2023 ABB — Black Basta ransomware; Active Directory and factory disruptions; confirmed data theft
Data compromised
Corporate documents and system exports per vendor allusion to stolen data—no unified PII count in first wave
Technical writeup
Swiss-Swedish industrial technology group ABB confirmed a May 2023 ransomware intrusion tied in press to the Black Basta affiliate ecosystem, describing compromised Windows Active Directory assets, temporary VPN disconnects for customers as containment, stalled plant functions, and verified exfiltration of unspecified corporate data while maintaining that customer OT product security was not directly breached in vendor quotes relayed by BleepingComputer and SC Media.
Root cause
Human-operated ransomware deployment and AD-centric lateral movement