SolidCAM Hit by Handala Ransomware, 50 GB of Data Exfiltrated and Published

Incident Date:

June 12, 2024

World map

Overview

Title

SolidCAM Hit by Handala Ransomware, 50 GB of Data Exfiltrated and Published

Victim

SolidCAM

Attacker

Handala

Location

Or Yehuda, Israel

, Israel

First Reported

June 12, 2024

Ransomware Attack on SolidCAM by Handala Group

Overview of SolidCAM

SolidCAM Ltd., founded in 1984 and headquartered in Or Yehuda, Israel, is a leading provider of computer-aided manufacturing (CAM) software solutions. The company is renowned for its innovative iMachining technology, which optimizes CNC machining toolpaths to reduce machining time and increase tool life. SolidCAM serves a global customer base, including over 1,000 large companies, and has subsidiaries in the UK, Germany, and other countries. The company employs over 300 people and generates an estimated annual revenue of $50-100 million.

Details of the Ransomware Attack

The ransomware group Handala has claimed responsibility for a cyberattack on SolidCAM, as announced on their dark web leak site. The group has exfiltrated and published 50 GB of data, including unreleased software versions such as SolidCAM2023SP3FullPack, SolidCAM2024, and iMachiningForNX2023_SP3. Handala's ransom note criticized SolidCAM for allegedly downplaying the breach and warned of further data releases if their demands were not met.

About Handala Ransomware Group

Handala Hack is a cybercriminal organization with a pro-Palestinian agenda, known for targeting Israeli institutions and their affiliates. The group employs sophisticated phishing campaigns and multi-stage malware loading processes to compromise targets. Handala has previously claimed responsibility for breaches involving Viber's source code and Israel's radar systems.

Potential Vulnerabilities

SolidCAM's integration with various CAD systems and its extensive global operations make it a lucrative target for ransomware groups. The company's reliance on digital tools and data for its CAM software solutions could have been exploited through phishing attacks or vulnerabilities in their network security. The attack underscores the importance of robust cybersecurity measures to protect sensitive data and intellectual property.

Implications of the Attack

The breach has significant implications for SolidCAM, potentially affecting its reputation and customer trust. The release of unreleased software versions could lead to financial losses and competitive disadvantages. The attack also highlights the ongoing threat posed by ransomware groups like Handala, emphasizing the need for continuous vigilance and advanced security protocols.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.