JBS Ransomware Attack Started in March and Much Larger in Scope than Previously Identified
ID: 4cea19e6-9633-5c45-9386-6b4b3f836d5a
STIX ID: report--4cea19e6-9633-5c45-9386-6b4b3f836d5a
Feed Name: SecurityScorecard Blog
SecurityScorecard investigated a REvil/Sodinokibi ransomware campaign against JBS, reporting reconnaissance in February 2021, repeated data exfiltration between March and May (≈45 GB to MEGA and up to 5 TB to hosts in Hong Kong), leaked employee credentials, persistent TeamViewer access, and encryption on June 1; the report attributes activity to REvil, documents related indicators (RDP probes, malicious source IPs), and highlights systemic cybersecurity hygiene issues across the food industry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
