Ransomware Attack on Erne AG by INC Ransom Group: Details and Impact

Incident Date:

July 13, 2024

World map

Overview

Title

Ransomware Attack on Erne AG by INC Ransom Group: Details and Impact

Victim

Erne AG

Attacker

Inc Ransom

Location

Laufenburg, Switzerland

, Switzerland

First Reported

July 13, 2024

Ransomware Attack on Erne AG by INC Ransom Group

Overview of Erne AG

Erne AG, operating under the domain erne.net, is a prominent company in the construction sector, specializing in modern wood construction and innovative building solutions. Headquartered in Laufenburg, AARGAU, Switzerland, Erne AG is known for its advanced technology and sustainable practices in the construction industry. The company has been recognized for its expertise in creating hybrid wood-concrete buildings and office spaces, showcasing its commitment to innovation and sustainability.

Details of the Ransomware Attack

On July 16, 2024, Erne AG fell victim to a ransomware attack orchestrated by the cybercriminal group INC Ransom. The attack involved the encryption and theft of sensitive data, with the threat of public disclosure if ransom demands were not met. The specifics of the data breach, including the size of the leak, remain under investigation. This incident highlights the vulnerabilities that even technologically advanced companies like Erne AG face in the evolving landscape of cyber threats.

About INC Ransom Group

INC Ransom is a sophisticated ransomware group known for its targeted attacks on corporate and organizational networks. The group employs advanced techniques such as spear-phishing campaigns and exploiting vulnerabilities like CVE-2023-3519 in Citrix NetScaler. Their modus operandi includes double extortion, where they not only encrypt data but also steal it, threatening to release it publicly to increase pressure on victims. INC Ransom has targeted various industries, including healthcare, education, government entities, and technology companies, making them a formidable threat in the cybersecurity landscape.

Penetration and Impact

The exact method of penetration in the Erne AG attack is not yet disclosed, but it is likely that INC Ransom used a combination of spear-phishing and exploiting known vulnerabilities. Companies in the construction sector, despite their technological advancements, can be vulnerable due to the extensive use of interconnected systems and third-party collaborations. This attack underscores the importance of robust cybersecurity measures and continuous monitoring to defend against sophisticated threat actors like INC Ransom.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.