The well-known German company in the building and construction materials industry, Knauf Group, announced that it was the target of a cyberattack (most likely ransomware) that resulted in the interruption of its business activities, after the IT team was forced to shut down all systems IT to isolate the incident.

The cyberattack took place on the evening of June 29th and Knauf is currently still in the process of investigating the incident and repairing the problems.
See also: How many data records containing usernames and passwords were breached in 2021?
“We are currently working intensively to mitigate the impact on our customers and partners – as well as to plan a safe recovery. However, we apologize for any inconvenience or delays in delivery processes that may occur,” reads the brief announcement posted on Knauf’s main page.
According to BleepingComputer, email were shut down as part of the response to the attack, but mobile phones and Microsoft Teams were still working to achieve communication.
Knauf is a German multinational company that holds a significant position in the building materials industry. The company operates 150 manufacturing plants in many countries around the world and owns Knauf Insulation and the US - based USG Corporation . Knauf Insulation has also posted a notice about the cyberattack on its website, which means that this entity has also been affected.
See also: CloudMensis malware: Used to spy on Macs

Knauf Group: Who is behind the cyberattack?
Knauf did not provide many details about the cyberattack. It did not say, for example, what type of attack it was or who was behind it. However, the impact and difficulty in restoring IT systems could indicate that this is a ransomware.
Indeed, the Black Basta ransomware gang appears to have claimed responsibility for the cyberattack on Knauf, via an announcement on its extortion site on July 16, 2022. In fact, the ransomware gang has published 20% of the files allegedly stolen during the attack Knauf . Bleeping Computer has seen samples of email communications, user credentials, employee contact information, production documents, and identity scans.
The fact that not all the filessuggests that some negotiation is underway or that the hackers are simply hoping that they can pressure the company into giving them money.
See also: Roaming Mantis malware campaign targets Android and iOS users in France
The Black Basta ransomware gang is quite well-known for attacks on large targets, which usually involve double extortion (file theft and device encryption).
Source: www.bleepingcomputer.com
