CSIDB logo
Incident

SHI International

Incident posture

Attack window
Jul 2022
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-18 00:00

Linked entities

Victim
SHI International
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

SHI International experienced a coordinated malware attack that prompted swift containment efforts by its security and IT teams, leading to minimized operational impact. The company took affected systems offline, including public websites and email services, causing temporary access disruptions and maintenance notifications; email functionality was restored shortly thereafter while other systems remained under recovery. Ongoing investigations involving federal agencies found no evidence of customer data exfiltration or compromise to third-party supply chain systems.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

SHI International, a major New Jersey-based IT solutions provider with $12.3 billion in 2021 revenue and global operations, experienced a significant cybersecurity incident during the Fourth of July holiday weekend in 2022. The company characterized the event as a "coordinated and professional malware attack" targeting its network. SHI's security and IT teams swiftly identified the intrusion and implemented containment measures to limit operational disruption. Immediate consequences included the voluntary shutdown of critical systems, including public-facing websites and email servers, to isolate the threat and preserve system integrity. Customers visiting SHI's website encountered initial notifications referencing a "sustained outage" for maintenance, later updated to an official malware attack disclosure on the corporate blog. Technical disruptions persisted post-attack, with some web pages generating Amazon CloudFront/S3 errors indicative of underlying infrastructure issues.

The company initiated comprehensive system integrity assessments and a formal investigation while coordinating with federal authorities including the FBI and CISA. Restoration efforts commenced promptly, with email servers fully reactivated by Wednesday morning following the holiday weekend. IT personnel prioritized bringing additional affected systems back online while maintaining security protocols. SHI publicly confirmed no evidence of customer data exfiltration during the breach and emphasized that third-party supply chain systems remained unaffected throughout the incident. Operational impacts were confined to SHI's internal infrastructure, with the organization committing to ongoing customer updates throughout the recovery and investigation processes. The incident response highlighted the company's focus on containment and restoration while maintaining transparency regarding attack characteristics and remediation progress.

Sources

Sources available to members: 1 source.

CSIDB