Ransomware Attack on Pier Foundry & Pattern Shop, Inc.

Incident Date:

May 15, 2024

World map

Overview

Title

Ransomware Attack on Pier Foundry & Pattern Shop, Inc.

Victim

Pier Foundry & Pattern Shop, Inc.

Attacker

Black Suit

Location

St Paul, USA

Minnesota, USA

First Reported

May 15, 2024

Ransomware Attack on Pier Foundry & Pattern Shop, Inc.

Victim Overview

Pier Foundry & Pattern Shop, Inc. is a manufacturing company based in St. Paul, MN, specializing in producing high-quality gray and ductile iron castings for various industries such as agriculture, construction, and industrial equipment. They also offer pattern making services to create custom molds for casting production. The company has 134 years of manufacturing experience and is ISO certified.

Company Profile

The company is known for its commitment to providing high-level service, support, and value to its customers. They offer assistance in design and castability from concept through production and have made significant investments in new technology, including a new M14 Tumble Blast System, mold machines, green sand controls system, 3D printer technology, and ergonomic workbenches. The company has also been recognized for its safety record, winning awards from the American Foundry Society.

Attack Details

The cybercrime group Black Suit targeted Pier Foundry & Pattern Shop, Inc. with ransomware, compromising the company's website. The attack resulted in the exfiltration of employees' and partners' data, some of which has been fully published, posing significant risks to individuals' privacy and security.

Ransomware Group Profile

Black Suit is a new ransomware family closely related to the notorious Royal ransomware group. The group targets both Windows and Linux systems, including critical VMware ESXi infrastructure. Black Suit appends the .blacksuit extension to encrypted files and provides a ransom note for victims to contact the operators. The ransomware group has significant similarities in code and functionality with the Royal ransomware, indicating a potential connection between the two groups.

Vulnerabilities

The company may have been targeted by threat actors due to the sensitive nature of the data they handle, including employees' and partners' information. Additionally, the company's investment in new technology could have provided avenues for cybercriminals to exploit vulnerabilities in their systems.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.