Ransomware – Danish Agro
Company
Danish Agro
Sector
Agriculture / Food
##Description
Ransomware was detonated across the Danish Agro group on 19 April 2020, encrypting around 350 servers and affecting roughly 2,500 IT users. The attackers entered through a foreign supplier whose systems they had taken over, then delivered a phishing email into Danish Agro's environment.
Production and delivery of feed, crop protection products, fertiliser and seed were partially disrupted, creating ordering and delivery problems across several group companies.
The attackers demanded an eight-figure DKK sum. Danish Agro refused to pay and rebuilt instead: around 30 internal IT staff plus 20–30 external consultants worked the incident around the clock for five weeks. The company was at roughly 90% normal IT operations by July 2020. Direct cost was reported at more than 10 million DKK, excluding thousands of internal work hours.
A clean example of supplier-mediated initial access and of a successful refuse-and-rebuild decision.
##Timeline
- 2020-04-19
Ransomware detonated across ~350 servers
- 2020-04 to 2020-05
Five weeks of 24/7 recovery work
- 2020-07
Approximately 90% of normal IT operations restored