RansomHub Threatens Major Mexican Airport

RansomHub has emerged as a significant ransomware threat, targeting OMA with demands for sensitive data release. The group exploits vulnerabilities in critical infrastructures, raising alarms in cybersecurity. Experts recommend mitigation strategies as ransom demands escalate.


RansomHub Threatens Major Mexican Airport

The RansomHub ransomware group has positioned itself as one of the most dangerous globally. The Brazilian company YKP was its first known victim, and in less than a year, they have attacked at least 190 global organizations, including the National Autonomous University of Mexico (UNAM), by encrypting the information of more than 37,000 users and demanding a ransom for its release. They operate under the Ransomware-as-a-Service (RaaS) model, where affiliates can use their tools in exchange for a percentage of the ransom. This system has allowed them to rapidly expand their operations and has made them one of the most active groups in the cybercrime network.

The current situation of RansomHub is critical, as they have threatened to disclose confidential information from the Central North Airport Group (OMA), including evidence of collaboration with drug cartels in Mexico if they do not receive the requested ransom before November 2, 2024. The leaked documents include financial data, internal communications, and critical databases, demonstrating the deep access they have achieved within OMA's infrastructure.

Taking advantage of the disruption of the LockBit group in February 2024, RansomHub gained strength by absorbing affiliates from that group. RansomHub has proven to be a global actor in cybercrime, attacking everyone from large corporations to educational institutions and healthcare entities with ransom demands that can reach enormous sums. Despite their global reach, they avoid attacking organizations from certain countries and non-profit entities.

Cybersecurity experts like Víctor Ruiz have recommended that OMA focus on mitigation strategies instead of yielding to RansomHub's extortion. The effectiveness and danger of RansomHub have been confirmed by their cyberattacks on strategic sectors, suggesting that they represent a real and unrestricted threat. The increase in ransomware attacks in Mexico, with groups like RansomHub at the forefront, demands strong responses and effective cybersecurity strategies to protect critical infrastructures.