Menu
Browse

Cyber Incident Victim: RR Donnelley

Date:

Dec 2021

Location:

United States of America

Summary

RR Donnelley suffered a Conti ransomware attack involving unauthorized system access and data exfiltration, prompting network shutdowns that disrupted customer operations, including delays in critical document processing. The threat actors initially leaked stolen data but removed it after negotiations, with the company later confirming corporate data compromise while emphasizing ongoing efforts to safeguard information. The incident coincided with a significant merger announcement, aligning with known ransomware tactics targeting major financial events to pressure victims.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

RR Donnelley (RRD), a global communications and marketing services firm with 33,000 employees and $4.93 billion in 2021 revenue, experienced a significant cybersecurity incident in December 2021. The company disclosed via a December 27 SEC Form 8-K filing that it had suffered a "systems intrusion" requiring proactive network shutdowns to contain the attack's spread. This defensive action caused operational disruptions affecting multiple client services, including delays in processing printed documents essential for vendor payments, disbursement checks, and motor vehicle documentation. While RRD's initial disclosure stated no evidence of client data compromise, subsequent developments revealed broader impacts. The Conti ransomware group publicly claimed responsibility for the attack on January 15, 2022, initially leaking approximately 2.5GB of allegedly stolen corporate data before temporarily removing it from public view following renewed negotiations with RRD.

Cyber Incident Image

On January 19, 2022, RRD filed an updated 8-K confirming data exfiltration had occurred during the December intrusion, clarifying this was not a new incident. The company acknowledged ongoing analysis to determine the nature of accessed data while implementing measures to protect corporate and client information. RRD maintained direct communication with affected clients throughout the incident response process. The ransomware attack occurred shortly after RRD's December announcement of a definitive merger agreement with Chatham Asset Management, aligning with FBI warnings from November 2021 about ransomware actors strategically timing attacks to coincide with major financial events like mergers and acquisitions. Operational recovery efforts proceeded alongside negotiations to prevent further data dissemination, though the company did not disclose whether ransom payments were made or specify technical details about the intrusion methodology.

Sources
Sources available to members
1 source