Industrial Cybersecurity Pulse
  • SUBSCRIBE
  • Threats & Vulnerabilities
  • Strategies
  • IIoT & Cloud
  • Education
  • Networks
  • IT/OT
  • Facilities
  • Regulations
Industrial Cybersecurity Pulse
Subscribe
Industrial Cybersecurity Pulse
  • Threats & Vulnerabilities
  • Strategies
  • IIoT & Cloud
  • Education
  • Networks
  • IT/OT
  • Facilities
  • Regulations
  • Threats & Vulnerabilities

Throwback Attack: Hackers steal 1 TB of data from beverage giant Brown-Forman

  • Gary Cohen
  • April 1, 2021
Courtesy: Rick Ellis
Courtesy: Rick Ellis
Total
0
Shares
0
0
0
0

Multinational brewery and beverage manufacturer Molson Coors was recently hit with a damaging cyberattack, but they’re far from the first adult beverage company to find themselves in hackers’ crosshairs. In August 2020, U.S. spirits and wine giant Brown-Forman suffered an attack in which intruders claimed to have stolen 1 TB of confidential data.

Brown-Forman, a 150-year-old company headquartered in Louisville, Kentucky, is the home of world-renowned whiskey and scotch brands such as Jack Daniel’s, Early Times and Woodford Reserve; vodka brand Finlandia; tequila brands El Jimador and Pepe Lopez; Champagne brand Korbel; and much more.   

The REvil (also known as Sodinokibi) ransomware crew compromised Brown-Forman’s networks and spent more than a month in the company’s systems, poring over data. They gathered employee information, contracts, company agreements and internal correspondence dating as far back as 2009.

“Most intrusions are over 200 days before they’re detected,” said Bryan Bennett, cybersecurity lead at ESD Global. “So somebody literally has seven months-ish, on average, just to look around and see what they can find.”

That’s exactly what the REvil hackers did. They claimed they were planning to auction off the most sensitive data to the highest bidder and then leak the rest unless their ransom demands were met, a common practice for the crew. REvil, which stands for Ransomware Evil, first appeared in 2019 and is a ransomware-as-a-service (RaaS) operation that has extorted large amounts of money from organizations worldwide. As proof of the Brown-Forman hack, the operators posted multiple screenshots showing directories and files belonging to the company on their leak site, as well as some internal correspondence.

REvil did not get a chance to encrypt the stolen data, often the final step in these sorts of intrusions, because Brown-Forman detected the attack and stopped it, a company representative told website BleepingComputer at the time.

Food and beverage manufacturers seem to be a growing target for hackers, as Australia’s Lion, Italy’s Licya Campari Group and Molson Coors have all suffered attacks in the last year.

Gary Cohen
Gary Cohen

Gary Cohen is senior editor/product manager at CFE Media.

Related Topics
  • CFE Content
  • Featured
  • news
Previous Article
Courtesy: Rick Ellis
  • Threats & Vulnerabilities

Molson Coors cyberattack impacts production, shipments

  • Gary Cohen
  • April 1, 2021
Read More
Next Article
  • Threats & Vulnerabilities

U.S. cybercrime surging, annual losses hit $4.2 billion in 2020

  • StockApps
  • April 2, 2021
Read More
You May Also Like
Test 2 Alt Text
Read More
  • Threats & Vulnerabilities

Throwback Attack: A Florida teen hacks the Department of Defense and NASA

  • Gary Cohen
  • April 8, 2021
Read More
  • Threats & Vulnerabilities

U.S. cybercrime surging, annual losses hit $4.2 billion in 2020

  • StockApps
  • April 2, 2021
Courtesy: Rick Ellis
Read More
  • Threats & Vulnerabilities

Molson Coors cyberattack impacts production, shipments

  • Gary Cohen
  • April 1, 2021
As threat increases, college cybersecurity programs are more in demand
Read More
  • Threats & Vulnerabilities

Evaluating 2021 cyber threat landscape trends

  • Derek Manky and Aamir Lakhani
  • March 26, 2021
Pranav Patel, CEO of ResiliAnt, discusses cybersecurity management
Read More
  • Threats & Vulnerabilities

Cybersecurity Maturity: CEO Interview Series, Pranav Patel, ResiliAnt

  • Gary Cohen
  • March 25, 2021
Read More
  • Threats & Vulnerabilities

Manufacturers need to prepare for cybersecurity threats

  • Suzanne Gill
  • March 22, 2021
Read More
  • Threats & Vulnerabilities

Understand the cyber-attack lifecycle

  • Daniel E. Capano
  • March 18, 2021
Many wonder where to start when attempting to protect embedded systems in OT cybersecurity? Here are some great places to start.
Read More
  • Threats & Vulnerabilities

Protecting the chip industry supply chain from cyberattacks

  • Mike Russo
  • March 15, 2021
NEWSLETTER

GET ON THE BEAT

Keep your finger on the pulse of top industry news

COUNT ME IN!
Hacks & Attacks
  • Throwback Attack: A Florida teen hacks the Department of Defense and NASA

    By Gary Cohen | April 8, 2021

  • U.S. cybercrime surging, annual losses hit $4.2 billion in 2020

    By StockApps | April 2, 2021

  • Molson Coors cyberattack impacts production, shipments

    By Gary Cohen | April 1, 2021

  • Evaluating 2021 cyber threat landscape trends

    By Derek Manky and Aamir Lakhani | March 26, 2021

  • ICS cybersecurity company appoints CEO

    By Mission Secure | March 19, 2021

EDUCATION BEAT

Introduction to Cybersecurity within Cyber-Physical Systems

Cyber-physical systems serve as the foundation and the invention base of the modern society making them critical to both government and business.

REGISTER NOW!
Recent News
  • Throwback Attack: A Florida teen hacks the Department of Defense and NASA

    By Gary Cohen | April 8, 2021

  • U.S. cybercrime surging, annual losses hit $4.2 billion in 2020

    By StockApps | April 2, 2021

  • Molson Coors cyberattack impacts production, shipments

    By Gary Cohen | April 1, 2021

  • Evaluating 2021 cyber threat landscape trends

    By Derek Manky and Aamir Lakhani | March 26, 2021

Resources
  • The International Society of Automation

  • Cybersecurity & Infrastructure Security Agency (CISA)

  • NIST: Guide to Industrial Control Systems Cybersecurity

  • Video: Cybersecurity for Energy Managers

  • Helpful links and Resources

Industrial Cybersecurity Pulse
  • Contact
  • Privacy Policy
  • Terms and Conditions
CFE Med Tech

Copyright 2021

BETA

Version 1.0

Connect With Us!
Facebook
Twitter
LinkedIn
Reddit

Input your search keywords and press Enter.

By using this website, you agree to our use of cookies. This may include personalization of content and ads, and traffic analytics. Review our Privacy Policy for more information. ACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled

Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.

Non-necessary

Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.

SAVE & ACCEPT