Ransomware

Rail giant Wabtec discloses data breach after Lockbit ransomware attack

0

U.S. rail and locomotive company Wabtec Corporation disclosed a data breach in which personal and sensitive information were exposed.

Wabtec, a U.S.-based public company, produces state-of-the-art locomotives and rail systems. The company employs around 25,000 people and has a presence in 50 countries, being the world’s market leader in freight locomotives and a major player in the transit segment.

Wabtec announced at the end of the year that hackers breached their network and installed malware on specific systems as early as March 15th, 2022.

On June 26th, Wabtec detected unusual activity on their network leading to an investigation of the attack to determine whether the hackers had stolen data.

The investigation of the incident was concluded on November 23rd, 2022, when data review specialists confirmed that LockBit had stolen files containing sensitive personal information.

This stolen data exposed a wide variety of sensitive information which includes names, date of birth, Non-US National ID Number, Non-US Social Insurance Number or Fiscal Code, Passport Number, IP Address, Employer Identification Number (EIN), USCIS or Alien Registration Number, NHS (National Health Service) Number (UK), Medical Record/Health Insurance Information, Photograph, Gender/Gender Identity, Salary, Social Security Number (US), Financial Account Information, Payment Card Information, Account Username and Password, Biometric Information, Race/Ethnicity, Criminal Conviction or Offense, Sexual Orientation/Life, Religious Beliefs, Union Affiliation.

Wabtec stated that even though there is no indication that any specific information was misused, considering the nature of the incident and of the affected personal data, they cannot rule out that there may be attempts to carry out fraudulent activity.

Wabtec advises individuals to be vigilant against incidents of identity theft and fraud by reviewing their financial account statements and credit reports for any anomalies.

The company started sending notices of a data breach to all impacted individuals on December 30th, 2022, but the exact number of people affected by the incident remains undisclosed.

Image Credits : Charged EVs

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

PyTorch compromised with malicious dependency

Previous article

Critical security flaws found in top carmakers

Next article

You may also like

More in Ransomware

Comments

Leave a reply

Your email address will not be published. Required fields are marked *