HomeSecurityDussmann Group: Data leaked after ransomware attack!

Dussmann Group: Data leaked after ransomware attack!

The group behind the Nefilim ransomware has begun publishing unencrypted files that it stole from a subsidiary of the Dussmann Group during a recent attack. The Dussmann Group is the largest multi-service provider in Germany, with subsidiaries focusing on facility management, corporate childcare, nursing care and elderly care, and provides business system solutions such as HVAC, electrical work and elevators. The Group confirmed that one of its subsidiaries, Dresdner Kühlanlagenbau GmbH (DKA) , was recently attacked by ransomware, which resulted in the theft and leakage of data stored on the company’s systems

Dussmann Group

The Nefilim operators reported that during their attack on DKA, they stole unencrypted files before deploying the ransomware. They also added that they are using the stolen data against victims to force them to pay ransom , threatening to leak the data on dark forums. The Nefilim ransomware operators posted 14 GB of stolen files on their site. These files appear to contain a variety of documents, including Word documents , images, accounting documents, and AutoCAD drawings.

Dussmann Group, after learning about the leak, confirmed to BleepingComputer that its subsidiary, DKA, was hacked and files were stolen. Specifically, the Group stated that the attack targeted Dresdner Kühlanlagenbau GmbH (DKA), which employs 570 people, and that the company's data was encrypted and copied during the attack.

DKA Germany-ransomware attack

Michaela Mehls, head of corporate communications at the Dussmann Group, said that after the breach, the company's servers were shut down as a precaution. In addition, the data protection authorities and the State Criminal Investigation Office in Saxony have been informed and charges have been filed. She added that DKA is in constant contact with the authorities and cybersecurity experts . The company has also already informed its customers and employees about the security incident and the data theft, while investigations are continuing to draw clearer conclusions.

The operators of the Nefilim ransomware told BleepingComputer that they encrypted four domains and stole approximately 200 GB of files. However, it is not yet known how the Nefilim operators gained access to the DKA network. At the same time, Bad Packets was unable to find any vulnerable VPN or devices on their network. Given that exposed remote desktop servers seem to be the cause of 70-80% of all network breaches, the attackers likely managed to gain access via an exposed server or via a phishing attack.

ransomware attack - ransom

What should companies do to protect themselves from a potential ransomware attack?

To protect a network from breaches during ransomware attacks, companies need to take a multi-layered approach to securing their systems. It is important to ensure that all RDP servers are only accessible via a corporate VPN. Ransomware typically targets VPN gateways and devices to gain access to corporate and government networks. With VPN gateways now exposed, they also need to be secured and hardened with the latest available security and firmware updates . Finally, MFA should be enabled for corporate accounts, and Windows event logs should be monitored for unusual entries.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS