Ransomware Attack on PBC Companies: 300GB Data Stolen by BianLian

Incident Date:

August 18, 2024

World map

Overview

Title

Ransomware Attack on PBC Companies: 300GB Data Stolen by BianLian

Victim

PBC Companies

Attacker

Bianlian

Location

Escondido, USA

California, USA

First Reported

August 18, 2024

Ransomware Attack on PBC Companies by BianLian

PBC Companies, a construction firm specializing in concrete, masonry, and paver projects, has recently fallen victim to a ransomware attack by the notorious BianLian group. The attackers claim to have exfiltrated 300GB of sensitive data, including crucial project information, from the company's systems.

About PBC Companies

PBC Companies operates primarily in California, with offices in Anaheim, Escondido, and Pacoima. The firm is known for its expertise in hardscaping and outdoor construction projects, having completed notable installations such as the San Clemente Plaza and the Elevon Campus. The company's specialization in concrete, masonry, and paver work has established it as a reputable player in the construction industry.

Attack Overview

The BianLian ransomware group has claimed responsibility for the attack on PBC Companies via their dark web leak site. The group asserts that they have accessed and exfiltrated 300GB of sensitive organizational data. This breach could have significant financial and reputational consequences for PBC Companies, given the nature of the data involved.

About BianLian Ransomware Group

BianLian is a sophisticated ransomware group that has evolved from targeting individual users to launching high-profile attacks on various sectors, including construction. Initially functioning as a banking trojan, BianLian transitioned into advanced ransomware operations, focusing on exfiltration-based extortion. The group is known for its ability to gain initial access through compromised Remote Desktop Protocol (RDP) credentials and implant custom backdoors specific to each victim.

Penetration Tactics

BianLian employs a range of tactics to penetrate company systems. These include using PowerShell and Windows Command Shell for defense evasion and employing various tools for discovery, lateral movement, collection, exfiltration, and impact. The group's shift towards exfiltration-based extortion underscores the evolving threat landscape posed by ransomware groups.

Vulnerabilities and Impact

PBC Companies' vulnerabilities likely stem from inadequate cybersecurity measures, such as weak RDP credentials and insufficient endpoint detection and response solutions. The attack highlights the urgent need for enhanced cybersecurity measures to protect against sophisticated ransomware groups like BianLian.

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.