UPDATED 21:53 EDT / NOVEMBER 08 2020

SECURITY

Italian drinks maker Campari hit by Ragnar Locker ransomware attack

Operations at Italian drinks maker Davide Campari-Milano S.p.A., best known simply as Campari, were knocked offline last week following a ransomware attack.

The attack, officially described by the company as a malware attack, was detected Nov. 2 and caused the encryption of certain data on some of the company’s servers. “We acknowledge that there has been some data loss: we are still investigating the attack and, in particular, determining to which extent there has been any loss of confidentiality and loss of availability of personal and business data,” Campari said in a statement.

Compari also note that it has employed cybersecurity experts to contain the issue, put in place additional security measures and contacted Italian cybersecurity police and the U.S. Federal Bureau of Investigation.

Although it didn’t confirm the form of the attack, the clear giveaway is that it describes data being encrypted, and that immediately points to ransomware.

According to ThreatPost, it was a Ragnar Locker attack and those behind the ransomware demanded a $15 million payment via bitcoin. A ransomware note states that “we have BREACHED your security perimeter and get [sic] access to every server of the company’s network in different countries across all your international offices,” before going on to detail the types of data compromised. The stolen data is said to include accounting files, bank statements, employee personal information and more totaling 2 terabytes.

“If no deal is made than [sic] all your data with be published and/or sold through an auction to any third parties,” the note adds. Some of the stolen data has already been posted on a leak site, including a contract between Wild Turkey and actor Matthew McConaughey.

Although there are various forms of ransomware and related gangs, those behind Ragnor Locker have been particularly busy, allegedly also targeting Japanese video games developer Capcom Co. Ltd. this week.

“This recent ransomware attack on Campari shows that cybercriminals are not just interested in targeting technology companies,” Boris Cipot, senior sales engineer at electronic design automation company Synopsys Inc., told SiliconANGLE. “In fact, any and every individual who owns a laptop or a mobile phone is a possible target. However, individual targets are only lucrative at scale. As such, bad actors tend to go for large organizations such as Campari where they can get more bang for their buck.”

Raif Mehment, vice president for Europe, the Middle East and Africa at cloud security company Bitglass Inc., noted that not only is there the demand of $15 million, if the ransom is paid, but there’s also the cost of downtime, lost sales opportunities, damage to brand reputation and potential fines for noncompliance that could come into play.

“Ransomware is one of the fastest-growing malware threats and this case is just one of many that demonstrates that most companies today are not prepared for a ransomware attack – let alone disaster recovery after the fact,” Mehment said. “Organizations should always take a comprehensive view of their security – evaluate all services in use and the gaps most likely to pose a risk to corporate data.”

Photo: Norio Nakayama/Flickr

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.