DENHAM the Jeanmaker confirms cyberattack linked to Akira ransomware
- Organization
- DENHAM the Jeanmaker
- Exploit
- Ransomware
- Industry
- Fashion Retail
DENHAM the Jeanmaker, the Amsterdam denim label founded in 2008, confirmed in January 2024 that it had been the target of a cyberattack. The company said the intrusion was discovered on December 27, 2023, when a message left by the threat actor was found on its systems.
DENHAM said its incident response team carried out a digital forensic investigation alongside an external cybersecurity firm and established that the attackers had reached some business data on the affected systems. It stated that the data did not include the personal information of consumers who had visited its webshop.
The brand notified the Dutch Data Protection Authority as a precautionary measure and said it had put additional security measures in place with its external advisers. Retail operations in stores and online were not materially affected, and the company described its recovery as swift.
The Akira ransomware group named DENHAM on its own leak site in mid January 2024, claiming around 100GB of data including part of the client database, financial records and other confidential files. The Cyber Express reported that claim on January 18, 2024. DENHAM declined either to confirm the attribution or to comment on it. Akira had been active against mid-sized European companies through 2023, and researchers have noted overlaps with the defunct Conti operation, including shared code, use of ChaCha encryption and similar key generation methods.