RansomHub claims responsibility for cyberattack on Kawasaki Motors Europe, leaks nearly 500GB of data

RansomHub, a rising player in the Ransomware-as-a-Service (RaaS) industry, has claimed responsibility for the cyberattack on Kawasaki Motors Europe, leaking 478GB of sensitive data. This leak includes financial records, internal communications, and more, highlighting the dangers companies face from the growing influence of ransomware groups.

Advertisement

Kawasaki Motors Europe (KME) has confirmed that it was recently the target of a cyberattack, leading to significant service disruptions. Despite KME’s efforts to implement a recovery plan, the infamous Ransomware-as-a-Service (RaaS) group, RansomHub, carried out its threat by leaking almost 500GB of stolen data on its extortion site on the dark web.

The attack occurred in early September, and KME responded swiftly by isolating its servers. However, the fallout of the cyberattack has been severe. RansomHub has already leaked 478GB of sensitive business documents, including banking records, internal communications, dealership details, and financial information belonging to KME. The public release of this data suggests that KME refused to pay the ransom demanded by RansomHub, prompting the group to act on its threat.

Since its inception in February 2024, RansomHub has quickly made a name for itself as a major force in the cybercrime landscape. The group claimed responsibility for 75 ransom attacks during Q2 of 2024, targeting well-known entities such as Change Healthcare and Planned Parenthood. Their rapid rise in notoriety is marked by their aggressive tactics and increasing ransom demands.

Advertisement

The U.S. Cybersecurity and Infrastructure Agency (CISA) has since issued an advisory to alert organizations about RansomHub’s methods and provide recommendations to mitigate the risk of becoming future targets. The advisory outlines key indicators of compromise (IoCs) and emphasizes the importance of preparedness in facing the escalating threat posed by ransomware groups.

One of the alarming trends emerging in 2024 is the significant increase in ransom demands. The average ransom requested by attackers has skyrocketed to $1.5 million, up from just $200,000 in 2023, underscoring the growing power and influence of RaaS groups like RansomHub. The damage inflicted by these groups not only threatens a company’s financial stability but also its operational integrity and reputation.

As cybercriminals like RansomHub continue to expand their operations and leverage increasingly sophisticated tactics, businesses worldwide must remain vigilant and invest in comprehensive cybersecurity measures to defend against such threats.