CSIDB logo
Incident

Stuller, Inc.

Incident posture

Attack window
Nov 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-11-28 00:00

Linked entities

Victim
Stuller, Inc.
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Nov 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Stuller, Inc. experienced a cyberattack that disrupted operations, leading to various unspecified technical issues. The company's president acknowledged the incident and stated teams worked continuously to restore normal business functions, though customers were warned they might encounter service inconsistencies during recovery efforts. The attack prompted immediate response measures to mitigate impacts on customer operations.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Stuller, Inc., a Louisiana-based company, experienced a disruptive cyberattack on the morning of November 28, 2020. The incident caused multiple operational problems that impacted normal business functions, though specific affected systems or data types were not publicly disclosed. Company President Danny Clark confirmed the attack in a statement issued on November 29, indicating cybersecurity personnel had been working continuously since discovery to restore operations. The attack timeline suggests intrusion activities occurred prior to Saturday morning detection, though no technical details about initial compromise vectors or attacker methodologies were released. Internal teams prioritized containment and recovery procedures throughout the weekend following incident identification.

The cyberattack resulted in significant service disruptions that Clark acknowledged would likely continue affecting customers during the week following the incident. Customers were warned to anticipate service inconsistencies described as "non-Stuller like" circumstances, indicating degraded operational capacity across unspecified business units. No ransomware claims or data exfiltration evidence appeared in initial disclosures, and the company avoided characterizing attacker motives or origins. Restoration efforts focused on rebuilding infrastructure to meet customer expectations, though Clark's statement emphasized ongoing work would be required beyond the initial response period. The public notification provided no specifics about forensic findings, third-party investigator involvement, or regulatory reporting obligations related to the security breach.

Sources

Sources available to members: 1 source.

CSIDB