Menu
Browse

Cyber Incident Victim: EMCOR Group

Date:

Feb 2020

Location:

United States of America

Summary

A Fortune 500 company specializing in construction and infrastructure services suffered a Ryuk ransomware attack affecting certain IT systems, prompting immediate shutdowns to contain the infection. The victim, operating globally through over 80 subsidiaries with 33,000 employees and $9 billion annual revenue, initiated restoration efforts without confirming whether ransom payments occurred or if backups were utilized. While the incident disrupted operations and led to adjusted financial projections for the year, internal investigations found no evidence of compromised employee or customer data. The attack aligned with Ryuk's typical behavior, contrasting ransomware strains known for data exfiltration tactics.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On February 15, 2020, EMCOR Group, a Fortune 500 company with over $9 billion in annual revenue, experienced a ransomware attack identified as an infection by the Ryuk strain. The company detected the incident and promptly shut down certain affected IT systems to contain the spread, emphasizing that not all systems were compromised. EMCOR initiated restoration efforts for impacted services but did not publicly disclose whether it paid the ransom demand or relied on backups for recovery. The organization stated its investigation found no evidence that employee or customer data was exfiltrated during the attack. Nearly three weeks after the incident, the ransomware notification message remained visible on the company's website, indicating ongoing disruptions. With operations spanning more than 170 locations globally through 80 subsidiaries and employing 33,000 people, the attack caused measurable operational downtime.

Cyber Incident Image

In its 2019 fourth-quarter financial report filed after the incident, EMCOR adjusted its 2020 earnings projections to account for losses attributable to the ransomware-induced downtime, though it withheld specific financial impact figures. The prolonged presence of the ransomware notification on its public-facing systems suggested extended recovery challenges. The attack placed EMCOR among prominent ransomware victims of the period, including defense contractor EWA, law firm Epiq Global, rail operator Railworks, and European energy provider INA Group. Ryuk's involvement contrasted with ransomware groups like REvil and Maze that typically combined encryption with data theft, aligning with EMCOR's assessment of no data compromise. The company maintained focus on restoring operations while withholding technical details about infection vectors or remediation methods.

Sources
Sources available to members
1 source