ENGlobal discloses ransomware attack that limited access to its IT systems

Organization
ENGlobal Corporation
Exploit
Ransomware
Industry
Energy

ENGlobal Corporation, a Houston-based engineering and automation contractor serving energy companies and U.S. government agencies, told the Securities and Exchange Commission on December 2, 2024 that it had been hit by ransomware.

In its Form 8-K the company said it detected the incident on November 25, 2024, and that a preliminary investigation found a threat actor had illegally accessed its information technology system and encrypted some of its data files. ENGlobal restricted employee access to systems supporting essential business operations only, opened an internal investigation and engaged external cybersecurity specialists. At the time of the filing it said the timing of a return to full access remained unclear and that it had not determined whether the attack would materially affect its results.

The restrictions cut off parts of the company's business applications, including financial and operating reporting systems, for roughly six weeks before operations returned to normal.

In a further regulatory filing on January 27, 2025, ENGlobal said the attacker had reached a portion of its systems that contained sensitive personal information and that it intended to notify affected parties as required by law. It did not disclose how many people were involved or what categories of data were taken. The company said the incident was not expected to have a material impact on its operations or financial condition, and no ransomware group publicly claimed responsibility.

Sources