Ransomware Attack on Brovedani Group by 8Base
Incident Date:
May 13, 2024
Overview
Title
Ransomware Attack on Brovedani Group by 8Base
Victim
Brovedani Group
Attacker
8base
Location
First Reported
May 13, 2024
Ransomware Attack on Brovedani Group by 8Base
Victim Overview
A global company specializing in precision mechanical components and special machinery for process automation, Brovedani Group, was targeted by a cyberattack orchestrated by the cybercrime group 8Base. The company operates in the Manufacturing sector and offers integrated logistics and supply chain solutions for industries such as automotive, industrial, and consumer goods.
Company Profile
Brovedani Group is a global company with over 900 employees working across multiple locations, including Italy, Slovakia, and Mexico. The company emphasizes teamwork, continuous improvement, and innovation to create value for its clients and the market. Their revenue forecast for 2024 is €107.5 million, showcasing consistent growth over the years. The company stands out for its commitment to teamwork, continuous improvement, and innovation. The company values creating a safe and healthy work environment, as well as personal growth and development for its employees.
Company Vulnerabilities
Being a global company with a diverse workforce and operating in the Manufacturing sector, Brovedani Group may have been targeted by threat actors due to the sensitive nature of the data they handle, including invoices, receipts, accounting documents, personal data, certificates, employment contracts, and more. The exposure of such confidential information can have severe repercussions for the company's brand and reputation.
Attack Overview
The cyberattack on Brovedani Group involved the deployment of ransomware by the 8Base group, resulting in the compromise of the victim's website. The attack led to the exposure of various types of sensitive data, which were fully published, indicating a significant breach of security.
Ransomware Group 8Base
The 8Base ransomware group has gained notoriety for its aggressive tactics, primarily targeting small and medium-sized businesses across sectors like manufacturing. They are known for their double-extortion tactics, where they encrypt files and steal data to pressure victims into paying the ransom. The group has been active since April 2022 and uses ransomware strains like Phobos, customized with a ".8base" extension.
Sources
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.