Ransomware Attack on Taylor Crane & Rigging, Inc. - LockBit 3.0 Targeting Industrial Machinery Company

Incident Date:

May 9, 2024

World map

Overview

Title

Ransomware Attack on Taylor Crane & Rigging, Inc. - LockBit 3.0 Targeting Industrial Machinery Company

Victim

Taylor Crane & Rigging, Inc.

Attacker

Lockbit3

Location

Coffeyville, USA

Kansas, USA

First Reported

May 9, 2024

Ransomware Attack on Taylor Crane & Rigging, Inc.

Victim Profile

Taylor Crane & Rigging, Inc. is a full-service industrial machinery moving and craning services company based in Coffeyville, Kansas, USA. Founded in 1975, the company has 100-200 employees and an estimated annual revenue of $5.0M - 25M. They specialize in plant relocations, heavy lifting, machinery installation, maintenance, and repair across North America.

Company Overview

The company stands out in the industry for its diverse inventory of equipment, professional services, and commitment to safety. They have a strong reputation for delivering high-quality services to a wide range of clients, including Fortune 500 companies and small independent operations.

Attack Details

The ransomware group LockBit 3.0 targeted Taylor Crane & Rigging, exfiltrating 76 GB of sensitive data, including accounting records, insurance documents, audits, employee information, financial data, and invoices. The attackers leaked a sample of this data on the internet and demanded a ransom, the amount of which is unspecified.

Vulnerabilities

Taylor Crane & Rigging's vulnerabilities in being targeted by threat actors include potential gaps in their cybersecurity defenses, lack of robust data protection measures, and possible weaknesses in their network security protocols. These vulnerabilities could have been exploited by the ransomware group to gain unauthorized access to the company's systems.

Ransomware Group

LockBit 3.0, also known as LockBit Black, is a Ransomware-as-a-Service (RaaS) group that has been actively recruiting affiliates and targeting various businesses and critical infrastructure organizations. The group is known for its advanced encryption capabilities, obfuscation techniques, and evasive tactics, making it a significant threat in the cybersecurity landscape.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.