- Home
- / Insights
- / Case Studies
- / Ransomware Response for an Engineering and Manufacturing Company
Ransomware Response for an Engineering and Manufacturing Company
-
June 10, 2024
-
An engineering and manufacturing company was actively experiencing a ransomware attack from a sophisticated threat actor group. The threat actors were locking the company out of their environment, moving laterally, and creating administrator accounts to gain further access to systems. The company contacted FTI Cybersecurity’s Incident Response Hotline for immediate assistance containing the attack.
Our Impact
FTI Cybersecurity’s initial response prevented the threat actor from deploying and executing their ransomware payload and prevented significant or impactful data exfiltration. The continued around-the-clock efforts of the team ensured that the incident did not cause any major operational outages or data exposure related to the company’s clients.
Our Role
FTI Cybersecurity responded at approximately 3am ET with support from both North America and EMEA-based team members. The team provided initial containment measures and support remotely to stop the most urgent aspects of the attack. When the North America team began their day, full forensic, investigation, containment, and remediation support began. The FTI Cybersecurity team managed all components of the incident and the various stakeholders involved, which included external counsel and the internal IT department.
FTI Cybersecurity provided a final written report and timeline to the company upon completion of the investigation. The company then needed additional support to monitor their systems in the aftermath of the incident and prevent and detect attempts at reinfection. The FTI Cybersecurity team performed active 24/7 monitoring with hands-on-keyboard support (e.g., remotely monitoring the client’s security tooling) for six weeks following the initial incident.
Published
June 10, 2024
Key Contacts
Managing Director
Senior Managing Director, Global Head of Cybersecurity