Menu
Browse

Cyber Incident Victim: D-Box Technologies

Date:

Jul 2021

Location:

Canada

Summary

D-Box Technologies experienced a ransomware attack that encrypted data across most of its systems, significantly disrupting business operations for multiple days with potential prolonged recovery. The incident occurred after business hours and was detected immediately, prompting containment measures and engagement of independent cybersecurity experts to mitigate impacts. While no customer data compromise was identified due to the company's business-focused clientele, some employee personal information may have been affected, with plans to address potential impacts if confirmed. Operations faced substantial adverse effects during recovery efforts.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On July 12, 2021, after the close of business, D-Box Technologies experienced a ransomware attack targeting its information technology systems. The attack involved malware that encrypted electronic data stored on the corporation’s network, rendering it unreadable and unusable. D-Box detected the intrusion on the same day it occurred and immediately initiated containment measures to mitigate potential impacts on data and operations. The company began recovery processes but confirmed the attack affected most of its systems, anticipating business operations would be adversely disrupted for several days or longer depending on data restoration and system recovery timelines. An investigation into the full scope of the incident was ongoing at the time of the July 16, 2021, public disclosure, with no conclusive evidence yet found regarding data exfiltration or the specific ransomware variant used.

Cyber Incident Image

D-Box stated there was no indication that customer personal information was compromised, noting its client base primarily consists of businesses that generally do not provide personal data to the corporation. However, the company acknowledged some employee personal information might have been accessed or exposed during the attack and committed to implementing measures to minimize impacts on affected individuals if confirmed. Independent cybersecurity experts were engaged to assist with the response, following industry best practices for incident management. The corporation emphasized operational disruptions but did not specify which systems or departments were most severely affected beyond the broad impact on "most of its systems." Recovery efforts focused on restoring encrypted data and regaining full system functionality, though no definitive timeline for complete resolution was provided in the initial disclosure.

Sources
Sources available to members
1 source