RansomHub Strikes: The Cyberattack on POLARIS INFORMATICA Y COMUNICACIONES

Incident Date:

April 27, 2024

World map

Overview

Title

RansomHub Strikes: The Cyberattack on POLARIS INFORMATICA Y COMUNICACIONES

Victim

POLARIS INFORMATICA Y COMUNICACIONES

Attacker

Ransomhub

Location

Madrid, Spain

, Spain

First Reported

April 27, 2024

Ransomware Attack on POLARIS INFORMATICA Y COMUNICACIONES by RansomHub

Overview of the Attack

POLARIS INFORMATICA Y COMUNICACIONES, a Spanish technology solutions provider, was recently targeted by the emerging ransomware group RansomHub. The attack involved the exfiltration of approximately 165 GB of data from the company's systems. This incident was publicly disclosed on RansomHub's dark web leak site, where they claimed responsibility and hinted at the presence of potentially unlicensed software within the stolen data.

Company Profile

Founded in 1996 and based in Madrid, Spain, Polaris specializes in custom application development, website design, and IT consulting. The company employs between 20-49 professionals and generates an estimated revenue of $3 million annually. Their expertise in responsive and innovative technology solutions for various sectors makes them a notable player in the Strategic Management Services, Computer Equipment & Peripherals, and Manufacturing industries.

Targeting and Vulnerabilities

The choice of this company as a target by RansomHub could be attributed to several factors. The company's significant data pool, including proprietary software and client information, presents a lucrative target for ransomware operators. Additionally, the presence of potentially unlicensed software as suggested by RansomHub could indicate lapses in software management and security practices, making them more vulnerable to cyber-attacks.

RansomHub Group Profile

RansomHub operates as a Ransomware-as-a-Service (RaaS) model, primarily targeting various international entities without a clear pattern. Their ransomware strains are noted for being developed in Golang, a choice that aligns with recent trends in the cyber threat landscape.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.