Belgian ale legend Duvel's brewery borked as ransomware halts production
- Reference: 1709815508
- News link: https://www.theregister.co.uk/2024/03/07/no_piss_up_in_duvels/
- Source link:
Spokesperson Ellen Aarts had a statement on tap for local media on Wednesday: "At 0130 last night, the alarms went off in Duvel's IT department because ransomware had been detected. Production was therefore immediately stopped. It is not yet known when it could start again. We hope today or tomorrow.
"Our IT department immediately intervened and is currently still mapping everything out. They are looking for a solution as quickly as possible."
[1]
El Reg tried to get Duvel to pour its heart out about the overall recovery progress and whether its Breendonk-based facility will be operational once again before the end of the week as expected, but it didn't immediately reply.
[2]
[3]
Details about the incident are generally sparse since the company hasn't publicized the break-in beyond a short statement offered to the press. It's not clear what group is behind the attack.
Duvel Moortgat not only brings Duvel to shop shelves, restaurants, and bars alike, but also other popular tipples such as La Chouffe, Vedett, Firestone Walker, and more.
[4]
Aarts [5]said fans needn't fear supply issues since the Breendonk facility is well stocked and the company isn't concerned about order fulfillment with the site's temporary downtime.
Other manufacturing organizations hit by ransomware often aren't so lucky and any kind of downtime can be operationally and financially damaging.
It's why the industry is such a common target for ransomware miscreants since they know that theoretically, manufacturers are more motivated to pay ransoms quickly, minimizing costly downtime.
[6]
IBM's most recent Cost of a Data Breach report found manufacturing was the single most targeted sector by cybercrims. The average cost of a data breach at a business like Duvel Moortgat, a consumer goods manufacturer, stands at $3.8 million according to [7]IBM's figures .
In reality, however, only a minority of organizations in the manufacturing sector actually pay ransoms – 34 percent compared to 73 percent that rely on backups for recovery, according to Sophos' figures. Ransom demands are growing, though, and data recovery rates remain a serious concern.
"While [the rate of paying victims] is a welcome improvement, manufacturing has the lowest rate of data recovery (88 percent got back encrypted data vs the 97 percent cross-sector average), suggesting that the sector should continue to focus on strengthening backup use," the report by Sophos [8]says .
[9]Japanese brewery using generative AI to dream up new beverages
[10]Chocolate beer barred from sale after child mistakes it for chocolate milk
[11]Pub landlords on notice as 'Internet of Beer' firm not only pulls pints, but can also clean the lines
[12]Cool story, brew: Utah karaoke crooners receive cold, refreshing shock as alcohol authority refuses beer licence
"The proportion of manufacturing organizations paying higher ransoms has increased from our 2022 study, with 40 percent paying a ransom between $100,000 and $999,999 vs. 29 percent who paid this amount the year before. In addition, 20 percent reported payments of $1 million or more compared to just eight percent the year prior."
Whether Duvel can recover from its [13]ransomware incident in the day or two it predicts is unclear, but it will surely be hopping for a full return schooner rather than later. Let's see if that survives the edit. ®
Get our [14]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZenywIwHBaL4a122C7Ob7gAAAMg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZenywIwHBaL4a122C7Ob7gAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZenywIwHBaL4a122C7Ob7gAAAMg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZenywIwHBaL4a122C7Ob7gAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://www.nieuwsblad.be/cnt/dmf20240306_93861112
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZenywIwHBaL4a122C7Ob7gAAAMg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.ibm.com/reports/data-breach
[8] https://news.sophos.com/en-us/2023/06/21/the-state-of-ransomware-in-manufacturing-and-production-2023/
[9] https://www.theregister.com/2023/12/19/kirin_ai_drink_development/
[10] https://www.theregister.com/2021/08/11/chocolate_beer_banned/
[11] https://www.theregister.com/2021/06/23/the_internet_of_beer_grows/
[12] https://www.theregister.com/2019/05/01/utah_karaoke_crooners_told_no_beer_with_control_authority_declares/
[13] https://www.theregister.com/2024/03/06/fbi_ransomware_cybercrime_costs/
[14] https://whitepapers.theregister.com/
Re: Too far
I wanted to confirm the brewery is on Belgian's Critical Infrastructure list (surely, right?) but their National Crisis Center site which handles such things is down at the moment: http://crisiscenter.be/
This is what happens when Belgian sysadmins run out of beer, everything grinds to a halt
Edit: It's back. They must have broken up the emergency crate
Re: Too far
Indeed, why couldn't the ransomware scum have hit Heineken instead? (I know, that's Dutch.)
Re: Too far
Or Stella!!!
Re: Too far
The Stella brewery doesn't only produce Stella,I've been on a tour.
Nice place, nice town.
The end of the world!
Just try and remember what it was like…
I hope they get it sorted quick, Duvel is a particularly delicious drop.
I don't think they're in danger of Mort Subite.
Als de Duvel.... ====>
A diabolic deed!
A new 'zero day'?
" Company reassures public it has enough beer "
They have enough already made in stock but 'production' is stopped, so how does ransomware stop beer fermenting?
Re: A new 'zero day'?
Because so many industrial control systems and HMIs run Windows, I would guess.
But also because they may have shut their whole network down to stop any further intrusion
The yeast is still fermenting, but if they can't pump it out into the next vessel in their process then the taste will be ruined. Or maybe it won't, and they will sell it as a 'limited edition' batch. They could call it Duvel Scumbag, with 'extra scummy' foam.
Re: A new 'zero day'?
@cyberdemon Sorry, that was actually an (obviously inadequate) attempt at a joke. However " ... because they may have shut their whole network down to stop any further intrusion " once again suggests that network segregation is a concept of the past. The vast majority of serious intrusions have been achieved due to appallingly inadequate network security -- no "sophisticated attack" needed. We must start making systems genuinely resilient as opposed to just assuming that once inside the perimeter the attacker has free reign.
A lack of cheer(s)
Must have been a bugger when they started brewing back in 1871 and the systems weren't available. Shirley someone wrote down how to do it in the BCP....
Alas, the El Reg beer icon is not the correct shape for Duvel. Or at least not the shape they say you should use, not sure it matters to my less-than-discerning palate.
a ransomware attack has brought its facility to a standstill
If this leaves the supermarket shelves empty, don't despair. To recreate the effects of a night's Duvel consumption, just eat a whole pack of laxatives before bedtime, then ask someone to hit you on the head with a hammer a few times the next morning.
Too far
These bastards have hit hospitals, governments and airlines
But now they've gone too far, hitting a brewer. Risking an interruption in the flow of that sweet sweet nectar.
I think we need a peoples army of hackers to take them out. If it's beer today tomorrow it could be crisp (chips for the west-pondians) or pizza.