The ransomware gang RansomEXX takes responsibility for the cyberattack against Bombardier Recreational Products (BRP), which was disclosed by the company on 8 August 2022.

See also: Dominican Republic: Quantum ransomware disrupts government service
At the time, the Canadian manufacturer of Ski-Doo snowmobiles, Sea-Doo jet skis, ATVs, motorcycles, boats and Rotax engines informed the public of a temporary suspension of all operations in response to “malicious online activity.”
The operational shutdown also affected production and was expected to cause delays in some transactions with customers and suppliers.
BRP employs over 20,000 people, has nearly $6 billion in annual sales, and distributes various products in more than 120 countries, so even a minimal disruption to production could have a serious financial impact.
On August 15, 2022, BRP provided an update on the situation, saying that four manufacturing facilities in Canada, Finland, the US , and Austria had restarted production, with the rest following suit by the end of that week.
In the same statement, the company presented the initial results of its internal investigation, saying that hackers breached its systems through a supply chain attack.
“The company confirms that the malware infiltration occurred through a third-party service provider. BRP believes that the impact of the cyberattack was limited to its internal systems ,” the company says.
BRP promised to notify individuals or companies directly if the ongoing investigation uncovers a more widespread data breach.
See also: GitLab: Warns of critical vulnerability - Update immediately!

RansomEXX leaks files
Yesterday, the RansomEXX gang listed Bombardier Recreational Products on the leak website along with 29.9 GB of files allegedly stolen from the company.
Samples provided on the website include non-disclosure agreements, passports and ID cards , material supply agreements, contract renewals , and more.
It appears that the data breach does not involve sensitive customer data, however the exposure of the documents in question is still damaging to BRP.
Bombardier Recreational Products issued a statement today confirming that the leaked documents are authentic, adding that it is actively supporting affected parties to mitigate the negative impacts due to the exposure.
See also: LockBit 3.0 strengthens its dominance of the ransomware ecosystem
The RansomEXX extortion site for 2022 lists seven victims, indicating that the gang's activity is relatively low. However, it remains a threat to many platforms.
Information source: bleepingcomputer.com
