Netgroup’s Cybersecurity Observatory has noted the publication of a post by the Monti Ransomware Group regarding an alleged data theft against the Italian company: “Compagnia Trasporti Integrati S.R.L.”
Compagnia Trasporti Integrati S.r.l. (CTI) is an Italian transportation company based in Livorno, Italy. Founded in 1994, CTI offers a wide range of road freight transportation services, both nationally and internationally. The company specializes in the transportation of:
- Dangerous goods
- Pharmaceuticals
- Food commodities
- Industrial Components
- Other types of goods
No previous attacks against the said company are known from public sources. At the moment, the type and amount of data stolen is not yet known from the group’s DLS, nor is the amount of ransom.
Monti Ransomware is a cybercriminal group active since mid-2022. It positions itself as RaaS (Ransomware as a Service), offering its ransomware attack service to other criminals. The group mainly uses code from the Conti ransomware, which was leaked online in March 2022. The Monti group is known in that their attacks are primarily targeted at Italian organizations, with a focus on sectors such as legal and government.
The group’s modus operandi is to infiltrate victims’ computer systems, steal sensitive data (such as medical records or financial information) and encrypt it.
Then, the criminals demand a ransom to decrypt the data, threatening to publicly disclose it if not paid.
Monti is also known for his double extortion tactics, in which he publishes the stolen data even if the victim pays the ransom.
Monti poses a serious cybersecurity threat, especially to Italian organizations. Their aggressive attack tactics and propensity for double extortion make them a dangerous adversary. It is important for companies to take appropriate security measures to protect themselves from these types of attacks.
