Ransomware Attack on Wright Brothers Construction: Impact and Implications

Incident Date:

April 16, 2024

World map

Overview

Title

Ransomware Attack on Wright Brothers Construction: Impact and Implications

Victim

Wright Brothers Construction Company, Inc.

Attacker

Akira

Location

Charleston, USA

Tennessee, USA

First Reported

April 16, 2024

Ransomware Attack on Wright Brothers Construction by Akira Group

Company Profile

Wright Brothers Construction Company, Inc., a prominent player in the construction sector, has been operational for over fifty years, specializing in complex projects across the Southeastern United States. Known for their commitment to quality and safety, they employ approximately 700 personnel during peak seasons. Their ability to self-perform all major work items allows them to tightly control both budget and schedule, ensuring project delivery that meets or exceeds client expectations.

Details of the Cyber Attack

The Akira ransomware group, known for its affiliation with the defunct Conti ransomware gang, targeted Wright Brothers Construction Company. During the attack, approximately 12 GB of sensitive data was stolen, including financial records, accounting documents, insurance information, and employee files. The exact ransom demand was not disclosed, but Akira's typical demands range significantly, indicating the potential financial impact on the victim.

Vulnerabilities and Target Selection

Wright Brothers Construction's significant data repositories, including financial and personal employee information, make them an attractive target for ransomware attacks like those conducted by Akira. The construction industry often involves large-scale transactions and extensive data on projects and personnel, increasing the potential payoff for cybercriminals. The method of entry, while not specified, likely exploited vulnerabilities in network security, possibly through compromised VPNs or stolen credentials, tactics commonly used by the Akira group.

Impact and Implications

The breach not only risks substantial financial loss due to ransom demands but also threatens severe reputational damage. The revelation of confidential employee and operational business data may result in additional security breaches and legal consequences, emphasizing the urgent requirement for strong cybersecurity protocols within the construction industry.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.