Breach taxonomy
Summary
On November 25, 2024, ENGlobal Corporation became aware of a cybersecurity incident in which a threat actor illegally accessed the company's IT systems and encrypted some data files. The company immediately restricted IT system access to essential business operations and engaged external cybersecurity specialists for investigation and remediation. As of the filing date, full access to IT systems had not been restored and materiality had not been determined.
Tagging rationale
ThreatUnknown
Filing refers to 'a threat actor' without attributing the incident to a specific actor category -> UNKNOWN.
MethodsRansomware
Filing explicitly states 'a threat actor illegally accessed the Company's information technology system and encrypted some of its data files' -> RANSOMWARE.