Infrastructure Manufacturer - Unit 42 IR Case Study
Learn how a manufacturer cut a ransom demand by 73%. This case study follows a U.S. infrastructure equipment manufacturer through simultaneous Black Basta and LockBit ransomware attacks. Unit 42 Incident Response identified the compromised contractor VPN account behind the breach, blocked known IoCs with Cortex XDR®, and restored operations within 12 days. Coverage later expanded to 100% of endpoints. Read the story to learn from this manufacturer's experience.
What happened during the dual ransomware attacks?
The manufacturer was hit by two coordinated ransomware campaigns, first by LockBit and then by Black Basta. The attackers followed a similar pattern in both cases:
- Initial access: Unit 42 traced the entry point to a compromised contractor VPN account that did not have MFA enabled.
- Data theft before encryption: The adversaries exfiltrated approximately 3 TB of sensitive data before triggering file encryption.
- Operational disruption: Within 24 hours, ransomware was detonated, encrypting critical files and impacting at least 20 systems with file encryption and another 80 systems where attacker tools were present.
The result was a serious risk to financial performance, day-to-day operations, and brand reputation. The company faced ransom demands and the threat of data exposure, while needing to restore production and protect its customers and partners.
How did Unit 42 contain and resolve the ransomware incidents?
Unit 42 applied a structured, threat-informed incident response approach that moved through four main phases: Assess, Secure, Recover, and Transform.
1. Assess (Days 0–4)
- Performed rapid crisis intervention and initial scoping.
- Analyzed firewall and VPN logs to understand how the attackers got in.
- Used Cortex Xpanse to map the external attack surface and identify vulnerabilities.
2. Secure (Days 5–7)
- Confirmed Black Basta as one of the ransomware families involved.
- Identified the contractor VPN account without MFA as the initial access point.
- Determined that 3 TB of data had been exfiltrated.
- Began direct threat actor negotiations to manage ransom and data exposure risk.
3. Recover (Days 8–14)
- Blocked ransomware indicators of compromise (IoCs) using Cortex XDR.
- Initiated 24/7 threat monitoring to stop further lateral movement.
- Uncovered earlier impact and data theft by LockBit in addition to Black Basta.
- Rebuilt affected systems and restored data from backups.
- Helped the client regain operational capacity within 12 days.
4. Transform (Days 15–30)
- Expanded Cortex XDR coverage from 70% to 100% of endpoints for full visibility.
- Implemented enhanced firewall rules to block known IoCs.
- Continued 24/7 monitoring through Unit 42 MDR and proactive threat hunting.
- Provided guidance to strengthen long-term resilience against future attacks.
This end-to-end approach not only contained and remediated the incidents but also helped the manufacturer reimagine its security posture for ongoing protection.
What business outcomes did the manufacturer achieve with Unit 42?
By partnering with Unit 42, the manufacturer was able to limit damage, restore operations, and strengthen its security posture with clear, measurable results:
- Ransom cost reduction: Through expert negotiation with the attackers, Unit 42 achieved a 73% reduction in the ransom demand.
- Data exposure prevented: Negotiations with LockBit helped prevent 2.5 million files from being exposed.
- Faster operational recovery: Systems were decrypted, rebuilt, and data was restored from backups, enabling the company to regain operational capacity within 12 days.
- Improved endpoint coverage: Cortex XDR coverage increased from 70% to 100% of endpoints, closing visibility gaps.
- Continuous protection: The organization now benefits from 24/7 threat monitoring and ongoing threat hunting via Unit 42 MDR.
Backed by Palo Alto Networks technology, extensive threat intelligence, and a team that handles over 1,000 incidents per year, the manufacturer was able to not only recover from the dual ransomware attacks but also rethink and strengthen its long-term security strategy.
Infrastructure Manufacturer - Unit 42 IR Case Study
published by GingerSec
GingerSec, LLC was founded with a passion for helping others stay secure in the digital world. We continuously strive to ensure our clients are as secure as they possibly can be, protecting their digital life. Because of this passion, our IT consulting to focus on providing you with security and operational function.
Because knowledge is power, we a full line of certification preparation courses and user awareness training. If you are an industry professional, allow us to help prepare you for the next certification exam. If you need security awareness training for your staff, you have you covered there as well.
GingerSec is also a reseller for your technology needs. We have the resources to provide you technology needs, whether at a personal use or enterprise-level we have the sources to help you. We have access to some of the more popular computer manufactures Dell, HP, and Lenovo.
#GingerSec