The Kelly Group Targeted by 8Base Ransomware Group: Cybersecurity Threats in Construction

Incident Date:

May 27, 2024

World map

Overview

Title

The Kelly Group Targeted by 8Base Ransomware Group: Cybersecurity Threats in Construction

Victim

The Kelly Group

Attacker

8base

Location

Decatur, USA

Illinois, USA

First Reported

May 27, 2024

The Kelly Group Targeted by 8Base Ransomware Group

Company Profile

The Kelly Group is a construction company specializing in industrial and commercial construction projects. They offer services such as design-build, general contracting, construction management, and maintenance services. With experience in industries like manufacturing, power generation, and food processing, The Kelly Group is renowned for its commitment to safety, quality, and customer satisfaction. Operating in multiple locations, the company has a team of over 500 skilled employees.

Ransomware Attack Overview

The 8Base ransomware group targeted The Kelly Group, seizing control of critical data and threatening to leak it unless a ransom is paid. The compromised data includes sensitive business, financial, and personal information. Known for their aggressive tactics, 8Base employs a double-extortion method where they encrypt files and steal data to pressure victims into paying the ransom.

Ransomware Group Profile

Active since April 2022, the 8Base ransomware group targets small and medium-sized businesses across various sectors. They utilize ransomware strains like Phobos and are believed to spread through phishing emails, exploit kits, and drive-by downloads. Distinguished by their double-extortion tactics, 8Base has gained notoriety for their aggressive ransom demands.

Company Vulnerabilities

The Kelly Group, operating in the construction sector, may have been targeted by 8Base due to the valuable data they possess, including project plans, financial records, and client information. The company's multiple locations and large workforce could present challenges in securing all systems effectively, making them susceptible to cyber attacks.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.