logo

JBS Ransomware Attack Started in March and Much Larger in Scope than Previously Identified

ID: 4cea19e6-9633-5c45-9386-6b4b3f836d5a

STIX ID: report--4cea19e6-9633-5c45-9386-6b4b3f836d5a

Feed Name: SecurityScorecard Blog

Threat Score
80/100

Date Published: 2025-02-13

Date Updated: 2026-04-29

...
...

SecurityScorecard investigated a REvil/Sodinokibi ransomware campaign against JBS, reporting reconnaissance in February 2021, repeated data exfiltration between March and May (≈45 GB to MEGA and up to 5 TB to hosts in Hong Kong), leaked employee credentials, persistent TeamViewer access, and encryption on June 1; the report attributes activity to REvil, documents related indicators (RDP probes, malicious source IPs), and highlights systemic cybersecurity hygiene issues across the food industry.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.