LockBit claims 4.5TB of data stolen from bicycle component maker Shimano

Organization
Shimano
Exploit
Ransomware
Industry
Manufacturing

Shimano, the Japanese manufacturer that dominates the market for bicycle drivetrains and components and also produces fishing tackle, appeared on the LockBit ransomware group's leak site in early November 2023. Cyber Daily dated the listing to November 2.

LockBit claimed to hold roughly 4.5 terabytes of company data. Its posting described employee records including home addresses, national identification numbers and passport scans, alongside bank statements, tax filings, balance sheets, contracts, non-disclosure agreements, a client database, sales and factory inspection reports, and drawings marked confidential. None of the claims were independently verified.

The group set a deadline of November 5, 2023 for payment. Shimano did not pay and said very little publicly. A European representative told reporters that headquarters was aware of the claims and that an investigation was underway, while the company's US arm declined to comment. Shimano's websites and commercial operations showed no visible disruption.

After the deadline passed, LockBit marked the entry as published. Cyber Daily reported that no files were actually visible on the leak site when it checked, and the entry stayed empty for more than a fortnight. Around November 24, 2023 the files, or at least a substantial subset of them, did appear, and reporters at Escape Collective and Cycling Weekly downloaded and described them. Shimano issued no formal breach notification during the reporting period.

Sources