shopping experience. The company's website, Golfoy, is user-friendly and caters to both professional and amateur golfers.

Attack Overview

RansomHub, a ransomware group believed to have roots in Russia, has claimed responsibility for the attack on Golfoy India. The attackers infiltrated Golfoy's systems, gaining access to all files and webmails. They encrypted and exfiltrated sensitive information from the company's servers. RansomHub is demanding a ransom payment, threatening to publicly leak private documents, databases, webmails, and source code if their demands are not met. This breach poses a significant risk to Golfoy's operations and data security.

About RansomHub

RansomHub is a relatively new player in the ransomware landscape, distinguishing itself by making claims and backing them up with data leaks. Operating as a Ransomware-as-a-Service (RaaS) group, RansomHub's affiliates receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, without following a specific pattern. Their ransomware strains are written in Golang, a language choice that is becoming increasingly popular among ransomware developers.

Potential Vulnerabilities

Golfoy India's rapid growth and strong online presence may have made it an attractive target for threat actors like RansomHub. The company's reliance on digital infrastructure for its operations and customer interactions could have exposed vulnerabilities that the attackers exploited. The use of advanced ransomware strains written in Golang suggests that RansomHub is leveraging cutting-edge techniques to penetrate and compromise systems.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.