Cyber Incident at Norrcom: Understanding the Lamberts Breach
Overview of the Cyber Incident
Norrcom, the parent company of Lamberts Business Systems, has publicly acknowledged a cyber security incident that resulted in significant operational disruptions. The firm promptly took systems offline as a precautionary measure to contain the situation. In a recent statement, Norrcom reached out to stakeholders, highlighting their swift response to ensure the integrity and security of affected systems.
Responding to the Threat
Norrcom’s response protocol was activated immediately upon discovery of the incident. The company has been working closely with external experts to assess and resolve the security threats posed to the Lamberts division. In their communication, they also mentioned that certain data related to Lamberts and its clients may have been accessed by unauthorized third parties.
Engagement with Affected Parties
In light of the ongoing investigation, Norrcom is taking proactive measures by engaging directly with clients who may have been impacted. They are committed to maintaining transparency and providing updates as more information becomes available.
The Involvement of the INC Ransom Gang
Norrcom’s breach appears to be linked to the notorious INC ransomware gang, which has gained a reputation for their aggressive hacking techniques. Recently, the group displayed Lamberts Business Systems on their dark web leak site, further raising concerns about potential data exposure.
Allegations of Data Exfiltration
While the exact details of the breach remain undisclosed, INC Ransom has shared a sample of allegedly exfiltrated data to support their claims. This sample reportedly includes sensitive information such as marketing documents, administrative paperwork, employee data, financial records, and even personal items like passports and photographs. The folders revealed in the sample imply a serious infiltration of confidential company data.
Clarifying the Scope of the Breach
It is important to note that Norrcom has stated that the breach specifically affected Lamberts systems, asserting that their core systems remained uncompromised. This clarification is vital for stakeholders, as it mitigates broader concerns regarding the overall security posture of the parent company.
Reassuring Stakeholders
Norrcom has conveyed its understanding of the anxiety this news may cause among clients and partners. The company emphasized that, as of now, they have found no evidence suggesting an extensive impact on their network. They are actively following procedures to inform the applicable government entities about the incident, underlining their commitment to compliance and transparency.
Past Activities of the INC Ransom Gang
The INC ransomware group is not new to the cyber crime landscape. They have targeted several organizations in Australia and New Zealand, including a recent breach of the Waiwhetu Medical Centre in Wellington. In June, the hackers claimed to have stolen a staggering 110 gigabytes of sensitive data, including contracts and human resources material. This data was subsequently verified when released to the public.
Noteworthy Attacks
In addition to Waiwhetu, INC Ransom has previously hacked multiple organizations, such as Expert Data Cabling and Spectrum Medical Imaging. The latter incident resulted in the exposure of patient data, prompting ongoing communications with affected patients.
Understanding INC Ransom’s Tactics
Emerging in August 2023, INC Ransom has been linked to attacks on over 330 organizations, demonstrating their growing influence and capacity for disruption. The gang typically employs spear phishing techniques to gain initial access to their targets. Once inside, they utilize double-extortion tactics, encrypting stolen data while also threatening to make it public unless a ransom is paid. This approach adds an unsettling layer of pressure on victims, who must navigate the complex landscape of cyber security threats and potential reputational damage.
As organizations like Norrcom navigate the challenges posed by cyber threats, the importance of robust security measures and incident response strategies remains paramount. Stakeholders in the digital landscape must remain vigilant, ensuring that cybersecurity protocols are not just in place but continually updated in response to evolving threats.


