Ransomware halted brewing at Duvel Moortgat's Belgian and US sites
- Organization
- Duvel Moortgat
- Exploit
- Ransomware
- Industry
- Food and Beverage
Duvel Moortgat, the Belgian brewer behind Duvel, Vedett, Maredsous and La Chouffe, detected a ransomware attack in the early hours of Wednesday, March 6, 2024. A company representative said its monitoring systems reported the attack as it was happening, and the brewer responded by switching off its servers.
The shutdown stopped brewing at all of the company's Belgian sites and at its brewery in the United States. Communications manager Ellen Aerts said Duvel Moortgat was confident it would be able to restart production soon and told reporters there was enough stock that drinkers did not need to worry about supply. Output at the Puurs-Sint-Amands plant resumed within days.
The Stormous ransomware group claimed responsibility on March 7, adding Duvel to the leak site it uses to pressure victims. The gang said it had taken 88 gigabytes of data and set a ransom deadline of March 25.
Duvel Moortgat did not pay. The Dutch technology outlet Techzine reported in late April 2024 that stolen files had been published, describing roughly a terabyte of material including employee passport copies and internal documents, and said Black Basta posted the data after apparently obtaining it from Stormous. The volume claimed in March and the volume described in April do not match, and the company confirmed neither figure.