Kawasaki Motors Europe restored servers after RansomHub attack

Organization
Kawasaki Motors Europe
Exploit
Ransomware
Industry
Automotive

Kawasaki Motors Europe, the Netherlands-based European arm of the Japanese manufacturer, said it was the subject of a cyberattack at the start of September 2024. The company said the attack did not achieve what its operators intended, but its IT team disconnected every server as a precaution while it assessed the damage.

The RansomHub ransomware group added the company to its dark web extortion portal on September 5, 2024, listing the domain kawasaki.eu and claiming it had exfiltrated 487GB of data. The group set a countdown to September 14, 2024 and threatened to publish the archive if its demands were not met.

Kawasaki Motors Europe spent the following week working with internal staff and external cybersecurity consultants, isolating servers individually and running what it described as a cleansing process to identify and remove suspicious files before restoring interconnectivity. By the start of the next week the company said more than 90 percent of server functionality had been recovered and that business with dealers, suppliers and logistics partners had resumed.

Kawasaki did not comment publicly on whether a ransom had been demanded or paid, and it did not respond to enquiries from The Record or CyberInsider. RansomHub said it had published the stolen material after the September 14 deadline passed, and Cyber Daily reported the leak on September 16, 2024.

Sources