Clop Ransomware Attack on DESMI

Year

2023

Month

April

Reference number

20230409

Impact area

Shore

Incident location

Denmark

Incident country

Denmark

Victim country

Denmark

Victim identity

DESMI

Victim Type

Company office

Method

Ransomware

Summary:

In April 2023, DESMI, a global pump solutions company based in Denmark, experienced a ransomware attack by the Clop gang. The attack led to the shutdown of all IT systems, but fortunately, the ERP and finance systems were not compromised, and production sites in China, India, America, and Denmark continued to operate without disturbances. The attack exploited the CVE-2023-34362 MOVEit vulnerability and occurred during the COVID-19 pandemic when employees were working from home. DESMI's CEO, Henrik Sørensen, confirmed that the company has no plans to pay the ransom. Third-party cybersecurity experts were hired to investigate and restore IT services. The incident has been reported to the authorities and Danish Police, and DESMI is notifying its customers and business partners about the breach. The company is focused on minimizing customer impact and expects to have systems operational within a couple of weeks.

Reference URL

https://securityaffairs.com/101495/hacking/desmi-discloses-cyber-attack.html
https://www.hackmageddon.com/2023/09/05/16-31-july-2023-cyber-attacks-timeline/
https://www.manageengine.com/log-management/ransomware-attacks/desmi-hit-by-cyberattack.html