JBS Hack Explained | REvil Ransomware Cyberattack – Cyberattack Forces JBS to Shut Down Operations

Опубликовано: 20 Май 2026
на канале: CSI digital
3,262
72

JBS Hack Explained | REvil Ransomware Cyberattack – Cyberattack Forces Meat Producer to Shut Down Operations

=================
Update June 11, 2021:
The REvil ransomware gang was paid $11M in ransom by JBS. The hack by REvil caused JBS, a multinational supplier of beef, chicken, and pork, to shut down a portion of its operations in the U.S. and Australia over Memorial Day weekend.
=====================

In this episode we are going to talk about the JBS USA Holdings, Inc. Ransomware attack, learn how these types of attacks work and how we can protect ourselves and our clients from these types of attacks. In case you are not familiar with them JBS USA Holdings, Inc. is an American food processing company and a wholly owned subsidiary of JBS S.A., a Brazilian company that is the world's largest processor of fresh beef and pork, with more than US$50 billion in annual sales as of 2017. The subsidiary was created when JBS entered the U.S. market in 2007 with its purchase of Swift & Company. JBS provides roughly 25% of Americas meat.

How did JBS get hacked?
The JBS attackers targeted several servers supporting North American and Australian IT systems of JBS Foods on Sunday, according to a statement by JBS USA.

Who is REvil Cyber gang AKA Sodinokibi?
Four people familiar with the matter who weren’t authorized to speak publicly told Bloomberg that the notorious Russia-linked hacking group is behind the attack against JBS SA. The REvil cyber gang also goes by the name Sodinokibi.
REvil is known for both audacious attacks on the world’s biggest organizations and suitably astronomical ransoms. In April, it put the squeeze on Apple just hours before its splashy new product launch, demanding a whopping $50 million extortion fee: a bold move, even for the notorious ransomware-as-a-service (RaaS) gang. The original attack was launched against Quanta, a Global Fortune 500 manufacturer of electronics, which claims Apple among its customers. The Taiwanese-based company was contracted to assemble Apple products, including Apple Watch, Apple Macbook Air and Pro, and ThinkPad, from an Apple-provided set of design schematics.

JBS Ransomware attack response.
Upon discovering the incident—the nature of which was not specified–“the company took immediate action, suspending all affected systems, notifying authorities and activating the company’s global network of IT professionals and third-party experts to resolve the situation,” according to the statement.

JBS’s IT system does have backup servers, which were not affected, and the company is working with a third-party incident-response firm to restore operations as soon as possible, according to the statement.
The White House has offered assistance to JBS: Its team and the Department of Agriculture have spoken to the company’s leadership several times since Sunday’s attack, Jean-Pierre said. As well, the FBI is investigating the incident in coordination with the Cybersecurity and Infrastructure Security Agency (CISA) to offer technical support to the company as it pulls itself back into production.


How does a ransomware attack work?
Wikipedia:
Ransomware is a type of malware from cryptovirology that threatens to publish the victim's data or perpetually block access to it unless a ransom is paid. While some simple ransomware may lock the system so that it is not difficult for a knowledgeable person to reverse, more advanced malware uses a technique called cryptoviral extortion. It encrypts the victim's files, making them inaccessible, and demands a ransom payment to decrypt them. In a properly implemented cryptoviral extortion attack, recovering the files without the decryption key is an intractable problem – and difficult to trace digital currencies such as paysafecard or Bitcoin and other cryptocurrencies are used for the ransoms, making tracing and prosecuting the perpetrators difficult.
Ransomware attacks are typically carried out using a Trojan disguised as a legitimate file that the user is tricked into downloading or opening when it arrives as an email attachment. However, one high-profile example, the WannaCry worm, traveled automatically between computers without user interaction.

How does ransomware infect?
Ransomware is often spread through phishing emails that contain malicious attachments or through drive-by downloading. Drive-by downloading occurs when a user unknowingly visits an infected website and then malware is downloaded and installed without the user's knowledge.


Should you pay a ransomware attack?
The FBI's official statement on ransomware advises victims not to pay the ransom. There is no guarantee that the hackers will restore your information. Worse, it could put a target on your back if your business is seen as unprepared to handle cyber attacks and willing to pay the ransom.





#revil #REvilcybergang #jbsransomwar #rootkit #CyberSecurity #ransomware