Spanish multinational cash logistics and private security firm Prosegur said Wednesday it had shut down its IT network to mitigate a Ryuk ransomware attack. The company’s website was offline Wednesday afternoon, but it said in a Twitter that it had experienced a “hacking incident on its telecommunications platforms.”

A few hours later Prosegur confirmed that it had taken “maximum security measures” to prevent the spread of the Ryuk ransomware internally and externally.
“Prosegur reports that the incident detected today corresponds to a general attack caused by the Ryuk ransomware. The company has enabled maximum security measures to be taken to prevent both the internal and external spread of the virus,” it said.
According to UK security researcher Kevin Beaumont, the first reports of the hacking attack came in at around 5 a.m. Prosegur's global IT network was reportedly shut down and its employees were sent home. However, the company has not confirmed this.
Prosegur is one of the world's largest suppliers of armored vehicles for transporting cash between banks and automated teller machines (ATMs), retail and restaurants. The company has 170,000 employees and operates in Europe, the US, Latin America and Asia Pacific.
The company operates a fleet of 10,000 security vehicles and manages 100,000 ATMs worldwide. The alarm “notification” function operates in nine countries and supports more than 550,000 alarms.

Ryuk ransomware has been linked to multi-million dollar targeting U.S. state and local governments. This month alone, Ryuk infected 400 veterinary hospitals operated by California and a Wisconsin-based virtual care provider that provides IT services to 110 hospitals in the U.S., according to Krebsonsecurity.com.
While much of Prosegur's website has been restored, the media remains unavailable. Beaumont pointed out this morning that a day after the attack, customers were reporting on Twitter that alarms were not working.
