Deadlock, a ransomware crew that publishes in rare bursts rather than a steady drip, resurfaced on July 25 with ten new victims. The batch includes Kenya's national highways authority and a Finnish manufacturer of power systems for critical infrastructure, and it marks the first time the group has claimed a government body.
As with every leak site posting, these are unverified extortion claims made by the gang itself. None of the organizations named has confirmed an intrusion, and publishing a victim name is itself a pressure tactic, timed to force a response before any data appears.
Who the group named
The most significant entry is KeNHA, the Kenya National Highways Authority, the state agency responsible for building and maintaining the country's trunk road network. In IntelFusions incident data it is Deadlock's first public sector claim and only its second anywhere in Africa, after a Nigerian pension manager listed in June. Kenya has become a steady target for financially motivated crews, as tracked on our Kenya country profile.
The rest of the batch is industrial and mid-market European. It names Enedo Power, a Finnish builder of power supplies for critical infrastructure and industrial use that now trades as part of Sweden's Inission group; Carrier Transport AB, a Swedish transport and logistics firm near Stockholm; Hidromek, the Ankara based heavy construction machinery maker; CNA Toscana Centro, an Italian trade association serving artisans and small businesses in Prato and Pistoia; BioResearch, a Warsaw clinical research center that runs early phase and bioequivalence trials; and Schaad, Balass, Menzl and Partner AG, a Swiss intellectual property law boutique. Entries for firms in Chile, Argentina and the Baltics round out the list.
A crew that works in waves
Deadlock has appeared in our incident tracking since mid June and has accumulated 86 claims in that time, but almost never posts daily. It listed ten victims on June 15, then 65 in a single day on July 10, a surge we covered at the time, then one on July 12, and now ten more. That rhythm suggests the operation banks compromises and releases them in waves for maximum effect, which means an organization named this week was likely breached well before its name went up.
The geography is consistent too. Italy, Spain and Poland lead its victim list, and only three of its 86 claims are US organizations, an unusual profile among active crews and one that makes European industrial suppliers and professional services firms its centre of gravity. Full history sits on the Deadlock actor profile.
What to do if you are on the list
Organizations that find themselves named should assume data theft rather than encryption until they establish otherwise, since extortion only brands increasingly skip the encryptor. Preserve logs and forensic images before rebuilding anything, review remote access and identity provider activity for the weeks preceding the listing rather than just the last few days, and notify regulators on the clock that applies locally, which for the European victims here means the 72 hour GDPR window once a personal data breach is established. Suppliers and customers of the named firms should treat the listing as a prompt to check what data those partners hold on their behalf.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.