HomeSecurityHSE: Slovenian electricity company hit by ransomware attack

HSE: Slovenian electricity company hit by ransomware attack

Slovenia's energy company Holding Slovenske Elektrarne (HSE) has been hit by a ransomware attack that compromised systems and led to file encryption . However, the company said the attack did not cause any disruption to electricity production.

HSE Slovenia

HSE is the largest electricity producer in Slovenia, accounting for approximately 60% of domestic production. Of course, it belongs to the country's critical infrastructure. It was founded in 2001 by the Slovenian government and is state-owned. It also has subsidiaries in Italy, Serbia and Hungary.

As first reported by local news outlet 24ur.com, the HSE suffered a ransomware attack last Wednesday.

See also: Henry Schein: “Hit” for the second time by BlackCat ransomware

The Director of the Information Security Office, Uroš Svete, told the media that all power generation companies remained unaffected. However, IT systems and files locked” by the “crypto virus.”

The National Cyber ​​Incident Response Office at Si-CERT and the police authorities were immediately notified. The HSE is also working with external cybersecurity experts to mitigate the attack and prevent the virus from spreading to other systems across Slovenia.

So far, there does not appear to be any ransom demand, but the company remains vigilant as the cleanup of the system is still ongoing.

Uroš Svete issued a joint statement with the Director General of the HSE, Tomaž Štokelj, assuring the public that the situation is under control and that no operational disruption or significant financial damage is expected due to this incident.

See also: Ethyrial: Echoes of Yore: Gamers lost their accounts due to ransomware

HSE ransomware

Rhysida ransomware responsible?

There is some unofficial information circulating that attributes the attack to the Rhysida ransomware gang . If this is true, then it goes some way to explaining why the HSE states that it did not receive a ransom demand. The Rhysida ransomware ransom notes only contain an email address for victims to contact the attackers.

It is said that the ransomware operators breached the HSE in Slovenia by stealing passwords for the systems from an unprotected cloud storage instance.

See also: The Rhysida Ransomware Group Invaded the Network of a Chinese Energy Group

This attack on HSE may not have caused an interruption in electricity production, but it affects the operation and security of the company's systems. As we mentioned earlier, HSE is the largest energy in Slovenia and the successful implementation of such an attack is worrying. The attack reveals the vulnerability of energy companies to cyberattacks. The attackers used malware to encrypt HSE's systems. This indicates the need to strengthen security measures and adopt preventive measures to protect energy companies from cyberattacks.

Rhysida ransomware first appeared in May 2023, quickly targeting large organizations including the Chilean military, Prospect Medical , and the British Library.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS