Lockbit attacks Cross City Tunnels

Incident Date: Jun 07, 2023

Attack Overview
VICTIM
Cross City Tunnel
INDUSTRY
Transportation
LOCATION
Australia
ATTACKER
Lockbit
FIRST REPORTED
June 7, 2023

Lockbit Ransomware Targets Cross City Tunnels

The Lockbit ransomware gang has allegedly attacked Cross City Tunnels. Lockbit posted Cross City Tunnels’ details on its data leak site on June 5th, stating that the stolen information would be published on June 26th if Cross City Tunnels failed to pay the ransom. The Cross City Tunnel is a twin-road tunnel tollway located in Sydney, Australia. It is 2.1km long and was opened in August 2005. It links Darlin Harbor to Rushcutters Bay, is owned by the government of New South Wales, and is run by Transurban. The organization has neither confirmed nor denied the attack.

LockBit's Modus Operandi

LockBit has been active since 2019 and is enabled with security tool evasion capabilities and an extremely fast encryption speed. LockBit is noted for using a triple extortion model where the victim may also be asked to purchase their sensitive information in addition to paying the ransom demand for decrypting systems. LockBit is considered to have been the most active attack group in 2022 as other high-profile groups became less active and demanded ransoms of more than $50 million.

Target Preferences

LockBit tends to target larger enterprises across any industry vertical with the ability to pay high ransom demands but also tends to favor Healthcare targets.

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.