13 April 2021

French pharmaceutical giant Pierre Fabre suffers a REvil ransomware attack


French pharmaceutical giant Pierre Fabre suffers a REvil ransomware attack

French pharmaceutical and cosmetics company Pierre Fabre has been hit with a REvil ransomware attack, with hackers demanding $25 million ransom from the manufacturer.

Last week, Pierre Fabre revealed it was the target of a cyberattack that the company brought under control in less than 24 hours. The incident took place on March 31. After learning about the cyberattack the company immediately put its IT system put into standby mode to prevent the infection from spreading. This led to the “temporary stoppage of most production activities (except for the production facility in Gaillac (in the Tarn in France), which manufactures active ingredients for pharmaceuticals and cosmetic products).”

In its announcement the company did not mention what kind of malware was used in the attack, however, according to Bleeping Computer, Pierre Fabre appears to be the victim of the REvil (Sodinokibi) ransomware operation.

According to the REvil’s Tor payment page, the group initially demanded $25 million ransom from the company, though the ransom had since been doubled to $50 million as Pierre Fabre had not contacted the attackers and the time limit expired.

The payment page does not indicate who the victim is, however, it contains a link to a currently hidden REvil data leak page for Pierre Fabre, which contains images of allegedly stolen passports, a company contact list, government identification cards, and immigration documents, according to Bleeping Computer.

In January 2021, massive pan-Asian retail chain operator Dairy Farm Group that operates numerous brands in the Asia market, was reportedly hit by the REvil ransomware operation, with attackers demanding $30 in ransom. Most recently, the gang attacked the world-leading French electronics manufacturing services (EMS) company Asteelflash. The company managed to contain the attack and said it has no evidence any data was stolen.

Back to the list

Latest Posts

Cyber Security Week in Review: April 19, 2024

Cyber Security Week in Review: April 19, 2024

In brief: the LabHost PhaaS platform shut down, Russian military hackers attacked critical infrastructure in the US and Europe, and more.
19 April 2024
Ukrainian military personnel targeted via messaging apps and dating sites

Ukrainian military personnel targeted via messaging apps and dating sites

The threat actor employs a range of software in their malicious activities, including both commercial programs and  open-source tools.
18 April 2024
Russian military hackers targeted US water utilities and hydroelectric facilities in Europe

Russian military hackers targeted US water utilities and hydroelectric facilities in Europe

This marks the first time Russian nation-state hackers have posed a direct threat to critical infrastructure in Western countries.
18 April 2024