Menu
Browse

Cyber Incident Victim: EVRAZ

Date:

Mar 2020

Location:

United States of America

Summary

A major steel manufacturing and mining company, owned by a prominent Russian billionaire, suffered a ransomware attack attributed to the Ryuk strain, disrupting its North American operations across multiple plants in the US and Canada. The incident forced manufacturing halts at most facilities while IT teams worked to contain the infection, impacting thousands of employees. The attack occurred amid financial challenges following a significant drop in annual revenues and profits disclosed shortly beforehand, aligning with a broader pattern of ransomware targeting large corporations globally.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 5, 2020, EVRAZ, a global steel manufacturing and mining company owned by Russian oligarch Roman Abramovich, suffered a ransomware attack impacting its North American operations. The intrusion was attributed to the Ryuk ransomware strain, which disrupted steel production plants across the United States and Canada. Internal sources confirmed manufacturing halted at most facilities as IT teams worked to contain the infection and prevent lateral movement within corporate networks. The attack specifically targeted EVRAZ’s North American division, which employs approximately 1,400 personnel in the US and 1,800 in Canada. No operational details about European branches were disclosed, and attempts to contact those offices after business hours were unsuccessful. The company did not publicly confirm the incident’s scope or provide restoration timelines.

Cyber Incident Image

The ransomware incident compounded existing financial challenges for EVRAZ, which had recently disclosed a 7.3% year-over-year revenue decline to $11.91 billion and a 72% drop in pretax profit to $902 million in 2019. These figures contributed to a 7% share price decline in late February 2020, preceding the cyberattack. EVRAZ joined a list of prominent ransomware victims including EMCOR, Epiq Global, and Bretagne Télécom, though no threat actor claimed responsibility or specified ransom demands in this case. The company’s North American division declined to comment on operational impacts or recovery efforts. No additional technical specifics regarding attack vectors, data exfiltration, or network containment methodologies were disclosed by EVRAZ or corroborating sources.

Sources
Sources available to members
1 source