Cyber Incident Victim: La Calera Agricola
Date:
Sep 2022
Location:
Peru
Summary
La Calera Agricola was targeted by the LockBit ransomware group, which listed the organization on its leak site but did not release any stolen data or proof of compromise at the time of reporting. The attackers linked to a domain associated with the company's egg production division, raising uncertainty about whether both its agricultural and poultry business segments were affected or only one. The victim organization did not respond to inquiries seeking clarification on the scope of the incident.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
In September 2022, the LockBit 3.0 ransomware group listed La Calera Agricola on their data leak site, signaling a potential compromise of the organization's systems. The listing initially referenced La Calera's agricultural division but linked to lacalera.pe, a domain associated with the company's egg production and marketing operations. This discrepancy raised questions about whether both divisions of the business – agriculture and egg production – were compromised or if the attackers had targeted only one segment. LockBit did not provide any leaked data or proof of compromise at the time of the incident report on September 9, leaving the exact scope of the intrusion unverified. DataBreaches.net attempted to clarify the situation by contacting La Calera directly but received no response prior to publication. The absence of confirmed data leaks or additional technical details prevented independent verification of the attack's severity or the validity of LockBit's claims.

No public statements from La Calera Agricola regarding the incident were documented in the available sources, leaving their awareness of or response to the situation unconfirmed. The lack of leaked data on LockBit's site as of September 9 suggested either ongoing negotiations between the parties, incomplete data exfiltration, or potential misidentification by the threat actors. The incident occurred amid other regional cyberattacks, including a ransomware attack on Ourique municipality and a COVID-19 tracking platform breach at mining company Codelco, though no direct connection between these events was established. Without further confirmation from La Calera or evidence of data exposure, the operational impact, data compromise scope, and remediation efforts remained unclear. The listing represented a typical ransomware group pressure tactic to compel payment while leaving the actual intrusion consequences indeterminate at the time of reporting.
