Infrastructure Manufacturer - Unit 42 IR Case Study
Learn how a manufacturer cut a ransom demand by 73%. This case study follows a U.S. infrastructure equipment manufacturer through simultaneous Black Basta and LockBit ransomware attacks. Unit 42 Incident Response identified the compromised contractor VPN account behind the breach, blocked known IoCs with Cortex XDR®, and restored operations within 12 days. Coverage later expanded to 100% of endpoints. Read the story to learn from this manufacturer's experience.
What happened during the dual ransomware attacks?
The manufacturer was hit by two coordinated ransomware campaigns, first by LockBit and then by Black Basta. The attackers followed a similar pattern in both cases:
- Initial access: Unit 42 traced the entry point to a compromised contractor VPN account that did not have MFA enabled.
- Data theft before encryption: The adversaries exfiltrated approximately 3 TB of sensitive data before triggering file encryption.
- Operational disruption: Within 24 hours, ransomware was detonated, encrypting critical files and impacting at least 20 systems with file encryption and another 80 systems where attacker tools were present.
The result was a serious risk to financial performance, day-to-day operations, and brand reputation. The company faced ransom demands and the threat of data exposure, while needing to restore production and protect its customers and partners.
How did Unit 42 contain and resolve the ransomware incidents?
Unit 42 applied a structured, threat-informed incident response approach that moved through four main phases: Assess, Secure, Recover, and Transform.
1. Assess (Days 0–4)
- Performed rapid crisis intervention and initial scoping.
- Analyzed firewall and VPN logs to understand how the attackers got in.
- Used Cortex Xpanse to map the external attack surface and identify vulnerabilities.
2. Secure (Days 5–7)
- Confirmed Black Basta as one of the ransomware families involved.
- Identified the contractor VPN account without MFA as the initial access point.
- Determined that 3 TB of data had been exfiltrated.
- Began direct threat actor negotiations to manage ransom and data exposure risk.
3. Recover (Days 8–14)
- Blocked ransomware indicators of compromise (IoCs) using Cortex XDR.
- Initiated 24/7 threat monitoring to stop further lateral movement.
- Uncovered earlier impact and data theft by LockBit in addition to Black Basta.
- Rebuilt affected systems and restored data from backups.
- Helped the client regain operational capacity within 12 days.
4. Transform (Days 15–30)
- Expanded Cortex XDR coverage from 70% to 100% of endpoints for full visibility.
- Implemented enhanced firewall rules to block known IoCs.
- Continued 24/7 monitoring through Unit 42 MDR and proactive threat hunting.
- Provided guidance to strengthen long-term resilience against future attacks.
This end-to-end approach not only contained and remediated the incidents but also helped the manufacturer reimagine its security posture for ongoing protection.
What business outcomes did the manufacturer achieve with Unit 42?
By partnering with Unit 42, the manufacturer was able to limit damage, restore operations, and strengthen its security posture with clear, measurable results:
- Ransom cost reduction: Through expert negotiation with the attackers, Unit 42 achieved a 73% reduction in the ransom demand.
- Data exposure prevented: Negotiations with LockBit helped prevent 2.5 million files from being exposed.
- Faster operational recovery: Systems were decrypted, rebuilt, and data was restored from backups, enabling the company to regain operational capacity within 12 days.
- Improved endpoint coverage: Cortex XDR coverage increased from 70% to 100% of endpoints, closing visibility gaps.
- Continuous protection: The organization now benefits from 24/7 threat monitoring and ongoing threat hunting via Unit 42 MDR.
Backed by Palo Alto Networks technology, extensive threat intelligence, and a team that handles over 1,000 incidents per year, the manufacturer was able to not only recover from the dual ransomware attacks but also rethink and strengthen its long-term security strategy.