Vikrant Springs Hit by LockBit 3.0 Ransomware Attack

Incident Date:

May 9, 2024

World map

Overview

Title

Vikrant Springs Hit by LockBit 3.0 Ransomware Attack

Victim

Vikrant Group

Attacker

Lockbit3

Location

Halol, India

, India

First Reported

May 9, 2024

Ransomware Attack on Vikrant Springs by LockBit 3.0

Victim Profile

Vikrant Springs, a leading manufacturer and exporter of multi-leaf and parabolic springs for the automotive industry, fell victim to a cyberattack by LockBit 3.0 on May 15th, 2024. The company, part of the Vikrant Group, boasts over 35 years of experience in providing world-class suspension system solutions.

They employ 196 individuals and operate in the manufacturing sector. Their annual revenue was reported to be $150 million in 2024, showcasing its significant presence in the industry.

Unique Selling Points

Vikrant Springs stands out in the industry due to its commitment to quality and excellence. The company's parabolic springs are designed with engineering precision, while their multi-leaf springs offer maximum support and stability to a wide range of vehicles. Vikrant Springs aims to be the most preferred automotive components manufacturer in India, emphasizing innovation and customer satisfaction.

Vulnerabilities and Attack Details

The cyberattack by LockBit 3.0 targeted Vikrant Springs' website, vikrantsprings.com, resulting in the exfiltration of sensitive data, including agreements and employee information. Despite not specifying a ransom demand initially, the attackers leaked a sample of the data and imposed a ransom deadline on the company, creating pressure to respond swiftly to the attack.

Ransomware Group Distinction

LockBit 3.0, also known as LockBit Black, is a Ransomware-as-a-Service (RaaS) group that has evolved from previous LockBit versions. The group is known for its advanced capabilities, including file encryption, desktop modifications, and lateral movement within networks. LockBit 3.0 is considered highly dangerous and evasive, making it challenging for security researchers to analyze and defend against.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.