Menu
Browse

Cyber Incident Victim: HENSOLDT SAS

Date:

Oct 2022

Location:

France

Summary

The Snatch ransomware group compromised HENSOLDT France, a provider of military and defense electronics solutions for sectors including aeronautics, energy, and transport. The attackers published a sample of stolen data on their Tor leak site as evidence of the breach. The company specializes in mission-critical systems, sensors, and secure communications, with products compliant with military standards. Snatch's malware employs tactics like rebooting systems into Safe Mode to evade security measures during encryption.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On or around October 31, 2022, the Snatch ransomware group publicly claimed responsibility for a cyberattack targeting HENSOLDT France, a company specializing in military and defense electronics. The attackers listed the French firm on their Tor-based leak site, a platform commonly used by ransomware operators to pressure victims by threatening data exposure. As evidence of the breach, Snatch published a 94 MB sample of allegedly stolen data. HENSOLDT France develops and provides critical electronic systems for aerospace, defense, energy, and transportation sectors, including mission management systems, advanced sensors, embedded systems, and secure communications solutions. The company’s products and services adhere to stringent military and aeronautical standards, with applications across air, naval, and land operations in domestic and international markets.

Cyber Incident Image

The Snatch ransomware, first identified in late 2019, employs distinctive tactics such as forcing infected systems to reboot into Safe Mode to circumvent security software. While the full scope of compromised systems at HENSOLDT France remains unspecified, the attackers’ publication of data samples indicates unauthorized access to internal information. No operational disruptions, financial demands, or containment measures were detailed in available reports. HENSOLDT France’s role in supplying cybersecurity solutions and technologies for hazardous environments underscores the potential sensitivity of accessed data, though specific data categories beyond the sample size were not disclosed. The incident highlights persistent targeting of defense-industrial entities by ransomware groups seeking to exploit critical infrastructure vulnerabilities.

Sources
Sources available to members
1 source