VM3 Fincas Hit by LockBit 3.0 Ransomware

Incident Date:

May 9, 2024

World map

Overview

Title

VM3 Fincas Hit by LockBit 3.0 Ransomware

Victim

VM3 Fincas

Attacker

Lockbit3

Location

Barcelona, Spain

, Spain

First Reported

May 9, 2024

Ransomware Attack on VM3 Fincas by LockBit 3.0

Attack Overview

A company based in Spain, VM3 Fincas fell victim to a cyberattack by the LockBit 3.0 ransomware group. The attack involved the exfiltration of 188 GB of data, including contracts, confidential documents, and personally identifiable information (PII). The attackers subsequently leaked a sample of the exfiltrated data, highlighting the ongoing threat posed by cybercriminals targeting organizations for data theft and ransomware attacks.

Company Profile

VM3 Fincas is a property consulting company based in Barcelona, Spain, specializing in property and asset management. They have been offering comprehensive advice on the management, administration, and sale of real estate since 1980. With a multidisciplinary team, VM3 Fincas provides highly qualified services covering all property needs, ensuring peace of mind and security for their clients.

Company Standout

The company stands out in the real estate sector for their extensive experience dating back to 1980. They offer consultancy services related to properties, providing expert advice and solutions to their clients.

Ransomware Group Profile

The LockBit 3.0 ransomware group is an evolution of the LockBit group, known for its Ransomware-as-a-Service (RaaS) model. LockBit 3.0, also referred to as LockBit Black, is considered one of the most dangerous and disruptive ransomware threats currently active. It encrypts files, modifies filenames, changes desktop wallpaper, and drops ransom notes on victims' desktops. The ransomware is heavily obfuscated and protected against analysis, making it challenging for security researchers to study.

Sources:

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.