Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Application Security

Military Vehicles Maker Navistar Reports Data-Theft Cyberattack

United States trucks and military vehicles maker Navistar International Corporation has confirmed a cyberattack that resulted in some data being stolen.

United States trucks and military vehicles maker Navistar International Corporation has confirmed a cyberattack that resulted in some data being stolen.

On Monday, in a Form 8-K filing with the Securities and Exchange Commission (SEC), Navistar said it learned of a credible potential cybersecurity threat to its information technology system on May 20, 2021.

Navistar immediately took the necessary measures to contain and mitigate the impact of the incident, and also launched an investigation into the matter, engaging with security and forensics experts.

The company also took steps to strengthen the security of its IT infrastructure and protect the data contained therein, and says that its systems have remained fully operational.

However, on May 31, Navistar “received a claim that certain data had been extracted from” its network.

The company continues to investigate “and address the scope and impact of the cybersecurity incident” and has already contacted law enforcement on the issue.

Navistar did not provide technical details on the incident, but there is a possibility that ransomware might have been involved, considering the rising number of ransomware incidents observed in recent months in which attackers stole victim data to use it as leverage.

Created in 1986, Navistar makes trucks, buses and diesel engines, while its Navistar Defense subsidiary produces military vehicles.

Advertisement. Scroll to continue reading.

Following a ransomware attack that forced Colonial Pipeline to shut down distribution systems at the beginning of May, JBS USA, the US subsidiary of the world’s largest meat processing company, announced last week that it too suspended operations in America and Australia.

Also last week, Steamship Authority, the largest ferry service to the Massachusetts Islands of Martha’s Vineyard and Nantucket from Cape Cod, was hit with a similar attack. Earlier this year, Molson Coors Beverage Company fell victim to ransomware.

Related: White House Urges Private Sector to Help in Ransomware Fight

Related: CISOs Blame Cyberattack Surge on Remote Working: VMware

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Gain valuable insights from industry professionals who will help guide you through the intricacies of industrial cybersecurity.

Register

Join us for an in depth exploration of the critical nature of software and vendor supply chain security issues with a focus on understanding how attacks against identity infrastructure come with major cascading effects.

Register

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Vulnerabilities

Less than a week after announcing that it would suspended service indefinitely due to a conflict with an (at the time) unnamed security researcher...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Identity & Access

Zero trust is not a replacement for identity and access management (IAM), but is the extension of IAM principles from people to everyone and...

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Data Breaches

OpenAI has confirmed a ChatGPT data breach on the same day a security firm reported seeing the use of a component affected by an...

Artificial Intelligence

The CRYSTALS-Kyber public-key encryption and key encapsulation mechanism recommended by NIST for post-quantum cryptography has been broken using AI combined with side channel attacks.