CSIDB logo
Incident

Asteelflash

Incident posture

Attack window
Apr 2021
Location
France
Status
Historical
CIA posture
Available to members
Updated
2025-10-25 00:00

Linked entities

Victim
Asteelflash
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Apr 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Asteelflash, a prominent French electronics manufacturing services provider, was targeted in a cyberattack by the REvil ransomware group, which demanded an initial $12 million ransom that escalated to $24 million after a deadline expired. The attackers demonstrated unauthorized access by leaking a compressed file containing employee-authored documents as proof of data exfiltration, though encryption impact remains unconfirmed. The company acknowledged evaluating the incident but provided no further details on negotiations or system compromises, reflecting the gang's common tactic of pressuring victims through stolen data threats alongside file encryption.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Asteelflash, a prominent French electronics manufacturing services company specializing in circuit board design and production, experienced a cyberattack by the REvil ransomware group (also known as Sodinokibi) around early April 2021. The ransomware gang established a Tor negotiation page accessible via a leaked ransomware sample, revealing their initial $12 million ransom demand, which doubled to $24 million after a specified deadline expired. Attackers provided evidence of data exfiltration by sharing a compressed file named 'asteelflash_data_part1.7z' containing stolen documents, with metadata confirming employee authorship of some files. This tactic aligned with REvil's established pattern of stealing data prior to encryption to pressure victims through threats of data exposure. The Tor page logs indicated stalled negotiations between the threat actors and Asteelflash, with no public disclosure of the company's response strategy.

BleepingComputer discovered the compromise through analysis of the REvil sample but could not verify whether file encryption succeeded on corporate systems. Asteelflash provided minimal official commentary, with one representative telling LeMagIT the incident remained under evaluation. Multiple outreach attempts by BleepingComputer received no response. The attackers' use of data theft as leverage reflected broader ransomware trends observed since 2020, where exfiltrated information supplemented encryption-based extortion. No technical details regarding attack vectors, compromised systems, or operational disruptions were disclosed publicly. The incident's resolution status remained unclear, with the ransom unpaid and no subsequent data leaks confirmed at the time of reporting.

Sources

Sources available to members: 1 source.

CSIDB