MarineMax Targeted by Rhysida Ransomware Group

Year

2024

Month

March

Reference number

20240301

Impact area

Shore

Incident location

Clearwater, Florida, USA

Incident country

USA

Victim country

United States

Victim identity

MarineMax

Victim Type

Luxury yachting company

Method

Ransomware

Summary:

In March 2024, MarineMax, a leading retailer of recreational boats and yachts, was targeted by the Rhysida ransomware group. The breach was first announced on March 12th, and the group posted samples of the stolen data, which include earnings reports, balance sheets, bank account wire transfers, customer databases, and other financial documents. Rhysida is demanding 15 BTC (approximately $950,000 to $1.007 million) as ransom. The company disclosed the cyberattack to the SEC, noting disruptions in its business operations due to containment measures. Rhysida is auctioning the stolen data on its Tor-based website, offering it exclusively to the highest bidder if the ransom is not paid. MarineMax's clientele, likely high earners, could be significantly impacted if sensitive information is leaked. The ransomware group is known for targeting various sectors and often uses phishing attacks and Cobalt Strike tools to breach networks. Researchers developed a decryption tool for Rhysida's encryption method in February 2024, but it is unclear if it remains effective. The extent of data sensitivity in the MarineMax breach is also uncertain.

Reference URL

https://cybernews.com/news/marinemax-yachts-ransomware-attack-rhysida-gang/
https://www.theregister.com/2024/03/21/luxury_yacht_dealer_rhysida/
https://www.securityweek.com/ransomware-group-takes-credit-for-attack-on-boat-dealer-marinemax/
https://25011010.fs1.hubspotusercontent-eu1.net/hubfs/25011010/Norma%20Cyber%20Annual%20Threat%20Assessment.pdf