Menu
Browse

Cyber Incident Victim: Marketron

Date:

Sep 2021

Location:

United States of America

Summary

Marketron, a media industry software provider serving over 6,000 customers, suffered a ransomware attack by the BlackMatter gang, which disrupted critical services including Traffic, Visual Traffic Cloud, Exchange, and Advertiser Portal platforms. The company preemptively took additional systems offline despite some remaining operational, while third-party investigators and the FBI assisted in the ongoing response. Despite recent cybersecurity enhancements like zero-trust protocols and isolated backup environments, the breach's root cause remained undetermined. BlackMatter, linked to the DarkSide operation behind the Colonial Pipeline incident, targeted multiple organizations globally, with the attackers communicating directly with the victim during the event.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On September 19-20, 2021, the BlackMatter ransomware gang breached Marketron, a provider of cloud-based revenue and traffic management software serving over 6,000 media industry clients handling $5 billion in annual advertising revenue. Marketron CEO Jim Howard notified customers via email on Sunday night, September 19, attributing the attack to a "Russian criminal organization" and apologizing for the disruption despite recent cybersecurity investments. These included implementing zero-trust access policies, segregating backup and disaster recovery systems across separate physical and network environments, and deploying new security detection tools. The company immediately engaged with the attackers and contacted the FBI while prioritizing system restoration efforts.

Cyber Incident Image

By Monday, September 20, Marketron publicly confirmed a "cyber event" had disrupted core business operations, forcing all services offline except Pitch, Email Marketing, and Mobile Messaging. Impacted platforms included Marketron Traffic, Visual Traffic Cloud, Exchange, and the Advertiser Portal. RadioTraffic and RepPak services remained operational initially but were proactively taken offline as a precaution. Third-party forensic investigators were brought in to determine the root cause, though Marketron VP of Marketing Bo Bandy stated the investigation remained ongoing with no confirmed breach methodology. The incident affected all customers, halting critical revenue management and audience engagement tools for broadcast and media organizations. BlackMatter, identified as a likely rebrand of the DarkSide ransomware operation responsible for the Colonial Pipeline attack, claimed responsibility amid a string of September 2021 breaches targeting global organizations across agriculture, finance, manufacturing, and technology sectors.

Sources
Sources available to members
1 source