RansomHub Ransomware Hits Lowe-Martin Group, 2TB Data Stolen

Incident Date:

August 10, 2024

World map

Overview

Title

RansomHub Ransomware Hits Lowe-Martin Group, 2TB Data Stolen

Victim

Lowe-Martin Group

Attacker

Ransomhub

Location

Mississauga, Canada

, Canada

First Reported

August 10, 2024

RansomHub Ransomware Attack on Lowe-Martin Group

The Lowe-Martin Group, a prominent Canadian business services company specializing in printing, fulfillment, and e-commerce solutions, has fallen victim to a significant ransomware attack. The attack, claimed by the ransomware group RansomHub, has resulted in the theft of over 2 terabytes of confidential client data.

About Lowe-Martin Group

Established in 1908, Lowe-Martin Group operates primarily out of Ottawa and Toronto, providing a wide range of services including digital printing, offset printing, large format printing, warehousing, inventory management, and order processing. The company is recognized for its commitment to quality and environmentally progressive practices, employing advanced technologies like HP Latex Printing Technologies. With approximately 193 employees and an annual revenue of $78.8 million, Lowe-Martin Group is a key player in the Canadian market.

Attack Overview

The ransomware attack occurred on July 14, 2024, and was orchestrated by RansomHub. Following the breach, RansomHub released a statement on the dark web, criticizing Lowe-Martin's cyber insurance provider, Boxx Insurance, for failing to provide the expected compensation and support. The insurance company allegedly refused to honor the claim, citing minor technicalities, leaving Lowe-Martin struggling to manage the financial fallout and address the damage caused to their clients.

RansomHub: The Ransomware Group

RansomHub is a relatively new ransomware group believed to have roots in Russia. Operating as a Ransomware-as-a-Service (RaaS) group, RansomHub's affiliates receive 90% of the ransom money, with the remaining 10% going to the main group. The group has targeted various countries, including the US, Brazil, Indonesia, and Vietnam, and has been known to target healthcare-related institutions. RansomHub's ransomware strains are written in Golang, a language choice that is becoming increasingly popular among ransomware developers.

Penetration and Vulnerabilities

While the exact method of penetration remains unclear, it is likely that RansomHub exploited vulnerabilities in Lowe-Martin's cybersecurity infrastructure. The group's use of Golang-written ransomware strains suggests a sophisticated approach, potentially bypassing traditional security measures. The incident highlights the importance of vigilant cybersecurity practices and the potential pitfalls of relying solely on cyber insurance for protection.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.