Ransomware Attack on Matadero de Gijón: A Cybersecurity Threat

Incident Date:

May 21, 2024

World map

Overview

Title

Ransomware Attack on Matadero de Gijón: A Cybersecurity Threat

Victim

Matadero de Gijón

Attacker

Ransomhub

Location

Gijón, Spain

, Spain

First Reported

May 21, 2024

Ransomware Attack on Matadero de Gijón by RansomHub

Victim Overview

Matadero de Gijón, a meat processing company based in Spain, was targeted in a ransomware attack by the cybercrime group RansomHub in May 2024. The company, Sociedad de Explotación del Matadero de Gijón SL, is dedicated to the slaughter and processing of various types of livestock, as well as the sale of meat and related products. Located in Gijón, Asturias, Spain, the company operates as a cultural center promoting contemporary art and culture through exhibitions, performances, workshops, and events.

Company Profile

The company's standout services include the slaughter and processing of various types of livestock, including beef, pork, and sheep. Matadero de Gijón stands out in the meat processing and distribution industry in Spain by providing high-quality meat products and services.

Attack Overview

RansomHub attackers exfiltrated 400 GB of critical data from Matadero de Gijón, gaining access to the company's SCADA control system and encrypting backups. The attackers have leaked a sample of the compromised data, although the ransom demand details have not been disclosed. This incident highlights the vulnerability of industrial control systems to cyberattacks, posing significant risks to operational integrity and data security.

Ransomware Group - RansomHub

RansomHub is a new ransomware group that has emerged in the cyber threat landscape, distinguishing itself by making claims and backing them up with data leaks. The group operates as a Ransomware-as-a-Service (RaaS) group, with affiliates receiving 90% of the ransom money and the remaining 10% going to the main group. RansomHub has targeted various countries without following a specific pattern, including the US, Brazil, Indonesia, and Vietnam.

How the Attack Happened

The group's ransomware strains are written in Golang, a relatively new trend in the ransomware world. The choice of this language may indicate a step towards future trends in ransomware attacks. The attackers could have penetrated Matadero de Gijón's systems through vulnerabilities in their network security or through social engineering tactics to gain unauthorized access to their SCADA control system.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.