ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Engineering firm McDowall Affleck targeted by ransomware group RansomHub

McDowall Affleck, an Australian engineering firm, has confirmed being the target of a cyberattack attributed to the ransomware group RansomHub. The attack, disclosed on August 1, 2024, involves the alleged exfiltration of 470 GB of sensitive internal data.

 

RansomHub, known for high-profile ransomware attacks, has claimed responsibility for the breach. Details of the attack were published on a dark web site associated with the group, revealing that the stolen data includes critical documents, insurance records, tender and contract details, and personal information of employees and clients. RansomHub has threatened to release this data publicly within 4-5 days if their demands are unmet.

The cyberattack details were outlined on RansomHub’s darknet site, mentioning the URL “mcdowallaffleck.com.au” and confirming the data size. The page noted 11 visits, with the last view recorded on August 1, 2024, at 10:31:02, and a countdown timer indicating the imminent threat of data release.

 

In response to the incident, a McDowall Affleck spokesperson told The Cyber Express, “McDowall Affleck recently experienced a cyber incident. As soon as we detected the issue, we immediately secured our systems. We engaged forensic experts to investigate the breach and ensure our systems are operational and secure.” The spokesperson emphasized the company’s commitment to protecting employees’ and clients’ information and noted that the firm has reached out to affected parties with guidance on securing their information.

 

The spokesperson added, “We have reported the incident to the Australian Cyber Security Centre (ACSC) and WA Police and are cooperating fully with law enforcement and privacy regulators.”

 

RansomHub, believed to be an evolved variant of the Knight ransomware and linked to the ALPHV group, operates using a Ransomware-as-a-Service model. The group exploits vulnerabilities like Zerologon to gain access, then encrypts data and demands a ransom, threatening to leak sensitive information if their demands are unmet. RansomHub has previously targeted high-profile organizations, including Christie’s, the renowned auction house.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543