Funlab confirms Lynx ransomware attack on Australian entertainment group

Organization
Funlab
Exploit
Ransomware
Industry
Entertainment

Funlab, the Australian entertainment operator behind venue brands including Strike Bowling, Holey Moley, Archie Brothers and Hijinx Hotel, confirmed it had been hit by ransomware after the Lynx group added the company to its dark web leak site in mid-October 2024. Funlab runs roughly 40 venues across Australia, New Zealand and the United States.

The company said the incident took place between September 20 and 22, 2024, and that normal operations were restored within about 48 hours. Funlab said it did not believe guest data had been accessed, and that a small number of current and former employees, which it put in the low double digits, had limited information accessed.

Lynx published screenshots and sample documents as proof of the intrusion but did not disclose a ransom figure or the volume of data it claimed to hold. Cyber Daily reported that the posted material pointed to payroll, finance and Google Workspace backup folders taken from a network attached storage device, including budget spreadsheets and internal correspondence.

Funlab said it engaged external cybersecurity specialists, reported the incident to the Australian Signals Directorate's Australian Cyber Security Centre and the Office of the Australian Information Commissioner, and contacted the employees it believed were affected to offer assistance. Lynx first appeared in July 2024 and is regarded by researchers as a rebrand of the INC Ransom operation.

Sources