The MCP Group: Facing Cybersecurity Challenges

Incident Date:

April 12, 2024

World map

Overview

Title

The MCP Group: Facing Cybersecurity Challenges

Victim

The MCP Group

Attacker

Black Suit

Location

Topeka, USA

Kansas, USA

First Reported

April 12, 2024

Ransomware Attack on The MCP Group

Company Profile

The MCP Group is a company involved in the production and distribution of bismuth, indium, gallium, selenium, tellurium, and bismuth chemicals. They also provide mining services for extracting indium, gallium, selenium, and tellurium ores, marketing their products to metal manufacturers. The company is located in Woking, Surrey, and operates under the names MCP Group Limited and MCP Group SA.

Company Size and Industry Standing

They are known for their involvement in the production and distribution of various metals and chemicals, catering to metal manufacturers. It's an active company with shareholders, contacts, financials, and industry information available.Their presence in the Organizations sector highlights their significance in the industry.

Vulnerabilities and Targeting

MCP's involvement in the production and distribution of valuable metals and chemicals makes them a lucrative target for threat actors like the BlackSuit ransomware group. Their operations in mining services and marketing to metal manufacturers may involve sensitive data and intellectual property that could be targeted for encryption and exfiltration. The company's online presence could also serve as a potential entry point.

Sources:

Pitchbook - The MCP Group Profile

Endole - MCP Group Limited Information

Bloomberg - MCP Group SA Overview

Tripwire - BlackSuit Ransomware Overview

HHS - BlackSuit Ransomware Analyst Note

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.