AmerisourceBergen, a healthcare company, recently announced that one of its subsidiaries had experienced a data breach in its IT system. The company has a large presence in the US, Canada, the UK, and other countries, with over 42,000 employees and 150 offices worldwide. They are a distributor of pharmaceutical products, a medical business consultant, and a patient services provider. The Lorenz ransomware gang posted information on their extortion site that they claim was taken from the AmerisourceBergen breach. The company has stated that they have stopped the intrusion and are now investigating to see if any important data was stolen. The file posted on the extortion site was dated November 1, 2022, suggesting that the incident occurred some time ago, even though the data was just posted now. Lorenz ransomware typically gains access to organizations' networks by exploiting vulnerabilities in Mitel telephony systems. After gaining access, they remain silent for months before exfiltrating and encrypting files using a backdoor. Although they don't carry out many ransomware attacks, they target large companies, ensuring that each incident has a major impact. Hensoldt, a multinational defense contractor, is one of their victims who had internal documents stolen. If you enjoyed this article, follow us on social media for more cybersecurity news and topics. Additionally, you can sign up for our newsletter to receive cybersecurity updates directly in your inbox.
This Cyber News was published on heimdalsecurity.com. Publication date: Thu, 09 Feb 2023 09:58:02 +0000