Cold storage and logistics giant Americold has confirmed that over 129,000 employees and their dependents had their personal information stolen in an April attack, later claimed by Cactus ransomware.
Americold employs 17,000 people worldwide and operates more than 24 temperature-controlled warehouses across North America, Europe, Asia-Pacific, and South America.
Americold also told customers via a private memo issued after the attack to cancel all inbound deliveries and reschedule outbound shipments, except for those deemed critically time-sensitive and nearing expiration.
In notification letters sent on December 8 to 129,611 current and former employees affected by the data breach, the company revealed the attackers were able to steal some data from its network on April 26.
Another cyberattack hit Americold in November 2020, impacting its operations, phone systems, email services, inventory management, and order fulfillment.
While multiple sources told BleepingComputer at the time that the 2020 breach was a ransomware attack, the company has yet to confirm it, and the ransomware group responsible for the November 2020 attack remains unknown.
Even though the company didn't connect the April 2023 incident to a specific ransomware operation, the Cactus ransomware operation claimed the attack on July 21.
The gang also leaked a 6GB archive of accounting and finance documents allegedly stolen from Americold's network, including private and confidential information.
The ransomware group also plans to release human resources, legal, company audit information, customer documents, and accident reports.
Cactus ransomware is a relatively new operation that surfaced in March this year with double-extortion attacks, first stealing data to use as leverage in ransom negotiations and then encrypting compromised systems.
An Americold spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today.
Toyota warns customers of data breach exposing personal, financial info.
Navy contractor Austal USA confirms cyberattack after data leak.
Cactus ransomware exploiting Qlik Sense flaws to breach networks.
Toronto Public Library confirms data stolen in ransomware attack.
Kansas courts confirm data theft, ransom demand after cyberattack.
This Cyber News was published on www.bleepingcomputer.com. Publication date: Mon, 11 Dec 2023 17:55:07 +0000