Ransomware Attack on Pier Foundry & Pattern Shop, Inc.
Incident Date:
May 15, 2024
Overview
Title
Ransomware Attack on Pier Foundry & Pattern Shop, Inc.
Victim
Pier Foundry & Pattern Shop, Inc.
Attacker
Black Suit
Location
First Reported
May 15, 2024
Ransomware Attack on Pier Foundry & Pattern Shop, Inc.
Victim Overview
Pier Foundry & Pattern Shop, Inc. is a manufacturing company based in St. Paul, MN, specializing in producing high-quality gray and ductile iron castings for various industries such as agriculture, construction, and industrial equipment. They also offer pattern making services to create custom molds for casting production. The company has 134 years of manufacturing experience and is ISO certified.
Company Profile
The company is known for its commitment to providing high-level service, support, and value to its customers. They offer assistance in design and castability from concept through production and have made significant investments in new technology, including a new M14 Tumble Blast System, mold machines, green sand controls system, 3D printer technology, and ergonomic workbenches. The company has also been recognized for its safety record, winning awards from the American Foundry Society.
Attack Details
The cybercrime group Black Suit targeted Pier Foundry & Pattern Shop, Inc. with ransomware, compromising the company's website. The attack resulted in the exfiltration of employees' and partners' data, some of which has been fully published, posing significant risks to individuals' privacy and security.
Ransomware Group Profile
Black Suit is a new ransomware family closely related to the notorious Royal ransomware group. The group targets both Windows and Linux systems, including critical VMware ESXi infrastructure. Black Suit appends the .blacksuit extension to encrypted files and provides a ransom note for victims to contact the operators. The ransomware group has significant similarities in code and functionality with the Royal ransomware, indicating a potential connection between the two groups.
Vulnerabilities
The company may have been targeted by threat actors due to the sensitive nature of the data they handle, including employees' and partners' information. Additionally, the company's investment in new technology could have provided avenues for cybercriminals to exploit vulnerabilities in their systems.
Sources:
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.