Menu
Browse

Cyber Incident Victim: USNR LLC

Date:

Sep 2020

Location:

United States of America

Summary

A manufacturing firm specializing in wood processing equipment suffered a ransomware attack that encrypted files and potentially exposed sensitive personal information of nearly 4,000 individuals. The compromised data included names, addresses, dates of birth, Social Security numbers, bank account details, and beneficiary information for current and former employees. Following the intrusion, the company initiated network and infrastructure rebuilding efforts while offering credit monitoring services to affected individuals despite no evidence of data misuse at the time of disclosure.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On September 28, 2020, USNR LLC, a Woodland, Washington-based manufacturing firm described as the world’s largest supplier of equipment for the wood processing industry, experienced a ransomware attack. The company first detected the intrusion nearly a month later, on October 25, indicating a prolonged period of undetected network access by the attackers. An investigation determined that the attackers encrypted files and potentially accessed sensitive personal information belonging to 3,950 current and former employees. The compromised data included names, addresses, dates of birth, Social Security numbers, and bank account information. Additionally, beneficiary information associated with employees—including beneficiaries’ names, addresses, dates of birth, and Social Security numbers—was exposed.

Cyber Incident Image

In response, USNR initiated a comprehensive rebuild of its internal network and infrastructure to mitigate further risks. The company stated it had no evidence of actual misuse of the stolen data but proactively offered credit monitoring and identity protection services through Equifax to affected individuals. Notification letters detailing the incident and the offered services were scheduled for distribution on December 7, 2020, over two months after the initial attack detection. The incident disrupted operations due to the encryption of files and necessitated significant remediation efforts to restore systems and secure compromised data. No information was disclosed regarding ransom demands, payment, or the specific ransomware variant involved.

Sources
Sources available to members
1 source