Ransomware Attack on W.I.S. Sicherheit-Service by 8Base

Incident Date:

May 13, 2024

World map

Overview

Title

Ransomware Attack on W.I.S. Sicherheit-Service by 8Base

Victim

W.I.S. Sicherheit

Attacker

8base

Location

Berlin, Germany

, Germany

First Reported

May 13, 2024

Ransomware Attack on W.I.S. Sicherheit-Service by 8Base

Victim Overview

W.I.S. Sicherheit-Service GmbH & Co. KG, a German security services company headquartered in Cologne, North Rhine-Westphalia, was targeted in a ransomware attack by the cybercrime group 8Base. Founded in 1901 as the "Kölner Wach- und Schließgesellschaft," W.I.S. Sicherheit has grown to become one of the largest security service providers in Germany, with over 4,000 employees and annual revenue exceeding 141 million euros. The company offers security technology, personnel security, and 24/7 monitoring through its security center, providing comprehensive security solutions to businesses and individuals.

Company Profile

The company stands out in the industry for its over 100 years of experience and expertise in the security field, as well as its nationwide presence with multiple branches across Germany. The company's "Security-as-a-Service" model combines experienced personnel and modern technology to deliver effective security solutions at a fixed monthly price, catering to the needs of its clients.

Attack Details

During the cyberattack, sensitive information such as invoices, receipts, accounting documents, personal data, certificates, employment contracts, confidentiality agreements, and personal files were compromised. The leaked data was fully published, posing significant risks to the privacy and security of the company and its stakeholders.

Ransomware Group 8Base

The 8Base ransomware group, active since April 2022, has gained notoriety for its aggressive tactics, primarily targeting small and medium-sized businesses across various sectors. 8Base distinguishes itself through its double-extortion tactics, where they encrypt files and steal data, threatening to publicly release it if the ransom is not paid. The group uses ransomware strains like Phobos and spreads through phishing emails, exploit kits, and drive-by downloads.

Penetration and Vulnerabilities

It is believed that 8Base could have penetrated W.I.S. Sicherheit's systems through phishing emails or exploit kits, taking advantage of potential vulnerabilities in the company's cybersecurity defenses. The use of double-extortion tactics by 8Base highlights the importance of robust cybersecurity measures to protect against ransomware attacks and safeguard sensitive data.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.