17 August 2020

REvil gang allegedly stole 1TB of confidential data from one of the largest U.S. manufacturer of alcoholic beverages


REvil gang allegedly stole 1TB of confidential data from one of the largest U.S. manufacturer of alcoholic beverages

Sodinokibi (REvil) ransomware operators announced last week they have compromised a computer network of Brown-Forman Corporation, one of the largest U.S. manufacturer of alcoholic beverages including Jack Daniel’s and Finlandia.

The gang claims to have stolen 1TB of data that includes confidential information about employees, company agreements, contracts, financial statements, and internal correspondence. According to the ransomware operators, they have spent more than a month examining the Brown-Forman’s computer infrastructure and services.

As a proof of the hack the group has published on their leak site multiple screenshots containing directory trees, files allegedly belonging to the firm, and internal conversations between some employees. The Sodinokibi ransomware operators plan to put up for auction the most sensitive data and leak the rest, which is their usual modus operandi aimed at forcing compromised companies into paying the ransom.

In a statement sent to Bloomberg, the manufacturer confirmed it suffered a cyber attack, but was able to prevent its systems from being encrypted.

“We are working closely with law enforcement, as well as world class third-party data security experts, to mitigate and resolve this situation as soon as possible. There are no active negotiations,” the company said.


Back to the list

Latest Posts

Ukrainian military personnel targeted via messaging apps and dating sites

Ukrainian military personnel targeted via messaging apps and dating sites

The threat actor employs a range of software in their malicious activities, including both commercial programs and  open-source tools.
18 April 2024
Russian military hackers targeted US water utilities and hydroelectric facilities in Europe

Russian military hackers targeted US water utilities and hydroelectric facilities in Europe

This marks the first time Russian nation-state hackers have posed a direct threat to critical infrastructure in Western countries.
18 April 2024
International police operation takes down massive PhaaS platform LabHost

International police operation takes down massive PhaaS platform LabHost

The investigation found over 40 000 phishing domains linked to LabHost, which had some 10 000 users worldwide.
18 April 2024