Bis Industries investigates RansomHub claims over December 2024 attack
- Organization
- Bis Industries
- Exploit
- Ransomware
- Industry
- Mining Services
Bis Industries, an Australian mining logistics and equipment services company headquartered in North Sydney, confirmed in March 2025 that it had suffered a ransomware incident the previous December. The company said an unauthorised third party accessed and encrypted part of its IT systems.
In a statement to Cyber Daily, Bis said it engaged external cyber specialists as soon as it became aware of the intrusion, and that they contained the incident and restored systems with little impact on operations. The company said it had since become aware of a dark web claim that data was stolen during the same incident, and that it was working with those specialists to investigate the allegation.
The RansomHub ransomware-as-a-service operation listed Bis Industries on its darknet leak site on 17 February 2025, a listing independently recorded by the extortion tracker Ransomware.live. Cyber Daily reported that the gang claimed to hold 502GB of company data and that the post had been viewed more than 7,000 times.
Bis supplies coal mining equipment for hire and provides mining services, including under its UGM brand, and employs more than 500 people across sites in New South Wales and Queensland. As of the March reporting the company had not said what information, if any, was taken, and the investigation remained open.