Ransomware Attack on Matki by Cactus Group Exposes Data

Incident Date:

October 8, 2024

World map

Overview

Title

Ransomware Attack on Matki by Cactus Group Exposes Data

Victim

Matki

Attacker

Cactus

Location

Yate, United Kingdom

, United Kingdom

First Reported

October 8, 2024

Ransomware Attack on Matki: A Deep Dive into the Cactus Ransomware Group's Latest Target

Matki, a renowned British manufacturer of luxury showering products, has recently been targeted by the Cactus ransomware group. This attack has resulted in the exfiltration of approximately 267 GB of sensitive data, posing significant operational and reputational risks to the company.

About Matki

Founded in 1971 and headquartered in Bristol, UK, Matki specializes in the design and manufacture of luxury bathroom products, including bespoke shower screens, trays, and brassware. The company is distinguished by its commitment to craftsmanship and innovation, with products crafted in the UK. Matki employs over 100 individuals, contributing to its reputation for high-quality products and exceptional customer service. The company's bespoke offerings and dedication to quality craftsmanship position it as a leader in the luxury bathroom market.

Details of the Attack

The Cactus ransomware group claims to have breached Matki's systems, compromising a wide array of critical information. The stolen data includes personally identifiable information, database backups, financial documents, and personal data of both executives and employees. Additionally, corporate confidential data and internal correspondence have been compromised. This breach highlights the vulnerabilities that even well-established companies face in the evolving landscape of cyber threats.

The Cactus Ransomware Group

Identified in March 2023, the Cactus ransomware group has quickly become a notable player in the ransomware landscape. It employs sophisticated tactics, including exploiting vulnerabilities in VPN appliances and leveraging phishing attacks. Cactus is known for its double-extortion strategy, encrypting data and threatening to leak sensitive information if the ransom is not paid. The group distinguishes itself through its rapid adaptation to newly discovered vulnerabilities and its ability to evade detection by encrypting its own binary.

Potential Vulnerabilities

Matki's reliance on bespoke craftsmanship and local manufacturing may have inadvertently exposed it to cyber threats. The company's focus on innovation and customer service, while strengths, also require effective cybersecurity measures to protect sensitive data. The Cactus ransomware group likely exploited vulnerabilities in Matki's network, potentially through VPN devices or phishing attacks, to gain access to its systems.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.