UPDATED 22:20 EST / DECEMBER 08 2020

SECURITY

Foxconn plant in Mexico struck in DoppelPaymer ransomware attack

Hon Hai Precision Industry Co., better known as Foxconn, has been struck by a ransomware attack that briefly caused issues at its production facilities in Mexico and resulted in data stolen.

First reported Monday by Bleeping Computer, the ransomware attack occurred over the Thanksgiving weekend and involved the infamous DoppelPaymer gang. The attack, which targeted the Foxconn plant in Ciudad Juárez, Chihuahua, infected approximately 1,200 servers, with the theft of 100 gigabytes of unencrypted files. The ransomware attack also resulted in the deletion of 20 to 30 terabytes of backup data.

The DoppelPaymer gang is said to have demanded a ransom payment of 1804.0955 bitcoin ($32.97 million) in return for an encryption key and a promise not to release the stolen data. Foxconn didn’t pay and at least some of the data has now been published on the dark web, a shady part of the internet reachable with a special browser.

“Our team had access to Doppel ransomware website on the deep web where they publish their victims’ stolen data and we can confirm that they have published data about Foxconn Technology Group,” Gustavo Palazolo, security researcher at secure access company Appgate, told SiliconANGLE. “By looking at the list of organizations/targets from this and other threat groups behind large ransomware operations, we found a very diverse list of targets, so we have the impression that the threat actors are trying to make money no matter the type or size of the organization.”

Reuters reported that services at the facility have gradually returned to normal, though the website for the plant remains offline. Foxconn’s facilities in Mexico primarily make televisions and servers. The company is also looking to expand its manufacturing in the country because of the U.S.-China trade war. Brands manufactured at the plant include Belkin and Sharp, both of which are owned by Foxconn.

Recent DoppelPaymer ransomware victims include Endemol Shine, the global production company behind television shows such as “Big Brother,” “MasterChef” and “The Voice” in November and an attack on Mexican state-owned petroleum company Petróleos Mexicanos, known as Pemex, in November 2019.

Ilia Kolochenko, founder and chief executive of web security company IllumniWeb, noted that the incident clearly indicates that ransomware mostly exploits major cybersecurity failures such as lack of internal network segregation.

“Allegedly, the attackers managed to compromised over 1,000 servers and delete all backups,” Kolochenko said. “If true, this is an unambiguous indicator of gross negligence and absence of the most fundamental security controls. It’s unlikely any cybersecurity insurance will ever pay a cent for the damages under the circumstances, while the victim will likely have a solid claim against IT and security vendors in charge of its network management.”

Photo: Nadkachna/Wikimedia Commons

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.