Security

Cyber-crime

US construction giant unearths concrete evidence of cyberattack

Simpson Manufacturing yanks systems offline, warns of ongoing disruption


Simpson Manufacturing Company yanked some tech systems offline this week to contain a cyberattack it expects will "continue to cause disruption."

The California-headquartered engineering biz, which produces wood and concrete construction products designed make structures more safe, confirmed the digital assault on the same day it was spotted.

"On October 10, 2023, Simpson Manufacturing Co., Inc. experienced disruptions in its Information Technology (IT) infrastructure and applications resulting from a cybersecurity incident," it states in an SEC filing [PDF].

"After becoming aware of the malicious activity, the Company began taking steps to stop and remediate the activity, including taking certain systems offline. The Company is working diligently to respond to and address this issue. The incident has caused, and is expected to continue to cause, disruption to parts of the Company's business operations."

The statement indicates a possible ransomware infection that the business is endeavoring to overcome but this remains unconfirmed at the time of writing. It is certainly a rich target for criminals, operating multiple research labs and holding thousands of patents and trademarks.

It employs more than 5,000 people across global operations, has a market capitalization of $6.1 billion, and turned over more than $2.1 billion in sales in the last full calendar year. The majority of its products are made in the US but some are produced in Europe, Canada, and Asia.

As is typical in these situations, Simpson Manufacturing has brought in third-party specialists to "support its investigation and recovery efforts." It added: "The investigation to assess the nature and scope of the incident remains ongoing and is in its early stages."

For years it seemed as though the construction industry was "immune" to security attacks, according to a research paper [PDF] by the Association of General Construction of America in 2021. Yet that "perspective no longer carries weight" and the sector in general is now "one of the leading industries impacted by data security incidents."

Why? "Threat actors know that the construction industry is in some areas behind in data security and privacy initiatives. This is in large part because this industry, to date, avoided heavy regulation in data security and privacy laws. The limited regulation and guidance in the construction industry may have contributed to less focus on cyber security than in other industries."

Many construction businesses are also using machine learning and robotics more, which poses a potential risk. "These new technologies still require data security and privacy risk assessments and proper controls in place, something that may be a second thought for those in the construction industry that may not have historically had cybersecurity top of mind."

Last but by no means least, the sector is a "big, lucrative target."

"The exposure of cyberattacks in construction, in part, is amplified by the amount of confidential and proprietary information digitally stored and shared across projects and their long information technology chains," the reports adds. "Infrastructure, financial accounts, as well as the data of employees, projects, and business sensitive information may be at risk. Accordingly, the number of cyber security attacks in the construction industry are growing exponentially."

The Register asked Simpson Manufacturing to comment. ®

Send us news
11 Comments

2.5M patients infected with data loss in Norton Healthcare ransomware outbreak

AlphV lays claims to the intrusion

Scores of US credit unions offline after ransomware infects backend cloud outfit

Supply chain attacks: The gift that keeps on giving

Five Eyes nations warn Moscow's mates at the Star Blizzard gang have new phishing targets

The Russians are coming! Err, they've already infiltrated UK, US inboxes

Uncle Sam probes cyberattack on Pennsylvania water system by suspected Iranian crew

CISA calls for stronger IT defenses as Texas district also hit by ransomware crew

Leader of pro-Russia DDoS crew Killnet 'unmasked' by Russian state media

Also: NXP China attack, Australia can't deliver on ransom payment ban (yet), and Justin Sun's very bad month

Black Basta ransomware operation nets over $100M from victims in less than two years

Assumed Conti offshoot averages 7 figures for each successful attack but may have issues with, er, 'closing deals'

BlackCat ransomware crims threaten to directly extort victim's customers

Accounting software firm Tipalti says it’s investigating alleged break-in of its systems

Europol shutters ransomware operation with kingpin arrests

A few low-level stragglers remain on the loose, but biggest fish have been hooked

Fancy Bear goes phishing in US, European high-value networks

GRU-linked crew going after our code warns Microsoft - Outlook not good

US readies prison cell for another Russian Trickbot developer

Hunt continues for the other elusive high-ranking members

Hershey phishes! Crooks snarf chocolate lovers' creds

Stealing Kit Kat maker's data?! Give me a break

Interpol moves against human traffickers who enslave people to scam you online

Scum lure folks with promises of good jobs in crypto and then won't let them leave