RansomHub Ransomware Hits Infotexim: 1.73TB Data Breach Analysis

Incident Date:

August 7, 2024

World map

Overview

Title

RansomHub Ransomware Hits Infotexim: 1.73TB Data Breach Analysis

Victim

Infotexim

Attacker

Ransomhub

Location

San Isidro, Peru

, Peru

First Reported

August 7, 2024

RansomHub Ransomware Attack on Infotexim: A Detailed Analysis

On August 8, 2024, Infotexim, a prominent Peruvian technology services company, became the latest victim of a ransomware attack orchestrated by the notorious RansomHub group. This attack resulted in a significant data breach, compromising 1.73TB of sensitive information.

About Infotexim

Infotexim is a technology services company based in Lima, Peru, specializing in providing comprehensive technological solutions across various sectors. The company focuses on technology integration, consulting services, support and maintenance, training, and sector-specific solutions. Infotexim aims to establish itself as a leading player in the national territory by adhering to high standards of quality and innovation in its service offerings.

Infotexim's mission is to enhance operational efficiency for businesses through integrated technology solutions, including advanced IT infrastructure tailored to meet specific client needs. The company also emphasizes human capital development by providing extensive training to ensure clients' staff are well-equipped to use the technologies provided.

Attack Overview

The ransomware attack on Infotexim was claimed by RansomHub via their dark web leak site. The attack led to the compromise of 1.73TB of sensitive data, significantly impacting the company's operations. The exact method of penetration remains unclear, but it is likely that the attackers exploited vulnerabilities in Infotexim's IT infrastructure or through phishing attacks targeting employees.

About RansomHub

RansomHub is a relatively new ransomware group that has quickly made a name for itself in the cyber threat landscape. Believed to have roots in Russia, RansomHub operates as a Ransomware-as-a-Service (RaaS) group, with affiliates receiving 90% of the ransom money and the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, without following a specific pattern.

RansomHub's ransomware strains are written in Golang, a language that is becoming increasingly popular among ransomware developers. This choice of language may indicate a trend towards more sophisticated and harder-to-detect ransomware attacks in the future.

Potential Vulnerabilities

Infotexim's focus on providing comprehensive technological solutions makes it a prime target for ransomware groups like RansomHub. The company's extensive IT infrastructure and reliance on technology for daily operations present multiple entry points for attackers. Additionally, the emphasis on human capital development, while beneficial, also introduces the risk of human error, which can be exploited through phishing and social engineering attacks.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.