Unveiling the BlackSuit Group's Ransomware Attack on Multi-Fill

Incident Date:

April 9, 2024

World map

Overview

Title

Unveiling the BlackSuit Group's Ransomware Attack on Multi-Fill

Victim

Multi-Fill

Attacker

Black Suit

Location

West Jordan, USA

Utah, USA

First Reported

April 9, 2024

Ransomware Attack on Multi-Fill by BlackSuit Group

Overview

A firm specializing in manufacturing and tallying machines for the food industry, Multi-Fill, found itself as another victim in the ransomware attacks conducted by the cybercriminal group BlackSuit in April 2024., Multi-Fill has been delivering top-notch machinery to bolster the food service sector for over three decades. The company, headquartered in West Jordan, Utah, employs between 11 to 50 individuals and reports revenue of $4.3 million.

Company Highlights

Distinguished for its efficient, dependable machinery capable of accommodating a broad spectrum of food products, Multi-Fill extends assistance with installation, provides on-site technicians, and offers warranty services for all their products, ensuring enduring customer satisfaction. The company emphasizes the speed, versatility, and ease of maintenance of its machinery, rendering them invaluable assets for food production lines.

Vulnerabilities

Multi-Fill's prominence in the manufacturing sphere, particularly within the food industry, renders it susceptible to targeting by threat actors such as the BlackSuit ransomware group. The sensitive data they manage, coupled with their reliance on technology, heightens vulnerability to cyber attacks. The company's dedication to customer support and the pivotal role their machinery plays in food production renders them attractive targets for ransomware groups aiming to disrupt business activities.

Attack Update

The ransomware assault by the BlackSuit group culminated in the complete exposure of the stolen data, emphasizing the pervasive and enduring consequences of cyber threats in today's interconnected business landscape.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.