RansomHub Targets LIDER IT Consulting in Ransomware Attack

Incident Date:

June 17, 2024

World map

Overview

Title

RansomHub Targets LIDER IT Consulting in Ransomware Attack

Victim

LIDER IT Consulting

Attacker

Ransomhub

Location

Madrid, Spain

, Spain

First Reported

June 17, 2024

Ransomware Attack on LIDER IT Consulting by RansomHub

Company Profile: LIDER IT Consulting

LIDER IT Consulting, a prominent technology consulting firm based in Spain, has been instrumental in enhancing business management through expert consulting and integrated solutions for over three decades. With more than 100 employees and 8 regional offices, LIDER IT Consulting specializes in IT infrastructure and develops standardized solutions. Their extensive service offerings include management programs, treasury management, CMMS, MES, computer maintenance, and web services, positioning them as a leader in the IT consulting sector in Spain.

Details of the Ransomware Attack

On June 18, 2024, LIDER IT Consulting fell victim to a ransomware attack orchestrated by the emerging cyber threat group, RansomHub. The attack was first identified through anomalies in network traffic and system performance, leading to the discovery of encrypted files and ransom notes demanding payment for data decryption. This incident highlights potential vulnerabilities in LIDER IT Consulting's cybersecurity measures, possibly exploited by the attackers.

RansomHub: The Perpetrator's Profile

RansomHub, a ransomware group with suspected roots in Russia, operates on a Ransomware-as-a-Service (RaaS) model. This group has been active in targeting various sectors globally without a specific pattern, distinguishing itself by using Golang for ransomware development. RansomHub's strategy includes leaking data on dark web platforms to pressure victims into paying the ransom, a tactic that was evidently employed in the attack on LIDER IT Consulting.

Potential Breach Points and Security Implications

The breach could have been facilitated through spear-phishing, exploiting unpatched systems, or other common entry points for ransomware. Given LIDER IT Consulting's extensive involvement in IT and web services, it is crucial for the firm to reassess and fortify its cybersecurity framework to thwart future attacks and safeguard sensitive client data.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.