Ransomware

WestRock Ransomware Attack (OT/Manufacturing Systems Disrupted)

πŸ“… 2021-01-23
Primary Source β†—

Incident Details

WestRock Company, one of the largest corrugated packaging and paperboard manufacturers in the world, disclosed on January 25, 2021 that it had suffered a ransomware attack on approximately January 23, 2021 that affected both its IT and OT (operational technology) systems. The attack disrupted the company’s manufacturing and distribution operations across multiple facilities. WestRock disclosed the incident in an SEC 8-K filing and in a quarterly earnings call, noting the ransomware had impacted some of its operational technology systems (which control manufacturing equipment). The company estimated the financial impact at approximately $170 million in lost revenue and incremental costs, making it one of the costlier ransomware incidents in the manufacturing sector. WestRock was slow to restore full operations at some facilities. The incident was notable because it was one of relatively few confirmed cases where ransomware directly impacted OT/manufacturing systems (not just IT), causing physical production line shutdowns β€” echoing concerns about IT/OT convergence security risks. The specific ransomware group responsible was not publicly attributed.

Technical Details

Initial Attack Vector
Ransomware attackers penetrated WestRock's network and deployed ransomware that affected both IT systems and operational technology (OT) systems, including manufacturing and operational systems at packaging production facilities

Timeline

  1. 2021-01-23 Breach occurred
  2. 2021-01-25 Publicly disclosed
  3. 2021-01-25 Customers notified