Maze Ransomware

French construction giant Bouygues Construction shut down their computer network to avoid having all of their data encrypted by the Maze Ransomware.

In a statement posted to their website, Bouygues stated that they shut down their computer network on January 30th, 2020, as a "precautionary measure" to prevent a ransomware attack from propagating further.

The company's full statement can be read below.

"A ransomware-type virus was detected on Bouygues Construction’s computer network on 30 January.

As a precautionary measure, information systems have been shut down to prevent any propagation.

Our teams are currently fully focused on returning to normal as quickly as possible, with the support of experts.

Installations are progressively being put back into service after being tested.

Operational activity on our construction sites has not been disrupted to date.

All our personnel are working flat out to ensure that our operations continue as smoothly as possible under these conditions, so that impact on our customers and partners is minimised. We are in close contact with them and with the relevant authorities.

The Group will issue a further update early next week."

According to the Maze Ransomware operators, they are responsible for this attack and state that they encrypted 237 computers. In addition, the ransomware operators claim to have encrypted over 1,000 Terabytes of data.

As the Maze Ransomware operators are known to steal a victim's data before encrypting the computers, the threat actors will likely try to extort Bouygues Construction by threatening to publicly release their data unless a ransom is paid.

Unfortunately, Maze Ransomware has followed through in the past with these threats.

It is not known at this time how much data, if any, was stolen from Bouygues Construction. 

It is good, though, that the company is being transparent about the attack and, due to the likelihood that their data was stolen, should treat this as a data breach of their company's, vendors', and employees' data.

BleepingComputer has contacted Bouygues Construction with questions, but have not heard back at this time.

Related Articles:

Lockean multi-ransomware affiliates linked to attacks on French orgs

Italian celebs' data exposed in ransomware attack on SIAE

Australia to tackle ransomware data breaches by deleting stolen files

Ransomware gang hacks Ecuador's largest private bank, Ministry of Finance

SnapMC hackers skip file encryption and just steal your files