Ransomware Attack on MAH Machine Co., Inc. by BianLian Group

Incident Date:

May 23, 2024

World map

Overview

Title

Ransomware Attack on MAH Machine Co., Inc. by BianLian Group

Victim

MAH Machine

Attacker

Bianlian

Location

Cicero, USA

Illinois, USA

First Reported

May 23, 2024

Ransomware Attack on MAH Machine Co., Inc. by BianLian Group

Victim Overview

MAH Machine Co., Inc. is a precision machining company founded in 1976 by Martin and Anna Hozjan. Based in Cicero, Illinois, the company specializes in CNC machining, turning, milling, and other machining services for various industries. With a revenue of $20 million, MAH Machine Co. is known for its high-quality products, timely delivery, and personalized service, making it a reliable partner for clients in the manufacturing sector.

Company Profile

MAH Machine Co., Inc. operates from a significant facility spanning over 125,000 square feet, indicating its substantial size in the machining industry. The company's focus on quality products, timely delivery, and personalized service sets it apart from competitors, making it a standout player in the market.

Attack Overview

The recent ransomware attack on MAH Machine Co., Inc. by the BianLian group resulted in the exfiltration and encryption of 227 GB of sensitive data. This included financial records, HR data, partner, vendor, and customer information, contracts, engineering data, images and drawings, and email correspondence. The attack poses significant risks to the company's operations and reputation, highlighting the cybersecurity challenges faced by manufacturing firms.

Ransomware Group - BianLian

BianLian is a sophisticated ransomware group that has evolved from targeting individual users to launching high-profile attacks on businesses globally. The group focuses on sectors with sensitive data and financial capacity, including manufacturing, among others. BianLian distinguishes itself through its exfiltration-based extortion tactics, threatening victims with financial, business, and legal consequences if ransom demands are not met.

Penetration and Vulnerabilities

BianLian likely gained initial access to MAH Machine Co.'s systems through compromised Remote Desktop Protocol (RDP) credentials, implanting custom backdoors specific to the victim. The company's substantial size and valuable data made it an attractive target for the ransomware group. The attack underscores the importance of robust cybersecurity measures, including endpoint detection and response solutions, to mitigate the risks posed by sophisticated threat actors like BianLian.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.