German car and weapons manufacturer Rheinmetall AG has confirmed that it has suffered a BlackBasta ransomware attack, which has affected its political business.
See also: Malicious Windows kernel drivers used in BlackCat ransomware attacks

See also: Play Store: “iRecorder – Screen Recorder” app was malware
Rheinmetall is a German manufacturer of automotive and military vehicles, armaments, air defense systems, engines, and various steel products. It employs over 25,000 people and has annual revenues of over $7 billion.
On Saturday, May 20, 2023, BlackBasta posted on its extortion website that it had stolen data from the German company Rheinmetall, along with samples of the data.
Published data samples include non-disclosure agreements, technical drawings, passport scans, and purchase orders.
Responding to a request for comment on the authenticity of the claims of a data leak and network breach, a Rheinmetall spokesperson confirmed the attack, clarifying that it only affects its civilian division.
In addition, the company stated that it had informed the relevant law enforcement authorities and filed a criminal complaint with the Cologne prosecutor's office.
Rheinmetall plays a major role in providing aid to Ukraine and recently upgraded its ties with a state-owned tank manufacturer in Ukraine, launching a new strategic cooperation.
See also: GoldenJackal hackers have been targeting governments since 2019

Recent BlackBasta activity
The BlackBasta ransomware gang began its activities in April 2022 and has had several successful breaches against high-profile entities recently.
On May 7, 2023, the threat group announced an attack against leading power and automation technology provider ABB.
In April 2023, BlackBasta breached Canadian directory publisher Yellow Pages Group, stealing sensitive documents and data in the process.
On March 22, 2023, threat actors infiltrated the corporate network of Capita, a British outsourcing giant that has contracts with many British government and the military.
Later, on May 13, Capital warned its clients that they should assume that BlackBastia had breached their data.
Information source: bleepingcomputer.com
